Best Incident Response Software - Page 3

How Many Incident Response Software Products Does G2 Track?

Total Products under this Category: 109

Category Stats (Sep 2026)

  • Average Rating: 4.48/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: ReliaQuest GreyMatter (+1.61%) - Among all products in this category, ReliaQuest GreyMatter recorded the largest rating increase compared to last month

Last updated: September 05, 2026

How Does G2 Rank Incident Response Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,500+ Authentic Reviews
  • 109+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Incident Response Software

G2 Grid® for Incident Response Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, KnowBe4 PhishER/PhishER Plus, Torq AI SOC Platform, Tines Stories, SentinelOne Singularity Endpoint, Cynet, Palo Alto Cortex XSIAM, and Microsoft Sentinel.

Underlying data: [Grid® JSON](https://www.g2.com/categories/incident-response/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=knowbe4-phisher-phisher-plus&focus%5B%5D=torq-ai-soc-platform&focus%5B%5D=tines-stories&focus%5B%5D=sentinelone-singularity-endpoint&focus%5B%5D=cynet&focus%5B%5D=palo-alto-cortex-xsiam&focus%5B%5D=microsoft-sentinel)

Splunk Synthetic Monitoring

Splunk Synthetic Monitoring helps you measure and improve uptime and performance for your critical apps and services. Splunk Synthetic Monitoring offers best-in class web performance optimization to delight your users and improve customer experience, while helping improve your SLAs and easily test your entire user funnel and key web and API functionality.

Average Rating: 4.5/5.0

Total Reviews: 26

How Do G2 Users Rate Splunk Synthetic Monitoring?

  • Threat Intelligence: 8.1/10 (Category avg: 8.9/10)
  • Quality of Support: 9.2/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.1/10 (Category avg: 8.5/10)
  • Incident Logs: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Splunk Synthetic Monitoring?

  • Seller: Cisco
  • Year Founded: 1984
  • HQ Location: San Jose, CA
  • Twitter: @Cisco
    720,366 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    95,294 employees on LinkedIn®
  • Ownership: NASDAQ:CSCO

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 50% Large, 38% Small

What Are Recent G2 Reviews of Splunk Synthetic Monitoring?

SIRP

SIRP is an AI-native Autonomous SOC platform designed to evolve traditional Security Orchestration, Automation, and Response (SOAR) into governed, decision-driven security operations. Unlike legacy SOAR tools that rely on static playbooks and workflow automation, SIRP enables intelligent AI agents to analyze alerts, compute risk, execute response actions, and continuously learn from outcomes within defined policy boundaries. The platform combines contextual reasoning, real-time intelligence, and adaptive learning to reduce manual triage, minimize alert fatigue, and accelerate incident response while maintaining governance, auditability, and control. SIRP supports enterprise SOC teams and MSSPs seeking to operate at machine speed without sacrificing human oversight for high-impact decisions.

Average Rating: 4.7/5.0

Total Reviews: 22

How Do G2 Users Rate SIRP?

  • Threat Intelligence: 9.8/10 (Category avg: 8.9/10)
  • Quality of Support: 9.8/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.8/10 (Category avg: 8.5/10)
  • Incident Logs: 9.5/10 (Category avg: 8.8/10)

Who Is the Company Behind SIRP?

  • Seller: SIRP
  • Year Founded: 2017
  • HQ Location: Bethesda, Maryland
  • Twitter: @sirp_io
    74 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    55 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 41% Small, 37% Medium

What Do G2 Reviewers Say About SIRP?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the comprehensive automation features of SIRP, enhancing their security orchestration and incident management efficiency.
  • Users value the excellent customer support from SIRP, enhancing their overall experience with the product.
  • Users praise SIRP for its ease of use, making security automation and incident management seamless and efficient.
  • Users value the easy integrations offered by SIRP, enhancing their security automation and orchestration experience.
  • Users praise SIRP for its ease of use and excellent support, along with comprehensive security features and integrations.

What Are Recent G2 Reviews of SIRP?

OpenCTI by Filigran

OpenCTI is an open-source threat intelligence platform designed to help users manage and operationalize threat intelligence effectively. Built by practitioners for practitioners, OpenCTI aims to break down data silos and ensure that threat intelligence is not only accessible but also actionable. This platform facilitates the seamless flow of threat intelligence across various security systems, making it relevant by integrating business context and enabling the creation of comprehensive threat exposure reports for enhanced executive visibility. The target audience for OpenCTI includes cybersecurity professionals, threat analysts, and organizations looking to improve their threat intelligence capabilities. By providing a centralized platform for threat data, OpenCTI allows users to visualize, link, and enrich threat intelligence, fostering collaboration among teams and enhancing the overall security posture of an organization. The platform is particularly beneficial for organizations that need to streamline their threat intelligence processes and ensure that critical information is readily available to decision-makers. Key features of OpenCTI include its unified and consistent data model based on the Structured Threat Information Expression (STIX) standard. This allows users to integrate diverse threat data sources into a single framework, making it easier to analyze and respond to threats. The platform supports various data formats and can ingest information from multiple feeds, enabling users to maintain a comprehensive view of the threat landscape. Additionally, OpenCTI offers advanced visualization tools that help users identify patterns and relationships within the data, facilitating more informed decision-making. Moreover, OpenCTI enhances the operationalization of threat intelligence by providing users with the tools to enrich their data with contextual information. This capability allows organizations to tailor their threat intelligence to their specific business needs, ensuring that the information is not only relevant but also actionable. By generating detailed threat exposure reports, OpenCTI empowers executives with the insights needed to understand their organization's risk landscape and make informed strategic decisions regarding cybersecurity investments and initiatives. Overall, OpenCTI stands out in the realm of threat intelligence platforms by prioritizing collaboration, accessibility, and contextual relevance. Its open-source nature encourages community involvement and continuous improvement, making it a valuable resource for organizations seeking to enhance their threat intelligence capabilities and strengthen their cybersecurity defenses.

Average Rating: 4.6/5.0

Total Reviews: 47

How Do G2 Users Rate OpenCTI by Filigran?

  • Threat Intelligence: 9.4/10 (Category avg: 8.9/10)
  • Quality of Support: 8.8/10 (Category avg: 8.9/10)
  • Incident Logs: 7.5/10 (Category avg: 8.8/10)

Who Is the Company Behind OpenCTI by Filigran?

  • Seller: Filigran
  • Company Website:
  • Year Founded: 2022
  • HQ Location: New York, US
  • Twitter: @FiligranHQ
    841 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    270 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 57% Large, 28% Medium

What Do G2 Reviewers Say About OpenCTI by Filigran?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of OpenCTI, enabling efficient threat analysis and integration without administration hassles.
  • Users value the powerful automation and flexibility of OpenCTI, enhancing teamwork and streamlining threat analysis.
  • Users commend the excellent customer support of OpenCTI, praising their eagerness to assist and provide guidance.
  • Users value the great bi-directional integrations in OpenCTI, enhancing their ability to link diverse data sources.
  • Users value the great bi-directional integration capabilities of OpenCTI, enhancing their threat intelligence and response workflows.
Cons
  • Users find the graphing functionality and dashboards limited, wishing for more flexibility and customization options.
  • Users find the complexity of dashboards and workflows challenging, affecting effective use and leading to frustration.
  • Users experience poor customer support with slow improvements and inadequate documentation, impacting overall satisfaction with OpenCTI.
  • Users express concern over poor documentation, finding it difficult to connect resources and use features effectively.
  • Users find the dashboard issues frustrating due to limitations in outputs and display options, despite potential improvements.

What Are Recent G2 Reviews of OpenCTI by Filigran?

LevelBlue USM Anywhere

LevelBlue USM Anywhere is a cloud-based security management solution that accelerates and centralizes threat detection, incident response, and compliance management for your cloud, hybrid cloud, and on-premises environments. USM Anywhere includes purpose-built cloud sensors that natively monitor your Amazon Web Services (AWS) and Microsoft Azure cloud environments. On premises, lightweight virtual sensors run on Microsoft Hyper-V and VMware ESXi to monitor your virtual private cloud and physical IT infrastructure. With USM Anywhere, you can rapidly deploy sensors into your cloud and on-premises environments while centrally managing data collection, security analysis, and threat detection from the AlienVault Secure Cloud. Five Essential Security Capabilities in a Single SaaS Platform AlienVault USM Anywhere provides five essential security capabilities in a single SaaS solution, giving you everything you need for threat detection, incident response, and compliance management—all in a single pane of glass. With USM Anywhere, you can focus on finding and responding to threats, not managing software. An elastic, cloud-based security solution, USM Anywhere can readily scale to meet your threat detection needs as your hybrid cloud environment changes and grows. 1. Asset Discovery 2. Vulnerability Assessment 3. Intrusion Detection 4. Behavioral Monitoring 5. SIEM

Average Rating: 4.4/5.0

Total Reviews: 102

How Do G2 Users Rate LevelBlue USM Anywhere?

  • Threat Intelligence: 9.2/10 (Category avg: 8.9/10)
  • Quality of Support: 8.6/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.3/10 (Category avg: 8.5/10)
  • Incident Logs: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind LevelBlue USM Anywhere?

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 62% Medium, 20% Small

What Are Recent G2 Reviews of LevelBlue USM Anywhere?

What Are G2 Users Discussing About LevelBlue USM Anywhere?

Mozilla Enterprise Defense Platform

The Mozilla Enterprise Defense Platform (MozDef) seeks to automate the security incident handling process and facilitate the real-time activities of incident handlers.

Average Rating: 4.3/5.0

Total Reviews: 10

How Do G2 Users Rate Mozilla Enterprise Defense Platform?

  • Threat Intelligence: 8.3/10 (Category avg: 8.9/10)
  • Quality of Support: 7.1/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.5/10 (Category avg: 8.5/10)
  • Incident Logs: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Mozilla Enterprise Defense Platform?

  • Seller: Mozilla
  • Year Founded: 2005
  • HQ Location: San Francisco, CA
  • Twitter: @mozilla
    261,861 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,774 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 40% Medium, 40% Small

What Are Recent G2 Reviews of Mozilla Enterprise Defense Platform?

What Are G2 Users Discussing About Mozilla Enterprise Defense Platform?

TheHive

TheHive is a collaborative security case management platform designed to help SOC, CERT, CSIRT and MSSP teams manage the full incident response lifecycle. It serves as a central hub where security analysts can receive and triage alerts, conduct investigations, coordinate team actions and close incidents—all without switching tools. The platform integrates natively with other security tools, allowing teams to operate within existing workflows rather than replacing them. TheHive supports multi-tenancy, making it suitable for MSSPs and large organizations that manage security operations across multiple clients, business units or environments. Key capabilities include: - 300+ pre-built integrations: Connect TheHive to your SIEM, EDR, threat intelligence platforms, ticketing systems and other tools to embed it into existing infrastructure. - Alert ingestion and triage: Automatically receive, deduplicate and prioritize alerts from connected sources, with full visibility into alert status and assignment across the team. - Case and task management: Organize investigations using cases and tasks with defined ownership to maintain transparency and accountability. - Multi-tenancy and client isolation: Run separate, isolated workspaces for different clients or internal teams from a single deployment, with granular access controls and role-based permissions. - Automation: Trigger automated investigation or response actions, analyst notifications and third-party integrations, reducing manual effort. - Reporting and compliance: Generate incident reports and maintain full audit trails across investigations. Give external stakeholders controlled access to specific case details. TheHive is developed and maintained by StrangeBee and is trusted by 3,500+ security professionals across 50+ countries. Organizations including BMW, Thales, Pipedrive, Garmin and Cisco use TheHive to centralize and speed up incident response actions, enforce consistent processes across distributed teams, scale security operations and reduce alert fatigue. The platform is available as an on-premises deployment or as a cloud-hosted service, with tiered plans designed to match the operational needs of mid-size to large security teams. It supports air-gapped environments and offers deployment flexibility for organizations with strict data residency or compliance requirements.

Average Rating: 4.3/5.0

Total Reviews: 18

How Do G2 Users Rate TheHive?

  • Threat Intelligence: 8.9/10 (Category avg: 8.9/10)
  • Quality of Support: 7.9/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.3/10 (Category avg: 8.5/10)
  • Incident Logs: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind TheHive?

  • Seller: StrangeBee
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Paris, FR
  • Twitter: @StrangeBee
    9,614 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    77 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Large, 33% Medium

What Do G2 Reviewers Say About TheHive?

AI-generated summary from verified user reviews

Pros
  • Users value the customizable workflows of TheHive, enhancing efficiency in incident management for teams.
  • Users find TheHive's ease of use and scalability ideal for efficiently managing incident response in SOCs and CSIRTs.
  • Users value the good integrations and customizable workflows of TheHive, enhancing collaborative incident management for SOCs and CSIRTs.
  • Users appreciate the excellent integrations of TheHive, enhancing collaboration and efficiency in incident management.
  • Users appreciate the customizable workflows and integrations of TheHive, enhancing collective incident management for SOCs and CSIRTs.
Cons
  • Users find the complex setup of TheHive daunting, often requiring community support for troubleshooting delays.
  • Users feel the lack of guidance in TheHive makes it challenging for new users to navigate and troubleshoot effectively.
  • New users find the steep learning curve of TheHive challenging, often requiring substantial community assistance for setup.

What Are Recent G2 Reviews of TheHive?

What Are G2 Users Discussing About TheHive?

D3 Security

D3 stands at the forefront of AI-powered security, providing real-time, autonomous SOC solutions that help organizations stay ahead of cyber threats. By merging autonomous investigation and triage with AI-guided remediation, D3 is delivering AI-powered, human-led cyber security solutions. Morpheus is D3 Security’s fully autonomous SOC solution that triages, investigates, and responds to every alert, 24/7. Morpheus covers 100% of your alerts — no exceptions — so your team never has to choose between chasing false positives or risking a breach. It triages 95% of alerts in under two minutes, integrating seamlessly with any SIEM, XDR, or security stack. Unlike traditional SOAR platforms, Morpheus doesn’t need endless playbook tuning; it can build response workflows on the fly, specific to your security stack. The result? Zero alert fatigue, fewer missed threats, and a dramatic boost in SOC efficiency, powered by a data privacy-friendly and SecOps-focused AI model.

Average Rating: 4.2/5.0

Total Reviews: 64

How Do G2 Users Rate D3 Security?

  • Threat Intelligence: 9.0/10 (Category avg: 8.9/10)
  • Quality of Support: 9.0/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.9/10 (Category avg: 8.5/10)

Who Is the Company Behind D3 Security?

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 49% Large, 41% Medium

What Are Recent G2 Reviews of D3 Security?

Guardsix

Guardsix is the sovereign security platform for lean European teams, bringing log management and audit-ready compliance to regulated industries, critical national infrastructure operators, and the Managed Security Service Providers (MSSPs) that serve them throughout Europe and beyond. Headquartered in Copenhagen, Denmark, Guardsix delivers sovereign-by-design security for organisations that carry real operational responsibility. The company employs several hundred cyber security specialists and keeps every organisation it serves in full control of their data, deployment, and operations. Guardsix provides a unified Command Centre platform combining: • Security Information and Event Management (SIEM) • Network Detection and Response (NDR) • Security Orchestration, Automation and Response (SOAR) • Fleet for enabling multi-tenant management • Governance for Healthcare internal risk compliance monitoring The platform is built to support European data sovereignty, regulatory compliance and operational control, with predictable node-based pricing and deployment options spanning on-premises, air-gapped, hybrid and cloud environments. Guardsix solutions help organisations: • Simplify audit readiness for regulations such as NIS2, DORA, and GDPR. • Support lean security teams with efficient log management and simplified workflows. • Scale security operations without increased complexity or ingestion-led pricing surprises. • Keep security data under European jurisdiction and control — where it lives, who operates it, and under whose laws. • Deploy on their own terms, on-prem and in infrastructure they control, keeping migration a real option at every renewal. • See clearly across their whole environment, with SIEM, NDR, SOAR, Fleet, and Governance in one sovereign platform rather than a stack of point tools. Guardsix maintains SOC 2 Type II attestation and designs its solutions in accordance with European data protection requirements. With a strong partner-first model, Guardsix works closely with regional MSSPs and service providers, combining sovereign-by-design security technology with European integrity and deployment flexibility.

Average Rating: 4.3/5.0

Total Reviews: 105

How Do G2 Users Rate Guardsix?

  • Threat Intelligence: 8.4/10 (Category avg: 8.9/10)
  • Quality of Support: 9.0/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.3/10 (Category avg: 8.5/10)
  • Incident Logs: 8.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Guardsix?

  • Seller: guardsix
  • Company Website:
  • Year Founded: 2001
  • HQ Location: Copenhagen, Capital Region
  • LinkedIn® Page: linkedin.com
    162 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 44% Medium, 31% Small

What Do G2 Reviewers Say About Guardsix?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Guardsix, simplifying administration and enhancing overall user experience.
  • Users appreciate the ease of use of Guardsix Log Management, making it simple and efficient for managing logs.
  • Users commend the excellent customer support of Logpoint, enhancing the overall experience and satisfaction with the product.
  • Users value the easy integrations of Logpoint, seamlessly unifying various telemetry types within their existing tech ecosystem.
  • Users value the efficiency of Logpoint, simplifying incident management and enhancing overall effectiveness in daily operations.
Cons
  • Users find the poor interface design challenging, making it difficult to navigate and utilize effectively.
  • Users find the UX improvement necessary as logs are poorly presented and the interface is slow and confusing.
  • Users find the interface complexity challenging, though improvements are expected in the near future.
  • Users find the confusing interface of Guardsix challenging and slow to navigate, impacting their overall experience.
  • Users feel there is an information deficiency about resource needs, leading to potential overuse and uncertainty in design.

What Are Recent G2 Reviews of Guardsix?

What Are G2 Users Discussing About Guardsix?

Check Point SmartEvent Event Management

SmartEvent event management provides full threat visibility with a single view into security risks. Take control and command the security event through real-time forensic and event investigation, compliance, and reporting. Respond to security incidents immediately and gain network true insights. Features include: integrated threat management, single view into security risks, customizable views and reports, full threat visibility, and real-time forensic and event investigation.

Average Rating: 4.4/5.0

Total Reviews: 13

How Do G2 Users Rate Check Point SmartEvent Event Management?

  • Threat Intelligence: 9.0/10 (Category avg: 8.9/10)
  • Quality of Support: 7.8/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.3/10 (Category avg: 8.5/10)
  • Incident Logs: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Check Point SmartEvent Event Management?

Who Uses This Product?

  • Company Size: 69% Large, 23% Medium

What Do G2 Reviewers Say About Check Point SmartEvent Event Management?

AI-generated summary from verified user reviews

Pros
  • Users value the full threat visibility of Check Point SmartEvent, enabling quick and informed responses to security risks.
  • Users appreciate the full threat visibility provided by SmartEvent, enabling quick responses to security risks easily.
  • Users value the effective alerting system of SmartEvent, providing clarity and context for quick responses.
  • Users appreciate the ease of use of Check Point SmartEvent, enabling quick and focused responses to network events.
  • Users value effective monitoring in SmartEvent, allowing quick response to relevant events without unnecessary clutter.
Cons
  • Users find the initial setup to have a steep learning curve, making the experience feel overwhelming at times.
  • Users face deployment difficulties with random CPSEMD process terminations, causing login failures and high CPU usage in SmartEvent.
  • Users experience difficult learning due to random CPSEMD terminations causing login failures and high CPU usage in SmartEvent GUI.
  • Users find the initial learning curve steep, making it challenging to filter data effectively and receive relevant alerts.
  • Users experience setup difficulties with Check Point SmartEvent, including random process terminations and high CPU usage issues.

What Are Recent G2 Reviews of Check Point SmartEvent Event Management?

What Are G2 Users Discussing About Check Point SmartEvent Event Management?

FortiEDR

FortiEDR identifies and stops breaches in real time automatically and efficiently with a lightweight agent. Part of the Fortinet Security Operations platform, it proactively shrinks the attack surface, prevents malware infection, detects and defuses potential threats immediately, and automates response and remediation procedures with customizable playbooks across legacy and current operating systems.

Average Rating: 4.5/5.0

Total Reviews: 12

How Do G2 Users Rate FortiEDR?

  • Threat Intelligence: 7.8/10 (Category avg: 8.9/10)
  • Quality of Support: 8.3/10 (Category avg: 8.9/10)
  • Incident Case Management: 7.5/10 (Category avg: 8.5/10)
  • Incident Logs: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind FortiEDR?

  • Seller: Fortinet
  • Year Founded: 2000
  • HQ Location: Sunnyvale, CA
  • Twitter: @Fortinet
    151,422 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    16,564 employees on LinkedIn®
  • Ownership: NASDAQ: FTNT

Who Uses This Product?

  • Company Size: 50% Medium, 33% Large

What Are Recent G2 Reviews of FortiEDR?

What Are G2 Users Discussing About FortiEDR?

ContraForce

ContraForce is an Agentic Security Delivery Platform. Security Delivery Agents run the complete delivery loop on every incident: triage, investigation, response, tuning, ticket, and report. Not a portion of the loop. Work arrives as an incident and leaves as a closed ticket and a finished report. THE PROBLEM ContraForce is built for MSPs, MSSPs, and enterprise security teams that operate security across many environments at once. Whether those environments are customer tenants, subsidiaries, or business units, they share one structural problem. Security delivery is paid for in analyst hours. Every environment you take on costs more of them while the revenue behind it stays flat. Growth compresses margin instead of building it. Hiring is the only lever most teams have, and the analysts are not available to hire. Detection tooling does not close that gap. Detection is already solved. What is not solved is the work that happens after an incident is created. HOW IT WORKS Security Delivery Agents pick up incidents as they are created and carry them to closure. They triage, gather evidence, build the investigation, take response actions, tune the detection that fired, update the ticket, and produce the report the customer reads. Each incident compiles its own Gamebook. The agent assembles a response sequence from the entities actually involved in that incident, then executes only the actions the incident's classification and confidence warrant. Nothing is replayed from a template written months earlier. Your team defines what requires human approval and what an agent completes on its own. Every action is logged with the reasoning behind it, so the work stands up to a customer review, an audit, or a post-incident report. CORE CAPABILITIES Security Delivery Agents. Autonomous execution of triage, investigation, response, tuning, ticketing, and reporting on every incident. Gamebooks. Response sequences compiled per incident from the entities involved, gated on classification and confidence. Governed autonomy. Approval gates you define, full audit trail, and role based control over what an agent may do in each environment. Multi environment operations. One place to run security delivery across every environment you manage, with no data duplication. Reporting. The customer facing report is produced as part of the loop, not assembled by an analyst at the end of the month. Ticketing and ITSM integration. Native connections to ConnectWise, Halo, and ServiceNow. ARCHITECTURE ContraForce is a delivery layer, not a detection layer. It does not replace the security tools you already run and it does not ingest or duplicate your data. It connects through federated access, reads telemetry where it already lives, and operates across every environment you manage from one place. Built natively on the Microsoft Security platform, and running equally against telemetry from other XDR and SIEM tools through API. Microsoft Sentinel is supported but not required. Detection stays with your existing stack. Delivery moves to ContraForce. DEPLOYMENT Deployment is a connection, not a migration. No data to move, no agents to install, nothing to rip out. Connect a workspace and agents begin working incidents the same day. Connect one workspace and see what happens on the first incident. Deployed and trusted by MSPs, MSSPs, and enterprise security teams globally. Microsoft Security ISV of the Year 2024. SOC 2 Type II certified.

Average Rating: 4.8/5.0

Total Reviews: 7

How Do G2 Users Rate ContraForce?

  • Threat Intelligence: 10.0/10 (Category avg: 8.9/10)
  • Quality of Support: 10.0/10 (Category avg: 8.9/10)
  • Incident Case Management: 10.0/10 (Category avg: 8.5/10)

Who Is the Company Behind ContraForce?

  • Seller: ContraForce
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Frisco, US
  • Twitter: @ContraForceSec
    22 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    25 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 57% Medium, 43% Small

What Do G2 Reviewers Say About ContraForce?

AI-generated summary from verified user reviews

Pros
  • Users commend the ease of use of ContraForce, noting its quick deployment and minimal resource requirements.
  • Users commend the excellent customer support and easy endpoint additions, enhancing their overall experience with ContraForce.
  • Users value the centralized alerting and monitoring system of ContraForce, enhancing efficiency for MSSP providers.
  • Users value the automation capabilities of ContraForce, enabling quick and efficient cybersecurity management in resource-limited environments.
  • Users value the centralized management of ContraForce, enhancing efficiency for MSSP providers with multiple clients.
Cons
  • Users report detection issues with ContraForce, lacking critical details and real-time logs for effective incident response.
  • Users find the platform expensive given its lack of essential features and limited logging capabilities.
  • Users express concern over the insufficient information, lacking essential logs and incident details for effective use.
  • Users find the limited functionality of ContraForce restricts effectiveness, lacking essential logging and alert details.
  • Users find missing features in ContraForce, lacking essential details and real-time log access for effective incident response.

What Are Recent G2 Reviews of ContraForce?

Exaforce

At Exaforce, we are on a mission to 10x the productivity and efficacy of security and operations (SOC) teams using our transformative multi-model AI engine. Our Agentic SOC Platform combines AI agents (“Exabots”) with advanced data exploration to deliver real-time insights, proactive detection and response, in-depth investigations, and automated workflows. Backed by Khosla Ventures, Mayfield, Thomvest Ventures, Touring Capital, and others, Exaforce helps SOC teams respond to threats and breaches faster, with higher precision, greater consistency, and at lower total costs—redefining how SOC teams function.

Average Rating: 4.9/5.0

Total Reviews: 7

How Do G2 Users Rate Exaforce?

  • Threat Intelligence: 8.3/10 (Category avg: 8.9/10)
  • Quality of Support: 10.0/10 (Category avg: 8.9/10)

Who Is the Company Behind Exaforce?

  • Seller: Exaforce
  • Company Website:
  • Year Founded: 2023
  • HQ Location: San Jose, CA
  • Twitter: @exaforceAI
    134 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    60 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 57% Medium, 29% Large

What Do G2 Reviewers Say About Exaforce?

AI-generated summary from verified user reviews

Pros
  • Users praise Exaforce for its robust security operations, combining AI and human review for effective threat management.
  • Users commend Exaforce's fantastic customer support, highlighting their responsiveness and collaboration on feature development.
  • Users value the efficient alerting system of Exaforce, which streamlines investigations and enhances focus on critical findings.
  • Users praise the fantastic customer support of Exaforce, making troubleshooting and feature requests a breeze.
  • Users find Exaforce to have exceptional ease of use, significantly streamlining investigations and prioritizing important findings.
Cons
  • Users often face query issues with Exaforce, as the interface can be slow and struggles with large datasets.
  • Users report that the slow performance of Exaforce impacts usability, especially with complex queries and large datasets.
  • Users experience slow interface loading and issues with complex queries and large datasets that hinder performance.

What Are Recent G2 Reviews of Exaforce?

ThreatConnect TI Ops

TI Ops is the threat intelligence platform built for operations, not just centralization. It ingests hundreds of internal and external sources, enriches them with AI, and aligns them to your intelligence requirements and MITRE ATT&CK gaps. Analysts can instantly operationalize insights across the SOC, IR, hunt, and vulnerability teams — no swivel-chairing required. When combined with Polarity and Risk Quantifier, TI Ops helps teams act on intelligence faster and focus on the threats that truly matter to the business.

Average Rating: 4.6/5.0

Total Reviews: 14

How Do G2 Users Rate ThreatConnect TI Ops?

  • Threat Intelligence: 9.2/10 (Category avg: 8.9/10)
  • Quality of Support: 8.8/10 (Category avg: 8.9/10)
  • Incident Case Management: 7.3/10 (Category avg: 8.5/10)
  • Incident Logs: 7.0/10 (Category avg: 8.8/10)

Who Is the Company Behind ThreatConnect TI Ops?

  • Seller: ThreatConnect
  • Year Founded: 2011
  • HQ Location: Arlington, US
  • Twitter: @ThreatConnect
    14,141 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    77 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 57% Large, 43% Medium

What Do G2 Reviewers Say About ThreatConnect TI Ops?

AI-generated summary from verified user reviews

Pros
  • Users praise the flexible no-code Playbook builder, enhancing automation and integration for improved threat detection and response.
  • Users value the effective threat detection capabilities of ThreatConnect TI Ops, enhancing security through collaborative intelligence.
  • Users value the ease of use of ThreatConnect TI Ops, benefiting from its intuitive interfaces and seamless integrations.
  • Users praise the automation capabilities of ThreatConnect TI Ops, enhancing efficiency and flexibility in security operations.
  • Users appreciate the ease of implementation of ThreatConnect TI Ops, making it user-friendly for effective threat management.
Cons
  • Users feel the UX needs improvement for a smoother investigation flow and enhanced overall interface usability.
  • Users note that additional licensing costs for some features can hinder accessibility for smaller organizations.
  • Users dislike the API limitations that hinder seamless integration with other tools and affect TQL writing.
  • Users find the difficult learning curve of ThreatConnect TI Ops challenging at first, but training reduces frustration.
  • Users find the difficult setup challenging initially, but appreciate the available training resources to ease the process.

What Are Recent G2 Reviews of ThreatConnect TI Ops?

What Are G2 Users Discussing About ThreatConnect TI Ops?

Corelight

Corelight's Open Network Detection and Response (NDR) Platform improves network detection coverage, accelerates incident response, and reduces operational costs by consolidating NDR, intrusion detection (IDS), and PCAP functionality in a single solution and by providing security analysts with machine learning-assisted investigations and one-click-pivots from prioritized alerts to the evidence needed to investigate and remediate them. Network Detection and Response platforms monitor and analyze network traffic, delivering telemetry into existing SIEM, XDR, or SaaS-based solutions. Corelight’s platform is unique because our detections and visibility engineering are community driven—with continuous content creation from Zeek®, Suricata IDS, and other Intel communities. And our integration with CrowdStrike XDR enables cross platform (EDR+NDR) analytics. This provides you with the most complete network visibility, powerful analytics, and threat hunting capabilities, and accelerates investigation across your entire kill chain. Corelight also delivers a comprehensive suite of network security analytics that help organizations identify more than 75 adversarial TTPs across the MITRE ATT&CK® spectrum including Exfiltration, Command and Control (C2), and Lateral Movement. These detections reveal known and unknown threats via hundreds of unique insights and alerts across machine learning, behavioral analysis, and signature-based approaches. CORELIGHT PRODUCTS + SERVICES Open NDR Platform Appliance, Cloud, Software, Virtual and SaaS Sensors IDS Fleet Manager Investigator Threat Hunting Platform Smart PCAP Corelight Training CERTIFICATIONS FIPS 140-2

Average Rating: 4.6/5.0

Total Reviews: 20

How Do G2 Users Rate Corelight?

  • Threat Intelligence: 7.8/10 (Category avg: 8.9/10)
  • Quality of Support: 9.1/10 (Category avg: 8.9/10)
  • Incident Case Management: 5.0/10 (Category avg: 8.5/10)
  • Incident Logs: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Corelight?

  • Seller: Corelight
  • Year Founded: 2013
  • HQ Location: San Francisco, CA
  • Twitter: @corelight_inc
    4,227 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    483 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 50% Medium, 50% Large

What Do G2 Reviewers Say About Corelight?

AI-generated summary from verified user reviews

Pros
  • Users value Corelight for its comprehensive security, offering exceptional network event insights and threat detection capabilities.
  • Users praise Corelight for its superior network telemetry, enhancing security detection and event clarity.
  • Users praise Corelight for its effective network telemetry, making security events easy to understand and actionable.
  • Users value the exceptional network security offered by Corelight, enabling easy detection of threats and efficient event analysis.
  • Users value the great network telemetry of Corelight, which simplifies security event analysis and enhances threat detection.
Cons
  • Users find the complex coding of Corelight challenging, especially for those without specialized knowledge.
  • Users find the complex configuration of Corelight difficult, especially for those without specialized knowledge or training.
  • Users find Corelight's complexity challenging, often requiring specialized knowledge and costly training for effective use.
  • Users find the complex setup of Corelight challenging, often requiring specialized knowledge and personalized training.
  • Users find the learning curve steep, making Corelight challenging for novice security analysts to navigate effectively.

What Are Recent G2 Reviews of Corelight?

Cybereason Defense Platform

Cybereason automatically detects malicious activity and presents it in an intuitive way. It deploys easily with minimal organizational impact and provides end-to-end context of an attack campaign. Most organizations deploy Cybereason and start detecting attacks within 24 to 48 hours.

Average Rating: 4.4/5.0

Total Reviews: 18

How Do G2 Users Rate Cybereason Defense Platform?

  • Threat Intelligence: 7.8/10 (Category avg: 8.9/10)
  • Quality of Support: 7.9/10 (Category avg: 8.9/10)
  • Incident Case Management: 9.2/10 (Category avg: 8.5/10)
  • Incident Logs: 7.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Cybereason Defense Platform?

  • Seller: Cybereason
  • Year Founded: 2012
  • HQ Location: La Jolla, San Diego, US
  • LinkedIn® Page: www.linkedin.com
    448 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 61% Large, 22% Small

What Do G2 Reviewers Say About Cybereason Defense Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the advanced security features of Cybereason Defense Platform, leading to swift and effective threat detection.
  • Users find Cybereason Defense Platform to be easy to set up and use, streamlining security management effortlessly.
  • Users appreciate the advanced security options of Cybereason, allowing seamless detection of malicious activities across all endpoints.
  • Users value the seamless automated threat detection in the Cybereason Defense Platform, enhancing security across all endpoints.
  • Users commend the advanced AI capabilities of Cybereason, which effectively identifies and mitigates threats across endpoints.
Cons
  • Users suggest enhancing the user interface and custom detection features to improve overall satisfaction with the platform.
  • Users report lack of clarity in after sales support, making business interactions challenging and frustrating.
  • Users note the limited customization options affect their satisfaction and usability of the Cybereason Defense Platform.
  • Users feel the need for enhanced features in the user interface and custom detection rules of Cybereason Defense Platform.
  • Users find poor customer support from Cybereason Defense Platform makes business interactions challenging and frustrating.

What Are Recent G2 Reviews of Cybereason Defense Platform?

What Are G2 Users Discussing About Cybereason Defense Platform?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated April 22, 2026