# Best Incident Response Software - Page 2

*By [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)*


Incident response software enables security teams to investigate, contain, remediate, and document cybersecurity incidents across their lifecycle within supported environments or threat domains. These solutions operationalize the response process by helping teams identify and organize security events into incidents and providing workflows for triage, investigation, containment, eradication, and post-incident review.

Incident response tools may focus on specific domains, such as endpoint, cloud, identity, SaaS, or email, or provide broader cross-environment capabilities. They often integrate with detection technologies such as EDR, XDR, or other security analytics platforms, but are distinguished by their ability to coordinate and run response actions, manage incident cases, and maintain documented records for operational reporting and audit purposes. Many incident response solutions function similarly to security information and event management (SIEM) software, but SIEM products provide a larger scope of security and IT management features. Incident response platforms focus on investigating and resolving security incidents, while SOAR platforms automate and orchestrate response workflows across security tools.

To qualify for inclusion in the Incident Response category, a product must:

- Identify and organize cybersecurity events into incidents within supported domains
- Provide structured investigation capabilities for suspected or confirmed incidents
- Enable containment and remediation through guided or automated response actions
- Maintain documented cybersecurity incident records for reporting and post-incident review




## Top Incident Response Software at a Glance
| # | Product | Rating | Best For | What Users Say |
|---|---------|--------|----------|----------------|
| 1 | [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) | 4.6/5.0 (417 reviews) | — | "[Crowdstrike Falcon: Proactive Security, Steep Learning Curve](https://www.g2.com/survey_responses/crowdstrike-falcon-endpoint-protection-platform-review-12958852)" |
| 2 | [KnowBe4 PhishER/PhishER Plus](https://www.g2.com/products/knowbe4-phisher-phisher-plus/reviews) | 4.5/5.0 (567 reviews) | Phishing email triage and automated response | "[PhishER Simplifies Phishing Review and Stops Threats Organization-Wide](https://www.g2.com/survey_responses/knowbe4-phisher-phisher-plus-review-13078008)" |
| 3 | [Tines](https://www.g2.com/products/tines/reviews) | 4.7/5.0 (396 reviews) | No-code SOAR automation for security teams | "[AI orchestration with Drag-and-Drop development tool](https://www.g2.com/survey_responses/tines-review-12620879)" |
| 4 | [Torq AI SOC Platform](https://www.g2.com/products/torq-ai-soc-platform/reviews) | 4.8/5.0 (149 reviews) | AI-driven SOAR with native integrations | "[Efficient Automation with Robust Integrations](https://www.g2.com/survey_responses/torq-ai-soc-platform-review-12301239)" |
| 5 | [Cynet](https://www.g2.com/products/cynet/reviews) | 4.7/5.0 (216 reviews) | Unified XDR with built-in MDR for lean teams | "[Great MDR/XDR Platform](https://www.g2.com/survey_responses/cynet-review-9481539)" |
| 6 | [SentinelOne Singularity Endpoint](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews) | 4.7/5.0 (195 reviews) | — | "[The Endpoint Security Platform That Actually Responds, Not Just Alerts.](https://www.g2.com/survey_responses/sentinelone-singularity-endpoint-review-13094863)" |
| 7 | [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews) | 4.4/5.0 (273 reviews) | — | "[Easy Log Ingestion Across Formats with Seamless Sentinel Integrations](https://www.g2.com/survey_responses/microsoft-sentinel-review-13073395)" |
| 8 | [ServiceNow Security Operations](https://www.g2.com/products/servicenow-security-operations/reviews) | 4.4/5.0 (72 reviews) | — | "[Strong platform for centralized security operations and incident response](https://www.g2.com/survey_responses/servicenow-security-operations-review-12737410)" |
| 9 | [IBM QRadar SIEM](https://www.g2.com/products/ibm-ibm-qradar-siem/reviews) | 4.4/5.0 (282 reviews) | Enterprise SIEM tied to broader IBM security tooling | "[QRADAR Integrates Easily and Makes Logs &amp; Alerts Report-Ready](https://www.g2.com/survey_responses/ibm-qradar-siem-review-13061810)" |
| 10 | [Tanium](https://www.g2.com/products/tanium/reviews) | 4.5/5.0 (70 reviews) | — | "[Real-Time Endpoint Visibility and Powerful Automation in One Platform](https://www.g2.com/survey_responses/tanium-review-13128393)" |

---
## What Are the Most Common Questions About Incident Response Software?
*AI-generated · Last updated: May 26, 2026*
### What is the best tool for coordinating cybersecurity incident response?
Based on G2 reviews, buyers evaluating incident response software often look for centralized workflows, alert triage, and cross-team coordination in one place. According to verified users, ServiceNow Security Operations stands out for bringing incidents, vulnerability workflows, and remediation tasks into a single platform, while reducing scattered tools and manual handoffs. G2 reviewers mention that teams value structured case management, integrations with broader IT workflows, and better visibility across remediation ownership. Reviews also note that setup can take planning, but once configured, the platform helps security and IT teams work from the same system and move incidents forward with clearer accountability and less back-and-forth.

**Here are some of the top-rated products on G2:**

- [ServiceNow Security Operations](https://www.g2.com/products/servicenow-security-operations/reviews/servicenow-security-operations-review-12823627) – centralizes incidents, case management, and remediation workflows for coordinated response
- [Tines](https://www.g2.com/products/tines/reviews/tines-review-12651671) – automates repetitive response steps and connects security workflows across teams and tools
- [Torq AI SOC Platform](https://www.g2.com/products/torq-ai-soc-platform/reviews/torq-ai-soc-platform-review-11924062) – helps automate cybersecurity processes and repetitive operational tasks for faster coordination


### Which vendor provides real-time threat intelligence integration?
Based on G2 reviews, Tines is a strong fit for teams that want real-time integrations across security tools and APIs. According to verified users, Tines connects with platforms such as CrowdStrike, Splunk, Jira, AWS, GCP, Microsoft Graph, and other security systems to automate data movement, alert handling, and response steps. G2 reviewers mention that its flexibility and API-driven approach make it useful for building workflows that enrich alerts and coordinate actions across multiple sources in near real time. Reviews also highlight that the platform is easy to start with, though more advanced workflows can require deeper knowledge when teams want to scale complex automation.


### What platform provides detailed incident investigation reports?
Based on G2 reviews, several incident response software buyers prioritize clear reporting and investigation context, especially when analysts need to move quickly from alert to root cause. According to verified users, CrowdStrike Falcon Endpoint Protection Platform is frequently praised for detailed endpoint visibility, process information, investigation support, and centralized telemetry that helps teams understand what happened. G2 reviewers mention process trees, host information, quarantine actions, and investigation workflows that reduce manual effort and support faster incident analysis. Reviews also note that reporting and customization can require tuning, but the platform is consistently valued for making investigations easier and giving security teams stronger visibility across endpoints.


### Which incident response platform offers the fastest containment capabilities?
Based on G2 reviews, incident response teams looking for fast containment often focus on automated isolation, host control, and rapid response from a single console. According to verified users, SentinelOne Singularity Endpoint is frequently recognized for autonomous response, ransomware rollback, and quick isolation of infected devices with limited manual intervention. G2 reviewers mention storyline-based investigation context, real-time protection, and the ability to contain harmful processes early, which helps reduce impact during active incidents. Reviews also point to a learning curve and some console usability concerns, but they consistently describe the platform as effective for speeding containment and reducing the amount of analyst effort required during urgent response scenarios.


### Which vendor offers AI-powered incident detection and triage?
Based on G2 reviews, Tines is often highlighted for AI-assisted workflow creation and automated handling of security and IT tasks, but for direct incident detection and triage support, Exaforce is repeatedly described in reviews as reducing alert noise and surfacing the findings that matter most. According to verified users, Exaforce correlates signals from multiple sources, applies prior context, and helps small teams focus on true incidents instead of manually sorting through logs. G2 reviewers mention agentic workflows, AI-assisted investigations, and MDR support that shorten response time and reduce analyst overload. Reviews also note some onboarding and interface complexity, but users consistently value the platform for faster triage and clearer prioritization.


### Which vendor provides real-time threat intelligence integration?
Based on G2 reviews, Tines is a strong fit for teams that want real-time integrations across security tools and APIs. According to verified users, Tines connects with platforms such as CrowdStrike, Splunk, Jira, AWS, GCP, Microsoft Graph, and other security systems to automate data movement, alert handling, and response steps. G2 reviewers mention that its flexibility and API-driven approach make it useful for building workflows that enrich alerts and coordinate actions across multiple sources in near real time. Reviews also highlight that the platform is easy to start with, though more advanced workflows can require deeper knowledge when teams want to scale complex automation.


### What is the most affordable incident response software for SMBs?
Based on G2 reviews, affordability for SMBs in incident response software is usually tied to simpler deployment, lower operational overhead, and good value from a smaller team’s perspective. According to verified users, Blumira Automated Detection &amp; Response stands out for ease of setup, a unified dashboard, and SOC support that helps small IT teams reduce research time and respond faster without a large internal staff. G2 reviewers also mention Cynet as a good-priced all-in-one option and Pondurance as an affordable managed monitoring choice that helps organizations extend coverage. Reviews suggest these products appeal to SMBs because they balance detection, response, and day-to-day manageability.

**Here are some of the top-rated products on G2:**

- [Blumira Automated Detection &amp; Response](https://www.g2.com/products/blumira-automated-detection-response/reviews/blumira-automated-detection-response-review-12373548) – helps small IT teams with quick detection, SOC support, and easy setup
- [Cynet](https://www.g2.com/products/cynet/reviews/cynet-review-12594700) – offers an all-in-one security platform reviewers describe as a good-price XDR option
- [Pondurance](https://www.g2.com/products/pondurance/reviews/pondurance-review-11283457) – gives smaller teams log monitoring and incident support with cost-effective managed coverage


### What is the top-rated incident response platform for large enterprises?
Based on G2 reviews, large enterprise buyers often value broad endpoint coverage, centralized visibility, and the ability to scale response without adding major operational overhead. According to verified users, CrowdStrike Falcon Endpoint Protection Platform is frequently described as effective in large environments because it supports fast deployment at scale, strong real-time detection, centralized telemetry, and investigation workflows that help reduce incident-response workload. G2 reviewers mention lean teams managing larger estates, cloud-based administration, and strong endpoint visibility across distributed environments. Reviews also note that training, tuning, and licensing can require planning, but the platform is consistently viewed as a strong fit for enterprise-scale incident response operations.

**Here are some of the top-rated products on G2:**

- [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews/crowdstrike-falcon-endpoint-protection-platform-review-12788064) – supports large-scale endpoint protection and helps lean teams manage bigger environments
- [ServiceNow Security Operations](https://www.g2.com/products/servicenow-security-operations/reviews/servicenow-security-operations-review-12737410) – centralizes security incidents and workflows for enterprises managing multiple teams and processes
- [Tanium](https://www.g2.com/products/tanium/reviews/tanium-review-12612683) – gives large environments real-time visibility and action across thousands of endpoints


### What platform integrates incident response with SIEM tools?
Based on G2 reviews, buyers looking to integrate incident response with SIEM tools often want one system that connects alerts, case management, and operational workflows. According to verified users, ServiceNow Security Operations is regularly used to pull together SIEM inputs and turn them into structured response processes, helping teams centralize incidents rather than work across email, spreadsheets, and separate tools. G2 reviewers mention integrations with security tools, centralized remediation tracking, and smoother collaboration between IT and security teams. Reviews also say that implementation quality matters, but once in place, the platform helps organizations move from fragmented alert handling to a more auditable and workflow-driven response model.


### Which tool supports incident response across hybrid cloud environments?
Based on G2 reviews, Microsoft Sentinel is a strong option for organizations managing incident response across cloud, on-premises, and hybrid environments. According to verified users, it centralizes logs, alerts, and investigations across multiple systems while improving SOC efficiency through correlation, analytics, and automation. G2 reviewers mention strong visibility across hybrid infrastructure, native integrations with Microsoft services, and easier scaling than traditional on-premises approaches. Reviews also note that teams may need time to tune rules and manage ingestion strategy, but they consistently describe the platform as useful for unifying detection and response across complex environments where cloud and on-prem systems need to be investigated together.




## G2 Grid® for Incident Response Software
![G2 Grid® for Incident Response Software plotting products by satisfaction and market presence](https://www.g2.com/categories/incident-response/grids.png?focus%5B%5D=68606&focus%5B%5D=139264&focus%5B%5D=98376&focus%5B%5D=164907&focus%5B%5D=70840&focus%5B%5D=16881&focus%5B%5D=122123&focus%5B%5D=55254)
Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, KnowBe4 PhishER/PhishER Plus, Tines, Torq AI SOC Platform, Cynet, SentinelOne Singularity Endpoint, Microsoft Sentinel, and ServiceNow Security Operations.
Underlying data: [Grid® JSON](https://www.g2.com/categories/incident-response/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&amp;focus%5B%5D=knowbe4-phisher-phisher-plus&amp;focus%5B%5D=tines&amp;focus%5B%5D=torq-ai-soc-platform&amp;focus%5B%5D=cynet&amp;focus%5B%5D=sentinelone-singularity-endpoint&amp;focus%5B%5D=microsoft-sentinel&amp;focus%5B%5D=servicenow-security-operations)


## How Many Incident Response Software Products Does G2 Track?
**Total Products under this Category:** 103

### Category Stats (Jul 2026)
- **Average Rating**: 4.47/5 (↓0.01 vs Jun 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product**: Tanium (+0.59%) - Among all products in this category, Tanium recorded the largest rating increase compared to last month
*Last updated: July 20, 2026*


## How Does G2 Rank Incident Response Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 5,200+ Authentic Reviews
- 103+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.


## Which Incident Response Software Is Best for Your Use Case?

- **Leader:** [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)
- **Highest Performer:** [Barracuda Incident Response](https://www.g2.com/products/barracuda-incident-response/reviews)
- **Easiest to Use:** [Tines](https://www.g2.com/products/tines/reviews)
- **Top Trending:** [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)
- **Best Free Software:** [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)


---

**Sponsored**

### 15Five

15Five is the AI-powered performance management platform built for business impact. 15Five’s AI-powered all-in-one people management system is easy to use, delivers effortless insights, and enables managers to lead with impact so that companies and their people can thrive. Within the flow of work, HR leaders are empowered with data-driven insights and recommendations while managers are transformed into changemakers, accelerating engagement, performance, and retention. 15Five combines generative AI, custom analytics, and human-centered principles within a complete platform, including 360° performance reviews, engagement surveys, goal tracking, manager coaching and training, and ongoing feedback tools like guided 1-on-1s and check-ins. Learn more at 15five.com.



[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&amp;secure%5Bad_slot%5D=category_product_list&amp;secure%5Bcategory_id%5D=1082&amp;secure%5Bchosen_at%5D=2026-07-21T07%3A29%3A52Z&amp;secure%5Bdisplayable_resource_id%5D=50&amp;secure%5Bdisplayable_resource_type%5D=Category&amp;secure%5Bmedium%5D=sponsored&amp;secure%5Bplacement_reason%5D=retargeted_product&amp;secure%5Bplacement_resource_ids%5D%5B%5D=3797&amp;secure%5Bprioritized%5D=false&amp;secure%5Bproduct_id%5D=3797&amp;secure%5Bresource_id%5D=1082&amp;secure%5Bresource_type%5D=Category&amp;secure%5Bsource_type%5D=category_page&amp;secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fincident-response%3Futf8%3D%25E2%259C%2593&amp;secure%5Btoken%5D=8ef4cbc3444b8e59accaaeb8f684219e54b4a233499dab5cc8a917ef7bb29027&amp;secure%5Burl%5D=https%3A%2F%2Fwww.15five.com%2Fdemo%3Futm_campaign%3D41091668-G2%2520PPC%26utm_source%3Dppc%26utm_medium%3Dcpc%26utm_term%3DG2-ppc%26utm_content%3Dcategory-placement&amp;secure%5Burl_type%5D=book_demo)

---

## What Are the Top-Rated Incident Response Software Products in 2026?
### 1. [IBM QRadar SOAR](https://www.g2.com/products/ibm-qradar-soar/reviews)
IBM QRadar® SOAR is designed to help your security team respond to cyberthreats with confidence, automate with intelligence and collaborate with consistency. It guides your team in resolving incidents by codifying established incident response processes into dynamic playbooks. The open and agnostic platform helps accelerate and orchestrate their response by automating actions with intelligence and integrating with other security tools. IBM QRadar SOAR is available on AWS Marketplace.


**Average Rating:** 4.0/5.0
**Total Reviews:** 25
**How Do G2 Users Rate IBM QRadar SOAR?**

- **Threat Intelligence:** 7.2/10 (Category avg: 8.9/10)
- **Quality of Support:** 7.9/10 (Category avg: 8.8/10)
- **Incident Case Management:** 7.7/10 (Category avg: 8.4/10)
- **Incident Logs:** 7.5/10 (Category avg: 8.8/10)

**Who Is the Company Behind IBM QRadar SOAR?**

- **Seller:** [IBM](https://www.g2.com/sellers/ibm)
- **Year Founded:** 1911
- **HQ Location:** Armonk, New York, United States
- **Twitter:** @IBMSecurity (74,660 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/1009/ (328,202 employees on LinkedIn®)
- **Ownership:** SWX:IBM

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services
- **Company Size:** 72% Enterprise, 21% Mid-Market


#### What Are IBM QRadar SOAR's Pros and Cons?

**Pros:**

- Ease of Use (5 reviews)
- Automation (3 reviews)
- Easy Integrations (3 reviews)
- Integrations (3 reviews)
- Customer Support (2 reviews)

**Cons:**

- Integration Issues (3 reviews)
- Complexity (2 reviews)
- Limited Integration (2 reviews)
- System Limitations (2 reviews)
- Bug Issues (1 reviews)


### What Do G2 Reviewers Say About IBM QRadar SOAR?
*AI-generated summary from verified user reviews*

**Pros:**

- Users highlight the **easy-to-use interface** of IBM QRadar SOAR, facilitating quick workflow creation and customization.
- Users find that IBM QRadar SOAR&#39;s **automation capabilities** significantly reduce manual tasks, enhancing efficiency in security operations.
- Users value the **easy integrations** with various tools, simplifying their security operations and workflows efficiently.
- Users appreciate the **seamless integration** with various tools, enhancing efficiency and streamlining security processes effectively.
- Users value the **responsive IBM support** and the ease of use of the QRadar SOAR console for quick resolutions.

**Cons:**

- Users face **integration issues** with IBM QRadar SOAR, limiting its functionality and complicating setups with other applications.
- Users find the **initial complexity** of IBM QRadar SOAR challenging, requiring time to master its extensive features.
- Users experience **limited integration** with IBM QRadar SOAR, making advanced configurations and implementation challenging.
- Users find the **system limitations** of IBM QRadar SOAR restrict effective transformations and complicate implementation efforts.
- Users report **bug issues** with IBM QRadar SOAR, including errors in workflows and occasional lagging performance.

#### What Are Recent G2 Reviews of IBM QRadar SOAR?

**"[Analyze Soar Qradar](https://www.g2.com/survey_responses/ibm-qradar-soar-review-9842312)"**

**Rating:** 5.0/5.0 stars
*— Aparecido A.*

[Read full review](https://www.g2.com/survey_responses/ibm-qradar-soar-review-9842312)

---

**"[IBM Security QRadar SOAR](https://www.g2.com/survey_responses/ibm-qradar-soar-review-9696782)"**

**Rating:** 4.5/5.0 stars
*— Prashanth K.*

[Read full review](https://www.g2.com/survey_responses/ibm-qradar-soar-review-9696782)

---



### 2. [Splunk SOAR (Security Orchestration, Automation and Response)](https://www.g2.com/products/splunk-soar-security-orchestration-automation-and-response/reviews)
Splunk SOAR provides security orchestration, automation and response capabilities that allow security analysts to work smarter by automating repetitive tasks; respond to security incidents faster with automated detection, investigation, and response; increase productivity, efficiency and accuracy; and strengthen defenses by connecting and coordinating complex workflows across their team and tools. Splunk SOAR also supports a broad range of security operations center (SOC) functions including event and case management, integrated threat intelligence, collaboration tools and reporting.


**Average Rating:** 4.4/5.0
**Total Reviews:** 39
**How Do G2 Users Rate Splunk SOAR (Security Orchestration, Automation and Response)?**

- **Threat Intelligence:** 8.8/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.8/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.0/10 (Category avg: 8.4/10)
- **Incident Logs:** 8.9/10 (Category avg: 8.8/10)

**Who Is the Company Behind Splunk SOAR (Security Orchestration, Automation and Response)?**

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco (720,366 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/cisco/ (95,545 employees on LinkedIn®)
- **Ownership:** NASDAQ:CSCO

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Consulting
- **Company Size:** 40% Mid-Market, 35% Enterprise


#### What Are Splunk SOAR (Security Orchestration, Automation and Response)'s Pros and Cons?

**Pros:**

- Automation (16 reviews)
- Security (13 reviews)
- Features (9 reviews)
- Threat Detection (8 reviews)
- Ease of Use (7 reviews)

**Cons:**

- Expensive (16 reviews)
- Learning Curve (7 reviews)
- Difficult Learning (6 reviews)
- Complexity (5 reviews)
- Poor Interface Design (4 reviews)


### What Do G2 Reviewers Say About Splunk SOAR (Security Orchestration, Automation and Response)?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **automation capabilities** of Splunk SOAR, enhancing security and response efficiency dramatically.
- Users value the **effective incident management** of Splunk SOAR, enhancing security response and automation in their workflows.
- Users value the **flexibility and integration** of Splunk SOAR, allowing seamless workflow orchestration for enhanced security.
- Users appreciate the **easy threat detection** capability of Splunk SOAR, enhancing security analysis and response efficiency.
- Users value the **ease of use** of Splunk SOAR, appreciating its intuitive UI and seamless integration capabilities.

**Cons:**

- Users find the **high cost** of Splunk SOAR prohibitive, making it difficult for average users to afford.
- Users find the **learning curve steep** , requiring extensive knowledge and training to effectively use Splunk SOAR.
- Users find the **difficult learning curve** to be challenging, especially for beginners new to automation platforms.
- Users find the **complexity** of Splunk SOAR challenging, requiring extensive learning for effective use.
- Users find the **poor interface design** of Splunk SOAR challenging, particularly for those new to automation platforms.

#### What Are Recent G2 Reviews of Splunk SOAR (Security Orchestration, Automation and Response)?

**"[Splunk SOAR is an awesome automation and security software](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922387)"**

**Rating:** 5.0/5.0 stars
*— Noor  Z.*

[Read full review](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922387)

---

**"[Splunk SOAR is a good software for automation](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922172)"**

**Rating:** 5.0/5.0 stars
*— Dheeraj T.*

[Read full review](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922172)

---


#### What Are G2 Users Discussing About Splunk SOAR (Security Orchestration, Automation and Response)?

- [What is Splunk SOAR (Security Orchestration, Automation and Response) used for?](https://www.g2.com/discussions/what-is-splunk-soar-security-orchestration-automation-and-response-used-for)

### 3. [Intezer](https://www.g2.com/products/intezer-intezer/reviews)
Intezer automates the entire alert triage process, like an extension of your team handling Tier 1 SOC tasks for every alert at machine-speed. Intezer monitors incoming incidents from endpoint, reported phishing pipelines, or SIEM tools, then autonomously collects evidence, investigates, makes triage decisions, and escalates only the serious threats to your team for human intervention. Power your SOC with artificial intelligence that makes sure every alert is deeply analyzed (including every single artifact like files, URLs, endpoint memory, etc.), detecting malicious code in memory and other evasive threats. Fast set up and integrations with your SOC team&#39;s workflows (EDR, SOAR, SIEM, etc.) means Intezer&#39;s AI can immediately start filtering out false positives, giving you detailed analysis about every threat, and speeding up your incident response time. With Intezer: • Reduce Tier 1 escalation, sending only 4% of alerts on average to your team for immediate action. • Identify up to 97% of false positive alerts without taking any time from your analysts. • Reduce average triage time to 5 minutes or less, while giving your analysts deep context about every alert to prioritize critical treats and respond faster.


**Average Rating:** 4.5/5.0
**Total Reviews:** 187
**How Do G2 Users Rate Intezer?**

- **Threat Intelligence:** 8.9/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.6/10 (Category avg: 8.8/10)
- **Incident Case Management:** 7.8/10 (Category avg: 8.4/10)
- **Incident Logs:** 9.4/10 (Category avg: 8.8/10)

**Who Is the Company Behind Intezer?**

- **Seller:** [Intezer](https://www.g2.com/sellers/intezer)
- **Year Founded:** 2015
- **HQ Location:** New York
- **Twitter:** @IntezerLabs (10,170 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/10656303/ (88 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** Software Engineer, Student
- **Top Industries:** Computer &amp; Network Security, Information Technology and Services
- **Company Size:** 54% Small-Business, 23% Mid-Market


#### What Are Intezer's Pros and Cons?

**Pros:**

- Security (3 reviews)
- Security Protection (3 reviews)
- Cybersecurity (2 reviews)
- Detection Accuracy (2 reviews)
- Ease of Use (2 reviews)

**Cons:**

- Access Control (1 reviews)
- Complex Interface (1 reviews)
- Data Privacy (1 reviews)
- Difficult Navigation (1 reviews)
- Expensive (1 reviews)


### What Do G2 Reviewers Say About Intezer?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **strong security features** of Intezer, ensuring timely detection and blocking of malware.
- Users value Intezer for its **effective malware detection and security features** that enhance overall system protection.
- Users value the **ease of malware detection and blocking** with Intezer, enhancing overall cybersecurity effectiveness.
- Users value the **high detection accuracy** of Intezer, ensuring timely malware detection and enhanced system security.
- Users appreciate the **ease of use** of Intezer, making malware detection and security integration straightforward and efficient.

**Cons:**

- Users find the **lack of access control** to file visibility a downside, though it facilitates peer review benefits.
- Users express frustration with the **complex interface** of Intezer, finding it difficult to navigate and use effectively.
- Users find the **lack of control over file visibility** a downside, despite potential benefits for peer review.
- Users find the **difficult navigation** in Intezer frustrating due to a poorly designed UI and small text size.
- Users find the **expensive pricing** of Intezer limiting, particularly due to the capping of the free tier.

#### What Are Recent G2 Reviews of Intezer?

**"[CTI coordinator](https://www.g2.com/survey_responses/intezer-review-5353729)"**

**Rating:** 4.0/5.0 stars
*— Verified User in Banking*

[Read full review](https://www.g2.com/survey_responses/intezer-review-5353729)

---

**"[Effortless Malware Detection and Robust Endpoint Security With Intezer](https://www.g2.com/survey_responses/intezer-review-12060113)"**

**Rating:** 4.5/5.0 stars
*— Franck P.*

[Read full review](https://www.g2.com/survey_responses/intezer-review-12060113)

---


#### What Are G2 Users Discussing About Intezer?

- [What is genetic malware analysis?](https://www.g2.com/discussions/what-is-genetic-malware-analysis) - 1 comment
- [Is Intezer good?](https://www.g2.com/discussions/is-intezer-good) - 1 comment
- [What does Intezer do?](https://www.g2.com/discussions/what-does-intezer-do) - 1 comment
- [What is Intezer analyze?](https://www.g2.com/discussions/what-is-intezer-analyze) - 2 comments

### 4. [LogRhythm SIEM](https://www.g2.com/products/exabeam-logrhythm-siem/reviews)
Rapidly deploy LogRhythm SIEM, the leading self-hosted SIEM, to secure your organization with powerful detections, synchronized threat intelligence, automated workflows, and achieve faster, more accurate threat detection, investigation, and response (TDIR).


**Average Rating:** 4.2/5.0
**Total Reviews:** 137
**How Do G2 Users Rate LogRhythm SIEM?**

- **Threat Intelligence:** 8.7/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.5/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.7/10 (Category avg: 8.4/10)
- **Incident Logs:** 8.8/10 (Category avg: 8.8/10)

**Who Is the Company Behind LogRhythm SIEM?**

- **Seller:** [Exabeam](https://www.g2.com/sellers/exabeam)
- **Year Founded:** 2013
- **HQ Location:** Broomfield, CO
- **Twitter:** @exabeam (5,374 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/exabeam (793 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** Information Security Analyst, Cyber Security Analyst
- **Top Industries:** Information Technology and Services, Computer &amp; Network Security
- **Company Size:** 40% Enterprise, 40% Mid-Market



#### What Are Recent G2 Reviews of LogRhythm SIEM?

**"[More than a SIEM](https://www.g2.com/survey_responses/logrhythm-siem-review-10516628)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Banking*

[Read full review](https://www.g2.com/survey_responses/logrhythm-siem-review-10516628)

---

**"[LogRhythm SIEM - Best Solution In Market](https://www.g2.com/survey_responses/logrhythm-siem-review-11463953)"**

**Rating:** 5.0/5.0 stars
*— Vishwa  K.*

[Read full review](https://www.g2.com/survey_responses/logrhythm-siem-review-11463953)

---


#### What Are G2 Users Discussing About LogRhythm SIEM?

- [What are some SIEM tools?](https://www.g2.com/discussions/what-are-some-siem-tools)
- [What does a SIEM platform do?](https://www.g2.com/discussions/what-does-a-siem-platform-do)
- [How does Siem LogRhythm work?](https://www.g2.com/discussions/how-does-siem-logrhythm-work)
- [What is LogRhythm software?](https://www.g2.com/discussions/what-is-logrhythm-software)

### 5. [Splunk Synthetic Monitoring](https://www.g2.com/products/splunk-synthetic-monitoring/reviews)
Splunk Synthetic Monitoring helps you measure and improve uptime and performance for your critical apps and services. Splunk Synthetic Monitoring offers best-in class web performance optimization to delight your users and improve customer experience, while helping improve your SLAs and easily test your entire user funnel and key web and API functionality.


**Average Rating:** 4.5/5.0
**Total Reviews:** 26
**How Do G2 Users Rate Splunk Synthetic Monitoring?**

- **Threat Intelligence:** 8.1/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.2/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.1/10 (Category avg: 8.4/10)
- **Incident Logs:** 9.1/10 (Category avg: 8.8/10)

**Who Is the Company Behind Splunk Synthetic Monitoring?**

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco (720,366 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/cisco/ (95,545 employees on LinkedIn®)
- **Ownership:** NASDAQ:CSCO

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security
- **Company Size:** 50% Enterprise, 38% Small-Business



#### What Are Recent G2 Reviews of Splunk Synthetic Monitoring?

**"[Splunk review](https://www.g2.com/survey_responses/splunk-synthetic-monitoring-review-11449320)"**

**Rating:** 4.5/5.0 stars
*— Rajesh J.*

[Read full review](https://www.g2.com/survey_responses/splunk-synthetic-monitoring-review-11449320)

---

**"[Best Proactive Monitoring Tool](https://www.g2.com/survey_responses/splunk-synthetic-monitoring-review-8658705)"**

**Rating:** 4.5/5.0 stars
*— Verified User in Computer Software*

[Read full review](https://www.g2.com/survey_responses/splunk-synthetic-monitoring-review-8658705)

---



### 6. [SIRP](https://www.g2.com/products/sirp/reviews)
SIRP is an AI-native Autonomous SOC platform designed to evolve traditional Security Orchestration, Automation, and Response (SOAR) into governed, decision-driven security operations. Unlike legacy SOAR tools that rely on static playbooks and workflow automation, SIRP enables intelligent AI agents to analyze alerts, compute risk, execute response actions, and continuously learn from outcomes within defined policy boundaries. The platform combines contextual reasoning, real-time intelligence, and adaptive learning to reduce manual triage, minimize alert fatigue, and accelerate incident response while maintaining governance, auditability, and control. SIRP supports enterprise SOC teams and MSSPs seeking to operate at machine speed without sacrificing human oversight for high-impact decisions.


**Average Rating:** 4.7/5.0
**Total Reviews:** 22
**How Do G2 Users Rate SIRP?**

- **Threat Intelligence:** 9.8/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.8/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.8/10 (Category avg: 8.4/10)
- **Incident Logs:** 9.5/10 (Category avg: 8.8/10)

**Who Is the Company Behind SIRP?**

- **Seller:** [SIRP](https://www.g2.com/sellers/sirp)
- **Year Founded:** 2017
- **HQ Location:** Bethesda, Maryland
- **Twitter:** @sirp_io (74 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/13684515/ (57 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services
- **Company Size:** 41% Small-Business, 37% Mid-Market


#### What Are SIRP's Pros and Cons?

**Pros:**

- Automation (1 reviews)
- Customer Support (1 reviews)
- Ease of Use (1 reviews)
- Easy Integrations (1 reviews)
- Features (1 reviews)



### What Do G2 Reviewers Say About SIRP?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **automation capabilities** of SIRP, appreciating its comprehensive tools for security orchestration and incident management.
- Users value the **excellent customer support** from SIRP, enhancing their experience with the tool&#39;s capabilities.
- Users find SIRP&#39;s **ease of use** enhances their experience with efficient security management tools and support.
- Users value the **easy integrations** with SIRP, facilitating seamless connectivity and enhancing overall security automation.
- Users commend SIRP for its **ease of use and excellent support** , enhancing security automation and incident management seamlessly.


#### What Are Recent G2 Reviews of SIRP?

**"[SIRP increased our SOC capabilities by 10x. Amazing automation with even better support team](https://www.g2.com/survey_responses/sirp-review-7612417)"**

**Rating:** 5.0/5.0 stars
*— Mushtaq Ahmed K.*

[Read full review](https://www.g2.com/survey_responses/sirp-review-7612417)

---

**"[Data Aggregation, Ease of Access and Quick Reporting](https://www.g2.com/survey_responses/sirp-review-4217597)"**

**Rating:** 4.5/5.0 stars
*— Iqra Z.*

[Read full review](https://www.g2.com/survey_responses/sirp-review-4217597)

---



### 7. [LevelBlue USM Anywhere](https://www.g2.com/products/levelblue-usm-anywhere/reviews)
LevelBlue USM Anywhere is a cloud-based security management solution that accelerates and centralizes threat detection, incident response, and compliance management for your cloud, hybrid cloud, and on-premises environments. USM Anywhere includes purpose-built cloud sensors that natively monitor your Amazon Web Services (AWS) and Microsoft Azure cloud environments. On premises, lightweight virtual sensors run on Microsoft Hyper-V and VMware ESXi to monitor your virtual private cloud and physical IT infrastructure. With USM Anywhere, you can rapidly deploy sensors into your cloud and on-premises environments while centrally managing data collection, security analysis, and threat detection from the AlienVault Secure Cloud. Five Essential Security Capabilities in a Single SaaS Platform AlienVault USM Anywhere provides five essential security capabilities in a single SaaS solution, giving you everything you need for threat detection, incident response, and compliance management—all in a single pane of glass. With USM Anywhere, you can focus on finding and responding to threats, not managing software. An elastic, cloud-based security solution, USM Anywhere can readily scale to meet your threat detection needs as your hybrid cloud environment changes and grows. 1. Asset Discovery 2. Vulnerability Assessment 3. Intrusion Detection 4. Behavioral Monitoring 5. SIEM


**Average Rating:** 4.4/5.0
**Total Reviews:** 102
**How Do G2 Users Rate LevelBlue USM Anywhere?**

- **Threat Intelligence:** 9.2/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.6/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.3/10 (Category avg: 8.4/10)
- **Incident Logs:** 9.2/10 (Category avg: 8.8/10)

**Who Is the Company Behind LevelBlue USM Anywhere?**

- **Seller:** [LevelBlue](https://www.g2.com/sellers/levelblue-49a2e3c1-ca90-4308-b899-08973f657bae)
- **HQ Location:** Dallas, Texas, United States
- **LinkedIn® Page:** https://www.linkedin.com/company/levelbluecyber/ (782 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 62% Mid-Market, 20% Small-Business



#### What Are Recent G2 Reviews of LevelBlue USM Anywhere?

**"[Comprehensive cloud security and monitoring platform](https://www.g2.com/survey_responses/levelblue-usm-anywhere-review-11718892)"**

**Rating:** 5.0/5.0 stars
*— Luis Emmanuel M.*

[Read full review](https://www.g2.com/survey_responses/levelblue-usm-anywhere-review-11718892)

---

**"[Impressive Cloud Based SIEM](https://www.g2.com/survey_responses/levelblue-usm-anywhere-review-9698214)"**

**Rating:** 4.5/5.0 stars
*— Goodness  I.*

[Read full review](https://www.g2.com/survey_responses/levelblue-usm-anywhere-review-9698214)

---


#### What Are G2 Users Discussing About LevelBlue USM Anywhere?

- [How has AlienVault USM supported your cybersecurity efforts, and what features do you rely on most?](https://www.g2.com/discussions/how-has-alienvault-usm-supported-your-cybersecurity-efforts-and-what-features-do-you-rely-on-most)
- [What is AlienVault USM (from AT&amp;T Cybersecurity) used for?](https://www.g2.com/discussions/what-is-alienvault-usm-from-at-t-cybersecurity-used-for)

### 8. [Guardsix](https://www.g2.com/products/guardsix/reviews)
Guardsix is the sovereign security platform for lean European teams, bringing log management and audit-ready compliance to regulated industries, critical national infrastructure operators, and the Managed Security Service Providers (MSSPs) that serve them throughout Europe and beyond. Headquartered in Copenhagen, Denmark, Guardsix delivers sovereign-by-design security for organisations that carry real operational responsibility. The company employs several hundred cyber security specialists and keeps every organisation it serves in full control of their data, deployment, and operations. Guardsix provides a unified Command Centre platform combining: • Security Information and Event Management (SIEM) • Network Detection and Response (NDR) • Security Orchestration, Automation and Response (SOAR) • Fleet for enabling multi-tenant management • Governance for Healthcare internal risk compliance monitoring The platform is built to support European data sovereignty, regulatory compliance and operational control, with predictable node-based pricing and deployment options spanning on-premises, air-gapped, hybrid and cloud environments. Guardsix solutions help organisations: • Simplify audit readiness for regulations such as NIS2, DORA, and GDPR. • Support lean security teams with efficient log management and simplified workflows. • Scale security operations without increased complexity or ingestion-led pricing surprises. • Keep security data under European jurisdiction and control — where it lives, who operates it, and under whose laws. • Deploy on their own terms, on-prem and in infrastructure they control, keeping migration a real option at every renewal. • See clearly across their whole environment, with SIEM, NDR, SOAR, Fleet, and Governance in one sovereign platform rather than a stack of point tools. Guardsix maintains SOC 2 Type II attestation and designs its solutions in accordance with European data protection requirements. With a strong partner-first model, Guardsix works closely with regional MSSPs and service providers, combining sovereign-by-design security technology with European integrity and deployment flexibility.


**Average Rating:** 4.3/5.0
**Total Reviews:** 105
**How Do G2 Users Rate Guardsix?**

- **Threat Intelligence:** 8.4/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.0/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.3/10 (Category avg: 8.4/10)
- **Incident Logs:** 8.7/10 (Category avg: 8.8/10)

**Who Is the Company Behind Guardsix?**

- **Seller:** [guardsix](https://www.g2.com/sellers/guardsix)
- **Company Website:** https://guardsix.com/
- **Year Founded:** 2001
- **HQ Location:** Copenhagen, Capital Region
- **LinkedIn® Page:** https://linkedin.com/company/guardsix (162 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security, Information Technology and Services
- **Company Size:** 44% Mid-Market, 31% Small-Business


#### What Are Guardsix's Pros and Cons?

**Pros:**

- Ease of Use (8 reviews)
- Log Management (5 reviews)
- Customer Support (4 reviews)
- Easy Integrations (4 reviews)
- Efficiency (4 reviews)

**Cons:**

- Poor Interface Design (3 reviews)
- UX Improvement (3 reviews)
- Complexity (2 reviews)
- Confusing Interface (2 reviews)
- Information Deficiency (2 reviews)


### What Do G2 Reviewers Say About Guardsix?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **ease of use** of Guardsix, making administration and navigation simple and efficient.
- Users appreciate the **effortless integration and usability** of Logpoint, enhancing efficiency in managing diverse log data.
- Users appreciate the **excellent customer support** provided by Logpoint, enhancing their experience and satisfaction with the product.
- Users appreciate the **easy integrations** of Guardsix, allowing seamless compatibility with their tech ecosystem for enhanced functionality.
- Users appreciate the **efficiency** of Guardsix in managing incidents and integrating with existing tools seamlessly.

**Cons:**

- Users criticize the **poor interface design** of Guardsix, finding it difficult to understand and navigate effectively.
- Users find the **poor log presentation** and overall interface slow, hindering their experience with Guardsix.
- Users find the **interface complexity** challenging, but hope for improvements in the near future.
- Users find the **confusing interface** of Guardsix difficult to navigate and slow to respond.
- Users find there is an **information deficiency** regarding appliance design and resource requirements for new devices.

#### What Are Recent G2 Reviews of Guardsix?

**"[Context-Driven SIEM That Enhances Incident Response](https://www.g2.com/survey_responses/guardsix-review-11985484)"**

**Rating:** 4.5/5.0 stars
*— Simon A.*

[Read full review](https://www.g2.com/survey_responses/guardsix-review-11985484)

---

**"[Review](https://www.g2.com/survey_responses/guardsix-review-11378057)"**

**Rating:** 4.0/5.0 stars
*— Ronny K.*

[Read full review](https://www.g2.com/survey_responses/guardsix-review-11378057)

---


#### What Are G2 Users Discussing About Guardsix?

- [What is your experience with Logpoint for SIEM, and what do you recommend for new users?](https://www.g2.com/discussions/what-is-your-experience-with-logpoint-for-siem-and-what-do-you-recommend-for-new-users)
- [What is LogPoint used for?](https://www.g2.com/discussions/what-is-logpoint-used-for)

### 9. [TheHive](https://www.g2.com/products/thehive/reviews)
TheHive is a collaborative security case management platform designed to help SOC, CERT, CSIRT and MSSP teams manage the full incident response lifecycle. It serves as a central hub where security analysts can receive and triage alerts, conduct investigations, coordinate team actions and close incidents—all without switching tools. The platform integrates natively with other security tools, allowing teams to operate within existing workflows rather than replacing them. TheHive supports multi-tenancy, making it suitable for MSSPs and large organizations that manage security operations across multiple clients, business units or environments. Key capabilities include: - 300+ pre-built integrations: Connect TheHive to your SIEM, EDR, threat intelligence platforms, ticketing systems and other tools to embed it into existing infrastructure. - Alert ingestion and triage: Automatically receive, deduplicate and prioritize alerts from connected sources, with full visibility into alert status and assignment across the team. - Case and task management: Organize investigations using cases and tasks with defined ownership to maintain transparency and accountability. - Multi-tenancy and client isolation: Run separate, isolated workspaces for different clients or internal teams from a single deployment, with granular access controls and role-based permissions. - Automation: Trigger automated investigation or response actions, analyst notifications and third-party integrations, reducing manual effort. - Reporting and compliance: Generate incident reports and maintain full audit trails across investigations. Give external stakeholders controlled access to specific case details. TheHive is developed and maintained by StrangeBee and is trusted by 3,500+ security professionals across 50+ countries. Organizations including BMW, Thales, Pipedrive, Garmin and Cisco use TheHive to centralize and speed up incident response actions, enforce consistent processes across distributed teams, scale security operations and reduce alert fatigue. The platform is available as an on-premises deployment or as a cloud-hosted service, with tiered plans designed to match the operational needs of mid-size to large security teams. It supports air-gapped environments and offers deployment flexibility for organizations with strict data residency or compliance requirements.


**Average Rating:** 4.3/5.0
**Total Reviews:** 18
**How Do G2 Users Rate TheHive?**

- **Threat Intelligence:** 8.9/10 (Category avg: 8.9/10)
- **Quality of Support:** 7.9/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.3/10 (Category avg: 8.4/10)
- **Incident Logs:** 8.6/10 (Category avg: 8.8/10)

**Who Is the Company Behind TheHive?**

- **Seller:** [StrangeBee](https://www.g2.com/sellers/strangebee)
- **Company Website:** https://strangebee.com/
- **Year Founded:** 2018
- **HQ Location:** Paris, FR
- **Twitter:** @StrangeBee (9,614 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/strangebee/ (73 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 50% Enterprise, 33% Mid-Market


#### What Are TheHive's Pros and Cons?

**Pros:**

- Customization (1 reviews)
- Ease of Use (1 reviews)
- Features (1 reviews)
- Integrations (1 reviews)
- Product Innovation (1 reviews)

**Cons:**

- Complex Setup (1 reviews)
- Lack of Guidance (1 reviews)
- Learning Curve (1 reviews)


### What Do G2 Reviewers Say About TheHive?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **customizable workflows** of TheHive, enhancing efficiency in incident management for teams.
- Users find TheHive&#39;s **ease of use** and scalability ideal for efficiently managing incident response in SOCs and CSIRTs.
- Users value the **good integrations and customizable workflows** of TheHive, enhancing collaborative incident management for SOCs and CSIRTs.
- Users appreciate the **excellent integrations** of TheHive, enhancing collaboration and efficiency in incident management.
- Users appreciate the **customizable workflows and integrations** of TheHive, enhancing collective incident management for SOCs and CSIRTs.

**Cons:**

- Users find the **complex setup** of TheHive daunting, often requiring community support for troubleshooting delays.
- Users feel the **lack of guidance** in TheHive makes it challenging for new users to navigate and troubleshoot effectively.
- New users find the **steep learning curve** of TheHive challenging, often requiring substantial community assistance for setup.

#### What Are Recent G2 Reviews of TheHive?

**"[Incident Response Platform: TheHive](https://www.g2.com/survey_responses/thehive-review-9717461)"**

**Rating:** 5.0/5.0 stars
*— Sam F.*

[Read full review](https://www.g2.com/survey_responses/thehive-review-9717461)

---

**"[Opensource Case Management: TheHive](https://www.g2.com/survey_responses/thehive-review-8248979)"**

**Rating:** 5.0/5.0 stars
*— Rohan G.*

[Read full review](https://www.g2.com/survey_responses/thehive-review-8248979)

---


#### What Are G2 Users Discussing About TheHive?

- [What is TheHive used for?](https://www.g2.com/discussions/what-is-thehive-used-for) - 1 comment

### 10. [Mozilla Enterprise Defense Platform](https://www.g2.com/products/mozilla-enterprise-defense-platform/reviews)
The Mozilla Enterprise Defense Platform (MozDef) seeks to automate the security incident handling process and facilitate the real-time activities of incident handlers.


**Average Rating:** 4.3/5.0
**Total Reviews:** 10
**How Do G2 Users Rate Mozilla Enterprise Defense Platform?**

- **Threat Intelligence:** 8.3/10 (Category avg: 8.9/10)
- **Quality of Support:** 7.1/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.5/10 (Category avg: 8.4/10)
- **Incident Logs:** 8.3/10 (Category avg: 8.8/10)

**Who Is the Company Behind Mozilla Enterprise Defense Platform?**

- **Seller:** [Mozilla](https://www.g2.com/sellers/mozilla)
- **Year Founded:** 2005
- **HQ Location:** San Francisco, CA
- **Twitter:** @mozilla (261,861 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/13948/ (1,751 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 40% Small-Business, 40% Mid-Market



#### What Are Recent G2 Reviews of Mozilla Enterprise Defense Platform?

**"[Best Defence Platform](https://www.g2.com/survey_responses/mozilla-enterprise-defense-platform-review-7817941)"**

**Rating:** 5.0/5.0 stars
*— Shreyas M.*

[Read full review](https://www.g2.com/survey_responses/mozilla-enterprise-defense-platform-review-7817941)

---

**"[Streamline Your Security Operations with MozDef](https://www.g2.com/survey_responses/mozilla-enterprise-defense-platform-review-7896625)"**

**Rating:** 4.0/5.0 stars
*— Hremant C.*

[Read full review](https://www.g2.com/survey_responses/mozilla-enterprise-defense-platform-review-7896625)

---


#### What Are G2 Users Discussing About Mozilla Enterprise Defense Platform?

- [What is Mozilla Enterprise Defense Platform used for?](https://www.g2.com/discussions/what-is-mozilla-enterprise-defense-platform-used-for) - 1 comment

### 11. [D3 Security](https://www.g2.com/products/d3-security/reviews)
D3 stands at the forefront of AI-powered security, providing real-time, autonomous SOC solutions that help organizations stay ahead of cyber threats. By merging autonomous investigation and triage with AI-guided remediation, D3 is delivering AI-powered, human-led cyber security solutions. Morpheus is D3 Security’s fully autonomous SOC solution that triages, investigates, and responds to every alert, 24/7. Morpheus covers 100% of your alerts — no exceptions — so your team never has to choose between chasing false positives or risking a breach. It triages 95% of alerts in under two minutes, integrating seamlessly with any SIEM, XDR, or security stack. Unlike traditional SOAR platforms, Morpheus doesn’t need endless playbook tuning; it can build response workflows on the fly, specific to your security stack. The result? Zero alert fatigue, fewer missed threats, and a dramatic boost in SOC efficiency, powered by a data privacy-friendly and SecOps-focused AI model.


**Average Rating:** 4.2/5.0
**Total Reviews:** 64
**How Do G2 Users Rate D3 Security?**

- **Threat Intelligence:** 9.0/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.0/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.9/10 (Category avg: 8.4/10)

**Who Is the Company Behind D3 Security?**

- **Seller:** [D3 Security Management Systems](https://www.g2.com/sellers/d3-security-management-systems)
- **Year Founded:** 2012
- **HQ Location:** Vancouver, British Columbia
- **Twitter:** @D3Security (1,118 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/342986/ (162 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 49% Enterprise, 41% Mid-Market



#### What Are Recent G2 Reviews of D3 Security?

**"[The best security operation platform](https://www.g2.com/survey_responses/d3-security-review-3110773)"**

**Rating:** 5.0/5.0 stars
*— George K.*

[Read full review](https://www.g2.com/survey_responses/d3-security-review-3110773)

---

**"[Next Generation SOAR Platform](https://www.g2.com/survey_responses/d3-security-review-7793810)"**

**Rating:** 4.5/5.0 stars
*— Kristian T.*

[Read full review](https://www.g2.com/survey_responses/d3-security-review-7793810)

---



### 12. [Check Point SmartEvent Event Management](https://www.g2.com/products/check-point-smartevent-event-management/reviews)
SmartEvent event management provides full threat visibility with a single view into security risks. Take control and command the security event through real-time forensic and event investigation, compliance, and reporting. Respond to security incidents immediately and gain network true insights. Features include: integrated threat management, single view into security risks, customizable views and reports, full threat visibility, and real-time forensic and event investigation.


**Average Rating:** 4.4/5.0
**Total Reviews:** 13
**How Do G2 Users Rate Check Point SmartEvent Event Management?**

- **Threat Intelligence:** 9.0/10 (Category avg: 8.9/10)
- **Quality of Support:** 7.8/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.3/10 (Category avg: 8.4/10)
- **Incident Logs:** 9.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Check Point SmartEvent Event Management?**

- **Seller:** [Check Point Software Technologies](https://www.g2.com/sellers/check-point-software-technologies)
- **Year Founded:** 1993
- **HQ Location:** Redwood City, CA
- **Twitter:** @CheckPointSW (70,955 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/check-point-software-technologies/ (8,554 employees on LinkedIn®)
- **Ownership:** NASDAQ:CHKP

**Who Uses This Product?**
- **Company Size:** 69% Enterprise, 23% Mid-Market


#### What Are Check Point SmartEvent Event Management's Pros and Cons?

**Pros:**

- Threat Detection (2 reviews)
- Visibility (2 reviews)
- Alerting (1 reviews)
- Ease of Use (1 reviews)
- Monitoring (1 reviews)

**Cons:**

- Complexity (1 reviews)
- Deployment Difficulties (1 reviews)
- Difficult Learning (1 reviews)
- Learning Curve (1 reviews)
- Setup Difficulty (1 reviews)


### What Do G2 Reviewers Say About Check Point SmartEvent Event Management?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **full threat visibility** of Check Point SmartEvent, enabling quick and informed responses to security risks.
- Users appreciate the **full threat visibility** of SmartEvent, enabling quick responses with essential context in security events.
- Users value the **effective alerting** of SmartEvent, providing clarity and context for quick response to events.
- Users appreciate the **ease of use** of SmartEvent, enabling quick responses by filtering out irrelevant network events.
- Users value the **effective event monitoring** of Check Point SmartEvent, enabling quick responses without unnecessary noise.

**Cons:**

- Users find SmartEvent to have a **steep learning curve** due to overwhelming amounts of data and setup challenges.
- Users face **deployment difficulties** with random CPSEMD terminations causing login failures and increased CPU usage in SmartEvent.
- Users face **difficult learning** curves due to random CPSEMD process termination, causing login failures and high CPU usage.
- Users find the **initial learning curve steep** , as it takes time to fine-tune filters for relevant alerts.
- Users report **setup difficulties** , including random CPSEMD process terminations causing login failures and high CPU usage.

#### What Are Recent G2 Reviews of Check Point SmartEvent Event Management?

**"[SmartEvent Keeps Us Ahead of the Curve](https://www.g2.com/survey_responses/check-point-smartevent-event-management-review-11790784)"**

**Rating:** 4.5/5.0 stars
*— D. A.*

[Read full review](https://www.g2.com/survey_responses/check-point-smartevent-event-management-review-11790784)

---

**"[SmartEvent](https://www.g2.com/survey_responses/check-point-smartevent-event-management-review-11095641)"**

**Rating:** 4.5/5.0 stars
*— Verified User in Banking*

[Read full review](https://www.g2.com/survey_responses/check-point-smartevent-event-management-review-11095641)

---


#### What Are G2 Users Discussing About Check Point SmartEvent Event Management?

- [What does an event management website do?](https://www.g2.com/discussions/what-does-an-event-management-website-do)
- [What are the benefits of event management?](https://www.g2.com/discussions/what-are-the-benefits-of-event-management)
- [What is SmartEvent?](https://www.g2.com/discussions/what-is-smartevent)
- [What are the features of event management?](https://www.g2.com/discussions/what-are-the-features-of-event-management)

### 13. [FortiEDR](https://www.g2.com/products/fortiedr/reviews)
FortiEDR identifies and stops breaches in real time automatically and efficiently with a lightweight agent. Part of the Fortinet Security Operations platform, it proactively shrinks the attack surface, prevents malware infection, detects and defuses potential threats immediately, and automates response and remediation procedures with customizable playbooks across legacy and current operating systems.


**Average Rating:** 4.5/5.0
**Total Reviews:** 12
**How Do G2 Users Rate FortiEDR?**

- **Threat Intelligence:** 7.8/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.3/10 (Category avg: 8.8/10)
- **Incident Case Management:** 7.5/10 (Category avg: 8.4/10)
- **Incident Logs:** 9.2/10 (Category avg: 8.8/10)

**Who Is the Company Behind FortiEDR?**

- **Seller:** [Fortinet](https://www.g2.com/sellers/fortinet)
- **Year Founded:** 2000
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @Fortinet (151,422 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/6460/ (16,279 employees on LinkedIn®)
- **Ownership:** NASDAQ: FTNT

**Who Uses This Product?**
- **Company Size:** 50% Mid-Market, 33% Enterprise



#### What Are Recent G2 Reviews of FortiEDR?

**"[FortiEDR Another Great Endpoint Solution from Fortinet](https://www.g2.com/survey_responses/fortiedr-review-8405780)"**

**Rating:** 4.5/5.0 stars
*— Pravin I.*

[Read full review](https://www.g2.com/survey_responses/fortiedr-review-8405780)

---

**"[The best defense against cyber attacks and threats](https://www.g2.com/survey_responses/fortiedr-review-8305682)"**

**Rating:** 4.5/5.0 stars
*— Marina B.*

[Read full review](https://www.g2.com/survey_responses/fortiedr-review-8305682)

---


#### What Are G2 Users Discussing About FortiEDR?

- [What is FortiEDR collector service?](https://www.g2.com/discussions/fortiedr-what-is-fortiedr-collector-service)
- [What is FortiEDR collector service?](https://www.g2.com/discussions/what-is-fortiedr-collector-service)
- [How good is FortiEDR?](https://www.g2.com/discussions/fortiedr-how-good-is-fortiedr)
- [How good is FortiEDR?](https://www.g2.com/discussions/how-good-is-fortiedr)
- [What is FortiEDR?](https://www.g2.com/discussions/fortiedr-what-is-fortiedr)

### 14. [OpenCTI by Filigran](https://www.g2.com/products/opencti-by-filigran/reviews)
OpenCTI is an open-source threat intelligence platform designed to help users manage and operationalize threat intelligence effectively. Built by practitioners for practitioners, OpenCTI aims to break down data silos and ensure that threat intelligence is not only accessible but also actionable. This platform facilitates the seamless flow of threat intelligence across various security systems, making it relevant by integrating business context and enabling the creation of comprehensive threat exposure reports for enhanced executive visibility. The target audience for OpenCTI includes cybersecurity professionals, threat analysts, and organizations looking to improve their threat intelligence capabilities. By providing a centralized platform for threat data, OpenCTI allows users to visualize, link, and enrich threat intelligence, fostering collaboration among teams and enhancing the overall security posture of an organization. The platform is particularly beneficial for organizations that need to streamline their threat intelligence processes and ensure that critical information is readily available to decision-makers. Key features of OpenCTI include its unified and consistent data model based on the Structured Threat Information Expression (STIX) standard. This allows users to integrate diverse threat data sources into a single framework, making it easier to analyze and respond to threats. The platform supports various data formats and can ingest information from multiple feeds, enabling users to maintain a comprehensive view of the threat landscape. Additionally, OpenCTI offers advanced visualization tools that help users identify patterns and relationships within the data, facilitating more informed decision-making. Moreover, OpenCTI enhances the operationalization of threat intelligence by providing users with the tools to enrich their data with contextual information. This capability allows organizations to tailor their threat intelligence to their specific business needs, ensuring that the information is not only relevant but also actionable. By generating detailed threat exposure reports, OpenCTI empowers executives with the insights needed to understand their organization&#39;s risk landscape and make informed strategic decisions regarding cybersecurity investments and initiatives. Overall, OpenCTI stands out in the realm of threat intelligence platforms by prioritizing collaboration, accessibility, and contextual relevance. Its open-source nature encourages community involvement and continuous improvement, making it a valuable resource for organizations seeking to enhance their threat intelligence capabilities and strengthen their cybersecurity defenses.


**Average Rating:** 4.6/5.0
**Total Reviews:** 41
**How Do G2 Users Rate OpenCTI by Filigran?**

- **Threat Intelligence:** 9.3/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.8/10 (Category avg: 8.8/10)
- **Incident Logs:** 7.5/10 (Category avg: 8.8/10)

**Who Is the Company Behind OpenCTI by Filigran?**

- **Seller:** [Filigran](https://www.g2.com/sellers/filigran)
- **Company Website:** https://filigran.io/
- **Year Founded:** 2022
- **HQ Location:** New York, US
- **Twitter:** @FiligranHQ (841 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/filigran (250 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security, Information Technology and Services
- **Company Size:** 56% Enterprise, 29% Mid-Market


#### What Are OpenCTI by Filigran's Pros and Cons?

**Pros:**

- Ease of Use (18 reviews)
- Features (18 reviews)
- Customer Support (11 reviews)
- Integrations (10 reviews)
- Integration Capabilities (9 reviews)

**Cons:**

- Feature Limitations (6 reviews)
- Complexity (5 reviews)
- Poor Customer Support (4 reviews)
- Poor Documentation (4 reviews)
- Dashboard Issues (3 reviews)


### What Do G2 Reviewers Say About OpenCTI by Filigran?
*AI-generated summary from verified user reviews*

**Pros:**

- Users commend the **ease of use** of OpenCTI, enabling seamless integration and efficient threat analysis from day one.
- Users praise OpenCTI&#39;s **powerful automation and flexibility** , facilitating actionable intelligence and enhancing team collaboration.
- Users commend the **excellent customer support** of OpenCTI, highlighting their eagerness to assist and improve experiences.
- Users praise the **seamless integrations** of OpenCTI, enhancing their ability to centralize and utilize diverse data sources.
- Users value the **strong integration capabilities** of OpenCTI, enhancing threat intelligence and response workflows effectively.

**Cons:**

- Users find the **graphing and dashboard limitations** hinder flexibility and overall effectiveness of OpenCTI&#39;s features.
- Users find the **complexity of outputs and workflows** challenging, impacting effective application and overall user experience.
- Users often face **poor customer support** , resulting in challenges with connector quality and documentation issues.
- Users report **poor documentation** , making it challenging to effectively utilize OpenCTI and its features.
- Users find the **dashboard limitations** frustrating, with restricted displays and limited customization options affecting usability.

#### What Are Recent G2 Reviews of OpenCTI by Filigran?

**"[OpenCTI Centralizes Threat Intelligence with Strong STIX/TAXII Integrations and Responsive Support](https://www.g2.com/survey_responses/opencti-by-filigran-review-13101716)"**

**Rating:** 4.5/5.0 stars
*— Verified User in Financial Services*

[Read full review](https://www.g2.com/survey_responses/opencti-by-filigran-review-13101716)

---

**"[OpenCTI: The Threat Intelligence Platform That Lets Us Focus on Intelligence](https://www.g2.com/survey_responses/opencti-by-filigran-review-12355320)"**

**Rating:** 5.0/5.0 stars
*— Jeroen d.*

[Read full review](https://www.g2.com/survey_responses/opencti-by-filigran-review-12355320)

---



### 15. [Exaforce](https://www.g2.com/products/exaforce/reviews)
At Exaforce, we are on a mission to 10x the productivity and efficacy of security and operations (SOC) teams using our transformative multi-model AI engine. Our Agentic SOC Platform combines AI agents (“Exabots”) with advanced data exploration to deliver real-time insights, proactive detection and response, in-depth investigations, and automated workflows. Backed by Khosla Ventures, Mayfield, Thomvest Ventures, Touring Capital, and others, Exaforce helps SOC teams respond to threats and breaches faster, with higher precision, greater consistency, and at lower total costs—redefining how SOC teams function.


**Average Rating:** 4.9/5.0
**Total Reviews:** 7
**How Do G2 Users Rate Exaforce?**

- **Threat Intelligence:** 8.3/10 (Category avg: 8.9/10)
- **Quality of Support:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Exaforce?**

- **Seller:** [Exaforce](https://www.g2.com/sellers/exaforce)
- **Company Website:** https://www.exaforce.com
- **Year Founded:** 2023
- **HQ Location:** San Jose, CA
- **Twitter:** @exaforceAI (134 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/exaforce (60 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 57% Mid-Market, 29% Enterprise


#### What Are Exaforce's Pros and Cons?

**Pros:**

- Security (3 reviews)
- Support (3 reviews)
- Alerting System (2 reviews)
- Customer Support (2 reviews)
- Ease of Use (2 reviews)

**Cons:**

- Query Issues (1 reviews)
- Slow Performance (1 reviews)
- System Limitations (1 reviews)


### What Do G2 Reviewers Say About Exaforce?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **enhanced security operations** of Exaforce, combining AI and human review for effective incident management.
- Users commend Exaforce&#39;s **fantastic customer support** , appreciating their responsiveness and assistance with feature requests.
- Users value the **effective alerting system** of Exaforce, enhancing focus and streamlining investigation processes significantly.
- Users praise Exaforce for its **fantastic customer support** , which greatly enhances troubleshooting and feature request processes.
- Users value the **ease of use** of Exaforce, significantly enhancing their workflow efficiency and focus on critical findings.

**Cons:**

- Users experience **query issues** with Exaforce, including slow loading times and failures with complex datasets.
- Users experience **slow performance** with Exaforce, especially when loading complex queries and large datasets.
- Users often experience **slow interface loading** and issues with large datasets affecting usability and performance.

#### What Are Recent G2 Reviews of Exaforce?

**"[Exaforce Cuts Security Alert Noise and Speeds Up Remediation](https://www.g2.com/survey_responses/exaforce-review-12644503)"**

**Rating:** 5.0/5.0 stars
*— Monde H.*

[Read full review](https://www.g2.com/survey_responses/exaforce-review-12644503)

---

**"[Collaborative, AI-Powered Security Operations](https://www.g2.com/survey_responses/exaforce-review-12407665)"**

**Rating:** 5.0/5.0 stars
*— Patrick M.*

[Read full review](https://www.g2.com/survey_responses/exaforce-review-12407665)

---



### 16. [ThreatConnect TI Ops](https://www.g2.com/products/threatconnect-ti-ops/reviews)
TI Ops is the threat intelligence platform built for operations, not just centralization. It ingests hundreds of internal and external sources, enriches them with AI, and aligns them to your intelligence requirements and MITRE ATT&amp;CK gaps. Analysts can instantly operationalize insights across the SOC, IR, hunt, and vulnerability teams — no swivel-chairing required. When combined with Polarity and Risk Quantifier, TI Ops helps teams act on intelligence faster and focus on the threats that truly matter to the business.


**Average Rating:** 4.6/5.0
**Total Reviews:** 14
**How Do G2 Users Rate ThreatConnect TI Ops?**

- **Threat Intelligence:** 9.2/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.8/10 (Category avg: 8.8/10)
- **Incident Case Management:** 7.3/10 (Category avg: 8.4/10)
- **Incident Logs:** 7.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind ThreatConnect TI Ops?**

- **Seller:** [ThreatConnect](https://www.g2.com/sellers/threatconnect)
- **Year Founded:** 2011
- **HQ Location:** Arlington, US
- **Twitter:** @ThreatConnect (14,141 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/threatconnect-inc/about/ (87 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services
- **Company Size:** 57% Enterprise, 43% Mid-Market


#### What Are ThreatConnect TI Ops's Pros and Cons?

**Pros:**

- Features (5 reviews)
- Threat Detection (5 reviews)
- Ease of Use (4 reviews)
- Automation (3 reviews)
- Implementation Ease (3 reviews)

**Cons:**

- UX Improvement (2 reviews)
- Additional Costs (1 reviews)
- API Limitations (1 reviews)
- Difficult Learning Curve (1 reviews)
- Difficult Setup (1 reviews)


### What Do G2 Reviewers Say About ThreatConnect TI Ops?
*AI-generated summary from verified user reviews*

**Pros:**

- Users praise the **flexible no-code Playbook builder** of ThreatConnect TI Ops for extensive automation and integration capabilities.
- Users value the **effective threat detection** capabilities of ThreatConnect TI Ops, enhancing accuracy and proactive defense.
- Users value the **ease of use** in ThreatConnect TI Ops, benefiting from its intuitive design and seamless integration.
- Users value the **extensive automation capabilities** of ThreatConnect TI Ops, enhancing efficiency and customization in security operations.
- Users praise the **ease of implementation** of ThreatConnect TI Ops, enabling seamless integration and efficient threat response.

**Cons:**

- Users find the **UX lacking** , noting the need for smoother workflows and improved UI for better efficiency.
- Users note that **additional licensing costs** for some features can be a barrier for smaller organizations.
- Users face **API limitations** when integrating with other tools, impacting their ability to effectively use ThreatConnect TI Ops.
- Users experience a **difficult learning curve** initially, but support and training resources aid adaptation to ThreatConnect TI Ops.
- Users find the **difficult setup** of ThreatConnect TI Ops challenging initially, but training resources help ease the process.

#### What Are Recent G2 Reviews of ThreatConnect TI Ops?

**"[The TIP is nice, the SOAR has become indispensable](https://www.g2.com/survey_responses/threatconnect-ti-ops-review-11275767)"**

**Rating:** 4.5/5.0 stars
*— Eric B.*

[Read full review](https://www.g2.com/survey_responses/threatconnect-ti-ops-review-11275767)

---

**"[A powerful and fully customizable Threat Intelligence Platform](https://www.g2.com/survey_responses/threatconnect-ti-ops-review-11254101)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Computer &amp; Network Security*

[Read full review](https://www.g2.com/survey_responses/threatconnect-ti-ops-review-11254101)

---


#### What Are G2 Users Discussing About ThreatConnect TI Ops?

- [How do you use Threatconnect?](https://www.g2.com/discussions/threatconnect-how-do-you-use-threatconnect)
- [How do you use Threatconnect?](https://www.g2.com/discussions/how-do-you-use-threatconnect)
- [What does ThreatConnect do?](https://www.g2.com/discussions/what-does-threatconnect-do)
- [What are threat capabilities?](https://www.g2.com/discussions/what-are-threat-capabilities)
- [What is ThreatConnect used for?](https://www.g2.com/discussions/what-is-threatconnect-used-for)

### 17. [Corelight](https://www.g2.com/products/corelight/reviews)
Corelight&#39;s Open Network Detection and Response (NDR) Platform improves network detection coverage, accelerates incident response, and reduces operational costs by consolidating NDR, intrusion detection (IDS), and PCAP functionality in a single solution and by providing security analysts with machine learning-assisted investigations and one-click-pivots from prioritized alerts to the evidence needed to investigate and remediate them. Network Detection and Response platforms monitor and analyze network traffic, delivering telemetry into existing SIEM, XDR, or SaaS-based solutions. Corelight’s platform is unique because our detections and visibility engineering are community driven—with continuous content creation from Zeek®, Suricata IDS, and other Intel communities. And our integration with CrowdStrike XDR enables cross platform (EDR+NDR) analytics. This provides you with the most complete network visibility, powerful analytics, and threat hunting capabilities, and accelerates investigation across your entire kill chain. Corelight also delivers a comprehensive suite of network security analytics that help organizations identify more than 75 adversarial TTPs across the MITRE ATT&amp;CK® spectrum including Exfiltration, Command and Control (C2), and Lateral Movement. These detections reveal known and unknown threats via hundreds of unique insights and alerts across machine learning, behavioral analysis, and signature-based approaches. CORELIGHT PRODUCTS + SERVICES Open NDR Platform Appliance, Cloud, Software, Virtual and SaaS Sensors IDS Fleet Manager Investigator Threat Hunting Platform Smart PCAP Corelight Training CERTIFICATIONS FIPS 140-2


**Average Rating:** 4.6/5.0
**Total Reviews:** 20
**How Do G2 Users Rate Corelight?**

- **Threat Intelligence:** 7.8/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.1/10 (Category avg: 8.8/10)
- **Incident Case Management:** 5.0/10 (Category avg: 8.4/10)
- **Incident Logs:** 9.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Corelight?**

- **Seller:** [Corelight](https://www.g2.com/sellers/corelight)
- **Year Founded:** 2013
- **HQ Location:** San Francisco, CA
- **Twitter:** @corelight_inc (4,227 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/corelight (474 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer &amp; Network Security
- **Company Size:** 50% Mid-Market, 50% Enterprise


#### What Are Corelight's Pros and Cons?

**Pros:**

- Comprehensive Security (2 reviews)
- Cybersecurity (2 reviews)
- Network Security (2 reviews)
- Security (2 reviews)
- Security Features (2 reviews)

**Cons:**

- Complex Coding (2 reviews)
- Complex Configuration (2 reviews)
- Complexity (2 reviews)
- Complex Setup (2 reviews)
- Learning Curve (2 reviews)


### What Do G2 Reviewers Say About Corelight?
*AI-generated summary from verified user reviews*

**Pros:**

- Users praise Corelight for its **comprehensive security** features, effectively detecting threats and simplifying network event analysis.
- Users value Corelight for its **effective network telemetry** , simplifying the detection of security threats and vulnerabilities.
- Users value the **great network telemetry** of Corelight, enhancing security event visibility and threat detection efficiency.
- Users commend Corelight for its **exceptional network security** capabilities, effectively detecting threats and simplifying event analysis.
- Users appreciate the **robust security features** of Corelight, enabling effective detection of network threats and smooth operation.

**Cons:**

- Users find Corelight&#39;s **complex coding** challenging, making it difficult for novice security analysts to navigate effectively.
- Users find the **complex configuration** of Corelight challenging, especially for novice security analysts requiring specialized knowledge.
- Users find Corelight&#39;s setup and management **complex and not suitable for novice security analysts** , requiring specialized knowledge and costly training.
- Users find the **complex setup** of Corelight challenging, especially for novice security analysts needing specialized knowledge.
- Users find the **learning curve challenging** , particularly for novice security analysts needing specialized training for effective use.

#### What Are Recent G2 Reviews of Corelight?

**"[Best NDR solution Guardians of  Network](https://www.g2.com/survey_responses/corelight-review-8692252)"**

**Rating:** 5.0/5.0 stars
*— Aman P.*

[Read full review](https://www.g2.com/survey_responses/corelight-review-8692252)

---

**"[Corelight the Threat Hunters](https://www.g2.com/survey_responses/corelight-review-11196044)"**

**Rating:** 4.5/5.0 stars
*— Andy V.*

[Read full review](https://www.g2.com/survey_responses/corelight-review-11196044)

---



### 18. [Cybereason Defense Platform](https://www.g2.com/products/cybereason-defense-platform/reviews)
Cybereason automatically detects malicious activity and presents it in an intuitive way. It deploys easily with minimal organizational impact and provides end-to-end context of an attack campaign. Most organizations deploy Cybereason and start detecting attacks within 24 to 48 hours.


**Average Rating:** 4.4/5.0
**Total Reviews:** 18
**How Do G2 Users Rate Cybereason Defense Platform?**

- **Threat Intelligence:** 7.8/10 (Category avg: 8.9/10)
- **Quality of Support:** 7.9/10 (Category avg: 8.8/10)
- **Incident Case Management:** 9.2/10 (Category avg: 8.4/10)
- **Incident Logs:** 7.8/10 (Category avg: 8.8/10)

**Who Is the Company Behind Cybereason Defense Platform?**

- **Seller:** [Cybereason](https://www.g2.com/sellers/cybereason)
- **Year Founded:** 2012
- **HQ Location:** La Jolla, San Diego, US
- **LinkedIn® Page:** https://www.linkedin.com/company/cybereason (482 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 61% Enterprise, 22% Small-Business


#### What Are Cybereason Defense Platform's Pros and Cons?

**Pros:**

- Cybersecurity (2 reviews)
- Ease of Use (2 reviews)
- Security (2 reviews)
- AI (1 reviews)
- AI Technology (1 reviews)

**Cons:**

- Feature Limitations (1 reviews)
- Lack of Clarity (1 reviews)
- Limited Customization (1 reviews)
- Limited Features (1 reviews)
- Poor Customer Support (1 reviews)


### What Do G2 Reviewers Say About Cybereason Defense Platform?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **strong security options** provided by Cybereason, benefiting from swift and automated threat detection.
- Users value the **ease of use** of Cybereason Defense Platform, enjoying its seamless setup and intuitive interface.
- Users value the **great security options** of the Cybereason Defense Platform, ensuring swift detection of threats.
- Users value the **seamless integration and swift detection** capabilities of the AI-driven Cybereason Defense Platform.
- Users appreciate the **AI-driven detection** of Cybereason, enabling quick identification of threats through advanced behavioral analysis.

**Cons:**

- Users suggest that there are **feature limitations** in custom detection rules and the user interface needs improvement.
- Users find there is a **lack of clarity** in after-sales support making business interactions challenging.
- Users feel the need for **limited customization** options, particularly regarding the user interface and detection rules.
- Users feel the need for **enhanced features** in custom detection rules to improve the overall usability of Cybereason.
- Users experience **poor customer support** , making interactions with Cybereason Defense Platform challenging and frustrating.

#### What Are Recent G2 Reviews of Cybereason Defense Platform?

**"[Uncomplicated defense](https://www.g2.com/survey_responses/cybereason-defense-platform-review-10564960)"**

**Rating:** 4.0/5.0 stars
*— Andre S.*

[Read full review](https://www.g2.com/survey_responses/cybereason-defense-platform-review-10564960)

---

**"[Great EDR and MDR!](https://www.g2.com/survey_responses/cybereason-defense-platform-review-9038436)"**

**Rating:** 4.5/5.0 stars
*— Elie H.*

[Read full review](https://www.g2.com/survey_responses/cybereason-defense-platform-review-9038436)

---


#### What Are G2 Users Discussing About Cybereason Defense Platform?

- [What does Cybereason Defense Platform do?](https://www.g2.com/discussions/cybereason-defense-platform-what-does-cybereason-defense-platform-do)
- [What does Cybereason Defense Platform do?](https://www.g2.com/discussions/what-does-cybereason-defense-platform-do)
- [What is the use of Cybereason Defense Platform?](https://www.g2.com/discussions/what-is-the-use-of-cybereason-defense-platform)
- [How does Cybereason EDR work?](https://www.g2.com/discussions/how-does-cybereason-edr-work)
- [What does Cybereason software do?](https://www.g2.com/discussions/what-does-cybereason-software-do)

### 19. [LMNTRIX](https://www.g2.com/products/lmntrix/reviews)
LMNTRIX has reimagined cybersecurity, turning the tables in favor of the defenders once again. We have cut out the bloat of SIEM, log analysis and false positives resulting in alert fatigue, and we created new methods for confounding even the most advanced attackers. We believe that in a time of continuous compromise you need continuous response – not incident response. Our approach turns inward and assumes that you’re already breached and that you’re continually going to be breached, so we take a pro-active, offensive, hunting, and adversarial pursuit stance as opposed to a reactive, defensive, legacy stance with analysts staring at a SIEM console wishing they could detect an APT. LMNTRIX Active Defense is a best in class Managed Detection &amp; Response (MDR) service that detects and responds to advanced threats that bypass perimeter controls. We combine deep expertise with cutting-edge technology, leading intelligence, and advanced analytics to detect and investigate threats with great speed, accuracy, and focus. The outcomes we deliver clients are validated breaches that are investigated, contained and remediated. All incidents are aligned to the kill chain and Mitre ATT&amp;CK frameworks and contain detailed investigative actions and recommendations that your organisation follows to protect against the unknown, insider threat and malicious attacker. Active Defense is made up of 3 elements: LMNTRIX GRID (XDR) – This is our cyber defence SaaS platform that provides a new utility model for enterprise security, delivering pervasive visibility, automated threat detection &amp; prevention, threat hunting, investigation, validation and unlimited forensic exploration on-demand and entirely from the cloud. It is a single investigative platform for insights into threats on enterprise, cloud, hybrid, and industrial control systems (ICS) networks. The LMNTRIX Grid delivers unique advantages over current network security solutions. It is a holistic and multi-vector platform with unlimited retention window of full-fidelity network traffic, innovative security visualizations, and the ease and cost-savings of an on-demand deployment model. LMNTRIX Technology Stack –This is our powerful proprietary threat detection stack that is deployed onsite, behind existing controls. It combines multiple threat detection systems, with deceptions everywhere, machine learning, threat intel, correlation, static file analysis, heuristics, and behavior and anomaly detection techniques to find threats in real-time. It decreases alarm fatigue by automatically determining which alerts should be elevated to security events, and reduces false positives by requiring consensus across detection. LMNTRIX Cyber Defense Centers - While these technologies are without peer, what sets us apart from the pack is our team of cybersecurity professionals who continually monitor our clients environments 24x7 while simultaneously hunting threats internally as well as monitoring developments on the deep and dark web. Our CDC&#39;s are a global network of cyber defense centers with highly trained and certified intrusion analysts who provide constant vigilance and on-demand analysis of your networks. Our intrusion analysts monitor your networks and endpoints 24x7, applying the latest intelligence and proprietary methodologies to look for signs of compromise. When a potential compromise is detected, the team performs an in- depth analysis on affected systems to confirm the breach. When data theft or lateral movement is imminent, our automated perimeter containment blocks attackers in their tracks while endpoint containment feature makes immediate reaction possible by quarantining affected hosts, whether they are on or off your corporate network, significantly reducing or eliminating the consequences of a breach.


**Average Rating:** 4.9/5.0
**Total Reviews:** 10
**How Do G2 Users Rate LMNTRIX?**

- **Threat Intelligence:** 10.0/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.6/10 (Category avg: 8.8/10)
- **Incident Case Management:** 10.0/10 (Category avg: 8.4/10)
- **Incident Logs:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind LMNTRIX?**

- **Seller:** [LMNTRIX](https://www.g2.com/sellers/lmntrix)
- **Year Founded:** 2015
- **HQ Location:** Orange, California
- **Twitter:** @lmntrixlabs (75 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/lmntrix (66 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 60% Mid-Market, 20% Enterprise



#### What Are Recent G2 Reviews of LMNTRIX?

**"[Ultimate tool for Cyber Defense](https://www.g2.com/survey_responses/lmntrix-review-8328112)"**

**Rating:** 4.5/5.0 stars
*— Prakash Gupta K.*

[Read full review](https://www.g2.com/survey_responses/lmntrix-review-8328112)

---

**"[Good level of security service !](https://www.g2.com/survey_responses/lmntrix-review-7834658)"**

**Rating:** 4.5/5.0 stars
*— Verified User in Computer &amp; Network Security*

[Read full review](https://www.g2.com/survey_responses/lmntrix-review-7834658)

---


#### What Are G2 Users Discussing About LMNTRIX?

- [What is LMNTRIX used for?](https://www.g2.com/discussions/what-is-lmntrix-used-for)

### 20. [ORNA](https://www.g2.com/products/orna-orna/reviews)
ORNA is an end-to-end incident response automation platform for lean teams in midsize businesses that helps streamline or automate detection, response, and even prevention of cyberattacks on the organization&#39;s assets, all in a single tool with live 24/7 specialist support. The platform monitors cloud, on-premises, and hybrid assets (such as servers, network devices, workstations, IoT devices, and more) the organization is looking to protect around the clock, but also brings together overarching cyber incident response across all business functions, such as legal, HR, communications, and others; as well as automates evidence collection, communications, vulnerability management, and more.


**Average Rating:** 4.7/5.0
**Total Reviews:** 7
**How Do G2 Users Rate ORNA?**

- **Threat Intelligence:** 9.4/10 (Category avg: 8.9/10)
- **Quality of Support:** 10.0/10 (Category avg: 8.8/10)
- **Incident Case Management:** 10.0/10 (Category avg: 8.4/10)
- **Incident Logs:** 8.9/10 (Category avg: 8.8/10)

**Who Is the Company Behind ORNA?**

- **Seller:** [ORNA](https://www.g2.com/sellers/orna)
- **Year Founded:** 2021
- **HQ Location:** Toronto, CA
- **LinkedIn® Page:** https://www.linkedin.com/company/orna-inc/ (42 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 71% Small-Business, 14% Enterprise


#### What Are ORNA's Pros and Cons?

**Pros:**

- Automation Ease (1 reviews)
- Customer Support (1 reviews)
- Detection Accuracy (1 reviews)
- Ease of Use (1 reviews)
- Email Security (1 reviews)



### What Do G2 Reviewers Say About ORNA?
*AI-generated summary from verified user reviews*

**Pros:**

- Users highlight the **ease of automation** in ORNA, enhancing efficiency through streamlined incident response processes.
- Users value the **helpful customer support** from ORNA, ensuring efficient solutions and responsive feedback.
- Users commend ORNA for its **high detection accuracy** , ensuring effective monitoring and incident management across platforms.
- Users highlight the **ease of use** in ORNA for tagging and managing devices efficiently.
- Users commend the **helpful support team** and appreciate their openness to feedback and suggestions.


#### What Are Recent G2 Reviews of ORNA?

**"[ORNA Cyber Incident Response Platform](https://www.g2.com/survey_responses/orna-review-10406528)"**

**Rating:** 4.5/5.0 stars
*— Robert M.*

[Read full review](https://www.g2.com/survey_responses/orna-review-10406528)

---

**"[User interface is Perfect](https://www.g2.com/survey_responses/orna-review-10827471)"**

**Rating:** 4.5/5.0 stars
*— Laia G.*

[Read full review](https://www.g2.com/survey_responses/orna-review-10827471)

---



### 21. [ReliaQuest GreyMatter](https://www.g2.com/products/reliaquest-greymatter/reviews)
ReliaQuest’s agentic AI security operations platform, GreyMatter, allows security teams to detect threats at the source, contain them in under 5 minutes, and eliminate Tier 1 and Tier 2 work for faster investigation and response. GreyMatter orchestrates 6 agentic AI personas with 200+ agent skills and 400+ AI tools to exponentially scale security operations and help organizations predict what&#39;s next.


**Average Rating:** 4.5/5.0
**Total Reviews:** 13
**How Do G2 Users Rate ReliaQuest GreyMatter?**

- **Threat Intelligence:** 9.2/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.9/10 (Category avg: 8.8/10)
- **Incident Case Management:** 9.2/10 (Category avg: 8.4/10)
- **Incident Logs:** 9.2/10 (Category avg: 8.8/10)

**Who Is the Company Behind ReliaQuest GreyMatter?**

- **Seller:** [ReliaQuest](https://www.g2.com/sellers/reliaquest)
- **Company Website:** https://www.ReliaQuest.com
- **Year Founded:** 2007
- **HQ Location:** Tampa, Florida, United States
- **Twitter:** @ReliaQuest (2,577 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/reliaquest/ (1,066 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 38% Mid-Market, 31% Enterprise


#### What Are ReliaQuest GreyMatter's Pros and Cons?

**Pros:**

- Features (8 reviews)
- Centralized Management (7 reviews)
- Customer Support (7 reviews)
- Ease of Use (7 reviews)
- Easy Integrations (6 reviews)

**Cons:**

- UX Improvement (3 reviews)
- Complexity (2 reviews)
- Inefficient Alert System (2 reviews)
- Learning Curve (2 reviews)
- Login Issues (2 reviews)


### What Do G2 Reviewers Say About ReliaQuest GreyMatter?
*AI-generated summary from verified user reviews*

**Pros:**

- Users applaud the **exceptional visibility** and seamless integration of ReliaQuest GreyMatter across diverse security environments.
- Users value the **centralized management** offered by ReliaQuest GreyMatter, streamlining security operations across multiple systems effectively.
- Users commend the **exceptional customer support** of ReliaQuest GreyMatter, enhancing their overall experience and satisfaction.
- Users find ReliaQuest GreyMatter&#39;s **ease of use** invaluable for streamlining security operations and facilitating quick investigations.
- Users value the **seamless integrations** of ReliaQuest GreyMatter, enhancing security operations through unified workflows and capabilities.

**Cons:**

- Users experience **slow report loading and clunky UI** on ReliaQuest GreyMatter, noting a need for enhancements, especially on Android.
- Users find the **complexity of configurations** time-consuming, often requiring additional effort to fine-tune automated rules.
- Users experience **inefficient alerts** with delays and duplicates, complicating workflows and requiring additional adjustments to automation rules.
- Users experience a **challenging learning curve** with advanced automation workflows, though support helps alleviate difficulties eventually.
- Users find the **login issues** with the ReliaQuest GreyMatter app clunky, hindering a smooth sign-in experience.

#### What Are Recent G2 Reviews of ReliaQuest GreyMatter?

**"[Effective Automation for MSSP with GreyMatter](https://www.g2.com/survey_responses/reliaquest-greymatter-review-12596289)"**

**Rating:** 4.5/5.0 stars
*— Pedro G.*

[Read full review](https://www.g2.com/survey_responses/reliaquest-greymatter-review-12596289)

---

**"[Saves Time with Seamless Integrations](https://www.g2.com/survey_responses/reliaquest-greymatter-review-11947996)"**

**Rating:** 4.5/5.0 stars
*— Ben B.*

[Read full review](https://www.g2.com/survey_responses/reliaquest-greymatter-review-11947996)

---



### 22. [RunReveal](https://www.g2.com/products/runreveal/reviews)
RunReveal is a modern security data platform built for AI-forward security teams. RunReveal unifies logs, data pipelines, detections, AI-investigations, and analytics into one platform, so security teams are no longer stitching together tools to manage and use their security data. The platform ingests from 70+ sources, supports built-in and custom detections, and includes an AI agent for faster and automated investigations. RunReveal also support unlimited ingest, and prices based off of predictable data storage. If you&#39;re evaluating your first SIEM, escaping renewal sticker shock, or tired of paying enterprise prices for a SIEM that still require additional tooling, RunReveal gives you a unified platform for log management without the complexity or cost.


**Average Rating:** 4.9/5.0
**Total Reviews:** 10
**How Do G2 Users Rate RunReveal?**

- **Quality of Support:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind RunReveal?**

- **Seller:** [RunReveal](https://www.g2.com/sellers/runreveal)
- **Company Website:** https://runreveal.com
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** https://www.linkedin.com/company/runreveal/ (20 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer Software
- **Company Size:** 50% Mid-Market, 30% Small-Business


#### What Are RunReveal's Pros and Cons?

**Pros:**

- Detection Speed (4 reviews)
- Security (4 reviews)
- Threat Detection (4 reviews)
- Artificial Intelligence (3 reviews)
- Features (3 reviews)

**Cons:**

- Expensive (1 reviews)
- Feature Limitations (1 reviews)
- Lack of Features (1 reviews)
- Limited Features (1 reviews)


### What Do G2 Reviewers Say About RunReveal?
*AI-generated summary from verified user reviews*

**Pros:**

- Users commend the **exceptional detection speed** of RunReveal, enhancing efficiency in security investigations and response.
- Users appreciate the **exceptional security capabilities** of RunReveal, transforming their detection and response processes effectively.
- Users value the **exceptional threat detection** capabilities of RunReveal, transforming their approach to security with unmatched efficiency.
- Users highlight the **thoughtful AI implementation** of RunReveal, enhancing threat detection and simplifying investigations effectively.
- Users highlight the **powerful MCP server** , revolutionizing large-scale investigations and enhancing detection and response capabilities.

**Cons:**

- Users are frustrated by the **expensive paywall** limiting access to features in RunReveal&#39;s free version.
- Users find the **feature limitations** of RunReveal restrictive, particularly with important tools behind a paywall.
- Users feel frustrated by the **lack of features** in the free version, limiting their use in homelabs.
- Users express frustration over **limited features** in RunReveal&#39;s free version, hindering full utilization in personal projects.

#### What Are Recent G2 Reviews of RunReveal?

**"[RunReveal Integrations and AI Triage Make Security Findings Easy to Act On](https://www.g2.com/survey_responses/runreveal-review-13022957)"**

**Rating:** 5.0/5.0 stars
*— Julio J.*

[Read full review](https://www.g2.com/survey_responses/runreveal-review-13022957)

---

**"[RunReveal is the only SIEM and Detection and Response Platform that is ready for the AI age](https://www.g2.com/survey_responses/runreveal-review-12350471)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Logistics and Supply Chain*

[Read full review](https://www.g2.com/survey_responses/runreveal-review-12350471)

---



### 23. [Cofense Reporter](https://www.g2.com/products/cofense-reporter/reviews)
To date, organizations have lacked an efficient process for gathering, organizing, and analyzing user reports of suspicious emails that may indicate early stages of a cyber attack. Cofense Reporter provides organizations with a simple, cost-effective way to fill this information gap.


**Average Rating:** 3.9/5.0
**Total Reviews:** 5
**How Do G2 Users Rate Cofense Reporter?**

- **Threat Intelligence:** 9.4/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.2/10 (Category avg: 8.8/10)
- **Incident Case Management:** 10.0/10 (Category avg: 8.4/10)
- **Incident Logs:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Cofense Reporter?**

- **Seller:** [Cofense](https://www.g2.com/sellers/cofense)
- **Year Founded:** 2011
- **HQ Location:** Leesburg, Virginia
- **Twitter:** @Cofense (5,955 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/11500065 (283 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 60% Enterprise, 20% Mid-Market


#### What Are Cofense Reporter's Pros and Cons?

**Pros:**

- Ease of Use (1 reviews)
- Phishing Prevention (1 reviews)
- Product Innovation (1 reviews)
- Setup Ease (1 reviews)
- User Interface (1 reviews)



### What Do G2 Reviewers Say About Cofense Reporter?
*AI-generated summary from verified user reviews*

**Pros:**

- Users love the **ease of use** of Cofense Reporter, making phishing reporting quick and enhancing security awareness effectively.
- Users appreciate the **ease of reporting phishing attempts** with Cofense Reporter, enhancing their security awareness effectively.
- Users appreciate the **ease of use and speed** of Cofense Reporter, significantly enhancing their security awareness.
- Users appreciate the **easy initial setup** of Cofense Reporter, making it simple to start reporting phishing attempts.
- Users appreciate the **easy-to-use interface** of Cofense Reporter, making reporting phishing attempts fast and intuitive.


#### What Are Recent G2 Reviews of Cofense Reporter?

**"[Easily Elevates Phishing Awareness and Security](https://www.g2.com/survey_responses/cofense-reporter-review-12118209)"**

**Rating:** 4.0/5.0 stars
*— Cristhian P.*

[Read full review](https://www.g2.com/survey_responses/cofense-reporter-review-12118209)

---

**"[A Great System](https://www.g2.com/survey_responses/cofense-reporter-review-7092344)"**

**Rating:** 4.0/5.0 stars
*— Verified User in Hospital &amp; Health Care*

[Read full review](https://www.g2.com/survey_responses/cofense-reporter-review-7092344)

---


#### What Are G2 Users Discussing About Cofense Reporter?

- [What is Cofense tool?](https://www.g2.com/discussions/what-is-cofense-tool)
- [How does Cofense reporter work?](https://www.g2.com/discussions/how-does-cofense-reporter-work)
- [What is Cofense Reporter software?](https://www.g2.com/discussions/what-is-cofense-reporter-software)

### 24. [ContraForce](https://www.g2.com/products/contraforce/reviews)
ContraForce is an AI operations control plane for MSSPs, MSPs, and security operations teams delivering managed detection and response on Microsoft Sentinel and Microsoft Defender XDR. The platform orchestrates multi-tenant incident operations by automating triage, investigation, enrichment, and guided response actions through Security Delivery Agents—AI-driven workflow operators that execute repeatable SOC tasks under policy controls. Core capabilities include: - Gamebooks – SOP-driven playbooks that standardize workflows and enforce consistent execution across customer environments. - Human-in-the-loop controls – Approval gates and audit logging for safe, governed response actions. - Multi-tenant operations – Centralized management across multiple Microsoft security tenants without data duplication. - PSA and ticketing integrations – Native connections to ServiceNow, Jira, Autotask, and service management tools. ContraForce deploys in approximately 30 minutes using federated access, keeping security data in the customer tenant with no complex data migration required. Security teams use ContraForce to reduce triage effort, improve investigation consistency, and scale Microsoft-native MXDR delivery without proportional headcount growth. Ideal for: MSSPs, MSPs, and enterprise SOC teams operating Microsoft Sentinel and Defender XDR at scale.


**Average Rating:** 4.8/5.0
**Total Reviews:** 5
**How Do G2 Users Rate ContraForce?**

- **Quality of Support:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind ContraForce?**

- **Seller:** [ContraForce](https://www.g2.com/sellers/contraforce)
- **Year Founded:** 2022
- **HQ Location:** Frisco, US
- **Twitter:** @ContraForceSec (22 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/contraforce/ (25 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 60% Mid-Market, 40% Small-Business


#### What Are ContraForce's Pros and Cons?

**Pros:**

- Ease of Use (2 reviews)
- Integrations (2 reviews)
- Alerting (1 reviews)
- Automation (1 reviews)
- Centralized Management (1 reviews)

**Cons:**

- Detection Issues (1 reviews)
- Expensive (1 reviews)
- Insufficient Information (1 reviews)
- Limited Functionality (1 reviews)
- Missing Features (1 reviews)


### What Do G2 Reviewers Say About ContraForce?
*AI-generated summary from verified user reviews*

**Pros:**

- Users highlight the **ease of use** of ContraForce, appreciating its quick setup and straightforward automation capabilities.
- Users appreciate the **easy endpoint integration** of ContraForce, benefiting from excellent customer support and continuous service enhancements.
- Users value the **centralized alerting and monitoring system** of ContraForce, enhancing efficiency for MSSP providers.
- Users commend the **automation capabilities** of ContraForce, streamlining cybersecurity processes and enhancing protection effectively.
- Users value the **centralized management** of ContraForce, enhancing efficiency for MSSP providers with multiple clients.

**Cons:**

- Users report **detection issues** with ContraForce, lacking critical details and real-time logs for effective incident response.
- Users find the platform **expensive** given its lack of essential features and limited logging capabilities.
- Users express concern over the **insufficient information** , lacking essential logs and incident details for effective use.
- Users find the **limited functionality** of ContraForce restricts effectiveness, lacking essential logging and alert details.
- Users find **missing features** in ContraForce, lacking essential details and real-time log access for effective incident response.

#### What Are Recent G2 Reviews of ContraForce?

**"[Excellent support for those worried about cybersecurity attacks](https://www.g2.com/survey_responses/contraforce-review-9296434)"**

**Rating:** 5.0/5.0 stars
*— Garland B.*

[Read full review](https://www.g2.com/survey_responses/contraforce-review-9296434)

---

**"[Highly Recommend ContraForce!](https://www.g2.com/survey_responses/contraforce-review-7390141)"**

**Rating:** 5.0/5.0 stars
*— Jennifer B.*

[Read full review](https://www.g2.com/survey_responses/contraforce-review-7390141)

---



### 25. [Datev](https://www.g2.com/products/datev/reviews)
DATEV in one sentence: tax consultants, lawyers, auditors, small and medium-sized enterprises, municipalities, and founders using DATEV software that meets all requirements at high standards regarding reliability, topicality, data protection, and data security.


**Average Rating:** 3.4/5.0
**Total Reviews:** 15
**How Do G2 Users Rate Datev?**

- **Quality of Support:** 5.8/10 (Category avg: 8.8/10)

**Who Is the Company Behind Datev?**

- **Seller:** [Datev](https://www.g2.com/sellers/datev)
- **Year Founded:** 1966
- **HQ Location:** Germany
- **Twitter:** @DATEV (7,602 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/37207 (5,125 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 80% Small-Business, 20% Mid-Market


#### What Are Datev's Pros and Cons?

**Pros:**

- Ease of Use (4 reviews)
- Data Management (2 reviews)
- Documentation Management (2 reviews)
- Ease of Learning (2 reviews)
- Helpful (2 reviews)

**Cons:**

- Complexity Issues (4 reviews)
- Expensive (3 reviews)
- Poor Interface Design (3 reviews)
- Poor UI Design (3 reviews)
- Complexity (2 reviews)


### What Do G2 Reviewers Say About Datev?
*AI-generated summary from verified user reviews*

**Pros:**

- Users find Datev to be an **easy-to-learn solution** , greatly simplifying the bookkeeping process for new accountants.
- Users value the **direct connection to the data center** , enabling efficient digitalization and seamless cooperation with tax consultants.
- Users value the **seamless digital documentation** in Datev, enhancing collaboration and access to important files.
- Users find **ease of learning** with Datev, making bookkeeping manageable even for new accountants and beginners.
- Users find Datev to be a **user-friendly solution** for new accountants, facilitating easy bookkeeping and document management.

**Cons:**

- Users find Datev to have **complexity issues** , citing its outdated interface and steep learning curve as significant drawbacks.
- Users find the **customer service expensive** and note the complexity hampers easy access and usability of Datev.
- Users complain about the **poor interface design** of Datev, describing it as outdated and complicated to use.
- Users criticize the **poor UI design** of Datev, finding it slow and outdated, complicating their experience.
- Users find the **complexity** of Datev overwhelming, with outdated design and slow login detracting from their experience.

#### What Are Recent G2 Reviews of Datev?

**"[Datev provides excellent support for accounting processes.](https://www.g2.com/survey_responses/datev-review-9856248)"**

**Rating:** 4.0/5.0 stars
*— Verified User in Information Technology and Services*

[Read full review](https://www.g2.com/survey_responses/datev-review-9856248)

---

**"[Best Financial Solution for small and mid sized Companys](https://www.g2.com/survey_responses/datev-review-12463219)"**

**Rating:** 4.5/5.0 stars
*— Sebastian C.*

[Read full review](https://www.g2.com/survey_responses/datev-review-12463219)

---


#### What Are G2 Users Discussing About Datev?

- [What is Datev used for?](https://www.g2.com/discussions/what-is-datev-used-for)


## What Is Incident Response Software?

[System Security Software](https://www.g2.com/categories/system-security)

## What Software Categories Are Similar to Incident Response Software?

- [Threat Intelligence Software](https://www.g2.com/categories/threat-intelligence)
- [Security Information and Event Management (SIEM) Software](https://www.g2.com/categories/security-information-and-event-management-siem)
- [Endpoint Detection &amp; Response (EDR) Software](https://www.g2.com/categories/endpoint-detection-response-edr)
- [Managed Detection and Response (MDR)  Software](https://www.g2.com/categories/managed-detection-and-response-mdr)
- [Security Orchestration, Automation, and Response (SOAR) Software](https://www.g2.com/categories/security-orchestration-automation-and-response-soar)
- [Extended Detection and Response (XDR) Platforms](https://www.g2.com/categories/extended-detection-and-response-xdr-platforms)
- [AI SOC Agents](https://www.g2.com/categories/ai-soc-agents)


---

## How Do You Choose the Right Incident Response Software?

### What You Should Know About Incident Response Software

### What is Incident Response Software?

Incident response software, sometimes called security incident management software, is a security technology used to remediate cybersecurity issues as they arise in real time. These tools discover incidents and alert the relevant IT and security staff to resolve the security issue. Additionally, the tools allow teams to develop workflows, delegate responsibilities, and automate low-level tasks to optimize response time and minimize the impact of security incidents.

These tools also document historical incidents and help provide context to the users attempting to understand the root cause to remediate security issues. When new security issues arise, users can take advantage of forensic investigation tools to root out the cause of the incident and see if it will be an ongoing or larger overall issue. Many incident response software also integrate with other security tools to simplify alerting, string together workflows, and provide additional threat intelligence.

#### What Types of Incident Response Software Exist?

**Pure incident response solutions**

Pure incident response solutions are the last line of defense in the security ecosystem. Only once threats go unseen and vulnerabilities are exposed, do incident response systems come into play. Their main focus is facilitating the remediation of compromised accounts, system penetrations, and other security incidents. These products store information related to common and emerging threats while documenting each occurrence for retrospective analysis. Some incident response solutions are also connected to live feeds to gather global information related to emerging threats.

**Incident management and response**

Incident management products offer many similar administrative features to incident response products, but other tools combine incident management, alerting, and response capabilities. These tools are often used in DevOps environments to document, track, and source security incidents from their emergence to their remediation.

**Incident management tracking and service tools**

Other incident management tools have more of a service management focus. These tools will track security incidents, but won’t allow users to build security workflows, remediate issues, or provide forensic investigation features to determine the root cause of the incident.

### What are the Common Features of Incident Response Software?

Incident response software can provide a wide range of features, but some of the most common include:

**Workflow management:** Workflow management features let administrators organize workflows that help guide remediation staff and provide information related to specific situations and incident types.

**Workflow automation:** Workflow automation allows teams to streamline the flow of work processes by establishing triggers and alerts that notify and route information to the appropriate people when their action is required within the compensation process.

**Incident database:** Incident databases document historical incident activity. Administrators can access and organize data related to incidents to produce reports or make data more navigable.

**Incident alerting:** Alerting features inform relevant individuals when incidents happen in real time. Some responses may be automated but users will still be informed.

**Incident reporting:** Reporting features produce reports detailing trends and vulnerabilities related to their network and infrastructure.

**Incident logs:** Historical incident logs are stored in the incident database and is used for user reference and analytics while remediating security incidents.

**Threat intelligence:** Threat intelligence tools, which are often combined with forensic tools, provide an integrated information feed detailing the cybersecurity threats as they’re discovered across the world. This information is gathered either internally or by a third-party vendor and is used to provide further information on remedies.

**Security orchestration:** Orchestration refers to the integration of security solutions and automation of processes in a response workflow.

**Automated remediation:** Automation addresses security issues in real time and reduces the time spent remedying issues manually. It also helps resolve common network and system security incidents quickly.

### What are the Benefits of Incident Response Software?

The main value of incident response technology is an increased ability to discover and resolve cybersecurity incidents. These are a few valuable components of the incident response process.

**Threat modeling:** Information security and IT departments can use these tools to gain familiarity with the incident response process and develop workflows before security incident occurrences. This allows companies to stand prepared to quickly discover, resolve, and learn from security incidents and how they impact business-critical systems.

**Alerting:** Without proper alerting and communication channels, many security threats can penetrate networks and remain undetected for extended periods. During that time, hackers, internal threat actors, and other cybercriminals can steal sensitive and other business-critical data and wreak havoc on IT systems. Proper alerting and communication can greatly shorten the time necessary to discover, inform relevant staff, and eradicate incidents.

**Isolation:** Incident response platforms allow security teams to contain incidents quickly when alerted properly. Isolating infected systems, networks, and endpoints can greatly reduce an incident’s scope of impact. If isolated properly, security professionals can monitor the activity of affected systems to learn more about the threat actors, their capabilities, and their goals.

**Remediation** : Remediation is the key to incident response and refers to the actual removal of threats such as malware and escalated privileges, among others. Incident response tools will facilitate the removal and allow teams to verify recovery before reintroducing infected systems or returning to normal operations.

**Investigation** : Investigation allows teams and companies to learn more about why they were attacked, how they were attacked, and what systems, applications, and data were negatively impacted. This information can help companies respond to compliance information requests, bolster security in vulnerable areas, and resolve similar, future issues, in less time.

### Who Uses Incident Response Software?

**Information security (InfoSec)**  **professionals:** InfoSec professionals use incident response software to monitor, alert, and remediate security threats to a company. Using incident response software, InfoSec professionals can automate and quickly scale their response to security incidents, above and beyond what teams can do manually.

**IT professionals:** For companies without dedicated information security teams, IT professionals may take on security roles. Professionals with limited security backgrounds may rely on incident response software with the more robust functionality to assist them in identifying threats, their decision making when security incidents arise, and threat remediation.

**Incident response service providers:** Practitioners at incident response service providers use incident response software to actively manage their client’s security, as well as other providers of managed security services.

### What are the Alternatives to Incident Response Software?

Companies that prefer to string together open-source or other various software tools to achieve the functionality of incident response software can do so with a combination of log analysis, SIEM, intrusion detection systems, vulnerability scanners, backup, and other tools. Conversely, companies may wish to outsource the management of their security programs to managed service providers.

[Endpoint detection and response (EDR) software](https://www.g2.com/categories/endpoint-detection-response-edr): They combine both [endpoint antivirus](https://www.g2.com/categories/endpoint-antivirus) and [endpoint management](https://www.g2.com/categories/endpoint-management) solutions to detect, investigate, and remove any malicious software that penetrates a network’s devices.&amp;nbsp;

[Managed detection and response (MDR) software](https://www.g2.com/categories/managed-detection-and-response-mdr): They proactively monitor networks, endpoints, and other IT resources for security incidents.&amp;nbsp;

[Extended detection and response (XDR) software](https://www.g2.com/categories/extended-detection-and-response-xdr-platforms): They are tools used to automate the discovery and remediation of security issues across hybrid systems.&amp;nbsp;

[Incident response services providers](https://www.g2.com/categories/incident-response-services) **:** For companies that do not want to purchase and manage their incident response in-house or develop their open-source solutions, they can employ incident response services providers.

[Log analysis software](https://www.g2.com/categories/log-analysis) **:** Log analysis software helps enable the documentation of application log files for records and analytics.

[Log monitoring software](https://www.g2.com/categories/log-monitoring) **:** By detecting and alerting users to patterns in these log files, log monitoring software helps solve performance and security issues.

[Intrusion detection and prevention systems (IDPS)](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps): IDPS is used to inform IT administrators and security staff of anomalies and attacks on IT infrastructure and applications. These tools detect malware, socially engineered attacks, and other web-based threats.&amp;nbsp;

[Security information and event management (SIEM) software](https://www.g2.com/categories/security-information-and-event-management-siem): SIEM software can offer security information alerting, along with centralizing security operations into one platform. However, SIEM software cannot automate remediation practices like some incident response software does, however. For companies that do not want to manage SIEM in-house, they can work with [managed SIEM service providers](https://www.g2.com/categories/managed-siem-services).

[Threat intelligence software](https://www.g2.com/categories/threat-intelligence): Threat intelligence software provides organizations with information related to the newest forms of cyber threats like zero-day attacks, new forms of malware, and exploits. Companies may wish to work with [threat intelligence services providers](https://www.g2.com/categories/threat-intelligence-services), as well.

[Vulnerability scanner software](https://www.g2.com/categories/vulnerability-scanner): Vulnerability scanners are tools that constantly monitor applications and networks to identify security vulnerabilities. They work by maintaining an up-to-date database of known vulnerabilities, and conduct scans to identify potential exploits. Companies may opt to work with [vulnerability assessment services providers](https://www.g2.com/categories/vulnerability-assessment-services), instead of managing this in-house.

[Patch management software](https://www.g2.com/categories/patch-management): Patch management tools are used to ensure that the components of a company’s software stack and IT infrastructure are up to date. They then alert users of necessary updates or execute updates automatically.&amp;nbsp;

[Backup software](https://www.g2.com/categories/backup): Backup software offers protection for business data by copying data from servers, databases, desktops, laptops, and other devices in case user error, corrupt files, or physical disaster render a business’ critical data inaccessible. In the event of data loss from a security incident, data can be restored to its previous state from a backup.

#### Software Related to Incident Response Software

The following technology families are either closely related to incident response software products or have significant overlap between product functionality.

[Security information and event management (SIEM) software](https://www.g2.com/categories/security-information-and-event-management-siem) **:** [SIEM](https://www.g2.com/categories/security-information-and-event-management-siem) platforms go together with incident response solutions. Incident response may be facilitated by SIEM systems but these tools are specifically designed to streamline the remediation process or add investigative capabilities during security workflow processes. Incident response solutions will not provide the same level of compliance maintenance or log storage capabilities but can be used to increase a team’s ability to tackle threats as they emerge.

[Data breach notification software](https://www.g2.com/categories/data-breach-notification) **:** [Data breach notification](https://www.g2.com/categories/data-breach-notification) software helps companies document the impacts of data breaches to inform regulatory authorities and notify impacted individuals. These solutions automate and operationalize the data breach notification process to adhere to strict data disclosure laws and privacy regulations within mandated timelines, which in some instances can be as few as 72 hours.

[Digital forensics software](https://www.g2.com/categories/digital-forensics) **:** [Digital forensics](https://www.g2.com/categories/digital-forensics) tools are used to investigate and examine security incidents and threats after they’ve occurred. They don’t facilitate the actual remediation of security incidents but they can provide additional information on the source and scope of a security incident. They also may offer more in-depth investigatory information than incident response software.

[Security orchestration, automation, and response (SOAR) software](https://www.g2.com/categories/security-orchestration-automation-and-response-soar) **:** [SOAR](https://www.g2.com/categories/security-orchestration-automation-and-response-soar) is a segment of the security market focused on automating all low-level security tasks. These tools integrate with a company’s SIEM to gather security information. They then integrate with monitoring and response tools to develop an automated workflow from discovery to resolution. Some incident response solutions will allow for workflow development and automation but don’t have a wide range of integration and automation capabilities of a SOAR platform.

[Insider threat management (ITM) software](https://www.g2.com/categories/insider-threat-management-itm): Companies use ITM software to monitor and record the actions of internal system users on their endpoints, such as current and former employees, contractors, business partners, and other permissioned individuals, to protect company assets, such as customer data or intellectual property.

### Challenges with Incident Response Software

Software solutions can come with their own set of challenges. The biggest challenge incident response teams may encounter with the software is ensuring that it meets the business’ unique process requirements.

**False positives:** Incident response software may identify a threat that turns out to be inaccurate, which is known as a false positive. Acting on false positives can waste company resources, time, and create unnecessary downtime for impacted individuals.

**Decision making:** Incident response software can automate remediation to some security threats, however, a security professional with knowledge of the company’s unique environment should weigh in on the decision-making process on how to handle automating these issues. This may require that companies consult with the software vendor and purchase additional professional services for deploying the software solution. Similarly, when designing workflows on who to alert in the event of a security incident and what actions to take and when, these must be designed with the organization’s specific security needs in mind.&amp;nbsp;&amp;nbsp;

**Changes in regulatory compliance:** It is important to stay up to date with changes in regulatory compliance laws, especially concerning data breach notification requirements for who to notify and within what time frame. Companies should also ensure the software provider is providing the necessary updates to the software itself, or work to handle this task operationally.

**Insider threats:** Many companies focus on external threats, but may not appropriately plan for threats from insiders like employees, contractors, and others with privileged access. It’s important to ensure the Incident Response solution addresses the company’s unique security risk environment, for both external and internal incidents.

### How to Buy Incident Response Software

#### Requirements Gathering (RFI/RFP) for Incident Response Software

It is important to gather the company’s requirements before starting the search for an incident response software solution. To have an effective incident response program, the company must utilize the right tools to support their staff and security practices. Things to consider when determining the requirements include:

**Enabling staff responsible for using the software:** The team that is tasked with managing this software and the company’s incident response should be heavily involved in gathering requirements and then assessing software solutions.&amp;nbsp;

**Integrations** : The software solution should integrate with the company’s existing software stack. Many vendors provide pre-built integrations with the most common third-party systems. The company must ensure the integrations they require are either offered pre-built by the vendor or can be built with ease.

**Usability** : The software should be easy to use for the incident response team. Features they may prefer in an incident response solution include, out-of-the-box workflows for common incidents, no-code automation workflow builders, decision-process visualization, communication tools, and a knowledge sharing center.

**Daily volume of threats:** It is important to select an incident response software solution that can meet the company’s level of need. If the volume of security threats received in a day is high, it may be better to select a tool with robust functionality in terms of automating remediation to reduce the burden on staff. For companies experiencing a low volume of threats, they may be able to get by with less robust tools that offer security incident tracking, without much automated remediation functionality.

**Applicable regulations:** Users should learn specific privacy, security, data breach notification, and other regulations apply to a business in advance. This may be regulation-driven, like companies operating in regulated industries like healthcare subject to HIPAA or financial services subject to the Gramm-Leach-Bliley Act (GLBA); it may be geographic like companies subject to GDPR in the European Union; or it may be industry-specific, like companies adhering to payment card industry security standards like the Payment Card Industry-Data Security Standard (PCI-DSS).&amp;nbsp;&amp;nbsp;

**Data breach notification requirements:** It is imperative to determine what security incidents may be reportable data breaches and whether the specific data breach must be reported to regulators, affected individuals, or both. The incident response software solution selected should enable the incident response team to meet these requirements.

#### Compare Incident Response Software Products

**Create a long list**

Users can research[incident response software](https://www.g2.com/categories/incident-response)providers on G2.com where they can find information such as verified software user reviews and vendor rankings based on user satisfaction and software segment sizes, such as small, medium, or enterprise businesses. It’s also possible to sort software solutions by languages supported.

Users can save any software products that meet their high-level requirements to their&amp;nbsp; “My List” on G2 by selecting the “favorite” heart symbol on the software’s product page. Saving the selections to the G2 My List will enable users to reference their selections again in the future.&amp;nbsp;

**Create a short list**

Users can visit their “My List” on G2.com to begin narrowing down their selection. G2 offers a product compare feature, where buyers can evaluate software features side by side based on real user rankings.&amp;nbsp;

They can also review [G2.com’s quarterly software reports](https://www.g2.com/reports) which have in-depth detail on the software user’s perception of their return on investment (in months), the time it took to implement their software solution, usability rankings, and other factors.

**Conduct demos**

Users can see the product they’ve narrowed down live by scheduling demonstrations. Many times, they can schedule demos directly through G2.com by clicking the “Get a quote” button on the vendor’s product profile.&amp;nbsp;

They can share their list of requirements and questions with the vendor in advance of their demo. It’s best to use a standard list of questions for each demonstration to ensure a fair comparison between each vendor on the same factors.&amp;nbsp;

#### Selection of Incident Response Software

**Choose a selection team**

Incident response software will likely be managed by InfoSec teams or IT teams. The people responsible for the day-to-day use of these tools must be a part of the selection team.

Others who may be beneficial to include on the selection team include professionals from the service desk, network operations, identity and access, application management, privacy, compliance, and legal teams.&amp;nbsp;

**Negotiation**

Most incident response software will be sold as a SaaS on a subscription or usage basis. Pricing will likely depend on the functions required by an organization. For example, log monitoring may be priced by the GB, while vulnerability assessments may be priced by the asset. Oftentimes, buyers can get discounts if they enter contracts for a longer duration.

Negotiating on implementation, support packages, and other professional services is also important. It is particularly important to set the incident response software up correctly when it is first deployed, especially when it comes to creating automated remediation actions and designing workflows.

**Final decision**

Before purchasing software, most vendors allow a free short-term trial of the product. The day-to-day users of the product must test the software’s capabilities before making a decision. If the selection team approves during the test phase and others on the selection team are satisfied with the solution, buyers can proceed with the contracting process.



