# Which SOAR tools are most trusted by security operations center directors based on user reviews?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Hi G2 community, which <a class="a a--md" elv="true" href="https://www.g2.com/categories/security-orchestration-automation-and-response-soar">SOAR tools</a> earn the strongest trust signals for security operations center directors? I focused on G2 reviews describing SOC workflows, alert triage, incident response, scalability, and analyst efficiency.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">A few platforms consistently stand out:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/torq-ai-soc-platform/reviews"><strong>Torq AI SOC Platform</strong></a><strong>:</strong> Reviewers value centralized incident management, extensive integrations, automated response, and the ability to handle large volumes of alerts without relying on analysts for every repetitive step.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/tines-stories/reviews"><strong>Tines Stories</strong></a><strong>:</strong> Security teams repeatedly praise its visual workflow builder, low-code automation, and ability to standardize alert enrichment, phishing triage, routing, and incident-response procedures.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/microsoft-sentinel/reviews"><strong>Microsoft Sentinel</strong></a><strong>:</strong> SOC-focused reviewers highlight centralized monitoring, strong Microsoft integrations, scalable log collection, automated playbooks, and faster movement from alert detection to investigation.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/splunk-soar-security-orchestration-automation-and-response/reviews"><strong>Splunk SOAR</strong></a><strong>:</strong> Its strength for established SOC environments is orchestration across security tools and repeatable response playbooks, particularly where Splunk is already part of the security stack.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/palo-alto-networks-cortex-xsoar/reviews"><strong>Palo Alto Networks Cortex XSOAR</strong></a><strong>:</strong> Reviews and its SOAR focus make it relevant for teams prioritizing incident orchestration, automated response, and coordination across a larger security ecosystem.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Trust in SOAR seems to come down to more than automation volume. SOC leaders also need workflows analysts can understand, integrations that remain dependable, and enough control to keep human review in the right places.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For SOC leaders running these platforms at scale, what builds trust fastest: lower MTTR, fewer manual triage steps, reliable integrations, or analysts actually adopting the automated playbooks?</p>

##### Post Metadata
- Posted at: 18 days ago
- Author title: Marketer
- Net upvotes: 1


## Comments
### Comment 1

Microsoft Sentinel and Splunk SOAR are both well-rated and trusted at the SOC leadership level, with strong automation and orchestration capabilities that matter to directors overseeing incident response at scale.

##### Comment Metadata
- Posted at: 9 days ago





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


