
  # Best Security Orchestration, Automation, and Response (SOAR) Software

  *By [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)*


   Security orchestration, automation, and response (SOAR) software products are tools used to help integrate security technologies and automate incident-related tasks. These tools integrate with a company’s existing security solutions to help users build and automate workflows, simplifying the incident response process and reducing the amount of human intervention necessary to handle security incidents. Companies use these tools to create a centralized system complete with visibility into a company’s security software and operational processes. These tools also reduce the time it takes to respond to incidents, as well as the potential for human error in remediating security threats and vulnerabilities.

SOAR platforms combine aspects of [vulnerability management](https://www.g2.com/categories/vulnerability-management), [incident response](https://www.g2.com/categories/incident-response), and [security information and event management (SIEM)](https://www.g2.com/categories/security-information-and-event-management-siem) solutions. SOAR products are designed to provide some of each tool’s respective functionality or integrate with third-party tools. Once integrated, processes can be designed to identify incidents and automate remediation tasks.

To qualify for inclusion in the Security Orchestration, Automation, and Response (SOAR) category, a product must:

- Integrate security information and incident response tools
- Allow security professionals to build response workflows
- Automate incident management and response tasks within workflows
- Provide formalized incident, workflow, and performance reports




  
  
## How Many Security Orchestration, Automation, and Response (SOAR) Software Products Does G2 Track?
**Total Products under this Category:** 79

### Category Stats (Jun 2026)
- **Average Rating**: 4.53/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product**: Palo Alto Networks Cortex XSOAR (+0.33%) - Among all products in this category, Palo Alto Networks Cortex XSOAR recorded the largest rating increase compared to last month
*Last updated: June 18, 2026*

  
## How Does G2 Rank Security Orchestration, Automation, and Response (SOAR) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 3,400+ Authentic Reviews
- 79+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

  
## Which Security Orchestration, Automation, and Response (SOAR) Software Is Best for Your Use Case?

- **Leader:** [Tines](https://www.g2.com/products/tines/reviews)
- **Highest Performer:** [Barracuda Incident Response](https://www.g2.com/products/barracuda-incident-response/reviews)
- **Easiest to Use:** [Torq AI SOC Platform](https://www.g2.com/products/torq-ai-soc-platform/reviews)
- **Top Trending:** [n8n](https://www.g2.com/products/n8n/reviews)
- **Best Free Software:** [Tines](https://www.g2.com/products/tines/reviews)

  
---

**Sponsored**

### Cydarm

Cydarm is a Cybersecurity Incident Response Management (CIRM) platform built to make cybersecurity operations teams better and faster. Cydarm is based on case management, built specifically for SOC. The platform enables collaboration across different levels of experience and trust, using playbooks and fine-grained access control integrated with case management. Cydarm allows you to integrate existing cybersecurity tools, including receiving alerts, enriching data, sending notifications, and generating incident reports and metrics reports automatically.



[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&amp;secure%5Bad_slot%5D=category_product_list&amp;secure%5Bcategory_id%5D=2178&amp;secure%5Bdisplayable_resource_id%5D=1082&amp;secure%5Bdisplayable_resource_type%5D=Category&amp;secure%5Bmedium%5D=sponsored&amp;secure%5Bplacement_reason%5D=neighbor_category&amp;secure%5Bplacement_resource_ids%5D%5B%5D=1082&amp;secure%5Bprioritized%5D=false&amp;secure%5Bproduct_id%5D=169593&amp;secure%5Bresource_id%5D=2178&amp;secure%5Bresource_type%5D=Category&amp;secure%5Bsource_type%5D=category_page&amp;secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsecurity-orchestration-automation-and-response-soar&amp;secure%5Btoken%5D=d19a21d33c7b49280037d212579746764420fa051fcd9c13f84d51707e0e92c3&amp;secure%5Burl%5D=https%3A%2F%2Fcydarm.com%2F&amp;secure%5Burl_type%5D=company_website)

---

  ## What Are the Top-Rated Security Orchestration, Automation, and Response (SOAR) Software Products in 2026?
### 1. [Tines](https://www.g2.com/products/tines/reviews)
  Tines is the intelligent workflow platform trusted by the world&#39;s most advanced organizations. Companies like Coinbase, Databricks, Mars, Reddit, and SAP use Tines to power their most important workflows. With Tines, they’ve built a secure, flexible foundation to operationalize AI agents and intelligent workflows, unlocking productivity, moving faster, and future-proofing how work gets done. You can start building right away, by signing up for our always-free Community Edition and importing one of our pre-built workflows from the library.


  **Average Rating:** 4.7/5.0
  **Total Reviews:** 395
**How Do G2 Users Rate Tines?**

- **Automated Remediation:** 9.3/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.6/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.2/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.6/10 (Category avg: 8.8/10)

**Who Is the Company Behind Tines?**

- **Seller:** [Tines](https://www.g2.com/sellers/tines)
- **Company Website:** https://www.tines.com/
- **Year Founded:** 2018
- **HQ Location:** Dublin, IE
- **LinkedIn® Page:** https://www.linkedin.com/company/tines-io/ (568 employees on LinkedIn®)

**Who Uses This Product?**
  - **Who Uses This:** Security Engineer, Software Engineer
  - **Top Industries:** Computer &amp; Network Security, Information Technology and Services
  - **Company Size:** 39% Mid-Market, 36% Enterprise


#### What Are Tines's Pros and Cons?

**Pros:**

- Ease of Use (73 reviews)
- Automation (57 reviews)
- Customer Support (39 reviews)
- Features (31 reviews)
- Time-saving (26 reviews)

**Cons:**

- Learning Curve (15 reviews)
- Missing Features (15 reviews)
- Lack of Features (12 reviews)
- Complexity (9 reviews)
- Difficult Learning (9 reviews)


### What Do G2 Reviewers Say About Tines?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **ease of use** of Tines, enabling effortless automation and workflow creation without coding knowledge.
- Users admire the **ease of automation** with Tines, allowing seamless integration and efficient workflow management.
- Users praise Tines for its **exceptional customer support** , ensuring quick resolutions and a smooth user experience.
- Users love Tines for its **ease of use and rapid implementation** , simplifying automation and improving workflow efficiency.
- Users highlight the **time-saving automation** capabilities of Tines, enabling focus on strategic tasks and improved efficiency.

**Cons:**

- Users note a **steep learning curve** with Tines, particularly for those new to automation tools.
- Users find Tines has **missing features** , which can hinder their experience, though updates are improving functionality.
- Users note a **lack of features** in Tines, highlighting missing functionalities and inconsistencies in its automation capabilities.
- Users find the **complexity of advanced functions** in Tines overwhelming, requiring clearer guidance for better navigation.
- Users note a **difficult learning curve** with Tines, particularly for those unfamiliar with automation tools.

#### What Are Recent G2 Reviews of Tines?

**"[AI orchestration with Drag-and-Drop development tool](https://www.g2.com/survey_responses/tines-review-12620879)"**

**Rating:** 4.5/5.0 stars
*— Dinesh  K.*

[Read full review](https://www.g2.com/survey_responses/tines-review-12620879)

---

**"[Streamlined Automation, Minimal Coding Required](https://www.g2.com/survey_responses/tines-review-12640960)"**

**Rating:** 5.0/5.0 stars
*— Shubham B.*

[Read full review](https://www.g2.com/survey_responses/tines-review-12640960)

---


#### What Are G2 Users Discussing About Tines?

- [How do you use Tines?](https://www.g2.com/discussions/how-do-you-use-tines)
- [Is tines a soar?](https://www.g2.com/discussions/is-tines-a-soar) - 1 comment
- [What does Tines do?](https://www.g2.com/discussions/what-does-tines-do) - 1 comment
- [What is Tines automation?](https://www.g2.com/discussions/what-is-tines-automation) - 2 comments

### 2. [n8n](https://www.g2.com/products/n8n/reviews)
  n8n is a workflow automation platform built for technical teams operationalizing AI. Built for technical teams, it offers 500+ integrations, custom code flexibility, and self-hosting options. With 180k+ Github Stars and a thriving community, n8n enables teams to build production-ready automation workflows that bridge AI with real business processes.


  **Average Rating:** 4.7/5.0
  **Total Reviews:** 279
**How Do G2 Users Rate n8n?**

- **Automated Remediation:** 8.2/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.1/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.4/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.4/10 (Category avg: 8.8/10)

**Who Is the Company Behind n8n?**

- **Seller:** [n8n GmbH](https://www.g2.com/sellers/n8n-gmbh)
- **Company Website:** https://n8n.io
- **Year Founded:** 2019
- **HQ Location:** Berlin, Berlin
- **Twitter:** @n8n_io (81,824 Twitter followers)
- **LinkedIn® Page:** https://linkedin.com/company/n8n (999 employees on LinkedIn®)

**Who Uses This Product?**
  - **Who Uses This:** CEO, Founder
  - **Top Industries:** Computer Software, Information Technology and Services
  - **Company Size:** 78% Small-Business, 17% Mid-Market


#### What Are n8n's Pros and Cons?

**Pros:**

- Ease of Use (77 reviews)
- Automation (72 reviews)
- Integrations (42 reviews)
- Workflow Management (36 reviews)
- Features (35 reviews)

**Cons:**

- Learning Curve (39 reviews)
- Difficult Learning (23 reviews)
- Missing Features (17 reviews)
- Limitations (14 reviews)
- Poor Interface Design (14 reviews)


### What Do G2 Reviewers Say About n8n?
*AI-generated summary from verified user reviews*

**Pros:**

- Users find n8n&#39;s **ease of use** remarkable, making complex workflow automation simple and effective with a visual editor.
- Users appreciate the **flexible and powerful automation** capabilities of n8n, streamlining complex workflows effortlessly.
- Users love the **extensive integrations** n8n offers, enabling seamless workflows and efficient automation across various tools.
- Users enjoy the **flexibility and ease of use** in n8n&#39;s workflow management, enhancing productivity and creativity.
- Users appreciate the **all-in-one powerhouse features** of n8n, enabling skill development and powerful workflow automation.

**Cons:**

- Users find n8n&#39;s **steep learning curve** challenging, particularly for non-developers managing complex workflows.
- Users find the **difficult learning** curve of n8n challenging, especially for those without technical backgrounds.
- Users find n8n lacking in **cost-control features** , leading to unexpected expenses and inefficient learning experiences.
- Users face **limitations with custom nodes** in n8n&#39;s cloud service, making it challenging for non-technical users.
- Users highlight the **poor interface design** of n8n, finding it challenging and limiting for workflow development.

#### What Are Recent G2 Reviews of n8n?

**"[Open-Source Powerhouse with Great MCP Integration and a Massive Community](https://www.g2.com/survey_responses/n8n-review-12845138)"**

**Rating:** 4.5/5.0 stars
*— Harsh S.*

[Read full review](https://www.g2.com/survey_responses/n8n-review-12845138)

---

**"[n8n: Intuitive Visual Workflows with Powerful Custom JavaScript and Self-Hosting Control](https://www.g2.com/survey_responses/n8n-review-12809735)"**

**Rating:** 5.0/5.0 stars
*— Sunil S.*

[Read full review](https://www.g2.com/survey_responses/n8n-review-12809735)

---


#### What Are G2 Users Discussing About n8n?

- [How do you use N8N?](https://www.g2.com/discussions/how-do-you-use-n8n)
- [Who uses n8n?](https://www.g2.com/discussions/who-uses-n8n)
- [Is n8n open source?](https://www.g2.com/discussions/is-n8n-open-source)
- [What does n8n do?](https://www.g2.com/discussions/what-does-n8n-do) - 3 comments

### 3. [KnowBe4 PhishER/PhishER Plus](https://www.g2.com/products/knowbe4-phisher-phisher-plus/reviews)
  PhishER Plus is a FedRAMP Moderate certified, lightweight Security Orchestration, Automation, and Response (SOAR) and full Incident Response product designed to help organizations manage email threats that bypass existing security measures. Offering enterprise-grade security automation while maintaining full transparency and control, PhishER Plus is ideal for organizations seeking enhanced email security without the traditional complexity that comes with other platforms. PhishER Plus addresses phishing attacks and malicious email activities through community-sourced intelligence from over 13 million global users, combined with precision AI analysis. This collaborative approach delivers actionable insights and rapid threat detection capabilities, suitable for IT security teams across organizations of all sizes looking to streamline their threat response processes. Organizations achieve significant financial returns, with users experiencing 362% to 650% ROI in the first year. PhishER Plus dramatically reduces investigation and remediation, with organizations reporting: - 85% faster investigation times - 99% reduction in manual email reviews - 90% auto-tagging of reported emails PhishER Plus seamlessly complements your existing security ecosystem, making it a valuable addition to any organization&#39;s cybersecurity strategy while delivering immediate operational and financial benefits.


  **Average Rating:** 4.5/5.0
  **Total Reviews:** 563
**How Do G2 Users Rate KnowBe4 PhishER/PhishER Plus?**

- **Automated Remediation:** 8.7/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.2/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)
- **Workflow Automation:** 8.6/10 (Category avg: 8.8/10)

**Who Is the Company Behind KnowBe4 PhishER/PhishER Plus?**

- **Seller:** [KnowBe4, Inc.](https://www.g2.com/sellers/knowbe4-inc)
- **Company Website:** https://www.knowbe4.com
- **Year Founded:** 2010
- **HQ Location:** Clearwater, FL
- **Twitter:** @KnowBe4 (16,161 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/2225282/ (2,540 employees on LinkedIn®)

**Who Uses This Product?**
  - **Who Uses This:** IT Manager, Director of IT
  - **Top Industries:** Financial Services, Non-Profit Organization Management
  - **Company Size:** 75% Mid-Market, 13% Enterprise


#### What Are KnowBe4 PhishER/PhishER Plus's Pros and Cons?

**Pros:**

- Phishing Prevention (50 reviews)
- Email Security (29 reviews)
- Automation (24 reviews)
- Security (22 reviews)
- Ease of Use (20 reviews)

**Cons:**

- False Positives (9 reviews)
- Ineffective Email Security (8 reviews)
- Email Management (7 reviews)
- Learning Curve (7 reviews)
- Setup Difficulty (7 reviews)


### What Do G2 Reviewers Say About KnowBe4 PhishER/PhishER Plus?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **effective phishing tests and automated email triage** , enhancing security and monitoring capabilities effortlessly.
- Users value the **proactive email threat assessment** feature, enhancing security through timely intervention and safe review processes.
- Users value the **automation features** of KnowBe4 PhishER, enhancing efficiency in managing and prioritizing phishing threats.
- Users value the **robust security features** of KnowBe4 PhishER, enhancing protection against phishing threats efficiently.
- Users praise the **ease of use** of KnowBe4 PhishER/PhishER Plus, appreciating its intuitive interface and efficient reporting functions.

**Cons:**

- Users face ongoing issues with **false positives** , complicating automation and necessitating more manual review than desired.
- Users express concerns about **ineffective email security** , as phishing emails can remain in Junk Email folders without automatic quarantine.
- Users report **inconsistent email management** , with emails often miscategorized in Junk folders and lacking clear feedback on scanned emails.
- Users find the **learning curve intimidating** without assistance, impacting their ability to adjust and troubleshoot effectively.
- Users find the **setup difficult** , requiring time and careful understanding of rules for proper configuration.

#### What Are Recent G2 Reviews of KnowBe4 PhishER/PhishER Plus?

**"[User friendly and great support!](https://www.g2.com/survey_responses/knowbe4-phisher-phisher-plus-review-7661687)"**

**Rating:** 4.0/5.0 stars
*— Scott W.*

[Read full review](https://www.g2.com/survey_responses/knowbe4-phisher-phisher-plus-review-7661687)

---

**"[Easy way to report phishing emails but setup could use some improvement](https://www.g2.com/survey_responses/knowbe4-phisher-phisher-plus-review-7730406)"**

**Rating:** 4.0/5.0 stars
*— Rob H.*

[Read full review](https://www.g2.com/survey_responses/knowbe4-phisher-phisher-plus-review-7730406)

---


#### What Are G2 Users Discussing About KnowBe4 PhishER/PhishER Plus?

- [What is phishing explain with example?](https://www.g2.com/discussions/what-is-phishing-explain-with-example)
- [Is KnowBe4 com legit?](https://www.g2.com/discussions/is-knowbe4-com-legit) - 2 comments
- [What is KnowBe4 Phish?](https://www.g2.com/discussions/what-is-knowbe4-phish) - 1 comment
- [What is a PhishER&#39;s tool?](https://www.g2.com/discussions/what-is-a-phisher-s-tool) - 4 comments

### 4. [Torq AI SOC Platform](https://www.g2.com/products/torq-ai-soc-platform/reviews)
  Torq is transforming cybersecurity with the Torq AI SOC Platform. Torq empowers enterprises to instantly and precisely detect and respond to security events at scale. Torq’s customer base includes major multinational enterprise customers, including Abnormal Security, Armis, Check Point Security, Chipotle Mexican Grill, Inditex (Zara, Bershka, and Pull &amp; Bear), Informatica, Kyocera, PepsiCo, Procter &amp; Gamble, Siemens, Telefónica, Valvoline, Virgin Atlantic, and Wiz.


  **Average Rating:** 4.8/5.0
  **Total Reviews:** 149
**How Do G2 Users Rate Torq AI SOC Platform?**

- **Automated Remediation:** 9.2/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.6/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.5/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.3/10 (Category avg: 8.8/10)

**Who Is the Company Behind Torq AI SOC Platform?**

- **Seller:** [torq](https://www.g2.com/sellers/torq)
- **Company Website:** https://torq.io/
- **Year Founded:** 2020
- **HQ Location:** New York, US
- **Twitter:** @torq_io (1,944 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/torqio/mycompany (441 employees on LinkedIn®)

**Who Uses This Product?**
  - **Top Industries:** Information Technology and Services, Computer &amp; Network Security
  - **Company Size:** 50% Mid-Market, 29% Small-Business


#### What Are Torq AI SOC Platform's Pros and Cons?

**Pros:**

- Ease of Use (67 reviews)
- Security (61 reviews)
- Automation (59 reviews)
- Features (55 reviews)
- Threat Detection (41 reviews)

**Cons:**

- Difficult Learning (18 reviews)
- Learning Curve (17 reviews)
- Missing Features (10 reviews)
- Improvement Needed (8 reviews)
- Poor Interface Design (8 reviews)


### What Do G2 Reviewers Say About Torq AI SOC Platform?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **ease of use** of Torq AI SOC Platform, enabling efficient security operations without coding knowledge.
- Users appreciate the **powerful security features** of Torq AI SOC Platform for effective vulnerability management and threat response.
- Users love the **ease of automation** in Torq AI SOC Platform, streamlining processes and enhancing efficiency effortlessly.
- Users value the **comprehensive incident management** and threat detection capabilities of the Torq AI SOC Platform, enhancing security operations.
- Users value the **powerful threat detection** capabilities of Torq, enabling swift response to network vulnerabilities and threats.

**Cons:**

- Users find the **difficult learning curve** of Torq AI SOC Platform challenging, especially with complex workflows and documentation.
- Users find the **steep learning curve** of Torq AI SOC Platform challenging, especially for beginners requiring adequate training.
- Users feel that the **missing features** like templates and training hinder Torq&#39;s effectiveness for schools and users.
- Users indicate that **improvement is needed** in integration, customization, and educational resources for a better experience.
- Users find the **poor interface design** makes debugging and navigation confusing, hindering efficient use of the platform.

#### What Are Recent G2 Reviews of Torq AI SOC Platform?

**"[Efficient Automation with Robust Integrations](https://www.g2.com/survey_responses/torq-ai-soc-platform-review-12301239)"**

**Rating:** 5.0/5.0 stars
*— Orlando  M.*

[Read full review](https://www.g2.com/survey_responses/torq-ai-soc-platform-review-12301239)

---

**"[Centralized Incident Management That Exceeds Expectations](https://www.g2.com/survey_responses/torq-ai-soc-platform-review-12121506)"**

**Rating:** 5.0/5.0 stars
*— Octave P.*

[Read full review](https://www.g2.com/survey_responses/torq-ai-soc-platform-review-12121506)

---



### 5. [ServiceNow Security Operations](https://www.g2.com/products/servicenow-security-operations/reviews)
  ServiceNow Security Operations is a sophisticated software solution designed to enhance threat and vulnerability management as well as incident response for organizations. By leveraging artificial intelligence, this platform empowers security teams to operate more efficiently and effectively, allowing for streamlined collaboration across IT, security, and risk management departments. The primary goal of ServiceNow Security Operations is to simplify complex security processes while minimizing risks associated with cybersecurity threats. Targeted at security teams within organizations of various sizes, ServiceNow Security Operations addresses the need for a cohesive approach to managing security incidents and vulnerabilities. It is particularly beneficial for organizations that utilize multiple security tools, as it integrates security and vulnerability data from these existing systems. This integration enables teams to respond to threats more rapidly by automating critical workflows and processes, thus reducing the manual effort traditionally required in incident response. Key features of ServiceNow Security Operations include intelligent workflows that automate routine tasks, allowing security professionals to focus on more strategic initiatives. The platform’s AI-driven capabilities facilitate the automatic correlation of threat intelligence from diverse sources, such as the MITRE ATT&amp;CK framework. This feature enhances situational awareness and enables teams to prioritize threats effectively based on real-time data. Additionally, the ability to take action within other security or IT management tools from a centralized console streamlines operations, ensuring that teams can respond to incidents without unnecessary delays. Moreover, the use of digital security workflows and orchestration significantly accelerates tasks such as analysis, prioritization, and remediation. By automating these processes, organizations can not only improve their response times but also enhance their overall cybersecurity posture. The integration of AI-driven automation within the ServiceNow AI Platform® further strengthens the platform&#39;s capabilities, enabling organizations to drive cyber resilience and reduce their exposure to potential threats. In summary, ServiceNow Security Operations is a comprehensive solution that addresses the complexities of modern cybersecurity challenges. By automating and simplifying threat and vulnerability management, it empowers security teams to respond more effectively, thereby enhancing the overall security framework of an organization.


  **Average Rating:** 4.4/5.0
  **Total Reviews:** 67
**How Do G2 Users Rate ServiceNow Security Operations?**

- **Automated Remediation:** 8.8/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.6/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.5/10 (Category avg: 8.8/10)

**Who Is the Company Behind ServiceNow Security Operations?**

- **Seller:** [ServiceNow](https://www.g2.com/sellers/servicenow)
- **Company Website:** https://www.servicenow.com/
- **Year Founded:** 2004
- **HQ Location:** Santa Clara, CA
- **Twitter:** @servicenow (55,548 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/29352/ (35,081 employees on LinkedIn®)

**Who Uses This Product?**
  - **Top Industries:** Information Technology and Services, Computer &amp; Network Security
  - **Company Size:** 51% Enterprise, 20% Mid-Market


#### What Are ServiceNow Security Operations's Pros and Cons?

**Pros:**

- Integration Capabilities (9 reviews)
- Integration Support (9 reviews)
- Integrations (8 reviews)
- Ease of Use (7 reviews)
- Incident Management (6 reviews)

**Cons:**

- Difficult Setup (4 reviews)
- Integration Issues (4 reviews)
- Licensing Issues (3 reviews)
- Complexity (2 reviews)
- Difficult Customization (2 reviews)


### What Do G2 Reviewers Say About ServiceNow Security Operations?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **comprehensive integration capabilities** of ServiceNow Security Operations, simplifying security process management effectively.
- Users value the **comprehensive integration capabilities** of ServiceNow Security Operations, simplifying security management and enhancing productivity.
- Users value the **seamless integration capabilities** of ServiceNow Security Operations, streamlining security management efficiently.
- Users commend the **ease of use** of ServiceNow Security Operations, particularly appreciating its efficient integration and workflow capabilities.
- Users value the **seamless integration** of ServiceNow Security Operations, enhancing workflow efficiency and incident management.

**Cons:**

- Users find the **difficult setup** process of ServiceNow Security Operations to be complex and costly, affecting integration efficiency.
- Users face challenges with **integration issues** , particularly in CI mapping and lack of clear documentation for initial setup.
- Users feel the **licensing issues** in ServiceNow Security Operations are restrictive and complicate effective remediation efforts.
- Users struggle with **complexity** in building playbooks and face challenges during initial setup and licensing costs.
- Users find **difficult customization** in ServiceNow Security Operations challenging, particularly in creating effective playbooks.

#### What Are Recent G2 Reviews of ServiceNow Security Operations?

**"[Strong platform for centralized security operations and incident response](https://www.g2.com/survey_responses/servicenow-security-operations-review-12737410)"**

**Rating:** 4.5/5.0 stars
*— Dharamveer p.*

[Read full review](https://www.g2.com/survey_responses/servicenow-security-operations-review-12737410)

---

**"[Centralized, Automated Security Workflows with ServiceNow Security Operations](https://www.g2.com/survey_responses/servicenow-security-operations-review-12823627)"**

**Rating:** 4.5/5.0 stars
*— Himanshu J.*

[Read full review](https://www.g2.com/survey_responses/servicenow-security-operations-review-12823627)

---


#### What Are G2 Users Discussing About ServiceNow Security Operations?

- [What is ServiceNow sir?](https://www.g2.com/discussions/what-is-servicenow-sir)
- [What is service now in cyber security?](https://www.g2.com/discussions/what-is-service-now-in-cyber-security)
- [What are the typical functions of the Security Operations Center SOC analysts?](https://www.g2.com/discussions/what-are-the-typical-functions-of-the-security-operations-center-soc-analysts)
- [What can ServiceNow security operations do?](https://www.g2.com/discussions/what-can-servicenow-security-operations-do)

### 6. [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)
  Microsoft Sentinel lets you see and stop threats before they cause harm, with SIEM reinvented for a modern world. Microsoft Sentinel is your birds-eye view across the enterprise. Put the cloud and large-scale intelligence from decades of Microsoft security experience to work. Make your threat detection and response smarter and faster with artificial intelligence (AI). Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. With Microsoft Sentinel, you can: - Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds - Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft - Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft -Respond to incidents rapidly with built-in orchestration and automation of common tasks


  **Average Rating:** 4.4/5.0
  **Total Reviews:** 272
**How Do G2 Users Rate Microsoft Sentinel?**

- **Automated Remediation:** 8.7/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.5/10)
- **Workflow Automation:** 8.4/10 (Category avg: 8.8/10)

**Who Is the Company Behind Microsoft Sentinel?**

- **Seller:** [Microsoft](https://www.g2.com/sellers/microsoft)
- **Year Founded:** 1975
- **HQ Location:** Redmond, Washington
- **Twitter:** @microsoft (13,091,739 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/microsoft/ (231,632 employees on LinkedIn®)
- **Ownership:** MSFT

**Who Uses This Product?**
  - **Who Uses This:** Senior Software Engineer, Cyber Security Analyst
  - **Top Industries:** Information Technology and Services, Computer &amp; Network Security
  - **Company Size:** 42% Enterprise, 31% Mid-Market


#### What Are Microsoft Sentinel's Pros and Cons?

**Pros:**

- Real-time Monitoring (27 reviews)
- Alerting (23 reviews)
- Dashboard Usability (21 reviews)
- Response Time (16 reviews)
- Data Management (15 reviews)

**Cons:**

- Cloud Dependency (12 reviews)
- Complex Configuration (12 reviews)
- Configuration Issues (11 reviews)
- Difficult Setup (10 reviews)
- Poor Interface Design (9 reviews)


### What Do G2 Reviewers Say About Microsoft Sentinel?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **real-time monitoring** of Microsoft Sentinel, enhancing security through immediate threat detection and alerts.
- Users value the **automated alert response** and centralized monitoring of Microsoft Sentinel, enhancing security and peace of mind.
- Users appreciate the **user-friendly dashboard usability** of Microsoft Sentinel, enhancing their security management experience with intuitive features.
- Users value the **fast response time** of Microsoft Sentinel, ensuring quick detection and mitigation of potential threats.
- Users value the **seamless data integration** of Microsoft Sentinel, enhancing workflow and ensuring comprehensive security management.

**Cons:**

- Users express concern about the **cloud dependency** of Microsoft Sentinel, highlighting connectivity issues with low-speed internet.
- Users find the **complex configuration** of Microsoft Sentinel challenging, requiring advanced technical skills and time investment.
- Users face **configuration issues** with Microsoft Sentinel, finding setup complex and integration with third-party tools challenging.
- Users find the **difficult setup** of Microsoft Sentinel challenging, especially without dedicated security experts and proper training.
- Users struggle with the **challenging interface design** of Microsoft Sentinel, causing navigation issues and confusion for new users.

#### What Are Recent G2 Reviews of Microsoft Sentinel?

**"[Strong Centralized Visibility and Scalable Detection for Faster SOC Response](https://www.g2.com/survey_responses/microsoft-sentinel-review-12823175)"**

**Rating:** 4.5/5.0 stars
*— Verified User in Information Technology and Services*

[Read full review](https://www.g2.com/survey_responses/microsoft-sentinel-review-12823175)

---

**"[Centralized Visibility with Smooth Integration](https://www.g2.com/survey_responses/microsoft-sentinel-review-12626167)"**

**Rating:** 4.0/5.0 stars
*— Anas M.*

[Read full review](https://www.g2.com/survey_responses/microsoft-sentinel-review-12626167)

---


#### What Are G2 Users Discussing About Microsoft Sentinel?

- [What is Microsoft Sentinel used for?](https://www.g2.com/discussions/what-is-microsoft-sentinel-used-for) - 3 comments, 2 upvotes
- [Why should I use Azure Sentinel?](https://www.g2.com/discussions/why-should-i-use-azure-sentinel) - 1 comment
- [Which feature provides the extended detection and response capabilities of Azure Sentinel?](https://www.g2.com/discussions/which-feature-provides-the-extended-detection-and-response-capabilities-of-azure-sentinel)
- [What is the difference between Azure security Center and Azure Sentinel?](https://www.g2.com/discussions/what-is-the-difference-between-azure-security-center-and-azure-sentinel)
- [What does Azure Sentinel provide?](https://www.g2.com/discussions/what-does-azure-sentinel-provide)

### 7. [Check Point Infinity Platform](https://www.g2.com/products/check-point-infinity-platform/reviews)
  Check Point Infinity is the only fully consolidated cyber security architecture that provides unprecedented protection against Gen V mega-cyber attacks as well as future cyber threats across all networks, endpoint, cloud and mobile. The architecture is designed to resolve the complexities of growing connectivity and inefficient security.


  **Average Rating:** 4.6/5.0
  **Total Reviews:** 109
**How Do G2 Users Rate Check Point Infinity Platform?**

- **Quality of Support:** 8.8/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.6/10 (Category avg: 8.5/10)

**Who Is the Company Behind Check Point Infinity Platform?**

- **Seller:** [Check Point Software Technologies](https://www.g2.com/sellers/check-point-software-technologies)
- **Year Founded:** 1993
- **HQ Location:** Redwood City, CA
- **Twitter:** @CheckPointSW (70,955 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/check-point-software-technologies/ (8,554 employees on LinkedIn®)
- **Ownership:** NASDAQ:CHKP

**Who Uses This Product?**
  - **Top Industries:** Computer &amp; Network Security, Information Technology and Services
  - **Company Size:** 44% Enterprise, 37% Mid-Market


#### What Are Check Point Infinity Platform's Pros and Cons?

**Pros:**

- Cloud Security (20 reviews)
- Cloud Integration (16 reviews)
- Detection (16 reviews)
- Comprehensive Security (14 reviews)
- Cloud Services (13 reviews)

**Cons:**

- Learning Curve (10 reviews)
- Complexity (6 reviews)
- Improvement Needed (6 reviews)
- Poor Support Services (6 reviews)
- Limited Customization (5 reviews)


### What Do G2 Reviewers Say About Check Point Infinity Platform?
*AI-generated summary from verified user reviews*

**Pros:**

- Users love the **advanced security features** of Check Point Infinity Platform, ensuring robust cloud protection effortlessly.
- Users appreciate the **unified management console** of Check Point Infinity Platform, simplifying security oversight and enhancing efficiency.
- Users appreciate the **unified security management** of Check Point Infinity Platform, allowing seamless protection across endpoints, cloud, and network.
- Users appreciate the **easy management** of Check Point Infinity Platform, consolidating all security tools into a single interface.
- Users appreciate the **unified security features** of Check Point Infinity Platform, simplifying management and enhancing overall protection.

**Cons:**

- Users face a **steep learning curve** due to the platform&#39;s complexity and lack of comprehensive documentation.
- Users find the **complexity** of the Check Point Infinity Platform overwhelming, with a steep learning curve and fragmented experience.
- Users experience **delays** due to long resolution times, affecting support and overall user satisfaction.
- Users find the **difficult configuration** of Check Point Infinity Platform challenging, complicating initial setup and daily management.
- Users note the **high pricing** of Check Point Infinity Platform, making it less accessible for small businesses.

#### What Are Recent G2 Reviews of Check Point Infinity Platform?

**"[Excellent option  Harmony Platform for security central](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11868343)"**

**Rating:** 4.5/5.0 stars
*— Tania V.*

[Read full review](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11868343)

---

**"[Seamless Hybrid Security Integration Across All Environments](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11954684)"**

**Rating:** 4.5/5.0 stars
*— Sonu S.*

[Read full review](https://www.g2.com/survey_responses/check-point-infinity-platform-review-11954684)

---


#### What Are G2 Users Discussing About Check Point Infinity Platform?

- [How does Check Point Infinity help customers?](https://www.g2.com/discussions/how-does-check-point-infinity-help-customers)
- [What are the benefits of Check Point unified security architecture?](https://www.g2.com/discussions/what-are-the-benefits-of-check-point-unified-security-architecture)
- [What are the 4 components of the Infinity architecture?](https://www.g2.com/discussions/what-are-the-4-components-of-the-infinity-architecture)
- [What is Infinity Total protection?](https://www.g2.com/discussions/what-is-infinity-total-protection)

### 8. [Palo Alto Networks Cortex XSOAR](https://www.g2.com/products/palo-alto-networks-cortex-xsoar/reviews)
  Palo Alto Networks&#39; Cortex XSOAR is a comprehensive Security Orchestration, Automation, and Response (SOAR) platform designed to streamline and enhance security operations. By integrating automation, case management, real-time collaboration, and threat intelligence management, Cortex XSOAR empowers security teams to respond to incidents more efficiently and effectively. Key Features and Functionality: - Process Standardization and Automation: Cortex XSOAR offers over 270 out-of-the-box playbooks, enabling the automation of numerous security use cases. These playbooks orchestrate response actions across more than 350 third-party products, facilitating seamless integration and operational consistency. - Security-Focused Case Management: The platform unifies alerts, incidents, and indicators from various sources into a single case management framework. This consolidation accelerates incident response by providing a comprehensive view of security events. - Real-Time Collaboration: Cortex XSOAR includes a Virtual War Room equipped with built-in ChatOps and a command-line interface. This feature allows security teams to collaborate in real time, execute commands across the entire product stack, and manage incidents more effectively. - Threat Intelligence Management: The platform aggregates disparate threat intelligence sources, customizes and scores feeds, and matches indicators against the organization&#39;s specific environment. This capability enables security teams to take informed actions swiftly. Primary Value and Problem Solving: Cortex XSOAR addresses the challenges faced by security teams, such as the overwhelming volume of alerts and the need for rapid incident response. By automating repetitive tasks and standardizing processes, the platform reduces the time spent on incidents by up to 90%, allowing analysts to focus on critical threats. The integration of threat intelligence management with SOAR capabilities ensures that organizations can operationalize threat feeds effectively, enhancing their overall security posture. Additionally, the platform&#39;s extensive integration ecosystem, with over 360 third-party integrations, enables organizations to orchestrate complex workflows across their existing security infrastructure without extensive custom development.


  **Average Rating:** 4.6/5.0
  **Total Reviews:** 28
**How Do G2 Users Rate Palo Alto Networks Cortex XSOAR?**

- **Automated Remediation:** 9.0/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)
- **Workflow Automation:** 8.9/10 (Category avg: 8.8/10)

**Who Is the Company Behind Palo Alto Networks Cortex XSOAR?**

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks (128,951 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/30086/ (22,313 employees on LinkedIn®)
- **Ownership:** NYSE: PANW

**Who Uses This Product?**
  - **Top Industries:** Computer &amp; Network Security
  - **Company Size:** 50% Enterprise, 32% Mid-Market


#### What Are Palo Alto Networks Cortex XSOAR's Pros and Cons?

**Pros:**

- Incident Management (3 reviews)
- User Interface (2 reviews)
- Accuracy of Information (1 reviews)
- Automation (1 reviews)
- Customer Support (1 reviews)

**Cons:**

- Learning Curve (2 reviews)
- Limited Customization (1 reviews)
- Logging Issues (1 reviews)
- Log Management Issues (1 reviews)
- Poor Reporting (1 reviews)


### What Do G2 Reviewers Say About Palo Alto Networks Cortex XSOAR?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **customizability and automation capabilities** of Cortex XSOAR for effective incident management and support.
- Users appreciate the **great UI** of Palo Alto Networks Cortex XSOAR, enhancing usability and efficiency in incident response.
- Users appreciate the **accuracy of information** in Palo Alto Networks Cortex XSOAR, enhancing security and efficiency in operations.
- Users value the **powerful automation** features of Palo Alto Networks Cortex XSOAR, streamlining incident response effectively.
- Users appreciate the **direct customer support** of Palo Alto Networks Cortex XSOAR, enhancing their incident response efficiency.

**Cons:**

- Users note a **steep learning curve** with Palo Alto Networks Cortex XSOAR, requiring significant time to become proficient.
- Users feel the need for improved reporting and express a desire for **more customization options** in Cortex XSOAR.
- Users find **logging issues** challenging as results are hard to read without opening in a new tab.
- Users find it challenging to read logs quickly due to **log management issues** , requiring them to open new tabs for clarity.
- Users desire improved **reporting** and more customization options for better functionality in Cortex XSOAR.

#### What Are Recent G2 Reviews of Palo Alto Networks Cortex XSOAR?

**"[Unlocking Security Operations automation with Cortex XSOAR](https://www.g2.com/survey_responses/palo-alto-networks-cortex-xsoar-review-10447892)"**

**Rating:** 5.0/5.0 stars
*— Jai P.*

[Read full review](https://www.g2.com/survey_responses/palo-alto-networks-cortex-xsoar-review-10447892)

---

**"[Powerful Tool with Clean Data and Seamless Integrations](https://www.g2.com/survey_responses/palo-alto-networks-cortex-xsoar-review-11967977)"**

**Rating:** 5.0/5.0 stars
*— Pablo V.*

[Read full review](https://www.g2.com/survey_responses/palo-alto-networks-cortex-xsoar-review-11967977)

---


#### What Are G2 Users Discussing About Palo Alto Networks Cortex XSOAR?

- [What is Palo Alto Networks Cortex XSOAR used for?](https://www.g2.com/discussions/what-is-palo-alto-networks-cortex-xsoar-used-for)

### 9. [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)
  Google Security Operations offers a unified experience across SIEM, SOAR, and threat intelligence to drive better detection, investigation, and response. Collect security telemetry data, apply threat intel to identify high priority threats, drive response with playbook automation, case management, and collaboration. It also provides Gemini-native agentic defense to help autonomously handle workflows like alert triage, threat hunting, and detection engineering. Google Security Operations also supports AI Threat Defense to monitor, detect, and respond to threats from code you do not own or cannot patch.


  **Average Rating:** 4.4/5.0
  **Total Reviews:** 44
**How Do G2 Users Rate Google Security Operations?**

- **Automated Remediation:** 9.8/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.3/10 (Category avg: 9.0/10)
- **Ease of Admin:** 7.8/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.8/10 (Category avg: 8.8/10)

**Who Is the Company Behind Google Security Operations?**

- **Seller:** [Google](https://www.g2.com/sellers/google)
- **Year Founded:** 1998
- **HQ Location:** Mountain View, CA
- **Twitter:** @google (31,899,995 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/1441/ (341,888 employees on LinkedIn®)
- **Ownership:** NASDAQ:GOOG

**Who Uses This Product?**
  - **Top Industries:** Information Technology and Services, Computer &amp; Network Security
  - **Company Size:** 41% Enterprise, 39% Mid-Market


#### What Are Google Security Operations's Pros and Cons?

**Pros:**

- Security (8 reviews)
- Threat Detection (5 reviews)
- Ease of Use (4 reviews)
- Comprehensive Security (3 reviews)
- Integrations (3 reviews)

**Cons:**

- Expensive (5 reviews)
- Learning Curve (4 reviews)
- Complexity (3 reviews)
- Learning Difficulty (2 reviews)
- Limited Customization (2 reviews)


### What Do G2 Reviewers Say About Google Security Operations?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **robust cybersecurity and threat detection** capabilities of Google Security Operations for their security needs.
- Users value the **effective threat detection** capabilities of Google Security Operations for secure data analysis and response.
- Users find Google Security Operations to be **easy to use** , benefiting from its seamless integration and effective threat detection.
- Users value the **comprehensive security** features of Google Security Operations for effective threat detection and response.
- Users appreciate the **seamless integrations** of Google Security Operations, enhancing security through a unified and robust experience.

**Cons:**

- Users find the service **expensive and complex** , particularly impacting large firms and requiring significant training time.
- Users note a **steep learning curve** with Google Security Operations, especially for those unfamiliar with Google Cloud services.
- Users find the **complexity of implementation and configuration** challenging, requiring time and resources to manage effectively.
- Users find the **learning difficulty** to be high due to complex setup and feature comprehensiveness compared to alternatives.
- Users find the **limited customization** in Google Security Operations restrictive, hindering adaptability to specific security needs.

#### What Are Recent G2 Reviews of Google Security Operations?

**"[Fast, Scalable Platform That Speeds Up Security Investigations](https://www.g2.com/survey_responses/google-security-operations-review-12789503)"**

**Rating:** 4.5/5.0 stars
*— Ankith T.*

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-12789503)

---

**"[Centralized Security Made Easy and Efficient](https://www.g2.com/survey_responses/google-security-operations-review-12181628)"**

**Rating:** 4.5/5.0 stars
*— Sushriya M.*

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-12181628)

---



### 10. [Palo Alto Cortex XSIAM](https://www.g2.com/products/palo-alto-cortex-xsiam/reviews)
  Product Description: Palo Alto Networks&#39; Cortex XSIAM is an AI-driven security operations platform designed to transform traditional Security Operations Centers by integrating and automating key functions such as data centralization, threat detection, and incident response. By leveraging machine learning and automation, it enables organizations to detect and respond to threats more efficiently, reducing manual workloads and improving overall security posture. Key Features and Functionality: - Data Centralization: Aggregates data from various sources into a unified platform, providing comprehensive visibility across the enterprise. - AI-Powered Threat Detection: Utilizes machine learning algorithms to identify anomalies and potential threats in real-time. - Automated Incident Response: Streamlines response processes through automation, enabling rapid mitigation of security incidents. - Integrated SOC Capabilities: Combines functions such as Extended Detection and Response , Security Orchestration, Automation, and Response , Attack Surface Management , and Security Information and Event Management into a cohesive platform, eliminating the need for multiple disparate tools. - Scalability: Designed to handle large volumes of data and adapt to the evolving needs of modern enterprises. Primary Value and Problem Solved: Cortex XSIAM addresses the challenges of disjointed data, weak threat defense, and heavy reliance on manual work in traditional SOCs. By centralizing data and automating security operations, it simplifies processes, enhances threat detection accuracy, and accelerates incident response times. This transformation enables organizations to proactively outpace threats, reduce operational costs, and achieve a more robust security posture.


  **Average Rating:** 4.4/5.0
  **Total Reviews:** 61
**How Do G2 Users Rate Palo Alto Cortex XSIAM?**

- **Automated Remediation:** 7.3/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.2/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.1/10 (Category avg: 8.5/10)
- **Workflow Automation:** 7.5/10 (Category avg: 8.8/10)

**Who Is the Company Behind Palo Alto Cortex XSIAM?**

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks (128,951 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/30086/ (22,313 employees on LinkedIn®)
- **Ownership:** NYSE: PANW

**Who Uses This Product?**
  - **Who Uses This:** Information Security Engineer
  - **Top Industries:** Computer &amp; Network Security, Information Technology and Services
  - **Company Size:** 48% Enterprise, 29% Mid-Market


#### What Are Palo Alto Cortex XSIAM's Pros and Cons?

**Pros:**

- Log Management (13 reviews)
- Dashboard Design (11 reviews)
- Real-time Monitoring (11 reviews)
- Simple (11 reviews)
- Dashboard Customization (9 reviews)

**Cons:**

- Resource Intensive (9 reviews)
- Complex Setup (8 reviews)
- Cost (7 reviews)
- Dashboard Issues (7 reviews)
- Difficult Setup (7 reviews)


### What Do G2 Reviewers Say About Palo Alto Cortex XSIAM?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **best-in-class log management** of Palo Alto Cortex XSIAM, enhancing operational efficiency and integration.
- Users value the **user-friendly dashboard** of Palo Alto Cortex XSIAM for its clear alerts and statistics presentation.
- Users appreciate the **real-time monitoring** capabilities of Palo Alto Cortex XSIAM, enhancing threat detection and response efficiency.
- Users appreciate the **simple and user-friendly interface** of Palo Alto Cortex XSIAM, enhancing their overall experience.
- Users value the **good dashboard customization** tools of Palo Alto Cortex XSIAM, enhancing ease of use and integration.

**Cons:**

- Users find the setup of Cortex XSIAM to be **resource intensive** , impacting workflows and increasing infrastructure costs.
- Users find the **complexity of implementation** challenging, requiring significant time and expertise for effective setup.
- Users find the **cost** of Palo Alto Cortex XSIAM to be higher than competitors, impacting small and mid-size companies.
- Users report significant **dashboard issues** that lead to poor visibility and a fragmented view of security events.
- Users experience **difficult setup** and complexity in implementing Palo Alto Cortex XSIAM, requiring significant expertise and training.

#### What Are Recent G2 Reviews of Palo Alto Cortex XSIAM?

**"[Data Automation, and AI Analytics for Faster Incident Response](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-12675702)"**

**Rating:** 4.5/5.0 stars
*— Ahmad O.*

[Read full review](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-12675702)

---

**"[Palo Alto Cortex XSIAM Streamlines SOC Work with Smart Noise Reduction and Automation](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-12626074)"**

**Rating:** 5.0/5.0 stars
*— Rohan K.*

[Read full review](https://www.g2.com/survey_responses/palo-alto-cortex-xsiam-review-12626074)

---


#### What Are G2 Users Discussing About Palo Alto Cortex XSIAM?

- [What is IBM Security ReaQta used for?](https://www.g2.com/discussions/what-is-ibm-security-reaqta-used-for)
- [What does QRadar stand for?](https://www.g2.com/discussions/what-does-qradar-stand-for) - 1 comment, 1 upvote
- [How do I use IBM QRadar?](https://www.g2.com/discussions/how-do-i-use-ibm-qradar) - 1 comment
- [What are the key component of IBM QRadar?](https://www.g2.com/discussions/what-are-the-key-component-of-ibm-qradar) - 1 comment
- [What is IBM QRadar Siem?](https://www.g2.com/discussions/what-is-ibm-qradar-siem) - 1 comment

### 11. [Barracuda Incident Response](https://www.g2.com/products/barracuda-incident-response/reviews)
  No email defense technology can protect against increasingly advanced email threats 100 percent of the time. Some advanced social engineering attacks like business email compromise will reach users’ mailboxes. And when they do, you need to respond quickly and accurately to minimize the scope and severity of damage. Barracuda Incident Response lets you respond to threats quickly and effectively, by automating investigative workflows and enabling direct removal of malicious emails


  **Average Rating:** 4.5/5.0
  **Total Reviews:** 16
**How Do G2 Users Rate Barracuda Incident Response?**

- **Automated Remediation:** 9.2/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.4/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.6/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.6/10 (Category avg: 8.8/10)

**Who Is the Company Behind Barracuda Incident Response?**

- **Seller:** [Barracuda](https://www.g2.com/sellers/barracuda)
- **Year Founded:** 2002
- **HQ Location:** Campbell, CA
- **Twitter:** @Barracuda (15,239 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/barracuda-networks/ (2,248 employees on LinkedIn®)
- **Ownership:** Private

**Who Uses This Product?**
  - **Company Size:** 50% Mid-Market, 25% Enterprise


#### What Are Barracuda Incident Response's Pros and Cons?

**Pros:**

- Email Security (3 reviews)
- Features (2 reviews)
- Security (2 reviews)
- Cybersecurity (1 reviews)
- Incident Management (1 reviews)

**Cons:**

- Email Management (1 reviews)


### What Do G2 Reviewers Say About Barracuda Incident Response?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **instant email threat removal** capabilities of Barracuda Incident Response for enhanced cybersecurity protection.
- Users value the **powerful email search and remediation capabilities** of Barracuda Incident Response for enhanced cybersecurity.
- Users value the **instant threat removal** capability of Barracuda Incident Response, enhancing their overall cybersecurity protection.
- Users find Barracuda Incident Response to be an **invaluable tool** for effective cybersecurity management and incident remediation.
- Users praise the **critical capabilities of Incident Management** in Barracuda, enhancing cybersecurity through effective remediation and investigation.

**Cons:**

- Users wish that the **email blocking feature** worked across all gateway levels for better management.

#### What Are Recent G2 Reviews of Barracuda Incident Response?

**"[Instant Email Threat Removal That Makes a Big Difference](https://www.g2.com/survey_responses/barracuda-incident-response-review-12340166)"**

**Rating:** 4.5/5.0 stars
*— Jose C.*

[Read full review](https://www.g2.com/survey_responses/barracuda-incident-response-review-12340166)

---

**"[Amazing product](https://www.g2.com/survey_responses/barracuda-incident-response-review-12337161)"**

**Rating:** 5.0/5.0 stars
*— Peter E.*

[Read full review](https://www.g2.com/survey_responses/barracuda-incident-response-review-12337161)

---


#### What Are G2 Users Discussing About Barracuda Incident Response?

- [What is Barracuda Incident Response used for?](https://www.g2.com/discussions/what-is-barracuda-incident-response-used-for)

### 12. [Proofpoint Threat Response](https://www.g2.com/products/proofpoint-threat-response/reviews)
  Proofpoint Threat Response takes the manual labor and guesswork out of incident response to help you resolve threats faster and more efficiently.


  **Average Rating:** 4.6/5.0
  **Total Reviews:** 17
**How Do G2 Users Rate Proofpoint Threat Response?**

- **Automated Remediation:** 9.0/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.8/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.3/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Proofpoint Threat Response?**

- **Seller:** [Proofpoint](https://www.g2.com/sellers/proofpoint)
- **Year Founded:** 2002
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @proofpoint (31,157 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/proofpoint (5,146 employees on LinkedIn®)
- **Ownership:** NASDAQ: PFPT

**Who Uses This Product?**
  - **Company Size:** 56% Mid-Market, 22% Small-Business


#### What Are Proofpoint Threat Response's Pros and Cons?

**Pros:**

- Email Security (2 reviews)
- Automated Response (1 reviews)
- Phishing Prevention (1 reviews)
- Security (1 reviews)
- Threat Detection (1 reviews)

**Cons:**

- Email Management (1 reviews)
- False Positives (1 reviews)
- Learning Curve (1 reviews)


### What Do G2 Reviewers Say About Proofpoint Threat Response?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **automatic recall of suspicious emails** that enhances security and keeps companies safe with Proofpoint.
- Users value the **automated recall of suspicious emails** , enhancing security and reducing risks of potential threats.
- Users appreciate the **automatic recall of suspicious emails** , enhancing their security and reducing phishing risks effectively.
- Users appreciate the **comprehensive security tools** of Proofpoint Threat Response, enhancing their company&#39;s safety effectively.
- Users value the **comprehensive threat detection tools** of Proofpoint Threat Response for enhancing company safety.

**Cons:**

- Users experience **frequent false positives** , leading to the recall and replacement of hundreds of emails.
- Users report experiencing **numerous false positives** , leading to significant email recalls and disruptions in communication.
- Users find the **learning curve steep** , but appreciate the ample training and assistance provided by Proofpoint.

#### What Are Recent G2 Reviews of Proofpoint Threat Response?

**"[Takes time to learn, but Great product!](https://www.g2.com/survey_responses/proofpoint-threat-response-review-9471662)"**

**Rating:** 4.0/5.0 stars
*— Joshua B.*

[Read full review](https://www.g2.com/survey_responses/proofpoint-threat-response-review-9471662)

---

**"[Quick Alerts and Clear, Detailed Summaries for Suspicious Emails](https://www.g2.com/survey_responses/proofpoint-threat-response-review-12478488)"**

**Rating:** 5.0/5.0 stars
*— Casey M.*

[Read full review](https://www.g2.com/survey_responses/proofpoint-threat-response-review-12478488)

---



### 13. [Splunk SOAR (Security Orchestration, Automation and Response)](https://www.g2.com/products/splunk-soar-security-orchestration-automation-and-response/reviews)
  Splunk SOAR provides security orchestration, automation and response capabilities that allow security analysts to work smarter by automating repetitive tasks; respond to security incidents faster with automated detection, investigation, and response; increase productivity, efficiency and accuracy; and strengthen defenses by connecting and coordinating complex workflows across their team and tools. Splunk SOAR also supports a broad range of security operations center (SOC) functions including event and case management, integrated threat intelligence, collaboration tools and reporting.


  **Average Rating:** 4.4/5.0
  **Total Reviews:** 39
**How Do G2 Users Rate Splunk SOAR (Security Orchestration, Automation and Response)?**

- **Automated Remediation:** 8.6/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.8/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.1/10 (Category avg: 8.5/10)
- **Workflow Automation:** 8.7/10 (Category avg: 8.8/10)

**Who Is the Company Behind Splunk SOAR (Security Orchestration, Automation and Response)?**

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco (720,366 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/cisco/ (95,545 employees on LinkedIn®)
- **Ownership:** NASDAQ:CSCO

**Who Uses This Product?**
  - **Top Industries:** Information Technology and Services, Consulting
  - **Company Size:** 40% Mid-Market, 35% Enterprise


#### What Are Splunk SOAR (Security Orchestration, Automation and Response)'s Pros and Cons?

**Pros:**

- Security (13 reviews)
- Threat Detection (8 reviews)
- Ease of Use (7 reviews)
- Real-time Monitoring (7 reviews)
- Alerting System (6 reviews)

**Cons:**

- Expensive (16 reviews)
- Complexity (5 reviews)
- Lack of Guidance (3 reviews)
- Poor Customer Support (3 reviews)
- Complex Implementation (2 reviews)


### What Do G2 Reviewers Say About Splunk SOAR (Security Orchestration, Automation and Response)?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **effective incident management** capabilities of Splunk SOAR, facilitating streamlined security automation and threat detection.
- Users value the **easy threat detection and analysis** , enhancing security measures across diverse environments and tools.
- Users value the **ease of use** of Splunk SOAR, enabling efficient analysis and customization without coding.
- Users value the **real-time monitoring** capabilities of Splunk SOAR for enhanced threat detection and response efficiency.
- Users value the **real-time threat alerting** of Splunk SOAR, enhancing security response and reducing human error.

**Cons:**

- Users find Splunk SOAR&#39;s **high pricing** to be a major barrier, especially for those with limited budgets.
- Users find the **complexity** of Splunk SOAR challenging, requiring extensive training to effectively utilize the software.
- Users find a **lack of guidance** challenging, requiring external help to navigate Splunk SOAR&#39;s complex configurations and workflows.
- Users face **poor customer support** as quick solutions are often unavailable, complicating the use of Splunk SOAR.
- Users find the **complex implementation** of Splunk SOAR to be time-consuming and challenging due to its architecture and cost.

#### What Are Recent G2 Reviews of Splunk SOAR (Security Orchestration, Automation and Response)?

**"[Splunk SOAR is an awesome automation and security software](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922387)"**

**Rating:** 5.0/5.0 stars
*— Noor  Z.*

[Read full review](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922387)

---

**"[Splunk SOAR is a good software for automation](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922172)"**

**Rating:** 5.0/5.0 stars
*— Dheeraj T.*

[Read full review](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922172)

---


#### What Are G2 Users Discussing About Splunk SOAR (Security Orchestration, Automation and Response)?

- [What is Splunk SOAR (Security Orchestration, Automation and Response) used for?](https://www.g2.com/discussions/what-is-splunk-soar-security-orchestration-automation-and-response-used-for)

### 14. [IBM QRadar SOAR](https://www.g2.com/products/ibm-qradar-soar/reviews)
  IBM QRadar® SOAR is designed to help your security team respond to cyberthreats with confidence, automate with intelligence and collaborate with consistency. It guides your team in resolving incidents by codifying established incident response processes into dynamic playbooks. The open and agnostic platform helps accelerate and orchestrate their response by automating actions with intelligence and integrating with other security tools. IBM QRadar SOAR is available on AWS Marketplace.


  **Average Rating:** 4.0/5.0
  **Total Reviews:** 25
**How Do G2 Users Rate IBM QRadar SOAR?**

- **Automated Remediation:** 7.5/10 (Category avg: 8.6/10)
- **Quality of Support:** 7.9/10 (Category avg: 9.0/10)
- **Ease of Admin:** 6.7/10 (Category avg: 8.5/10)
- **Workflow Automation:** 7.4/10 (Category avg: 8.8/10)

**Who Is the Company Behind IBM QRadar SOAR?**

- **Seller:** [IBM](https://www.g2.com/sellers/ibm)
- **Year Founded:** 1911
- **HQ Location:** Armonk, New York, United States
- **Twitter:** @IBMSecurity (74,660 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/1009/ (328,202 employees on LinkedIn®)
- **Ownership:** SWX:IBM

**Who Uses This Product?**
  - **Top Industries:** Information Technology and Services
  - **Company Size:** 72% Enterprise, 21% Mid-Market


#### What Are IBM QRadar SOAR's Pros and Cons?

**Pros:**

- Ease of Use (5 reviews)
- Automation (3 reviews)
- Easy Integrations (3 reviews)
- Integrations (3 reviews)
- Customer Support (2 reviews)

**Cons:**

- Integration Issues (3 reviews)
- Complexity (2 reviews)
- Limited Integration (2 reviews)
- System Limitations (2 reviews)
- Bug Issues (1 reviews)


### What Do G2 Reviewers Say About IBM QRadar SOAR?
*AI-generated summary from verified user reviews*

**Pros:**

- Users benefit from the **ease of use** of IBM QRadar SOAR, enabling quick workflows and seamless integrations.
- Users value the **fast automation capabilities** of IBM QRadar SOAR, significantly reducing manual work in security operations.
- Users value the **easy integrations** with various tools, simplifying workflows and enhancing security operations efficiency.
- Users appreciate the **seamless integration** with various tools, enhancing efficiency in security processes and workflows.
- Users value the **responsive IBM support** , appreciating quick resolutions and the user-friendly QRadar SOAR console.

**Cons:**

- Users face **integration issues** with IBM QRadar SOAR, as it lacks out-of-the-box options and complicates sophisticated implementations.
- Users find the **initial complexity** of IBM QRadar SOAR challenging, requiring significant time to adapt to all features.
- Users are frustrated with the **limited integration** in IBM QRadar SOAR, hindering advanced transformations and usability.
- Users experience **system limitations** in IBM QRadar SOAR, facing difficulties in transformations and lack of dynamic features.
- Users report occasional **bug issues** causing workflow errors and slowness, disrupting their overall experience with QRadar SOAR.

#### What Are Recent G2 Reviews of IBM QRadar SOAR?

**"[Analyze Soar Qradar](https://www.g2.com/survey_responses/ibm-qradar-soar-review-9842312)"**

**Rating:** 5.0/5.0 stars
*— Aparecido A.*

[Read full review](https://www.g2.com/survey_responses/ibm-qradar-soar-review-9842312)

---

**"[IBM Security QRadar SOAR](https://www.g2.com/survey_responses/ibm-qradar-soar-review-9696782)"**

**Rating:** 4.5/5.0 stars
*— Prashanth K.*

[Read full review](https://www.g2.com/survey_responses/ibm-qradar-soar-review-9696782)

---



### 15. [Blink](https://www.g2.com/products/blink-ops-blink/reviews)
  Automate Everything Security in the Blink of AI Blink is a security workflow automation platform designed to make building, collaborating, and scaling all things security &amp; beyond effortless using generative AI. Whether you prefer code, low-code, or no-code, Blink has got you covered. Easily drag and drop the actions you want into a workflow, leveraging the over 30,000 integrations available in the automation library, or use Blink Copilot to generate a workflow with a natural language prompt. Use Blink as an automation hub, where security teams go to quickly develop, collaborate, and automate their security ideas. Leverage the platform’s 10,000+ workflows that come out of the box to quickly build workflows for real-time remediation. Generate automation workflows for standalone use cases or build an end-to-end proactive automation strategy, streamlining security responses across your entire organization.


  **Average Rating:** 4.7/5.0
  **Total Reviews:** 19
**How Do G2 Users Rate Blink?**

- **Automated Remediation:** 9.0/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.8/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.5/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.6/10 (Category avg: 8.8/10)

**Who Is the Company Behind Blink?**

- **Seller:** [Blink Ops](https://www.g2.com/sellers/blink-ops)
- **Company Website:** https://www.blinkops.com
- **Year Founded:** 2021
- **HQ Location:** Austin, US
- **Twitter:** @getBlinkOps (706 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/blink-ops/ (126 employees on LinkedIn®)

**Who Uses This Product?**
  - **Top Industries:** Computer Software
  - **Company Size:** 63% Mid-Market, 21% Enterprise


#### What Are Blink's Pros and Cons?

**Pros:**

- Ease of Use (2 reviews)
- Automation (1 reviews)
- Customer Support (1 reviews)
- Easy Setup (1 reviews)
- Features (1 reviews)

**Cons:**

- Limitations (2 reviews)
- Limited Features (1 reviews)


### What Do G2 Reviewers Say About Blink?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **ease of use** of Blink, enabling a smooth setup and efficient operation in web projects.
- Users commend the **powerful automation** capabilities of Blink, noting significant outcomes and prompt support.
- Users highlight the **excellent customer support** of Blink, enhancing the platform&#39;s usability and effectiveness significantly.
- Users value the **easy setup** of Blink, allowing for a quick and seamless introduction to the software.
- Users appreciate the **seamless integration with V8** , enhancing JavaScript performance and ensuring optimal browsing for web projects.

**Cons:**

- Users identify **limited extensibility** in Blink, which can be challenging for larger, more complex projects.
- Users find Blink&#39;s **limited extensibility** problematic, especially for large and complex projects requiring more features.

#### What Are Recent G2 Reviews of Blink?

**"[Compatibility Champion, Limited Extensibility](https://www.g2.com/survey_responses/blink-review-11995069)"**

**Rating:** 4.5/5.0 stars
*— VISHNU S.*

[Read full review](https://www.g2.com/survey_responses/blink-review-11995069)

---

**"[Collaboration with Blink, focusing on outcomes over possibilities](https://www.g2.com/survey_responses/blink-review-9911596)"**

**Rating:** 5.0/5.0 stars
*— Uriel A.*

[Read full review](https://www.g2.com/survey_responses/blink-review-9911596)

---



### 16. [Sumo Logic](https://www.g2.com/products/sumo-logic/reviews)
  Sumo Logic, Inc. unifies and analyzes enterprise data, translating it into actionable insights through one AI-powered cloud-native log analytics platform. This single source of truth enables Dev, Sec and Ops teams to simplify complexity, collaborate efficiently and accelerate data-driven decisions that drive business value. Customers around the world rely on the Sumo Logic SaaS Log Analytics Platform for trusted insights to ensure application reliability, secure and protect against modern security threats, and gain insights into their cloud infrastructures. For more information, visit: SUMOLOGIC.COM


  **Average Rating:** 4.3/5.0
  **Total Reviews:** 390
**How Do G2 Users Rate Sumo Logic?**

- **Automated Remediation:** 8.8/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.4/10 (Category avg: 8.5/10)
- **Workflow Automation:** 8.3/10 (Category avg: 8.8/10)

**Who Is the Company Behind Sumo Logic?**

- **Seller:** [Sumo Logic](https://www.g2.com/sellers/sumo-logic)
- **Company Website:** https://www.sumologic.com
- **Year Founded:** 2010
- **HQ Location:** Redwood City, CA
- **Twitter:** @SumoLogic (6,542 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/1037816/ (838 employees on LinkedIn®)

**Who Uses This Product?**
  - **Who Uses This:** Software Engineer, Senior Software Engineer
  - **Top Industries:** Information Technology and Services, Computer Software
  - **Company Size:** 49% Mid-Market, 37% Enterprise


#### What Are Sumo Logic's Pros and Cons?

**Pros:**

- Ease of Use (63 reviews)
- Log Management (46 reviews)
- Features (37 reviews)
- Real-time Monitoring (37 reviews)
- Insights (35 reviews)

**Cons:**

- Difficult Learning (21 reviews)
- Learning Curve (21 reviews)
- Learning Difficulty (21 reviews)
- Expensive (19 reviews)
- Slow Performance (18 reviews)


### What Do G2 Reviewers Say About Sumo Logic?
*AI-generated summary from verified user reviews*

**Pros:**

- Users find Sumo Logic&#39;s **ease of use** remarkable, enabling powerful queries and simple configurations for monitoring.
- Users value the **ease of log searching** and clear grouping in Sumo Logic for efficient monitoring.
- Users value the **Continuous Intelligence feature** of Sumo Logic for its ability to quickly transform data into actionable insights.
- Users value the **real-time monitoring** capabilities of Sumo Logic, enhancing insights and streamlining data management effortlessly.
- Users value the **actionable insights** from Sumo Logic&#39;s Continuous Intelligence feature, enhancing efficiency and decision-making.

**Cons:**

- Users find the **difficult learning** curve of Sumo Logic frustrating, as it requires significant time to master.
- Users face a **steep learning curve** with Sumo Logic, making it challenging to gain proficiency quickly.
- Users find the **steep learning curve** of Sumo Logic challenging, requiring significant time to master its features.
- Users feel that Sumo Logic is **expensive** , making them question if the features justify the high cost.
- Users experience **slow performance** with Sumo Logic, facing delays in alerts and unwieldy navigation through the UI.

#### What Are Recent G2 Reviews of Sumo Logic?

**"[AI Activity Monitoring That Makes Auditing and Debugging Easy](https://www.g2.com/survey_responses/sumo-logic-review-12888562)"**

**Rating:** 4.5/5.0 stars
*— Vishal S.*

[Read full review](https://www.g2.com/survey_responses/sumo-logic-review-12888562)

---

**"[Live Tail and LogReduce Make Real-Time Troubleshooting Fast](https://www.g2.com/survey_responses/sumo-logic-review-12595490)"**

**Rating:** 4.0/5.0 stars
*— aarti y.*

[Read full review](https://www.g2.com/survey_responses/sumo-logic-review-12595490)

---


#### What Are G2 Users Discussing About Sumo Logic?

- [What is Cloud SOAR used for?](https://www.g2.com/discussions/what-is-cloud-soar-used-for) - 1 comment, 1 upvote
- [Is Sumo Logic a SIEM?](https://www.g2.com/discussions/is-sumo-logic-a-siem)
- [What is Sumo Logic used for?](https://www.g2.com/discussions/what-is-sumo-logic-used-for)
- [Who are Sumo Logic competitors?](https://www.g2.com/discussions/who-are-sumo-logic-competitors) - 1 comment
- [How much does Sumo Logic cost?](https://www.g2.com/discussions/how-much-does-sumo-logic-cost)

### 17. [Demisto](https://www.g2.com/products/demisto/reviews)
  Demisto is a platform that provides automated and collaborative security solutions.


  **Average Rating:** 4.5/5.0
  **Total Reviews:** 15
**How Do G2 Users Rate Demisto?**

- **Automated Remediation:** 10.0/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.8/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.5/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Demisto?**

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks (128,951 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/30086/ (22,313 employees on LinkedIn®)
- **Ownership:** NYSE: PANW

**Who Uses This Product?**
  - **Top Industries:** Information Technology and Services
  - **Company Size:** 53% Mid-Market, 40% Small-Business



#### What Are Recent G2 Reviews of Demisto?

**"[Great Product for SOC Team](https://www.g2.com/survey_responses/demisto-review-8594931)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Banking*

[Read full review](https://www.g2.com/survey_responses/demisto-review-8594931)

---

**"[great tool for a SOC center](https://www.g2.com/survey_responses/demisto-review-4499570)"**

**Rating:** 5.0/5.0 stars
*— Parth P.*

[Read full review](https://www.g2.com/survey_responses/demisto-review-4499570)

---



### 18. [Exabeam New-Scale Platform](https://www.g2.com/products/exabeam-exabeam-new-scale-platform/reviews)
  The Exabeam New-Scale Security Operations Platform is built to help organizations detect, investigate, and respond to insider threats tied to both human users and non-human identities. It brings together behavioral analytics, automation, and AI-driven workflows to help security operations teams reduce risk and maintain operational integrity. The platform supports AI agent-powered threat detection, investigation, and response (TDIR) by automating high-friction tasks and applying behavioral context to every signal. By combining proactive risk identification with fast, guided response, the New-Scale Platform helps teams move from alert handling to informed decision-making. Designed for enterprise security operations teams, the New-Scale Platform supports organizations that need consistent visibility into internal risk without adding operational overhead. Analysts use behavioral analytics to understand what is normal for a user or agent, then quickly spot meaningful deviations. This approach is especially valuable in data-sensitive industries such as finance, healthcare, and technology, where internal misuse, compromised credentials, or agent misuse can create immediate business impact. At the core of the New-Scale Platform is advanced behavioral analytics. The platform analyzes activity patterns across identities, devices, and services to establish baselines of normal behavior. When activity deviates from those baselines, dynamic risk scoring helps security teams focus on the activity most likely to indicate misuse or compromise. This reduces alert noise and shortens the time it takes to understand what is happening and why. The New-Scale Platform also extends user and entity behavior analytics (UEBA) to non-human identities through Agent Behavior Analytics (ABA). ABA applies the same behavior-based approach as UEBA to service accounts, APIs, automation tools, and AI agents. By monitoring how agents typically interact with data and systems, the platform helps teams detect misuse, drift, or compromise that traditional controls often miss. Automation plays a central role in improving day-to-day operations. The New-Scale Platform automates investigation steps, enrichment, and response actions within TDIR workflows, allowing analysts to spend less time on repetitive tasks and more time validating risk and containing incidents. Behavioral context and AI-driven prioritization help teams address the most relevant threats first, improving response consistency without increasing workload. With the Exabeam New-Scale Platform, security teams can benchmark and prove the value of their security program against peers and measurable outcomes. Outcomes Navigator translates raw security data into business-relevant insights to demonstrate progress against the most strategic use cases, MITRE ATT&amp;CK TTPs, and compliance initiatives. Together, user and entity behavior analytics (UEBA), Agent Behavior Analytics (ABA), and agent-powered automated TDIR workflows help security operations teams detect insider risk earlier, investigate faster, and respond with greater precision. The New-Scale Platform gives organizations a practical way to manage insider threats tied to people and agents, accelerate security operations, and prove security impact over time.


  **Average Rating:** 4.6/5.0
  **Total Reviews:** 14
**How Do G2 Users Rate Exabeam New-Scale Platform?**

- **Automated Remediation:** 10.0/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.1/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.5/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Exabeam New-Scale Platform?**

- **Seller:** [Exabeam](https://www.g2.com/sellers/exabeam)
- **Company Website:** https://www.exabeam.com
- **Year Founded:** 2013
- **HQ Location:** Broomfield, CO
- **Twitter:** @exabeam (5,374 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/exabeam (793 employees on LinkedIn®)

**Who Uses This Product?**
  - **Company Size:** 57% Enterprise, 29% Mid-Market


#### What Are Exabeam New-Scale Platform's Pros and Cons?

**Pros:**

- Ease of Use (5 reviews)
- Detection Accuracy (3 reviews)
- Features (3 reviews)
- Security (3 reviews)
- Automation (2 reviews)

**Cons:**

- Complexity (2 reviews)
- Complex Setup (2 reviews)
- Difficult Setup (2 reviews)
- Parsing Issues (2 reviews)
- Software Complexity (2 reviews)


### What Do G2 Reviewers Say About Exabeam New-Scale Platform?
*AI-generated summary from verified user reviews*

**Pros:**

- Users commend the **ease of use** of Exabeam New-Scale Platform, enhancing integration and streamlining incident management.
- Users praise the **detection accuracy** of Exabeam New-Scale Platform, enhancing quick incident response and threat identification.
- Users appreciate the **robust integration and comprehensive security features** of Exabeam New-Scale Platform for enhanced visibility.
- Users value the **comprehensive security features** of Exabeam, praising its integration ease and visibility in monitoring.
- Users benefit from the **fully automated incident response** of Exabeam, enhancing efficiency and reducing manual investigation efforts.

**Cons:**

- Users find the **complexity** of Exabeam New-Scale Platform challenging, requiring significant expertise for setup and configuration.
- Users find the **complex setup** of Exabeam New-Scale Platform challenging, requiring significant expertise for effective management.
- Users find the **difficult setup** of the Exabeam New-Scale Platform challenging, requiring significant expertise for effective configuration.
- Users find **parsing issues** hinder usability, complicating tasks like risk behavior analysis and data field mapping.
- Users find the **software complexity** challenging, especially with setup, configuration, and manual data field mapping.

#### What Are Recent G2 Reviews of Exabeam New-Scale Platform?

**"[Gives Security Teams Their Time Back with Smart Threat Visibility](https://www.g2.com/survey_responses/exabeam-new-scale-platform-review-9889355)"**

**Rating:** 4.5/5.0 stars
*— Verified User in Computer Software*

[Read full review](https://www.g2.com/survey_responses/exabeam-new-scale-platform-review-9889355)

---

**"[The perfect SIEM](https://www.g2.com/survey_responses/exabeam-new-scale-platform-review-10644742)"**

**Rating:** 5.0/5.0 stars
*— Jorge T.*

[Read full review](https://www.g2.com/survey_responses/exabeam-new-scale-platform-review-10644742)

---


#### What Are G2 Users Discussing About Exabeam New-Scale Platform?

- [What are the components of SIEM?](https://www.g2.com/discussions/what-are-the-components-of-siem) - 1 comment
- [What are three characteristics of SIEM?](https://www.g2.com/discussions/what-are-three-characteristics-of-siem) - 1 comment

### 19. [SIRP](https://www.g2.com/products/sirp/reviews)
  SIRP is an AI-native Autonomous SOC platform designed to evolve traditional Security Orchestration, Automation, and Response (SOAR) into governed, decision-driven security operations. Unlike legacy SOAR tools that rely on static playbooks and workflow automation, SIRP enables intelligent AI agents to analyze alerts, compute risk, execute response actions, and continuously learn from outcomes within defined policy boundaries. The platform combines contextual reasoning, real-time intelligence, and adaptive learning to reduce manual triage, minimize alert fatigue, and accelerate incident response while maintaining governance, auditability, and control. SIRP supports enterprise SOC teams and MSSPs seeking to operate at machine speed without sacrificing human oversight for high-impact decisions.


  **Average Rating:** 4.7/5.0
  **Total Reviews:** 22
**How Do G2 Users Rate SIRP?**

- **Automated Remediation:** 9.2/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.8/10 (Category avg: 9.0/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.5/10)
- **Workflow Automation:** 8.3/10 (Category avg: 8.8/10)

**Who Is the Company Behind SIRP?**

- **Seller:** [SIRP](https://www.g2.com/sellers/sirp)
- **Year Founded:** 2017
- **HQ Location:** Bethesda, Maryland
- **Twitter:** @sirp_io (74 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/13684515/ (56 employees on LinkedIn®)

**Who Uses This Product?**
  - **Top Industries:** Information Technology and Services
  - **Company Size:** 41% Small-Business, 37% Mid-Market


#### What Are SIRP's Pros and Cons?

**Pros:**

- Automation (1 reviews)
- Customer Support (1 reviews)
- Ease of Use (1 reviews)
- Easy Integrations (1 reviews)
- Features (1 reviews)



### What Do G2 Reviewers Say About SIRP?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **comprehensive automation** features of SIRP, enhancing their security orchestration and response capabilities.
- Users value the **excellent customer support** from SIRP, enhancing their experience with the platform significantly.
- Users find SIRP&#39;s **ease of use** enhances their experience, complemented by excellent support and integration options.
- Users value the **easy integrations** offered by SIRP, allowing seamless connectivity with various tools without extra costs.
- Users value the **comprehensive support** and **ease of use** offered by SIRP&#39;s extensive features and integrations.


#### What Are Recent G2 Reviews of SIRP?

**"[SIRP increased our SOC capabilities by 10x. Amazing automation with even better support team](https://www.g2.com/survey_responses/sirp-review-7612417)"**

**Rating:** 5.0/5.0 stars
*— Mushtaq Ahmed K.*

[Read full review](https://www.g2.com/survey_responses/sirp-review-7612417)

---

**"[Data Aggregation, Ease of Access and Quick Reporting](https://www.g2.com/survey_responses/sirp-review-4217597)"**

**Rating:** 4.5/5.0 stars
*— Iqra Z.*

[Read full review](https://www.g2.com/survey_responses/sirp-review-4217597)

---



### 20. [Swimlane](https://www.g2.com/products/swimlane/reviews)
  At Swimlane, we believe the convergence of agentic AI and automation can solve the most challenging security, compliance and IT/OT operations problems. With Swimlane, enterprises and MSSPs benefit from the world’s first and only hyperautomation platform for every security function. Only Swimlane gives you the scale and flexibility to build your own hyperautomation applications to unify security teams, tools and telemetry ensuring today’s SecOps are always a step ahead of tomorrow’s threats.


  **Average Rating:** 4.5/5.0
  **Total Reviews:** 45
**How Do G2 Users Rate Swimlane?**

- **Automated Remediation:** 9.2/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.1/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.5/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.3/10 (Category avg: 8.8/10)

**Who Is the Company Behind Swimlane?**

- **Seller:** [Swimlane](https://www.g2.com/sellers/swimlane)
- **Year Founded:** 2014
- **HQ Location:** Boulder, US
- **Twitter:** @swimlane (1,628 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/4807837/ (254 employees on LinkedIn®)

**Who Uses This Product?**
  - **Top Industries:** Information Technology and Services, Computer Software
  - **Company Size:** 60% Mid-Market, 31% Small-Business


#### What Are Swimlane's Pros and Cons?

**Pros:**

- Ease of Use (6 reviews)
- Easy Integrations (6 reviews)
- Features (6 reviews)
- Integrations (6 reviews)
- Automation (5 reviews)

**Cons:**

- Complexity (2 reviews)
- Learning Curve (2 reviews)
- Limited Resources (2 reviews)
- Poor Customer Support (2 reviews)
- Poor Interface Design (2 reviews)


### What Do G2 Reviewers Say About Swimlane?
*AI-generated summary from verified user reviews*

**Pros:**

- Users find Swimlane to be **extremely easy to learn** , enabling seamless automation and integration with various tools.
- Users value the **easy integrations** of Swimlane, which enhance business processes and support seamless security monitoring.
- Users value the **versatility and support** from Swimlane, allowing for easy, tailored workflow solutions.
- Users value the **seamless integration capabilities** of Swimlane, enhancing security monitoring across various tools effortlessly.
- Users value the **low-code automation** of Swimlane, enabling extensive customization and quick responses across security operations.

**Cons:**

- Users find Swimlane&#39;s setup process to be **complex and confusing** initially, requiring time to gain comfort and understanding.
- Users face a steep **learning curve** with Swimlane, requiring time and possibly technical help for effective use.
- Users find Swimlane has **limited resources** , complicating deployment and requiring skilled expertise for effective setup.
- Users experience **slow customer support** and challenges with upgrades, though some assistance is available when needed.
- Users find the **poor interface design** of Swimlane cluttered and difficult to navigate, needing a modern refresh.

#### What Are Recent G2 Reviews of Swimlane?

**"[I have used swimlane as an analyst and have had a little experience working with the backend.](https://www.g2.com/survey_responses/swimlane-review-8789592)"**

**Rating:** 4.5/5.0 stars
*— Maguire S.*

[Read full review](https://www.g2.com/survey_responses/swimlane-review-8789592)

---

**"[Powerful Automation with Swimlane](https://www.g2.com/survey_responses/swimlane-review-8782607)"**

**Rating:** 4.5/5.0 stars
*— Verified User in Financial Services*

[Read full review](https://www.g2.com/survey_responses/swimlane-review-8782607)

---


#### What Are G2 Users Discussing About Swimlane?

- [What is Swimlane used for?](https://www.g2.com/discussions/what-is-swimlane-used-for)

### 21. [Blumira Automated Detection &amp; Response](https://www.g2.com/products/blumira-automated-detection-response/reviews)
  Blumira is an integrated security operations platform built for growing teams and the partners supporting them to gain complete visibility into their environment, identify and address risk faster, and deliver advanced security and compliance. The platform includes: - Managed Detections for automated threat hunting to identify attacks early - AI Investigation with 98.5% accurate, human-in-the-loop triage validated against real cases - Rapid Response with automation and 1-click actions to contain and block threats immediately - One Year of Data Retention with unlimited log ingestion to satisfy compliance requirements - Advanced Reporting and dashboards for forensics and easy investigation - Endpoint &amp; Identity Protection (EDR/ITDR) for real-time remediation across devices and users - 24/7 Security Operations support for critical priority issues


  **Average Rating:** 4.6/5.0
  **Total Reviews:** 122
**How Do G2 Users Rate Blumira Automated Detection &amp; Response?**

- **Automated Remediation:** 7.5/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.0/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.7/10 (Category avg: 8.8/10)

**Who Is the Company Behind Blumira Automated Detection &amp; Response?**

- **Seller:** [Blumira](https://www.g2.com/sellers/blumira)
- **Company Website:** https://www.blumira.com
- **Year Founded:** 2018
- **HQ Location:** Ann Arbor, Michigan
- **Twitter:** @blumira (1 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/blumira/ (67 employees on LinkedIn®)

**Who Uses This Product?**
  - **Who Uses This:** IT Manager
  - **Top Industries:** Information Technology and Services, Computer &amp; Network Security
  - **Company Size:** 51% Mid-Market, 36% Small-Business


#### What Are Blumira Automated Detection &amp; Response's Pros and Cons?

**Pros:**

- Ease of Use (33 reviews)
- Customer Support (20 reviews)
- Setup Ease (20 reviews)
- Alerting (16 reviews)
- Alert Management (16 reviews)

**Cons:**

- Limited Customization (11 reviews)
- Alert System (7 reviews)
- Expensive (6 reviews)
- Faulty Detection (6 reviews)
- Inefficient Alert System (6 reviews)


### What Do G2 Reviewers Say About Blumira Automated Detection &amp; Response?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **ease of use** of Blumira Automated Detection &amp; Response, highlighting its simple workflows and effective support.
- Users appreciate the **terrific customer support** of Blumira, enhancing security understanding and simplifying integration processes.
- Users appreciate the **easy setup** of Blumira, valuing the quick integration with essential services and support.
- Users value the **timely and clear email alerts** from Blumira, enhancing security awareness and response efforts.
- Users value the **clear and effective email alerts** from Blumira, enhancing security awareness and response capabilities.

**Cons:**

- Users desire **greater customization** in workflows and rules, feeling the current options lack flexibility for unique needs.
- Users find the **false positive alerts** to be frustrating, often wasting time and causing unnecessary stress.
- Users find Blumira Automated Detection &amp; Response to be **prohibitively expensive** , limiting its accessibility for some customers.
- Users report issues with **faulty detection** , including frustrating false positives that waste time and require manual review.
- Users face an **inefficient alert system** with frequent false positives, causing frustration and wasted time in response efforts.

#### What Are Recent G2 Reviews of Blumira Automated Detection &amp; Response?

**"[A well-rounded detection system with fantastic support](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-10479545)"**

**Rating:** 5.0/5.0 stars
*— Jeremy A.*

[Read full review](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-10479545)

---

**"[Breeze From Sales to Onboarding With an Intuitive, Easy-to-Configure UI](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-12984186)"**

**Rating:** 5.0/5.0 stars
*— Blake C.*

[Read full review](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-12984186)

---


#### What Are G2 Users Discussing About Blumira Automated Detection &amp; Response?

- [What are the benefits and drawbacks of using Blumira for threat detection?](https://www.g2.com/discussions/what-are-the-benefits-and-drawbacks-of-using-blumira-for-threat-detection)
- [What is cloud SIEM?](https://www.g2.com/discussions/what-is-cloud-siem)
- [What does the term Siem stand for?](https://www.g2.com/discussions/what-does-the-term-siem-stand-for)
- [What does Blumira do?](https://www.g2.com/discussions/what-does-blumira-do)
- [What is Blumira automated detection &amp; response?](https://www.g2.com/discussions/what-is-blumira-automated-detection-response)

### 22. [CrowdSec](https://www.g2.com/products/crowdsec/reviews)
  CrowdSec is an open-source security stack that detects aggressive behaviors and prevents them from accessing your systems. Its user-friendly design and ease of integration into your current security infrastructure offer a low technical entry barrier and a high-security gain. Once an unwanted behavior is detected, it is automatically blocked. The aggressive IP, scenario triggered and the timestamp is sent for curation, to avoid poisoning &amp; false positives. If verified, this IP is then redistributed to all CrowdSec users running the same scenario. By sharing the threat they faced, all users are protecting each other.


  **Average Rating:** 4.7/5.0
  **Total Reviews:** 85
**How Do G2 Users Rate CrowdSec?**

- **Automated Remediation:** 9.1/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.9/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.5/10)
- **Workflow Automation:** 7.8/10 (Category avg: 8.8/10)

**Who Is the Company Behind CrowdSec?**

- **Seller:** [CrowdSec](https://www.g2.com/sellers/crowdsec)
- **Year Founded:** 2020
- **HQ Location:** Paris, FR
- **Twitter:** @Crowd_Security (19,491 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/crowdsec/?originalSubdomain=fr (30 employees on LinkedIn®)

**Who Uses This Product?**
  - **Top Industries:** Computer &amp; Network Security, Information Technology and Services
  - **Company Size:** 69% Small-Business, 20% Mid-Market



#### What Are Recent G2 Reviews of CrowdSec?

**"[Crowdsec best endpoint in SMB](https://www.g2.com/survey_responses/crowdsec-review-11691179)"**

**Rating:** 5.0/5.0 stars
*— Pramod s.*

[Read full review](https://www.g2.com/survey_responses/crowdsec-review-11691179)

---

**"[It&#39;s a real life-saver in terms of hosting stuff](https://www.g2.com/survey_responses/crowdsec-review-8191423)"**

**Rating:** 5.0/5.0 stars
*— Rei B.*

[Read full review](https://www.g2.com/survey_responses/crowdsec-review-8191423)

---


#### What Are G2 Users Discussing About CrowdSec?

- [What are the benefits and drawbacks of using CrowdSec for cybersecurity, and what do you recommend for improvement?](https://www.g2.com/discussions/what-are-the-benefits-and-drawbacks-of-using-crowdsec-for-cybersecurity-and-what-do-you-recommend-for-improvement)
- [What is CrowdSec used for?](https://www.g2.com/discussions/what-is-crowdsec-used-for) - 1 comment

### 23. [Shuffle](https://www.g2.com/products/shuffle/reviews)
  Shuffle is an open source automation platform for security professionals (SOAR). Run it locally: https://github.com/frikky/shuffle Try it out here: https://shuffler.io/register Join the community: https://discord.gg/B2CBzUm


  **Average Rating:** 4.8/5.0
  **Total Reviews:** 15
**How Do G2 Users Rate Shuffle?**

- **Automated Remediation:** 9.5/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.4/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.4/10 (Category avg: 8.5/10)
- **Workflow Automation:** 9.8/10 (Category avg: 8.8/10)

**Who Is the Company Behind Shuffle?**

- **Seller:** [Shuffle AS](https://www.g2.com/sellers/shuffle-as)
- **HQ Location:** San Francisco, US
- **LinkedIn® Page:** https://www.linkedin.com/company/getshuffleapp/ (7 employees on LinkedIn®)

**Who Uses This Product?**
  - **Top Industries:** Computer &amp; Network Security
  - **Company Size:** 67% Mid-Market, 33% Small-Business



#### What Are Recent G2 Reviews of Shuffle?

**"[Perfect automation tool for your soc](https://www.g2.com/survey_responses/shuffle-review-10067052)"**

**Rating:** 5.0/5.0 stars
*— Ayush G.*

[Read full review](https://www.g2.com/survey_responses/shuffle-review-10067052)

---

**"[Shuffle Open-Source SOAR](https://www.g2.com/survey_responses/shuffle-review-8284361)"**

**Rating:** 5.0/5.0 stars
*— Rohan G.*

[Read full review](https://www.g2.com/survey_responses/shuffle-review-8284361)

---


#### What Are G2 Users Discussing About Shuffle?

- [What is Shuffle used for?](https://www.g2.com/discussions/what-is-shuffle-used-for) - 2 comments

### 24. [guardsix](https://www.g2.com/products/guardsix/reviews)
  guardsix is a comprehensive cybersecurity solution designed specifically for Managed Security Service Providers (MSSPs) and Critical National Infrastructure Providers (CNI). guardsix command center, a unified SecOps platform, enables organizations to effectively detect cyberattacks while ensuring compliance with various data regulations. By offering a robust framework for monitoring and managing security events, guardsix addresses the increasing need for advanced threat detection and regulatory adherence in today’s complex digital landscape. guardsix command center stands out by providing complete visibility across IT environments through the integration of multiple security technologies, including Security Information and Event Management (SIEM), Network Detection and Response (NDR), and Security Orchestration, Automation, and Response (SOAR). This integration allows organizations to monitor their systems holistically, ensuring that potential threats are identified and addressed promptly. Additionally, guardsix employs hypergraph technology, which connects detections from diverse sources, enabling users to determine whether an incident is part of a more extensive attack. This capability enhances situational awareness and improves incident response times. One of the key advantages of guardsix is its open, vendor- and platform-agnostic nature, allowing users to choose how and from where to ingest data. This flexibility is crucial for organizations that operate in heterogeneous environments, as it enables them to tailor their security solutions to fit their specific needs. Furthermore, guardsix automatically normalizes data into a common taxonomy, simplifying the analysis and utilization of ingested information. This feature ensures that users can easily derive insights from their data, regardless of its original format or source. guardsix also prioritizes compliance with major regulatory frameworks, including NIS2, Schrems II, HIPAA, GDPR, PCI-DSS, and SOX. By providing centralized logging and reporting capabilities, the platform facilitates adherence to security guidelines such as CERT-In, SOC 2 Type II, and ISO27001. This focus on compliance not only helps organizations avoid potential legal pitfalls but also enhances their overall security posture by ensuring that they meet industry standards and best practices. In summary, guardsix is a versatile cybersecurity solution that empowers MSSPs and CNI providers to detect threats effectively while maintaining compliance with regulatory requirements. Its integration of essential security technologies, flexible data ingestion options, and emphasis on compliance make it a valuable asset for organizations looking to strengthen their cybersecurity defenses.


  **Average Rating:** 4.3/5.0
  **Total Reviews:** 105
**How Do G2 Users Rate guardsix?**

- **Automated Remediation:** 8.5/10 (Category avg: 8.6/10)
- **Quality of Support:** 9.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.0/10 (Category avg: 8.5/10)
- **Workflow Automation:** 8.9/10 (Category avg: 8.8/10)

**Who Is the Company Behind guardsix?**

- **Seller:** [guardsix](https://www.g2.com/sellers/guardsix)
- **Company Website:** https://guardsix.com/
- **Year Founded:** 2001
- **HQ Location:** Copenhagen, Capital Region
- **LinkedIn® Page:** https://linkedin.com/company/guardsix (117 employees on LinkedIn®)

**Who Uses This Product?**
  - **Top Industries:** Computer &amp; Network Security, Information Technology and Services
  - **Company Size:** 44% Mid-Market, 31% Small-Business


#### What Are guardsix's Pros and Cons?

**Pros:**

- Ease of Use (8 reviews)
- Log Management (5 reviews)
- Customer Support (4 reviews)
- Easy Integrations (4 reviews)
- Efficiency (4 reviews)

**Cons:**

- Poor Interface Design (3 reviews)
- UX Improvement (3 reviews)
- Complexity (2 reviews)
- Confusing Interface (2 reviews)
- Information Deficiency (2 reviews)


### What Do G2 Reviewers Say About guardsix?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **ease of use** of Guardsix, finding it simple to learn and operate effectively.
- Users value the **simplicity and ease of use** of Log Management in LogPoint, enhancing their overall experience.
- Users commend the **excellent customer support** of Logpoint, ensuring rapid responses and satisfaction across various industries.
- Users value the **easy integrations** with existing tools, enhancing compatibility and adaptability in their tech ecosystems.
- Users appreciate the **efficiency** of Logpoint, enabling effortless investigations and streamlined incident management across diverse systems.

**Cons:**

- Users find the **poor interface design** of Guardsix frustrating, as it complicates user experience and functionality.
- Users find the **UX improvement** necessary due to poor log presentation and a slow, confusing interface.
- Users find the **complex interface** of guardsix challenging, though improvements are expected in the future.
- Users find the **confusing interface** of guardsix difficult to navigate, impacting their overall experience.
- Users feel there is a lack of **technical information** to aid in optimal device design and comparison with competitors.

#### What Are Recent G2 Reviews of guardsix?

**"[Context-Driven SIEM That Enhances Incident Response](https://www.g2.com/survey_responses/guardsix-review-11985484)"**

**Rating:** 4.5/5.0 stars
*— Simon A.*

[Read full review](https://www.g2.com/survey_responses/guardsix-review-11985484)

---

**"[Review](https://www.g2.com/survey_responses/guardsix-review-11378057)"**

**Rating:** 4.0/5.0 stars
*— Ronny K.*

[Read full review](https://www.g2.com/survey_responses/guardsix-review-11378057)

---


#### What Are G2 Users Discussing About guardsix?

- [What is your experience with Logpoint for SIEM, and what do you recommend for new users?](https://www.g2.com/discussions/what-is-your-experience-with-logpoint-for-siem-and-what-do-you-recommend-for-new-users)
- [What is LogPoint used for?](https://www.g2.com/discussions/what-is-logpoint-used-for)

### 25. [Intezer](https://www.g2.com/products/intezer-intezer/reviews)
  Intezer automates the entire alert triage process, like an extension of your team handling Tier 1 SOC tasks for every alert at machine-speed. Intezer monitors incoming incidents from endpoint, reported phishing pipelines, or SIEM tools, then autonomously collects evidence, investigates, makes triage decisions, and escalates only the serious threats to your team for human intervention. Power your SOC with artificial intelligence that makes sure every alert is deeply analyzed (including every single artifact like files, URLs, endpoint memory, etc.), detecting malicious code in memory and other evasive threats. Fast set up and integrations with your SOC team&#39;s workflows (EDR, SOAR, SIEM, etc.) means Intezer&#39;s AI can immediately start filtering out false positives, giving you detailed analysis about every threat, and speeding up your incident response time. With Intezer: • Reduce Tier 1 escalation, sending only 4% of alerts on average to your team for immediate action. • Identify up to 97% of false positive alerts without taking any time from your analysts. • Reduce average triage time to 5 minutes or less, while giving your analysts deep context about every alert to prioritize critical treats and respond faster.


  **Average Rating:** 4.5/5.0
  **Total Reviews:** 187
**How Do G2 Users Rate Intezer?**

- **Automated Remediation:** 9.2/10 (Category avg: 8.6/10)
- **Quality of Support:** 8.6/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.5/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Intezer?**

- **Seller:** [Intezer](https://www.g2.com/sellers/intezer)
- **Year Founded:** 2015
- **HQ Location:** New York
- **Twitter:** @IntezerLabs (10,170 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/10656303/ (88 employees on LinkedIn®)

**Who Uses This Product?**
  - **Who Uses This:** Software Engineer, Student
  - **Top Industries:** Computer &amp; Network Security, Information Technology and Services
  - **Company Size:** 54% Small-Business, 23% Mid-Market


#### What Are Intezer's Pros and Cons?

**Pros:**

- Detection Accuracy (3 reviews)
- Ease of Use (3 reviews)
- Malware Protection (3 reviews)
- Security (3 reviews)
- Security Protection (3 reviews)

**Cons:**

- Complex Interface (2 reviews)
- Poor Interface Design (2 reviews)
- UX Improvement (2 reviews)
- Access Control (1 reviews)
- Data Privacy (1 reviews)


### What Do G2 Reviewers Say About Intezer?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **high detection accuracy** of Intezer, ensuring proactive protection against malware and security threats.
- Users value the **ease of use** of Intezer, which streamlines malware detection and incident response effectively.
- Users value the **effective malware protection** of Intezer, ensuring timely detection and enhanced endpoint security.
- Users appreciate the **effective malware detection and security features** of Intezer, providing peace of mind and protection.
- Users value the **effective malware detection and blocking** capabilities of Intezer, ensuring robust system security.

**Cons:**

- Users find the **complex interface** challenging, citing small text and various GUI issues affecting usability.
- Users report **poor interface design** , citing small text and various GUI issues that hinder usability.
- Users report **poor UI and small text size** in Intezer, making it challenging to navigate and read content.
- Users find the lack of **access control** over file visibility to be a significant limitation in certain situations.
- Users find the **lack of control over file visibility** a downside, though it encourages positive peer collaboration.

#### What Are Recent G2 Reviews of Intezer?

**"[Effortless Malware Detection and Robust Endpoint Security With Intezer](https://www.g2.com/survey_responses/intezer-review-12060113)"**

**Rating:** 4.5/5.0 stars
*— Franck P.*

[Read full review](https://www.g2.com/survey_responses/intezer-review-12060113)

---

**"[CTI coordinator](https://www.g2.com/survey_responses/intezer-review-5353729)"**

**Rating:** 4.0/5.0 stars
*— Verified User in Banking*

[Read full review](https://www.g2.com/survey_responses/intezer-review-5353729)

---


#### What Are G2 Users Discussing About Intezer?

- [What is genetic malware analysis?](https://www.g2.com/discussions/what-is-genetic-malware-analysis) - 1 comment
- [Is Intezer good?](https://www.g2.com/discussions/is-intezer-good) - 1 comment
- [What does Intezer do?](https://www.g2.com/discussions/what-does-intezer-do) - 1 comment
- [What is Intezer analyze?](https://www.g2.com/discussions/what-is-intezer-analyze) - 2 comments


    ## What Is Security Orchestration, Automation, and Response (SOAR) Software?
  [System Security Software](https://www.g2.com/categories/system-security)
  ## What Software Categories Are Similar to Security Orchestration, Automation, and Response (SOAR) Software?
    - [Security Information and Event Management (SIEM) Software](https://www.g2.com/categories/security-information-and-event-management-siem)
    - [Incident Response Software](https://www.g2.com/categories/incident-response)
    - [AI SOC Agents](https://www.g2.com/categories/ai-soc-agents)

  
---

## How Do You Choose the Right Security Orchestration, Automation, and Response (SOAR) Software?

### What You Should Know About Security, Orchestration, Automation, and Response (SOAR) Software

### What is Security, Orchestration, Automation, and Response (SOAR) Software?

Security orchestration, automation, and response (SOAR) software helps coordinate, execute, and automate tasks between various IT workers and tools. SOAR tools allow organizations to respond quickly to cybersecurity attacks and observe, understand, and prevent future incidents.

SOAR software gives organizations a comprehensive view of their existing security systems while centralizing the security data. By automating security responses and reducing manual tasks, SOAR helps to generate a faster and more accurate response to security attacks. It also helps better coordinate and route incident response to the most appropriate IT worker in real time.

**What Does SOAR Stand For?**

SOAR stands for security orchestration, automation, and response. SOAR software significantly contributes to identifying potential future security threats.

### What are the Common Features of Security, Orchestration, Automation, and Response (SOAR) Software?

Usually, a SOAR software offering operates under three primary software capabilities:

**Threat and vulnerability management:** Threat and vulnerability management examines key assets and prioritizes efforts to reduce risk. Working with other security teams, threat and vulnerability management helps prevent attacks by threat actors.

**Security incident response:** Security incident response addresses and manages the aftermath of a security breach, cyberattack, computer incident, or security incident. Security incident response is to handle the aftermath of a security breach in a way that limits damage, reduces recovery time, and reduces cost.

**Security operations automation:** Security operations automation is the technology that enables the automation and orchestration of security tasks. This can include both administrative duties and incident detection and response.

### What are the Benefits of Security, Orchestration, Automation, and Response (SOAR) Software?

The benefits of using a SOAR tool are that it lessens the impact of security incidents and reduces the risk of legal liability. SOAR software helps companies’ security teams by enabling them to:

**Maintain a central view:** One of the benefits of SOAR software is that it gives security staff a central view and enables control of existing security systems while centralizing data collection to improve a company&#39;s security posture, operational efficiency, and productivity.&amp;nbsp;

**Automate manual tasks:** As with most software today, users are looking for help in terms of automation. SOAR software helps to manage and automate all aspects of a security incident lifecycle. This removes manual tasks, gives security staff more time to be productive, and allows them to focus on more mission-critical security tasks that do not require manual tasks.

**Define incident and response procedures:** SOAR software helps security systems define incident and response procedures. This helps to route security incidents to the correct security staff. SOAR can also prioritize and standardize the security response processes in a consistent, transparent, and documented way.&amp;nbsp;

**Optimize incident response** : Because SOAR software helps security staff define incident and response procedures, incident response is more accurate. This accuracy enables security systems and staff to have improved responses where they may have to contain, eradicate, or recover crucial data.&amp;nbsp;

**Identify and assign incident severity levels:** SOAR software helps to identify and assign incident severity levels. Severity levels in cybersecurity measure how severely a security incident impacts various parts of the organization. SOAR software automatically identifies and assigns severity levels, enabling the right security system and staff to respond appropriately. This means both can respond immediately to security incidents that may negatively affect an organization, such as networks, software, employee or customer data, etc.

**Support collaboration and unstructured investigations:** SOAR software supports collaboration and unstructured investigations in real time, helping route each security incident to the security system and security staff best suited to respond. Collaboration with other IT teams for tasks such as remediation or other departments such as legal is possible.&amp;nbsp;

**Streamline operations:** By using SOAR software, organizations can streamline security operations for threat and vulnerability management, security incident response, and security operations automation. SOAR software connects these security elements while integrating disparate security systems. SOAR software’s playbooks allow users to orchestrate, streamline and automate tasks. Playbooks also codify the process workflows that streamline the SOAR software functions.

### Who Uses Security, Orchestration, Automation, and Response (SOAR) Software?

**IT and cybersecurity staff:** They use SOAR software to handle security alerts such as phishing, which includes looking for threat feed data from endpoints, failed user logins, logins from unusual locations, malicious VPN access attempts, and so on. It&#39;s also used to hunt for threats and respond to incidents from attached files for malware analysis, cloud-aware incident response, and automate data enrichment. Cybersecurity staff who assign incident severity and check other products for vulnerability scores also use SOAR platforms.

### Challenges with Security, Orchestration, Automation, and Response (SOAR) software

There are a number of challenges with SOAR software that IT teams can encounter.

**Skill gaps:** While there is the misconception that SOAR software could replace security staff, the tool is meant to augment security teams, allowing them to work efficiently and effectively but not replacing them. However, there still may be a skills gap as the security team must be able to create detailed workflows of their processes.

**Effective deployment:** Another challenge of SOAR software is that it must be deployed to the enterprise but also connected to the other applications and technologies, which can be very complicated. An organization must also have staff with enough skills to deploy and maintain the platform. The applications and technologies used by the enterprise must also be able to support or be integrated into the SOAR software. One of SOAR software’s greatest strengths is to connect and orchestrate other technologies; however, if each technology is unable to be integrated, it hampers the benefits of deploying SOAR software.

### How to Buy Security, Orchestration, Automation, and Response Software

#### Requirements Gathering (RFI/RFP) for Security, Orchestration, Automation, and Response (SOAR) Software

If an organization is just starting out and looking to purchase SOAR software, g2.com can help select the best one.

Most business pain points might be related to all of the manual work that must be completed. If the company is large and has a lot of networks, data, or devices in its organization, they may need to shop for a SOAR software that can grow with its organization. Users should think about the pain points in security to help create a checklist of criteria. Additionally, the buyer must determine the number of employees who will need to use the SOAR software and if they currently have the skills to administer it.&amp;nbsp;

Taking a holistic overview of the business and identifying pain points can help the team springboard into creating a checklist of criteria. The checklist serves as a detailed guide that includes both necessary and nice-to-have features, including budget, features, number of users, integrations, security staff skills, cloud or on-premises solutions, and more.

Depending on the scope of the deployment, it might be helpful to produce an RFI, a one-page list with a few bullet points describing what is needed from SOAR software.

#### Compare Security, Orchestration, Automation, and Response (SOAR) Software

**Create a long list**

Vendor evaluations are an essential part of the software buying process from meeting the business functionality needs to implementation. For ease of comparison, after all demos are complete, it helps to prepare a consistent list of questions regarding specific needs and concerns to ask each vendor.

**Create a short list**

From the long list of vendors, it is helpful to narrow down the list of vendors and come up with a shorter list of contenders, preferably no more than three to five. With this list in hand, businesses can produce a matrix to compare the features and pricing of the various solutions.

**Conduct demos**

To ensure the comparison is comprehensive, the user should demo each solution on the shortlist with the same use cases. This will allow the business to evaluate like for like and see how each vendor stacks up against the competition.&amp;nbsp;

#### Selection of Security, Orchestration, Automation, and Response (SOAR) Software

**Choose a selection team**

Before getting started, creating a winning team that will work together throughout the entire process, from identifying pain points to implementation, is crucial. The software selection team should consist of organization members with the right interest, skills, and time to participate in this process. A good starting point is to aim for three to five people who fill roles such as the main decision maker, project manager, process owner, system owner, or staffing subject matter expert, as well as a technical lead, head administrator, or security administrator. In smaller companies, the vendor selection team may be smaller, with fewer participants multitasking and taking on more responsibilities.

**Compare notes**

The selection team should compare notes and facts and figures which they noted during the process, such as costs, security capabilities, and alert and incident response times.

**Negotiation**

Just because something is written on a company’s pricing page does not mean it&#39;s final. It is crucial to open up a conversation regarding pricing and licensing. For example, the vendor may be willing to give a discount for multi-year contracts or for recommending the product to others.

**Final decision**

After this stage, and before going all in, it is recommended to roll out a test run or pilot program to test adoption with a small sample size of users. If the tool is well used and well received, the buyer can be confident that the selection was correct. If not, it might be time to go back to the drawing board.

### What does Security, Orchestration, Automation, and Response (SOAR) Software cost?

SOAR is considered a long-term investment. This means there must be a careful evaluation of vendors, and the software should be tailored to each organization&#39;s specific requirements. Once a SOAR solution is purchased, deployed, and integrated into an organization’s security system, the cost could be high, which is why the evaluation stage of selecting SOAR software is so crucial. The notion of rip-and-replace cost can be high. The SOAR vendor chosen should continue to provide support for the SOAR solution with flexibility and open integration.

#### Return on Investment (ROI)

Organizations decide to purchase SOAR software with some type of return on investment (ROI). As they want to recoup the money spent on the software, it is critical to understand the costs that will be saved in terms of efficiency.

SOAR software saves security staff costs by eliminating manual tasks. For example, SOAR software automatically investigates the scenario of email phishing attacks which is very common, so this task can be very repetitive and consumes security staff time if it is done manually. A large enterprise used actual data from its SOAR software deployment and compared it to the cost of handling email phishing investigations automatically using SOAR software versus handling them manually. The enterprise found that the reduction in staff time required to handle phishing emails equated to savings of over $680,000 per year.

### Security, Orchestration, Automation, and Response (SOAR) Software Trends

**Enterprises:** Due to the requirements to maintain such large-scale IT and network infrastructure, organizations such as large enterprises tend to be more interested in purchasing SOAR software. Having such large networks and more complex IT makes such organizations more vulnerable to security threats which is another drive to purchase SOAR software. Also, larger organizations have more employees with more devices, which increases threats if they are accessing workplace applications on these devices.

**Retail and e-commerce:** These industries have increased interest in SOAR software due to the vulnerabilities in PoS)transactions and online purchases. It is the processing of these monetary transactions which creates a security risk, especially there personal and financial information of customers. Adopting technologies such as location-based marketing for these types of purchases also makes the retail industry more vulnerable to security threats.



    
