Security Operations
SIEM, detection and response, incident response, forensics, offensive testing, and SOC management.
21 companies ranked by Innovation Matrix score.
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Google Security Operations
Google's cloud-scale SIEM/SOAR (formerly Chronicle), unifying a petabyte-scale data lake with Mandiant frontline threat intelligence and Gemini-powered investigation.
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…
Microsoft Sentinel
Microsoft's cloud-native SIEM, deeply integrated with Azure and Microsoft 365 telemetry, now layering agentic AI (Security Copilot/Sentinel agents)…
Arctic Wolf
Managed detection and response provider delivering a 24/7 human 'Concierge Security Team' as a de facto outsourced SOC…
Huntress
Managed detection and response platform purpose-built for small and midsize businesses, delivered primarily through managed service providers rather…
Corelight
Network detection platform built on the open-source Zeek framework, converting raw network traffic into structured 'network evidence' for…
Expel
Vendor-agnostic managed detection and response provider known for transparent, plain-language alert explanations layered on top of a customer's…
SentinelOne
AI-driven EDR/XDR vendor whose Singularity platform uses on-agent machine learning and automated storyline correlation for autonomous detection and…
Red Canary (a Zscaler company)
MDR provider known for detection-engineering rigor and its open-source Atomic Red Team testing framework, acquired by Zscaler in…
Cynet
All-in-one XDR platform (Cynet 360) bundling endpoint, network, and deception technology with an included 24/7 MDR service, aimed…
Splunk (a Cisco company)
Long-standing machine-data and log-analytics platform, now Cisco's security and observability backbone, powering SIEM and SOAR for a large…
Dropzone AI
An agentic 'AI SOC Analyst' that autonomously investigates security alerts end-to-end across a customer's existing tool stack and…
Vectra AI
Network detection and response platform using AI ('Attack Signal Intelligence') to identify attacker behavior across hybrid cloud, identity,…
Darktrace
Self-learning AI security platform that builds an unsupervised behavioral baseline of each customer's network and autonomously contains anomalous…
Hunters
A 'SOC platform' positioned as a SIEM alternative, built on a cloud data lake to decouple security-data storage…
Exabeam
SIEM and UEBA vendor formed by the 2024 merger of Exabeam and LogRhythm, combining behavioral-analytics-driven detection with a…
Binalyze
Binalyze AIR is an automated digital forensics and incident response (DFIR) platform that collects forensically sound evidence at…
Secureworks (a Sophos company)
Taegis XDR/MDR provider and Counter Threat Unit threat-intelligence team, now part of Sophos, together forming one of the…
Swimlane
SOAR platform (Turbine) that routes security alerts across deterministic automation, AI-assisted investigation, or fully agentic investigation paths depending…