OpenSOAR

Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed

About

OpenSOAR is an open-source, self-hosted platform for automating security alert triage, enrichment, and response with Python playbooks. Alerts can arrive through webhooks, Elasticsearch polling, or syslog; the platform can normalize payloads, extract indicators of compromise, and deduplicate events. Playbooks are asynchronous Python functions that can be tested, versioned, and run with standard Python packages. The execution engine supports parallel actions, timeouts, retries, and exponential backoff. Case tools can create and link incidents, assign cases, add timeline comments and observables, and show correlation suggestions. Listed integrations include Elastic Security, VirusTotal, AbuseIPDB, Slack, and Email, alongside an extensible Python SDK. AI options include Claude, OpenAI, and Ollama for summarization, triage recommendations, playbook generation, auto-resolution, and correlation. The maker says local Ollama can be used without data leaving the network. OpenSOAR is free under Apache 2.0, with no feature gates or per-action billing; its homepage labels the product as currently in beta.

Who it is for

OpenSOAR is aimed at SOC teams, MSSPs, incident responders, SREs, infrastructure and on-call teams, and DevOps teams. It suits users able to deploy a self-hosted Python-playbook system.

What is good

  • Free under Apache 2.0 with no per-action billing.
  • Accepts alerts via webhooks, Elasticsearch polling, and syslog.
  • Python playbooks support retries and parallel actions.
  • Includes incident and case management tools.
  • Local Ollama option can keep data on-network.

What to know first

  • The product is currently labeled as beta.
  • Deployment is self-hosted.
  • AI provider options include services with their own policies.

Verdict

OpenSOAR combines alert intake, Python automation, and case management in a self-hosted package. Its beta status is the main caveat for teams evaluating it for operational use.

Compared on SOAR software

Free plan
Yesopensoar.app
Playbook automation
Yesopensoar.app
Alert enrichment
Yesopensoar.app
Threat intel actions
Yesopensoar.app
Case management
Yesopensoar.app
Deployment model
self_hostedopensoar.app

Facts

Purpose
OpenSOAR is an open-source platform for automating alert triage, enrichment, and response using Python playbooks.opensoar.app · 30 Sept 2026
Playbooks
Playbooks are Python async functions that can be tested, versioned, and run with standard Python packages.opensoar.app · 30 Sept 2026
Ingestion
It supports alert intake through webhooks, Elasticsearch polling, and syslog, with payload normalization, IOC extraction, and deduplication.opensoar.app · 30 Sept 2026
Execution
The async playbook engine supports parallel actions and per-action timeouts, retries, and exponential backoff.opensoar.app · 30 Sept 2026
Integrations
The maker lists Elastic Security, VirusTotal, AbuseIPDB, Slack, and Email as integrations, with an extensible Python SDK.github.com · 30 Sept 2026
AI
AI features include LLM summarization, triage recommendations, playbook generation, auto-resolve, and correlation, with Claude, OpenAI, and Ollama listed as options.github.com · 30 Sept 2026
Data control
The maker says AI triage can use local Ollama and that no data leaves the network if the user does not want it to.opensoar.app · 30 Sept 2026
Security controls
The maker lists JWT authentication, integration API keys, three core roles, and admin-managed local accounts.github.com · 30 Sept 2026
Audit
The maker says automation actions are logged with timestamps and full context, and AI decisions include logged inputs, outputs, and reasoning.opensoar.app · 30 Sept 2026
Deployment
OpenSOAR is self-hosted and its repository documents a Docker Compose deployment.github.com · 30 Sept 2026
Intended users
The maker identifies SOC teams, MSSPs, incident responders, SREs, infrastructure and on-call teams, and DevOps teams as use cases.opensoar.app · 30 Sept 2026
Support and docs
The maker provides canonical documentation covering setup, playbooks, deployment, API usage, troubleshooting, and engineering references.docs.opensoar.app · 30 Sept 2026
Notable limit
The maker's homepage labels the product as currently in beta.opensoar.app · 30 Sept 2026

Best OpenSOAR alternatives

See all 12

Where it ranks on Inferse

Sources