← 开源
TracecatHQ

tracecat

Open-source security automation platform for teams and AI agents

ApplicationsProductivityPython
在 GitHub 打开
增长势头
+-124 小时新增 Star-0.0%
3.82k
Star
429
Fork
+6
本周
47
贡献者
创建于 2024-02-27 · 更新于 2026-10-05 · 今日第 16654 名
主要开发者
README

The AI-native security automation platform.

The agentic security automation platform.

Commits License Discord

Introduction

Tracecat is the open source security automation platform for teams and AI agents. A unified platform with everything AI-native security teams need to build agents and automate cyber defense.

Core Features

Unlimited agents, cases, lookup tables, and workflows.

   ![An agent preset in Tracecat with its tools and skills, then a chat where the agent investigates a case by calling tools](img/readme/agents.gif) 

Agents and skills — build custom agents with prompts, tools, MCP, and skills

   ![The Tracecat case list, then a case with an agent-written verdict, timeline, IoCs, and evidence](img/readme/cases.gif) 

Case management — track, automate, and resolve incidents with agents

   ![A workflow DAG in the Tracecat builder, zoomed out to show every step, then an agent step opened for editing](img/readme/workflows.gif) 

Workflows — execute deterministic logic with resilience and scale on Temporal

   ![Tracecat workspace tables, opening an entities table and an entity observations table](img/readme/tables.gif) 

Tables — store and query structured data

   ![A Claude Code session that calls Tracecat MCP tools to list and summarize the open critical cases](img/readme/mcp.gif) 

Tracecat MCP — turn prompts into automations from Claude Code, Codex, Copilot, and more

   ![Tracecat credentials, OAuth integrations, and the hosted MCP server catalog](img/readme/integrations.gif) 

Integrations — 100+ pre-built connectors and 50+ hosted MCP servers for security tools

Other Highlights

  • Pre-built MCP servers: 50+ Tracecat-hosted MCP servers for security operations
  • MCP client: connect custom agents any MCP server (remote HTTP / OAuth or local via npx / uvx commands)
  • Custom registry: sync custom Python scripts from your Git repo into Tracecat
  • Sandboxed: run untrusted code and agents within nsjail sandboxes or pid runtimes
  • Durable execution: built on Temporal for resilience and scale
  • Variables: reuse values across workflows and agents
  • No SSO tax: SAML / OIDC support
  • Free audit logs: exportable into your SIEM
  • Deploy anywhere: sign up for Tracecat Cloud, or self-host with Docker, AWS Fargate, or Kubernetes. Runs fully air-gapped.

Enterprise Edition

  • Multi-tenant: isoated different teams and dev / prod environments into workspaces
  • Fine-grained access control: RBAC, ABAC, OAuth2.0 scopes for humans and agents
  • Human-in-the-loop: review and approve sensitive tools calls from a unified inbox, Slack, or email
  • Workspace version control: sync workflows, agents, and table schemas to GitHub, GitLab, Bitbucket, etc.
  • Metrics and monitoring: for workflows, agents, and cases

Open Source vs Enterprise

This repo is available under the AGPL-3.0 license except for:

  • Code under the packages/tracecat-ee directory
  • Code that gates ee features

These exceptions are fall under Tracecat's paid EE (Enterprise Edition) license. Code that fall under the above exceptions must not be redistributed, sold, used in production, or otherwise commercialized without permission.

[!NOTE] Tracecat Enterprise is available as managed Cloud with US or EU hosting, or as a self-hosted deployment with dedicated support. Book a demo today.

Community

Have questions? Feedback? Come hang out with us in the Tracecat Community Discord.

Tech Stack

  • Backend: Python with FastAPI, SQLAlchemy, Pydantic, uv
  • Frontend: Next.js with TypeScript, React Query, Shadcn UI
  • Durable workflows and jobs: Temporal
  • Sandbox: nsjail
  • Database: PostgreSQL
  • Object store: S3-compatible

Contributors

Thank you all our amazing contributors for contributing code, integrations, docs, and support. Open source is only possible because of you. Check out our Contribution Guide for more information.

Tracecat is distributed under AGPL-3.0