Incident ResponseAlienVault USM1https://dudodiprj2sv7.cloudfront.net/product-logos/LF/Ap/TPOL9A2198T5.JPEGCrowdStrike Falcon Endpoint Protection2https://dudodiprj2sv7.cloudfront.net/vendor-logos/QJ/nR/NGAP2XUTKHMV-180x180.JPEGIBM Resilient Incident Response Platform3https://dudodiprj2sv7.cloudfront.net/vendor-logos/yf/sf/DNSXTG99HOK3-180x180.JPEGCybereason Deep Detection & Response Platform4https://dudodiprj2sv7.cloudfront.net/vendor-logos/cV/hK/TPQPBH4GE957-180x180.PNGCb Response5https://dudodiprj2sv7.cloudfront.net/product-logos/s4/U6/76DTIOBSOFIM.PNGDFLabs IncMan6https://dudodiprj2sv7.cloudfront.net/vendor-logos/xN/FG/ELPWFLFG5N8O-180x180.JPEGEnCase Endpoint Security7https://dudodiprj2sv7.cloudfront.net/vendor-logos/Jo/Dc/J5BO5E4D2RK8-180x180.JPEGDERDACK Enterprise Alert8https://dudodiprj2sv7.cloudfront.net/product-logos/XY/c1/NRRULDF1IZUE.PNGCyber Triage9https://dudodiprj2sv7.cloudfront.net/vendor-logos/Kt/S0/7LFJVSRXESE9-180x180.JPEGEverbridge IT Alerting10https://dudodiprj2sv7.cloudfront.net/vendor-logos/J6/wK/QA6OI29WN9OJ-180x180.PNGD3 Security11https://dudodiprj2sv7.cloudfront.net/vendor-logos/YS/Xo/N7M1TAC11PQF-180x180.JPEGResolve Systems12https://dudodiprj2sv7.cloudfront.net/vendor-logos/FE/UN/L05DO48JOV11-180x180.PNGDemisto13https://dudodiprj2sv7.cloudfront.net/vendor-logos/kZ/HQ/MKM3SEJM6QSH-180x180.JPEGWindows Defender Advanced Threat Protection (Hexadite AIRS)14https://dudodiprj2sv7.cloudfront.net/vendor-logos/tf/J4/RTX1AO2GSVNS-180x180.JPEGCylanceOPTICS15https://dudodiprj2sv7.cloudfront.net/vendor-logos/YM/ti/6V4RD3ZDVDEE-180x180.JPEGInsightIDR16https://dudodiprj2sv7.cloudfront.net/vendor-logos/Jt/nm/DMQHRCTTH9CT-180x180.JPEGFireEye Security Orchestrator17https://dudodiprj2sv7.cloudfront.net/vendor-logos/NG/Ce/Z0M72RNSMBG5-180x180.JPEGAyehu eyeShare18https://dudodiprj2sv7.cloudfront.net/vendor-logos/is/Qi/392705B8DSTW-180x180.PNGCyberSponse19https://dudodiprj2sv7.cloudfront.net/vendor-logos/sp/O1/OK4IHXODHB2J-180x180.PNGSiemplify20https://dudodiprj2sv7.cloudfront.net/product-logos/K2/dY/7G7ZPENFB8XI.JPEGCynet 36021https://dudodiprj2sv7.cloudfront.net/vendor-logos/g5/d3/JCM06L4PZHAB-180x180.JPEGExabeam Security Intelligence Platform22https://dudodiprj2sv7.cloudfront.net/vendor-logos/2f/Iu/3CV52KIWX2FF-180x180.JPEGProofpoint Threat Response Auto-Pull23https://dudodiprj2sv7.cloudfront.net/product-logos/F0/xp/RZBWSU7FF2IS.JPEGProofpoint ThreatResponse24https://dudodiprj2sv7.cloudfront.net/vendor-logos/8m/3w/841F4UFBJE69-180x180.JPEGCenturyLink Analytics and Threat Management25https://dudodiprj2sv7.cloudfront.net/vendor-logos/OK/UO/KTW2ZSTJRMM2-180x180.JPEG

Incident Response Platforms

Incident Response Platform Overview

What are Incident Response Platforms?

Incident response (IR) platforms guide countermeasures against a security breach and deploy preplanned, automated threat responses. Automated tasks can include threat hunting, anomaly detection, and real-time threat response via a playbook. After a breach, IR platforms can generate incident reports for analysis. Through IR software incident response may be planned, orchestrated and logged in accordance with policy, and best practice.


IR platforms may provide a response playbook designed to help contain and remediate breaches. Playbooks, or runbooks, are planned workflows that guide or automatically orchestrate responses to threats in real-time. These playbooks can be triggered by detecting known threats or incident types, and run in accordance with policy or SLA. For instance, the playbook may escalate a threat level if a high priority device is infected.


Through automated orchestration, incident response platforms help response teams minimize the time and resources required to manage incidents. IR platforms enable remediation teams to work on a broader scale and can identify and remediate network events that may have been missed due to a lack of resources.

Features of Incident Response Platforms

Incident response platforms may offer the following features:

  • Knowledgebase of regulations and best practice response plans

  • SIEM data ingestion, anomaly detection

  • Correlate data from SIEM, endpoints, and other sources

  • Pre-built customizable standards-based incident response playbooks

  • Automated response to security alerts

  • Process tree & timeline analysis to identify threats

  • Attack behavior analytics, for real-time detection & forensics

  • Access & credential lockdown, network access analysis

  • Isolation of infected systems, malicious files

  • Automate escalation to assign tasks to the right people

  • Service-level agreement (SLA) tracking and management

  • Forensic data retention for post-incident reporting, analysis

  • Remediation planning & process automation

  • Privacy breach reporting policy (e.g. GDPR) preparation

  • Compliance report issuance

Pricing Information & Availability

Incident response is very often offered as a service by cybersecurity outsourcing specialists. However strictly technology-based IR Platforms like those below are available to SOCs and in-house enterprise IT security teams. These offerings are often part of a suite from vendors specializing in cybersecurity software. In this case, they may be bundled with endpoint protection and antivirus applications from the same vendor. Vendors of IR software will boast integrations with popular SIEM applications, or other IT automation applications. Incident response platforms

share featural overlap with SOAR platforms (for Security Orchestration, Automation and Response), such as automated playbooks.

Incident Response Products

Listings (1-25 of 32)

AlienVault USM

<a href='https://www.trustradius.com/static/about-trustradius-scoring#question3' target='_blank' rel='nofollow'>Customer Verified: Read more.</a>
343 Ratings

AlienVault USM Anywhere is a cloud-based security management solution that promises to accelerate and centralize threat detection, incident response, and compliance management for cloud, hybrid cloud, and on-premises environments. The vendor says that USM Anywhere includes purpose-built cloud sen...

We don't have enough ratings and reviews to provide an overall score.

Carbon Black offers Cb Response, an IR and threat hunting solution. Cb Response gives users visibility through continuous recording of all activity on their endpoints. Capturing all threat activity, users can visualize the attack kill chain to hunt threats in real time allowing them to respond an...

We don't have enough ratings and reviews to provide an overall score.

Italian company DFLabs offers IncMan, their flagship security automation and orchestration platform emphasizing rapid incident detection, a higher proportion of incidents receiving response, and faster incident response time.

We don't have enough ratings and reviews to provide an overall score.

EnCase Endpoint Security is an endpoint threat detection and incident response cyber security application developed by Guardian Software and now owned and supported by OpenText since the acquisition in summer 2017.

We don't have enough ratings and reviews to provide an overall score.

Basis Technology in Cambridge, MA offers Cyber Triage, an incident response software emphasizing the rapid and accurate collection of endpoint data, touted as better and more comprehensive than antivirus and ideal for non-forensics experts.

We don't have enough ratings and reviews to provide an overall score.

Everbridge's IT Alerting system is an incident response system allowing deployment of a predefined business process to alert personnel and create the necessary bridging and orchestration to address the threat.

We don't have enough ratings and reviews to provide an overall score.

Vancouver company D3 Security offers their incident response suite, featuring an incident knowledgebase and response templates, built-in and configurable workflow with task assignment and assignable threat alerting threshold, among other features.

We don't have enough ratings and reviews to provide an overall score.

The flagship product from Resolve Systems in Irvine is their incident response platform, which features automated security and threat diagnosis, an incident tracking dashboard, and automated remediation workflow.

We don't have enough ratings and reviews to provide an overall score.

Demisto in Cupertino offers a comprehensive incident response and cyber defense orchestration platform, featuring a virtual "playbook," a workflow designer, and a reporting dashboard for incident review.

We don't have enough ratings and reviews to provide an overall score.

Cylance, a Blackberry company since the early 2019 acquisition, offers a range of cyber security solutions, including CylanceOPTICS, an incident response solution emphasizing fast endpoint detection and automated smart threat response, root cause and context analysis, and other features.

We don't have enough ratings and reviews to provide an overall score.

In addition to their incident response service, Rapid7 offers InsightIDR, a relatively broad offering covering SEIM and incident response automation.

We don't have enough ratings and reviews to provide an overall score.

Ayehu offers eyeShare, their IT automation platform powered by machine learning to support rapid incident response and process automation.

We don't have enough ratings and reviews to provide an overall score.

CyberSponse in Arlington offers their flagship cybersecurity orchestration and incident response platform that supplies automation and intelligence to threat containment and elimination.

We don't have enough ratings and reviews to provide an overall score.

Siemplify provides a holistic security operations platform that empowers security analysts to work smarter and respond faster. Siemplify uniquely combines security orchestration and automation with patented contextual investigation and case management to deliver intuitive, consistent and measurab...

We don't have enough ratings and reviews to provide an overall score.

New York based Cynet offers their intrusion detection and threat response platform Cynet 360, which monitors endpoints and networks, correlates and analyzes suspicious behavior, and provides automated remedial protection and manual remediation guidance to contain and eliminate cyber attackers.

We don't have enough ratings and reviews to provide an overall score.

Exabeam headquartered in San Mateo, offers their security intelligence and SIEM platform, the Exabeam Security Intelligence Platform, featuring unlimited security data collection (Exabeam Data Lake), threat detection via Exabeam Advanced Analytics, security response and orchestration via Exabeam ...