Directory / SIEM & SOC
Security information and event management and SOC platforms used to detect, investigate, and respond at scale.
Microsoft Sentinel
Microsoft
Cloud SIEM with the fastest enterprise adoption via Azure and Defender bundling.
Splunk Enterprise Security
Splunk / Cisco
Long-time SIEM standard for large SOCs, now inside Cisco.
CrowdStrike Falcon Next-Gen SIEM
CrowdStrike
High-speed SIEM on Falcon log data, replacing a slice of legacy SIEM spend.
Cortex XSIAM
Palo Alto Networks
AI SOC platform combining SIEM, SOAR, and XDR into one operations console.
Google Security Operations
Chronicle-based SIEM with petabyte search and Google threat intel.
Exabeam
Exabeam
UEBA-first SIEM used by SOCs that want behavior analytics over raw logs.
Elastic Security SIEM
Elastic
Search-native SIEM popular with detection engineers and MSSPs.
Securonix
Securonix
Cloud SIEM with strong UEBA for large enterprise log volumes.