SIEM / Security Analytics
15 providers in this category.
SIEM platforms aggregate logs and security telemetry to detect threats, investigate incidents, and meet audit requirements. Modern options are cloud-native and increasingly bundle SOAR for automated response. Look at detection content, built-in SOAR, deployment model (SaaS versus self-hosted), free tier, and compliance; pricing is typically ingest- or quote-based.
Companies
Neutral ordering. Not a recommendation.
CrowdStrike Falcon
www.crowdstrike.com
CrowdStrike Falcon is a cloud-delivered endpoint protection platform combining endpoint detection and response (EDR), extended detection and response (XDR), and threat intelligence through a lightweight agent.
Datadog Cloud SIEM
www.datadoghq.com/product/cloud-siem
Datadog Cloud SIEM applies real-time threat detection to the logs already flowing through Datadog, correlating security signals with the observability context of the same platform.
Elastic Security
www.elastic.co/security
Elastic Security is a SIEM and endpoint security solution built on the Elastic Stack for threat detection and investigation.
Exabeam
www.exabeam.com
Exabeam is a SIEM and security analytics platform that uses behavioral analytics (UEBA) to detect threats based on user and entity behavior.
Google SecOps
cloud.google.com/security/products/security-operations
Google Security Operations (formerly Chronicle) is a cloud-native, Google-scale security operations platform that unifies SIEM, SOAR, and applied threat intelligence, with Gemini AI-assisted investigation.
Hunters
www.hunters.security
Hunters is an AI-driven, cloud-delivered next-generation SIEM and SOC platform that automates threat detection, alert triage, and investigation.
IBM QRadar
www.ibm.com/qradar
IBM QRadar is an enterprise SIEM for threat detection, correlation, and response across high volumes of log and network telemetry.
LimaCharlie
limacharlie.io
LimaCharlie is a cloud-native 'SecOps Cloud Platform' offering EDR sensors, vendor-agnostic telemetry ingestion, a YAML-based detection-and-response engine, and automation APIs.
Microsoft Sentinel
www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-sentinel
Microsoft Sentinel is a cloud-native SIEM and SOAR platform on Azure for collecting, detecting, and responding to security threats.
Panther
panther.com
Panther is a cloud-native, detection-as-code SIEM built on a Snowflake-backed security data lake for engineering-oriented security teams.
Rapid7
www.rapid7.com
Rapid7 InsightVM is a vulnerability-management platform spanning endpoint to cloud, using a single Insight Agent plus agentless scan engines.
Securonix
www.securonix.com
Securonix is a cloud-native SIEM and security analytics platform that emphasizes behavior analytics (UEBA) and threat detection.
