Tracecat
Open-source workflow automation and case management platform.
Tracecat hits 1.0 RC with open-source agent presets, agent-case @mentions, and 20+ new security integrations.
◆Recent moves
- 13h ago
Tracecat 1.0.0-rc.2
RC.2 adds SSRF blocking for MCP and custom LLM requests — a security hardening move appropriate for a platform handling sensitive incident data. AWS role chaining lands for boto3, S3, and DuckDB, enabling more complex multi-account cloud investigation workflows. The MCP UI now surfaces connected server status and sorts connected servers first.
View source ↗ - 1d ago
Tracecat 1.0.0-rc.1
⚡ SPARKRC.1 opens up agent presets, skills, and the MCP catalog as open source — moving from a closed integration catalog to a community-extensible one. Four new LLM backend providers (Ollama, vLLM, LiteLLM, OpenRouter) make air-gapped and self-hosted model setups viable for the first time. This is the release where Tracecat explicitly invites external contributions to its integration surface.
View source ↗ - 4d ago
Tracecat 1.0.0-beta.53-rc.1: Case aggregation and skill tool grants
Case aggregation by dropdowns and tags extends the query surface for investigations — analysts can now aggregate cases without writing custom queries. Agent skills can now declare and grant specific tools, giving more fine-grained control over what agents are allowed to do within a workflow. Vercel security firewall templates add a pre-built response option for web infrastructure incidents.
View source ↗ - 4d ago
Tracecat 1.0.0-beta.52: Agent @mentions in cases and 20+ new integrations
⚡ SPARKBeta.52 is the largest single release in Tracecat's history: agents can be invoked from case comment @mentions and record their mutations back to cases, establishing a bidirectional human-agent workflow for investigation. The integration catalog added 20+ providers including Rippling, Jamf, Microsoft Graph, Databricks, Snowflake, and Recorded Future. OpenTelemetry tracing, rich text comments, case version history with restore, and an agent OTel UI all land in this release.
View source ↗ - 7d ago
Tracecat 1.0.0-beta.52-rc.24
Pre-release RC filling in the final capabilities before beta.52 general availability: case field resolver, rich text comments, table field resolver, row aggregation endpoint, and secret-dependent error withholding (where errors that would leak secrets are suppressed in outputs). Infrastructure work removing Glacier transitions from Fargate buckets and improving Sentry failure capture rounds out the changes.
View source ↗ - 12d ago
Tracecat 1.0.0-beta.52-rc.23
Security hardening (nsjail bind mount handoffs), Splunk remote MCP server integration, webhook workflow tracing through agents, and MCP instruction trimming to stay within prompt budgets. Routine but meaningful work on the execution hardening track that runs parallel to feature development.
View source ↗