Pillar
See the event, decide if it matters, act before the queue buries it. SIEM alternatives, XDR, and AI SOC are the lists we stand behind today. Read the job line on each card before the vendor name.
See data the SIEM never ingested
Open the listCorrelate more than the endpoint
Open the listTriage the queue
Open the listTicket to an action you already own
Open the listA detection you can grep
Open the listCheap durable ingest when SIEM is the tax
Open the listOne case, one timeline
Open the listQuestions about Security Operations
It is how you notice a failure in production and what you do next. Engineers feel it as logging, detections, and the ticket that comes back to the service. Analysts feel it as the queue. The lists here are for the people who pick that stack, not for a SOC-as-a-service brochure.
A SIEM is where events go to be stored, searched, and turned into a case. XDR is the claim that the same case can join the host, the identity, and the mailbox without you writing the join. We keep two lists because teams are sold both, and the jobs are not the same. If the product cannot show you data it did not already own, it is a weak row on the SIEM list.
Microsoft Sentinel, Elastic Security, Wazuh, Security Onion, Panther, and Vega. We care whether you can see the log the application never sent, whether you can keep the data, and whether the query is yours. A cheaper Sentinel is not automatically the answer.
CrowdStrike Falcon, Microsoft Defender XDR, LimaCharlie, Velociraptor, Fleet, and OpenEDR. The job is correlation past the endpoint. If it only shines on the laptop timeline, it is EDR with a new name.
When the queue is the bottleneck, not the lack of another dashboard. The AI SOC list is Vega, Microsoft Security Copilot, Dropzone AI, Shuffle, TheHive, and Keep. We score whether they read the same evidence as the analyst and whether a human can still open the case.
It belongs in this category and it is not a published list yet. We will not fold six scanner logos into the SIEM page to look complete. When that list ships, it will get its own card under Security Operations.