Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Choosing a platform

Soarcery vs Splunk SOAR. One agent that investigates, compared to a library of playbooks you author and maintain.

Splunk SOAR, formerly Phantom and now part of Cisco, is a mature orchestration and automation platform: it fires pre-built playbooks across a large connector library. Soarcery is a single accountable agent, the Familiar, that investigates a case end to end, with automation that runs only after a human reviews the plan. Here is where each earns its place, sourced from Splunk's and Cisco's own materials.

Splunk SOAR
Soarcery
Core idea
A playbook-driven orchestration and automation engine. Splunk states it "orchestrates your security stack by connecting with 300+ third-party tools and supporting 2,800+ automated actions."1 The unit of automation is the playbook, built in a visual editor backed by Python.2
One agent, the Familiar, investigates a case end to end. Spells are plan-first automations a human reviews before they run.
The thinking
The intelligence lives in the playbooks a team writes. Splunk describes the workflow as assembling "custom workflows with prebuilt code blocks and action strings," with prebuilt playbooks "aligned to foundational SOC tasks."12
The Familiar reasons through the full Investigation itself and cites its evidence, informed by a native multi-engine verdict spread rather than a single scan result.
The acting
Playbooks fire actions across integrated tools: Splunk says teams can "execute actions across security and IT tools in seconds instead of hours."1 How much runs on its own is set by the playbooks and the automation each team chooses to enable.
The Seal is the default gate: consequential actions wait on explicit human approval, every time, with a receipt. It is not an opt-in setting.
Maintenance
Playbooks are hand-authored artifacts. The visual editor sits on top of editable Python, so "whether you're new to coding or a Python expert," a team creates and customizes them.2 Generative "AI Playbook Authoring" that turns natural language into playbooks was announced by Cisco for availability "in 2026," not shipped today.3
Spells are described in plain language. There is no flowchart to redraw when a connected tool changes shape.
Auditability
Splunk SOAR keeps a downloadable audit trail, exportable as CSV and reachable through the REST API.4 On the on-premises product, that tracking is not on out of the box: Splunk's own docs state "by default, all audit tracking in Splunk SOAR (On-premises) is disabled."5
The Seal's approval receipts form one replayable trail per Investigation: evidence, reasoning, the approver, and the action, in one place, on by default.
Where it wins
A large, mature connector library (300+ tools, 2,800+ actions), prebuilt playbooks aligned to MITRE ATT&CK and D3FEND, deep integration with Splunk Enterprise Security, and the backing of Cisco after its roughly $28 billion acquisition of Splunk.16
Investigation depth from a single accountable agent, a native multi-engine verdict spread, and an approval gate that ships as the default rather than a configuration choice.
Honest risk
Pre-authored playbooks are yours to build and maintain, and that burden grows with playbook count and shifts each time a connected tool changes shape. The most compelling generative-AI authoring is targeted for 2026, not available now.3 Pricing is not published; Splunk's own FAQ states its workload pricing "does not currently apply to Splunk SOAR," so cost comes through a sales conversation.7
Soarcery is a newer platform. It has not run at Splunk SOAR's scale, integration count, or ecosystem maturity yet, and that gap is real.
The architectural difference

Where the two platforms actually diverge.

Playbooks you author versus an agent that investigates

Splunk SOAR is orchestration and automation: it "orchestrates your security stack by connecting with 300+ third-party tools and supporting 2,800+ automated actions,"1 and the way a team encodes what to do is the playbook, assembled from "prebuilt code blocks and action strings" in a visual editor over Python.2 That model is powerful and proven, but the reasoning is front-loaded into playbooks a human writes ahead of time; the platform runs the branch you scripted for the situation you anticipated. Soarcery takes the opposite bet. The Familiar reasons through the Investigation itself when the alert arrives, following the evidence rather than a pre-drawn branch, and cites what it found. There is no library of playbooks to keep current for every tool and every case shape.

Where the intelligence lives, and when it arrives

Splunk and Cisco clearly see the authoring burden: the headline fix is "AI Playbook Authoring," which Cisco describes as translating "natural language intent into functional, tested SOAR playbooks."3 That is a real answer to a real problem, but Cisco's own release states it "will be available in 2026,"3 so a team buying today still authors and maintains playbooks by hand, with guided and prompt-driven automation as aids rather than an agent that reasons for itself. Soarcery's intelligence is the agent, available now: the Familiar investigates and recommends, and Spells are plan-first, proposed in plain language for a human to review before anything executes.

The default posture: automation-first versus approval-first

Splunk SOAR is built to run actions fast: "execute actions across security and IT tools in seconds instead of hours."1 How much runs unattended, and how much is logged, depends on how each team configures its playbooks and, on the on-premises product, whether audit tracking is enabled at all, since Splunk's docs note it "is disabled" by default there.5 Soarcery starts from the other end. The Familiar investigates and recommends, but the Seal is the default gate on consequential actions, not a setting an admin has to remember to turn on, and every approval produces a receipt, every time, with no configuration required to get that behavior.

Where Splunk SOAR wins

To be fair to a platform with real scale behind it.

  • A large, mature connector library. 300+ third-party tools and 2,800+ automated actions, distributed through Splunkbase, is a lot of ground already covered, and it matters on day one of a deployment.1
  • Deep integration with Splunk Enterprise Security and the Cisco stack. If your SOC already runs on Splunk, SOAR playbooks live right inside that workflow, and Cisco's roughly $28 billion acquisition puts substantial platform and telemetry behind it.6
  • Framework-aligned prebuilt content and dual authoring. Prebuilt playbooks aligned to MITRE ATT&CK and D3FEND give teams a running start, and the visual-plus-Python model suits analysts who want to drop to code.12

Fair fight

If your SOC already runs on Splunk and a substantial library of built-out SOAR playbooks, that investment is real and migrating away from it has a cost. Soarcery is the better fit when what you want is one agent that reasons through a full Investigation end to end, a native multi-engine verdict spread informing that reasoning, and an approval gate that is the default behavior, not a setting someone has to remember to configure.

Settle it with evidence

Watch the difference on a real case.

Three minutes, ungated. Then bring your own alerts and compare for real.

Sources

Where this comparison comes from.

Every claim about Splunk SOAR above traces back to one of these, almost entirely Splunk's and Cisco's own pages, confirmed by direct fetch where noted.

  1. 1Splunk, "Splunk SOAR", splunk.com/en_us/products/splunk-security-orchestration-and-automation.html. "300+ third-party tools and 2,800+ automated actions," "execute actions across security and IT tools in seconds instead of hours," prebuilt playbooks aligned to MITRE ATT&CK and D3FEND.
  2. 2Splunk, "Splunk SOAR Features", splunk.com/en_us/products/splunk-security-orchestration-and-automation-features.html. "Whether you're new to coding or a Python expert, Splunk SOAR provides you with the means to create and customize playbooks. The Visual Playbook Editor simplifies the playbook creation process by allowing you to assemble custom workflows with prebuilt code blocks and action strings."
  3. 3Cisco, "Cisco Elevates the SOC with Agentic AI...", September 9, 2025, newsroom.cisco.com. "AI Playbook Authoring: Translates natural language intent into functional, tested SOAR playbooks," and that this and related capabilities "will be available in 2026."
  4. 4Splunk docs, "Download audit trail logs in Splunk SOAR (Cloud)", help.splunk.com. Audit trail downloadable as CSV and accessible via the REST API. Confirmed by direct fetch.
  5. 5Splunk docs, "Enable and download audit trail logs in Splunk SOAR (On-premises)", help.splunk.com. "By default, all audit tracking in Splunk SOAR (On-premises) is disabled." Confirmed by direct fetch.
  6. 6Cisco, "Cisco Completes Acquisition of Splunk", March 18, 2024, newsroom.cisco.com. Approximately $28 billion in equity value; Splunk now part of Cisco.
  7. 7Splunk, "Cybersecurity pricing FAQs", splunk.com/en_us/products/pricing/faqs/cyber-security.html. Workload pricing "does not currently apply to Splunk SOAR"; no public list pricing for SOAR, engagement is sales-led.