Torq AI SOC Platform
Automation has transformed phishing triage and freed analysts for deeper security work
What is our primary use case?
We are primarily using Torq for phishing alert handling, which means we are getting the alert data from Splunk and then using that data to pull back the phishing emails and their attachments, detonate those in various sandboxes, and then collate all that data up into an incident for the security team. We have a couple of workflows in that vein. We handle phishing, malware detections, and AI use cases in a similar manner, and we are also doing a lot of data syncs between our various vulnerability platforms. We are using Torq for that, and eventually we will be using it for case management, but that is currently in the works.
Regarding Torq's Identity AI, we have not really gotten to use it a whole lot because of the nature of the transition project that we are currently working on, so I do not have a lot to say about it.
We are actually using Torq to automate triage, investigation, and remediation actions across multiple attack surfaces like endpoint, identity, cloud, and IT right now. Outside of the piecemeal automations we have, which encompass all three of those different security domains, the new case management workflow ecosystem we are building out is exactly that.
How has it helped my organization?
Torq has changed the day-to-day experience for my security analysts and me by saving literally thousands of man-hours per month since we have implemented some of these use cases. The analysts now have a lot more free time to do their work.
What is most valuable?
My favorite thing about Torq thus far is the ease of use. Once you get over the initial learning curve, which for me was not that bad, it is a very simple platform with a lot of drag and drop tools. It is flexible enough that I could use Python if I needed to, and logically, it is a clean editor that makes a lot of sense for me and is just simple and intuitive.
What needs improvement?
What I dislike about it is that because my background is primarily in Python, the platform itself can run on Python scripts, and when those fail, it is really easy for me to figure out what is going on. The underlying code being run by the platform for all of the built-in parts of the built-in automations that you can create uses Go, which is a different programming language, and the way it displays errors within the platform when something goes wrong is not as intuitive for me to debug or do a traceback on. That would be the biggest issue I have with it. Sometimes when it spits out an error, it is either because I am not familiar with Go or the platform itself just is not giving me enough to usually go off of.
The comparison of Torq's unified platform approach to SOC automation and case management to any other experiences managing multiple point solutions across the stack is a loaded one. The automation side is really great. However, the case management piece, due to the platform being an automation-first tool, lacks real robust out-of-the-box case templates or good solutions for creating those without spending a lot of time doing development work, which makes the overall experience poor, honestly. In a previous life, I managed Phantom, Phantom SOAR, Splunk SOAR, whatever you want to call it, and another tool called IBM Resilient, which was our external ticketing system. That tool itself had pre-made case templates you could use. Out-of-the-box, you could get the integration going between the two platforms, and it was relatively simple. With Torq, you have to build everything from scratch, and I wish it had a little bit more of a case management feature that was a bit more developed.
For how long have I used the solution?
I have been working with it for just over a year now, since we did our demo with them and got access.
What do I think about the stability of the solution?
I have not really noticed any issues with stability. The UI can be a little laggy at times, but I do not think that is really the platform. I think it might just be the implementation at Marriott. We have never had an outage, so I can at least say we have not had that happen. Any lag I think is usually client-side, not server-side.
What do I think about the scalability of the solution?
Torq seems to be very scalable. There are some limitations with the platform in terms of how many workflows you can run. There is only so many that you are allowed to run in the system before pricing starts becoming an issue, and that can be a little frustrating, but the actual platform itself seems to scale very well.
How are customer service and support?
I have contacted their technical support, and that is usually what I am doing when I am reporting bugs.
If I were to put them on a scale from one to ten, I would give them a ten. They are fantastic.
The quality and speed of the support from Torq are very much on top of their game. You put in a ticket, and you usually hear something back within an hour. If it is a big bug, we have got dedicated resources from Torq that we can reach out to directly. Even if it is something as simple as asking how to do something in an automation and it is just not working, they will usually get back to me about that. They are very attentive and very much on top of making sure we have all the resources that we need to do what we need to do.
Which solution did I use previously and why did I switch?
I have used Splunk SOAR as an alternative that I can compare Torq to.
Comparing Torq and Splunk SOAR is tough because it is not exactly an apples-to-apples comparison. Overall, I would still say I probably prefer Torq. There are things I like more about Splunk SOAR, like that it is entirely Python-based, so I feel a lot more comfortable writing custom code in there. However, the way that it handles certain data objects requires designing from a different angle in both tools, and I feel like Torq's angle is a little more intuitive.
Addressing the specific challenges to our SOC that led us to consider changes before implementing Torq is an odd situation because I was not very involved in that decision. I am just dedicated to development work on this platform, but I do not work for the SOC. They are more or less my customer in a way. I think the primary driver was budgetary concerns, as well as issues with ServiceNow. We have a ServiceNow team managing a lot of this, and our SOC wanted more flexibility and a little bit more control over when they could make changes to their case management or their automations. I am pretty sure that was the main driver—putting some of that ownership back into our security teams, with me being their primary technical resource for it.
How was the initial setup?
The initial deployment was super easy. Because Torq is a SaaS solution, there is not a lot that goes into it. They basically spin it up for you and then hand you the keys, essentially. That portion of it was like maybe a day, and there were some internal activities that had to happen for setting up things like SSO on our side. That was not difficult. It is just a big corporation, so it takes time to get all the different teams to do what they need to do.
What was our ROI?
I saw the benefits of Torq almost immediately after we deployed it because we transitioned our already existing SOAR workflows from Phantom. Pretty much anything that was running in Phantom is now running in Torq as of day one, so it was immediate savings.
What's my experience with pricing, setup cost, and licensing?
I would not be the right person to ask about my opinion on the pricing. That would be my manager.
Which other solutions did I evaluate?
Torq's abilities compared to other tools I have looked at are similar in that they all do a lot of the same things. I would say all SOAR platforms are kind of the same, at least in essence, in what they are trying to achieve. What differentiates them really is ease of use, and I would say Torq is probably the easiest one that I have gotten to use so far.
What other advice do I have?
In my current field overall, I have been working in SOAR automation and software development specifically for roughly six years.
I have never really done any maintenance myself. That is all being taken care of by the Torq developers. The only thing I have really helped out with in that regard is bug fix type things where I catch an actual platform bug and then report it.
I do not know what measurable security outcomes matter most to our leadership team. I do not really talk to management all that much. I code for them and let them worry about the KPIs and other matters.
Overall, I would give Torq a score of nine out of ten. I think it is fantastic. There are some headaches that come with the platform, and the case management part does have issues, but as a SOAR platform, I think it is fantastic. I give Torq a rating of nine out of ten.
Automation has reduced response times and now improves service management for happy clients
What is our primary use case?
My main use case for Torq is for managing IT services and providing faster response.
How has it helped my organization?
One of the workflows I manage with Torq looks good and provides faster response, saving time and resulting in happy clients.
Torq has not changed the day-to-day experience for my security analysts; they are doing their job quickly and effectively, saving time for other organizations.
The measurable security outcomes that matter most to my leadership team include Torq helping to show real SOC impact through effective team management.
It delivered immediate value after I started using it.
What is most valuable?
In my experience, the best features Torq offers include IT enterprises data management and data transformation; everything is excellent.
Regarding Torq's AI capabilities, I find its governance and security are secure, and the AI data governance security is very good.
In terms of accuracy and reliability of output, I find that Torq has very good accuracy and reliability.
Torq's unified platform approach to AI SOC automation and case management is good; security points are secure, and data is safe with my organization.
I have used Torq to automate triage, investigation, and remediation actions across multiple attack surfaces, finding that it performs very well and provides faster response with good latency, saving time compared to other tools.
My experience with Torq's generative AI in terms of increasing alert handling capacity for my SecOps staff is good.
What needs improvement?
What has not worked as well as I hoped with Torq is related to product data management and storing data, although it still provides faster response and saves time.
I think Torq is a good product as it is.
For how long have I used the solution?
I have been using Torq for the past year.
What do I think about the stability of the solution?
I find Torq to be stable.
What do I think about the scalability of the solution?
The scalability of Torq is very good.
How are customer service and support?
Currently, we do not have any challenges in our SOC; if we face any, we contact customer support, and they help very effectively.
Customer support is also excellent.
I would rate customer support a 10.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
What was our ROI?
I have seen a return on investment, including money saved, time saved, and fewer employees needed.
What's my experience with pricing, setup cost, and licensing?
I purchased Torq through AWS Marketplace.
My experience with pricing, setup cost, and licensing is also good.
Which other solutions did I evaluate?
We have not evaluated any other option before choosing Torq.
What other advice do I have?
I would rate Torq a 10 on a scale of 1 to 10.
I chose this rating because customer service is excellent.
I suggest to others looking into using Torq that it provides a positive response, and I recommend they use it as it is a good product that saves time and leads to happy clients.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Agentic Hyperautomation That Slashes Alert Fatigue—No Fragile Code Needed
Enables IT to Handle Triggers and Alerts with Ease
Automation has transformed incident triage and investigation while freeing analysts for deeper work
What is our primary use case?
My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs.
A main example of how I use Torq for automation would be a classic one: opening of a security incident in an ITSM, bidirectional synchronization, enrichment, and auto-remediation based on closure of the incident. Everything is automated.
I use Torq for automation of triage, investigation, and remediation actions across multiple attack surfaces such as endpoint, identity, cloud, or IT. It automates the investigation with enrichment such as logs. I do not dive deeper into remediation actions, but they are present, and it automates triage, for example, for phishing incidents. It helps tremendously to have those kinds of data. Its abilities compared to other tools were evaluated through an RFP where we compared multiple tools, and Torq was literally the one, the outsider that stood out, and we chose it. As a technical team, we chose Torq compared to the one that we were using before. We did not start from scratch, as we already had a baseline, and we were searching for a tool that would bring something new to the table with the already existing technical tools that we had, but would bring new innovation and new capabilities. That was the objective, and Torq answered that.
What is most valuable?
One of the best features of Torq, I would highlight two main ones. The first one is the capability of transforming an action that you develop yourself, such as an HTTP request that you develop yourself, and make it available as a custom action to all of the other members of the team that you have, which in a sense increases the scalability of the tool and lets the tool be available for people that don't really know the specifics of APIs, HTTP requests, and just know how to click and drop some actions and want to do their small playbooks. Torq is, in a sense, a tool that is ever-evolving based on the usage that you do with it.
The second one is the look and feel is quite good, and it would be all the AI initiatives that are inside the tool. I can feel that Torq and the company that is behind it are pushing forward what SOAR is, not letting it stale in its current state, and they're pushing it further to make SOAR a new tool in itself by leveraging AI, making it the center of what a SOC is and what incident response is.
The custom action feature in Torq has helped my team tremendously. For example, SharePoint HTTP requests were quite difficult in one of our scenarios. You only have to do the job once of scraping the documentation, understanding how it works, developing the HTTP request by yourself, and then you can save them, put a meaningful description, and add some dynamic fields that the next person that will use that will find much easier than understanding how the logic is and how the documentation is. For the SharePoint example, it has helped tremendously to deliver automation quickly around SharePoint, CSV file upload, and other related tasks.
Torq has impacted my organization positively by allowing us to earn time and invest resources in other projects that are more meaningful and more interesting, pushing deeper into what a SOC is, and building our processes. Torq is a good way to reinvest time in something more interesting, whether for the humans, for the analysts, or for the company in a more secure way. This is what automation brings: interesting subject matter, new capabilities, and more time, fundamentally.
It is quite difficult to quantify, but a good example would be a playbook that is automatically analyzing a phishing incident developed with Torq. It frees up approximately 200 or 250 incidents per week or per month. You take one incident, which took about five minutes to ten minutes, and multiply that across all incidents. The human cost is also significant, such as the fatigue of doing always the same incident, always the same things. This is not easily measurable, but I think it is important to highlight that as it may sometimes be the best resource, the best gain that Torq can bring to the table.
What needs improvement?
There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other areas that can be improved. There are some ideas, and Torq always takes them into consideration. Unfortunately, they are currently focused too much on AI and how the tool is evolving. I can understand because this is how they can keep their head above the water and ahead of all the other tools. This is how they can be this disruptive and interesting for companies. However, it is also important to have some good bases, some solid baselines. There are some issues and bugs that I think need to be fixed, but they are currently not focused on it. The tool is working overall. It is doing what we need. No tool can be perfect, and there is room for improvement, but Torq is already quite far advanced compared to others in the market.
One of the things that I think would be the most interesting for Torq is the ability, when you are debugging, when you have a crash in a playbook, to rerun the playbook from the step that has crashed. This is not implemented, and it is painful to relaunch a playbook manually and do everything when you have actions inside a playbook that have impact. For example, if you reset the token of a user and then the playbook crashes, and it was supposed to send a notification in Teams or add the user to a specific table, just to have the information, you want to have this information, but you don't want to relaunch the whole playbook because it will reset the token of the user again. This is an example where it is quite important, but the feature is lacking.
For how long have I used the solution?
I have been using Torq for approximately one year to a year and a half.
What do I think about the stability of the solution?
Torq is stable.
What do I think about the scalability of the solution?
The scalability of Torq is quite good. The customer support is quite responsive and helpful. Most cases are handled in less than a week.
How are customer service and support?
I would rate the customer support a four. They are present and help a lot.
Which solution did I use previously and why did I switch?
I previously used Logic App from Microsoft. The two main pain points were the number of connectors available with built-in actions. We needed to redevelop every HTTP request every time that we started to create a new playbook. Scalability was not present in that case. Additionally, the tool was quite stale. It did not move a lot in the last year. It has started to move a bit now, but when we were doing the RFP and thinking of changing, we wanted a tool that has a roadmap, innovation, and people that were working on it.
What's my experience with pricing, setup cost, and licensing?
Pricing is pretty straightforward and adaptable based on what you need and what you want to use. The pricing is based on the number of playbooks that you have, which makes it interesting based on how you design your SOC's architecture and makes you spend more time on how you want to design your automation SOCs.
What other advice do I have?
Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with the tool and understand how JQ works, how the sprig function works, and not diving directly into automation without being sure that your processes and what you want to automate have already been tested out and are a good return on investment for the time that your SOAR team will spend on it. I would rate this review as an 8 out of 10.
Automation has transformed incident response workflows and still needs a more mature visual interface
What is our primary use case?
My main use case for Torq is enterprise automation, focusing on the cybersecurity application to support security automation and orchestration as well as case management.
For example, we have Splunk which aggregates the logs and generates high-fidelity alerts. With Torq automation, we automate the process to poll for the alerts, enrich all the alerts, and build workflows for the security teams, including security operations, the SOC, and incident response, to quickly investigate the alerts. The automation then determines the maliciousness of the alerts and progresses through all other stages of the case life cycle.
At this point, we primarily focus on cybersecurity for incident response as well as internal insider risk automation, which is our main use case for Torq.
What is most valuable?
The best feature of Torq is the ease of developing workflows. It has templates, and visually, it is very easy to build the steps, called automation steps. It is easy to debug, as you can see the input and output, making it very clear where issues occur, allowing for quick fixes. This is the best feature I see compared to command line options.
The impact of Torq on my team's efficiency is significant because with compiled code, you go through the whole cycle, and it takes a long time to figure out bugs. With Torq automation, every step is a container, clearly defining the input and output, which significantly speeds up the debugging process. It helps us produce workflows quickly, and we can also quickly respond to issues and fix them.
Additionally, Torq integrates with many other technologies very easily, making integration reusable.
What needs improvement?
Regarding improvements for Torq, there is definitely work still to be done to mature it. The biggest thing I think is the GUI. If you want to build a full-fledged workflow with the visual interface, it is not as fully functional as other counterparts. Currently, if you want to build a screen and then have a pop-up and then go back, it is not possible. It is just one way instead of having a mature UI component. Some work needs to be done to make UI development easier and more mature.
For documentation, I think Torq has good documentation, but it occasionally needs updates, as some parts are outdated. In general, their documentation is sufficient. For integration, it is not always smooth, but generally, it goes well. However, we did encounter some problems with custom steps, which definitely affected our progress, and the speed of bug fixes is also a bit slower than expected.
For how long have I used the solution?
I have been using Torq for more than a year.
What do I think about the stability of the solution?
Torq is relatively stable, though not always, but stable enough.
What do I think about the scalability of the solution?
So far, Torq's scalability appears good, but we still need to see how it holds up over time.
How are customer service and support?
The customer support for Torq is a little above average, though not super excellent.
Which solution did I use previously and why did I switch?
Previously, we were using IBM QRadar, which is a legacy three-tier on-premises solution. We switched to the cloud-based automation system that also has AI capabilities, as it offers a new generation tool that leverages AI.
The specific challenges in our SOC that led us to consider changes before implementing Torq included the legacy SOAR product from IBM, which is very hard to maintain and troubleshoot. People felt that an AI-enabled new product would be better.
Before choosing Torq, we evaluated Swimlane as well.
How was the initial setup?
We just started to operationalize Torq, and we have just gone into production. It is definitely well-received by the security operation team, who appreciate the neat GUI and what they see. I believe they think it is better than the legacy SOAR product we had.
What was our ROI?
We have seen a return on investment regarding time saved. It used to take us weeks to develop a workflow, but now it can be done in days or even hours. We have a two-person team, and we are accomplishing the workload of five people.
It took about half a year to realize value with Torq.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing is that it could be clearer, especially related to the AI aspects, which seem a bit fuzzy. The licensing and cost for the AI agent are not easy to understand, and I hope it becomes clearer once we start to use it more actively.
What other advice do I have?
In this early stage, they are able to capture the metrics they want, such as MTTD and MTTR. It is very clear from the case life cycle to have those metrics, and they like what they see.
SOC has good potential, and for integration, we still need to see how HyperSOC can manage multiple point solutions. We have a very complex environment, but I think we are moving in a good direction as we have started to integrate with Defender and other technologies like Splunk.
Torq has definitely changed the day-to-day experience for our security analysts, as they feel more excited and feel that Torq interface and workflow allow them to build things themselves. They think it is a better product than the legacy product.
We have started to build workflows in Torq to triage, analyze, and contain incidents, including enrichment and integration of intelligence into the workflow. I find it a very good framework for integration compared to completely in-house built tools, as it is easier to maintain due to its vendor components and appears scalable.
What matters most to our leadership team is risk reduction through automation and using the automation system to amplify efficiency, allowing us to do more with fewer people, along with leveraging some AI agent capabilities. Torq has helped us show real SOC impact in this regard.
Regarding Torq's AI capabilities, I note they do have guardrails. I have not fully explored its AI capabilities, except for playing around with Socrate, which appears to have a triage agent. I still need more time to explore it, but the potential is there. Socrate can automatically summarize the case information; we just need more time to actually use it.
So far, the AI agent from Socrate seems good enough in terms of accuracy and reliability of output. It is a generalized AI agent, and for other capabilities, we have not tried them, so I cannot comment.
We have not started to use Torq's agentic AI capabilities yet, but we are definitely looking into it, hoping it will provide additional resources for our operations.
My advice for others looking into using Torq is that those who are capable of developing will be able to utilize its features to leverage Torq platform effectively. I would rate this product a 7.5 out of 10.
Automation and ai integration have transformed incident response and reduced alert fatigue
What is our primary use case?
My main use case for Torq is reviewing the incidents and responding to them. After that, I investigate them and take appropriate actions.
For example, a user has logged in from a blacklisted country and it triggers an alert. I investigate the alert and contact the user through Torq.
Another use case is when an IP from my client side has tried to connect to an external IP which is malicious. It may also trigger an alert, and if at the firewall it's not blocked, the action is not blocked. So that may trigger an alert and I will have to do further investigation and complete the required action.
What is most valuable?
Torq offers the best feature through integration with AI. I can use AI alongside Torq.
AI helps me add work notes, resolve notes, and also assists in the investigation and checking of IPs, IP reputation, and more. AI helps me accomplish all of these things.
Torq has minimized the alert fatigue and also reduced the time I need to work on the alerts. Runbooks are present for each use case that helps eliminate other tasks such as going through all of the alerts manually.
The automation Torq provided for some use cases removed the false positives, which saved me time. The number of alerts is reduced after fine-tuning the false positives.
Torq has changed my approach in many ways. It reduced the manual tasks and also helped me in resolving high volume alerts. I also work on the malware alerts more efficiently through Torq.
Torq's ability to solve an operational security issue is commendable. It meets all the compliances and also helps me resolve threats. I also use runbooks to contain malware.
What needs improvement?
Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I don't have to code for everything.
Torq could add API dependency and also on-premise connectivity. If on-premise connectivity is available, organizations wanting to work on Torq could implement it that way.
For how long have I used the solution?
I have been using Torq for three months now.
What do I think about the stability of the solution?
Torq is very stable.
What do I think about the scalability of the solution?
Regarding the scalability of Torq, I need to consider the elasticity as well. Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.
How are customer service and support?
I haven't had any issues using Torq so far, so I haven't contacted customer support. That is why I cannot comment on that.
Which solution did I use previously and why did I switch?
I used Splunk and I wanted to work on a different tool with more enhanced features. That is why I switched to Torq.
What was our ROI?
The standardized processes helped me guarantee identical incident response every time.
Torq fortified my workflows and secured my cloud infrastructure.
What's my experience with pricing, setup cost, and licensing?
I am the end user. I don't have knowledge about pricing, setup cost, or licensing.
Which other solutions did I evaluate?
I also evaluated Azure Sentinel and QRadar. Those are the two options I evaluated before choosing Torq.
What other advice do I have?
I would definitely recommend others to use Torq as it is an all-rounder tool which even integrates AI. As we all know, it is the era of AI users, so we have to integrate AI into every tool. Torq is best suited for all the SOC analysts.
Torq is a very scalable, elastic tool and also throttles integration of the tools, drops events, and creates message processing backlogs. It also shares back-end resources, so it is a good tool overall. I give Torq a rating of eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Automation has transformed incident investigations and now simplifies alert triage and response
What is our primary use case?
My main use case for Torq is to automate security incidents. By using Socrates CI, I am able to automate the investigation steps with the runbook and integrate other devices to forward their logs, customizing recording coordinates and parsing with jq.
A recent scenario where I used Torq involved integrating Elasticsearch with Torq to forward the entire log from Elasticsearch to Torq, where I wrote a runbook for the investigation. For example, there is an RDP to the internet use case requiring ten to fifteen steps to investigate the incident. With Torq and Socrates, I automate everything to reach the final outcome.
I have used Torq to automate triage, investigations, and remediation actions across multiple attack surfaces. It performs better than other tools because of its extensive integration capabilities and customizable features, allowing me to tailor responses according to my needs.
I primarily utilize Torq for investigation and alert automation, and I do not have any other business relationships with the vendor.
What is most valuable?
I find Torq very helpful from an automation point of view, with customizable suite features that allow me to customize according to my needs. Initially, developing workflows was complex due to the numerous customization options available, but with Torq's support, I can successfully do that. I also utilize the available templates in Torq as a guideline for developing workflows based on these templates.
Torq offers features like the shocker rates, allowing me to give prompts to the procreate, which investigates each alert according to my defined handbook—a feature I really appreciate. Additionally, I can integrate any third-party tool to Torq using the webhook connector and Torq's default connectors, which is another excellent feature I appreciate.
The Socrates feature is a basic AI model that I develop according to my needs and offer some context in the Socrates tool. I write runbooks and provide prompts to automate the investigation steps using Socrates, which connects every tool and software to enrich the data I need. This feature significantly aids my daily activities, especially since it automates many tasks previously performed by manual analysts. Currently, I am using the WayBook connector and Torq's default connector to integrate third-party tools with Torq, along with various tools like Elasticsearch.
I appreciate Torq's GUI interface, which is easy for every analyst to understand. Additionally, the dashboard features enable monitoring spikes, device integrations, and device statuses according to my needs, allowing me to develop comprehensive visualizations for alerts. Recently introduced migration features in the GUI add value by showing connected tools to my endpoints and assisting my investigation processes, which I find beneficial.
What needs improvement?
To improve Torq, I suggest that known alerts and attacks in the market should lead to developed use cases and workflows. Implementing these would help map known traits automatically when integrating third-party tools and require minimal credential configurations. Having examples of steps to investigate specific alerts would assist in developing other cases effectively.
Torq provides comprehensive support, and I find their documentation useful for addressing challenges in my workflows. Walking through the documentation available on Torq's website gives me clarity on solving issues. If Torq could enhance its AI features, it would benefit customers significantly by making the platform even more user-friendly.
For how long have I used the solution?
I have been using Torq for the last one to two years.
What do I think about the stability of the solution?
Torq is stable and functions reliably within my operations.
What do I think about the scalability of the solution?
Torq's scalability is highly effective, allowing me to customize features according to my specific requirements.
How are customer service and support?
Torq provides comprehensive support, and I find their documentation useful for addressing challenges in my workflows. Walking through the documentation available on Torq's website gives me clarity on solving issues. If Torq could enhance its AI features, it would benefit customers significantly by making the platform even more user-friendly.
Customer support is very good, available twenty-four seven, offering quick resolutions through group chats or calls.
Which solution did I use previously and why did I switch?
My experience managing various point solutions was complicated compared to using Torq's unified platform approach for AI SOC automation and case management.
Before Torq, using separate security platforms posed challenges in enabling log forwarding and investigating alerts efficiently with manual documentation. With Torq, I automate actions while achieving SLA compliance and streamline alert investigation processes much better.
What was our ROI?
I started realizing value with Torq right away; the benefits became apparent immediately as I transitioned to automation.
I have seen a return on investment with Torq, as the automation reduces the number of employees needed and significantly saves both time and resources.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Torq, as my focus remains on employing Torq as my solution.
What other advice do I have?
I would rate Torq a perfect ten on a scale of one to ten.
I chose ten because Torq meets all my expectations, providing support for any challenges I face during workflow, integration, and runbook development. They also have comprehensive documentation for knowledge sharing, along with Torq Academy, which offers multiple certifications to help users understand how Torq features work, especially the SOC analyst certification for beginners.
While comparing various AI outputs, I find that accuracy is not always one hundred percent, but it reaches about eighty percent with precise prompts. Accuracy depends significantly on the clarity of prompts given to Torq's AI, with good prompts yielding better responses.
The effect of using Torq's Agentic AI on stress levels and focus is positive, as it automates procedures, allowing staff to follow predefined protocols without additional manual effort.
Metrics that matter most to my leadership team include investigating every alert and resolving issues as per defined parameters. Automation from Torq helps us show real SOC impact through efficient handling and timely responses.
Before using Torq, I relied on manual investigation steps detailed in my playbook for alerts. Now, with Torq, I automate procedures through a defined software model, allowing runbooks to handle alerts effectively. When an alert is triggered in Elasticsearch, it forwards to Torq, which follows the runbooks I have set up for each alert. If additional actions are required, it sends alerts and notifications, categorizing legitimate alerts and closing them automatically at both Torq and Elasticsearch levels.
I can monitor alert severity and manage how many alerts I have based on this metric, which is a positive impact since investigating alerts efficiently was challenging during manual processes. I can now see how many alerts are pending and their severity levels, contributing to meeting my SLA and TRA requirements.
Torq significantly changes day-to-day experiences for security analysts by automating alert handling and reducing overall workload, thus improving job satisfaction and operational efficiency.
Torq's Agentic AI significantly increases the alert handling capacity for my SecOps staff, streamlining their responsibilities and ensuring they manage alerts effectively. I would rate this product ten out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
AI-driven automation has transformed incident response speed and boosted analyst confidence
What is our primary use case?
For Torq, first of all, it's a hyperautomation and AI assistant usage. Our EDR SentinelOne is integrated in Torq and besides the vendor itself having hyperautomation abilities, Torq helps me to analyze incidents and to respond to incidents more quickly and more efficiently.
Torq's AI SOC automation case management is much faster and more efficient compared to the manual tools I have used before. Torq is an ideal assistant for AI SOC in automation challenges.
Torq changed the day-to-day experience for my security analysts. They are more confident and can test more approaches in the security operation center every day as workflows and routine.
What is most valuable?
I rely on Torq's AI assistant in most of my incident response and in building right and less complex workflows for automation.
Torq helped me also in some infrastructure and ticketing challenges, for example, to organize the ticketing system in our company, but I am still in a process of learning about Torq and realizing different scenarios using Torq.
The most valuable feature of Torq is hyperautomation and AI assistant because the quality of speed and recommendation from the AI assistant is really high. Another outstanding feature is that you don't need to write code. There is a library of prepared scripts or JSON scripts which can be right and adapted. You can face quite complex challenges without a programming background and can successfully solve these issues and challenges.
Torq's no-code library helps me to be more efficient and respond to incidents more flexibly. The support of the AI assistant makes my actions more efficient and quicker.
What needs improvement?
The only thing is more out-of-the-box integrations. Torq already has a lot of supported integrations and adding new ones is not difficult, but for some customers, it's easier to have a plug and play interface to start onboarding.
We didn't evaluate other options because we tested Torq and we liked it.
At this stage, I have no additional suggestions. I will update my review several months later and maybe then I will have some suggestions to prove and to what in addition I would like to see in the solution.
I can't evaluate Torq's agentic AI, but I think in my next review, I can provide more information.
For how long have I used the solution?
I have been using Torq for the last six months.
What do I think about the stability of the solution?
I haven't experienced any downtime or technical issues while running the platform.
What do I think about the scalability of the solution?
Torq can handle growth and increase easily without any downtime or lack of service.
How are customer service and support?
Customer support is responsive and helpful, but most of my questions were more how-to questions.
Which solution did I use previously and why did I switch?
I used online SIEMs with integrated SOARs, not online but on-premises, and we switched because it was too slow and too inefficient to use.
How was the initial setup?
From my point of view, Torq has excellent documentation and a support portal. You can find literally everything on the support portal. There are visual manuals and quite simple instructions for onboarding and for every use case you can imagine in your infrastructure.
My advice would be to test Torq in your environment, ask as many questions as possible during POC and refer to documentation in cases you feel not confident about your new solution.
What about the implementation team?
At this stage, we are just customers of Torq.
What was our ROI?
Regarding Torq's pricing and license costs, as long as our existing team started to work more efficiently and quicker, I think we have quite a return of investment and we suppose to add more security management center tools. The return of investment is also the money we saved not adding another security tool. For me and for our security stack, it's about 30% return on investment.
What's my experience with pricing, setup cost, and licensing?
Torq is a standalone solution from Torq providers.
Which other solutions did I evaluate?
We didn't evaluate other options because we tested Torq and we liked it.
What other advice do I have?
I think I have told everything about Torq that I can share at this stage, but I am still in the process of learning the platform and I still think that there are many more features which can be adapted and can be used inside the company.
According to positive outcomes, Torq reduced manual work and made incident response more efficient. From Torq workflows, I learn much more about my company ecosystem. This also reflects on the defensive side of the company. I see the gaps that I had according to incidents and I can fix and address the gaps relying on knowledge I get from automation results.
I think the speed of work increased minimum by 50%, but I think with more automation and more optimization, we can make this result much better.
The easiness of integration, good quality of support and good quality of documentation make this product easy to work with. From what I see, the vendor itself is oriented on improvement, which means that they will not stop at the level they reached by now.
I am quite confident in Torq because I have checked, for example, compliance to ISO 27001 and this is the most relevant standard here in Georgia. I trust in Torq and I trust in the security compliance the platform provides.
Torq's AI recommendations are consistently helpful. There was no case when the system provided me with a false recommendation or inaccurate response.
Alert fatigue is something I would like Torq to help me address.
My overall rating for this review is 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Automation has streamlined incident handling and AI now summarizes and responds to threats
What is our primary use case?
My main use case for Torq is to handle the correct cases using it as a SOAR platform. We have created a work plan and we've used Torq as a SOAR platform to handle the incidents from start to closure.
What is most valuable?
In my opinion, the best features Torq offers are ease of navigation and good AI usage as Socrates. There are different stages of the incident when it comes into the queue, and we could easily navigate to the sections that we would want to update and work on. That is how it brings a lot of customization to the incidents navigation and all other stages of the incident. The good usage of AI is regarding Socrates, the AI that summarizes and can respond to the threats or the incidents on its own when it's assigned to the incident. Those are two of the strongest points of Torq.
Torq is good in the reporting structure and showing metrics to the leadership. I think Torq plays a good role in that sense.
What needs improvement?
Torq can probably use more ML and look at what can be closed and what cannot be closed in terms of data classification. In terms of auto closure of incidents, it can do better when it uses ML. I choose that number because it's a great SOAR tool. It's not one of those existing SOAR platforms or just a pure SOAR. It has good incident handling, good UI, and a good user-friendly environment, but it can also improve its automation workbooks, work plans, and usage of ML to better cater to the market or consumers.
For how long have I used the solution?
I have used Torq for five months.
What do I think about the stability of the solution?
I did not see it buffer, take a lot of time to load, or be unresponsive. I haven't seen those issues in Torq. I think that's a good experience.
What do I think about the scalability of the solution?
If scalability is rated out of ten, I would rate it seven out of ten.
Which solution did I use previously and why did I switch?
It was Demisto XSOAR, and we shifted because we needed a more user-friendly SOAR platform.
How was the initial setup?
I would just make sure to replace the old or the previous solution with Torq point by point. If that is good, I think everything else will be taken care of.
What about the implementation team?
We were just consumers.
What was our ROI?
I can share the time saved from my work alone and cannot disclose or specify any other employees. I saved nearly roughly about ten hours of my time while I was working in Torq because it's much better than the previous tool.
Which other solutions did I evaluate?
I have heard Hyper Automate is pretty user-friendly and has less coding compared to other leaders in the market or other players in the market. Its drag and drop tasks or work plan building is what I heard.
What other advice do I have?
We have seen fewer failures of automations from the time Torq came into the picture. We've had a more streamlined process of handling incidents, and at the same time, we've learned to embed the AI into our incident types, and that is how it has helped us in the automation. I think Torq can really integrate other tools within the case management platform, and it can make the work a little more efficient. I would rate this review eight out of ten.