No more typing reviews! Try our Samantha, our new voice AI agent.
Alon Barazani - PeerSpot reviewer
SOC Analyst at AppsFlyer
Real User
Top 5
Mar 16, 2026
Automation has transformed daily alert handling and now frees hours for deeper security work
Pros and Cons
  • "Since we started working with Torq, I am handling much fewer alerts, it is becoming really easy for me to handle an alert, I have all the information that I need, I do not need to connect to different vendors to receive this information, and the main thing I got from Torq is time, which now helps me to build another automated system and learn."
  • "We have MCP that we are working with our cloud security platform, and we wanted to connect this MCP to the case management."

What is our primary use case?

I use Torq as my case management and alert system. Working as a SOC analyst, the first thing I do every morning is get into Torq, review all the open cases and incidents, understand their severity, investigate them, and close them if they are legitimate. I also investigate whether there is anything malicious. I use Torq daily.

We build workflows inside Torq—automations that can automate every action that we do manually. For example, we send Slack messages to users who we think shared corporate data, or investigate specific machines where we suspect there is some sort of SQL injection. We can automate every type of security-related incident through the workflows in Torq.

What is most valuable?

All the workflows are something really particular. From what I have seen in the past, I have never seen this maturity of automated processes, and the whole idea of drag and drop automation is really simple. This is something I have never seen before. Even with our previous vendor, we did not have this type of maturity. We needed to manually create our own tasks, and it took much longer than what we are doing with Torq.

AI is helping us summarize security alerts. The first thing I do in the morning is get into cases and review all the open cases and incidents. The first thing I see is the AI summary, and it is already telling me all the details that I need to know. Of course, we configured it so that all the relevant details appear in the AI summary, but I almost never need to check the actual details in the logs of the case because I have this summary. On the workflow aspect, I have created multiple tasks that work with AI. For example, I summarize some sort of log and extract only the relevant data from it. I created an agent that can automate processes and make manual API calls to review and collect data that I need for some specific alerts. Recently, they upgraded the Hyperagents and added many automated processes that I am looking forward to using. For example, they created a prompt that can help analyze JSON, which is really good for me because I needed to use it and looked for something like this. They have an option to output from an LLM as JSON, which also really helped me. I am using it on a daily basis.

In the previous system, we were not happy with it. We saw that there were many processes we needed to do manually, while there are options around the market that can help us do those processes automatically. For example, for collecting data, we needed to create the HTTP request ourselves, while in Torq, there are already multiple custom-made tasks that collect the API data themselves, and we do not need to build the whole HTTP request. We looked for a way to save time and automate processes, and Torq really answered those questions.

What needs improvement?

This is exactly what we discussed two days ago with the Torq team. We told them where we want to see improvements. For example, we have MCP that we are working with our cloud security platform, and we wanted to connect this MCP to the case management. When I go inside a case, I want to have a search bar where I can search details about my cloud and everything in my cloud, details about the specific vendors of the alert, not only the alert itself. Currently, we have a search bar for the alert itself, but we do not have a search bar for the connectors. This is one place for improvement.

We already talked about some filtering that they can add. They have a dashboard case dashboard, which is a separate page from the cases itself. We thought about adding a specific widget to the cases page so that we can see statistics inside the cases page. However, there were a few things before that we wanted them to work on, and they have already solved them. For example, we wanted to implement Torq to have access only within our VPN, and as far as I know, they worked on it. A month ago, it succeeded, and we are currently only connecting inside of the VPN.

For how long have I used the solution?

I have been using Torq for the past four to five months.

Buyer's Guide
Torq
August 2026
Learn what your peers think about Torq. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.

What do I think about the stability of the solution?

As far as I know for now, I have never seen any message from them that there is maintenance and we need to wait or something like that.

What do I think about the scalability of the solution?

I would rate scalability about nine.

How are customer service and support?

I would rate customer service nine.

Which solution did I use previously and why did I switch?

Our previous solution was Cortex. When we reviewed multiple SOAR solutions, we saw that all the new SOAR companies are doing basically the same thing. We then looked for the specific company that could help us automate and create automated processes with the most mature solution. Torq really answered those questions and really helped us with it. When we started the process and began working with Torq and seeing all the system, we saw that it became really easy to create a workflow. I do not need to think too much. I know I have many drag and drop tasks that can automate a process, which I could have done manually for months.

How was the initial setup?

The setup was easy. All of our security operations team got into Torq and started working on workflows in parallel, which made the entire onboarding process really easier. Something that should have taken half a year took two to three months, and then we finished everything and migrated everything.

What about the implementation team?

Only our teams implemented Torq.

What was our ROI?

The main thing that I got when we started working with Torq is time. I used to have much more time to review alerts, and most of the alerts were manually closed rather than automatically closed. I had most of my day investigating alerts and solving them. A huge part of them are false positives and things that are legitimate and just need a quick check or sending a message.

Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert. I have all the information that I need. I do not need to connect to different vendors to receive this information. The main thing I got from Torq is time, and this free time helps me to build another automated system, learn, and there is no need to explain what time is and how important it is.

I used to spend something like three to four hours each day working on cases. Now when we are working in Torq, in the first hour and a half to two hours, I am solving all the cases and the open cases, and I am free to do whatever I need.

What's my experience with pricing, setup cost, and licensing?

Unfortunately, I am not aware of the pricing itself. This is something that my manager would be able to answer, but I am not aware of the price.

What other advice do I have?

I would definitely recommend Torq. I have no doubt, really. When we looked for another vendor, Torq really answered all our questions. It really helps us to receive the best solution for our SOAR.

We already connected Torq with our EDR, SIM logs, and DLP systems. When we connected it, the whole idea of Torq was collecting all the data to a specific place. We created alerts in the SIM and then automatically sent them to Torq. We do not handle the alerts in the SIM, only on Torq. When we collected the data from all the vendors, it is really easy when everything is in one place. We have everything in Torq, and then we do not need to connect to each system to review all the data.

I believe we looked for a maturity that they did not have at first, but right now I can see and tell that they have this maturity, and we are going to use the Agentic AI. It used to be like a six, and right now it seems like an eight, maybe nine even when we review it. I would rate this review an eight overall.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Mar 16, 2026
Flag as inappropriate
PeerSpot user
reviewer2802333 - PeerSpot reviewer
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Real User
Top 20
Feb 18, 2026
Automation has transformed security operations and streamlines complex incident triage
Pros and Cons
  • "Any request that comes in, regardless of how complex it is, I can accomplish it with Torq."
  • "Regarding the pricing of Torq, I would say it is expensive."

What is our primary use case?

My use case for Torq encompasses all aspects of security automation. I utilize it for running automation for the security department, not all departments in my organization, but mainly for the security department.

I use it for operations automation, where I automate some of the operations processes. I also use it for a SOC platform, as I get all of my security incidents into Torq and prioritize and escalate to the relevant person to review and take response actions automatically.

How has it helped my organization?

reduced MTTD MTTR MTTE

What is most valuable?

The best features in Torq make it feel versatile and comprehensive. I can do everything with Torq. If something is not possible through out-of-the-box integration between two vendors, I can put Torq in the middle of the process and Torq will help me connect systems together, automate the entire process, and automate data flows, prioritization, and data manipulation.

Any request that comes in, regardless of how complex it is, I can accomplish it with Torq. If there are no direct integrations between two systems, Torq can always come in between them and automate the integration.

It has so many capabilities that I can connect everything by using APIs or HTTP requests or running scripts to automate the connection between systems. Regardless of how complex the things I would like to do with Torq are, I will always be able to do that. There is no such thing as not being able to do something with Torq; I will find a way to do that.

Agentic AI helps with alert handling by simplifying the process of parsing different data where data sources can change the schema of the data. It is really simple for me to do that with Torq and the Agentic AI; I do not need to keep track of everything and manage that manually in the automation, as the Agentic AI can do that for me.

Also, for the enrichment part, the Agentic AI can enrich all of my data straightforwardly with the right guardrails in place.

Regarding Torq's unified platform approach to AI SOC automation, I understand it is not a global feature yet, but they are working on one of the most critical features called Auto Triage. This feature would dramatically change the way AI SOC is provided to customers.

The AI can investigate cases or security incidents, and through their AI agents or engines, they can determine whether a case is a true positive benign, true positive malicious, or false positive. Based on this categorization, I can really reduce the amount of work that escalates for a human being to review and take action upon.

What needs improvement?

The areas that have room for improvement in Torq include the way cases or data can be presented and data manipulation in automation.

For how long have I used the solution?

My experience using Torq is about a year and a half, or even more than that, maybe two years.

What do I think about the stability of the solution?

I would rate Torq's product stability at eight, acknowledging that there are bugs, glitches, and downtimes.

What do I think about the scalability of the solution?

From a scalability perspective, I would rate Torq as a ten for my 30 people working globally.

How are customer service and support?

I would rate the vendor's technical support as an eight.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

When I decided to go with Torq, I did a POC with three other major players in the SOAR world. What I appreciated most about Torq is the simplicity to connect systems or to do things that are not available outside of the box.

If Torq does not provide a step or an action out of the box to do with a third-party system, I can simply and straightforwardly plug it into Torq by reviewing the third-party system documentation and do it on my own without a lot of complexity. It is easy and impressive.

How was the initial setup?

Torq is very easy to maintain.

What about the implementation team?

Regarding how often maintenance is required, I would say that the maintenance involves automation, not the platform itself. It is maintaining the things that I have built, so I would say maintenance occurs on a weekly basis.

What was our ROI?

In terms of return on investment, I think I have saved about one hundred fifty percent in time, resources, and money.

What's my experience with pricing, setup cost, and licensing?

Regarding the pricing of Torq, I would say it is expensive. All cyber solutions are expensive. When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.

Which other solutions did I evaluate?

The other vendors I looked at include Demisto Palo Alto and Tines, as well as Simplify, which is Google's Chronicle automation SOAR platform.

What other advice do I have?

I realized the value of Torq even within days. It was much easier and much simpler. Even on the demo call, I asked very specific questions because I knew the gaps that I had in other platforms.

In the demo call, I saw that they had solutions to all of my pain points, so I knew from the beginning that it was going to be a match. I do recommend this product.

My advice to others looking into implementing it would be to utilize their AI agents to help build things they do not know how to do. Their AI assistants and AI agents helped me accomplish many complex tasks with minimal effort. I would rate this product a nine overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Feb 18, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Torq
August 2026
Learn what your peers think about Torq. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.
reviewer2767650 - PeerSpot reviewer
Senior Consultant at a university with 10,001+ employees
MSP
Top 20
Oct 22, 2025
Have found automation to save analyst time but miss more accurate data classification
Pros and Cons
  • "As an analyst, it has demonstrated potential to reduce workforce requirements and time needed for related activities."
  • "It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet."

What is our primary use case?

I used Torq for conducting one of the proof of evaluations for a vendor we are connected with. I am currently working with Omnisoc, which provides SOC services for twenty-three other higher education institutions in the US. As part of vendor evaluations, we used Torq to differentiate between the manual workflow we had and the security automation provided with the Torq AI automation capability.

We have used it to differentiate between our manual workflow and the capability it brought us in creating playbooks for many of the detections we have had. In that scenario, although we are an education organization which deals with education-related logs, we should not have much exposure to the data held at different members. From our research and testing with the tool, we realized there have to be modifications and changes to train the LLM on the back end. It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet. It was unable to do that sort of classification. We concluded this tool would be more suitable for initial ticket management rather than security automation.

With the use of AI prompts, we were able to start with preparation of the tool through the last chain of niche, which is the remediation part. With the help of prompts, we were able to perform everything present on instant response plan.

How has it helped my organization?

As an analyst, it has demonstrated potential to reduce workforce requirements and time needed for related activities. This has been a significant improvement we have observed from our research with the tool.

What is most valuable?

As someone currently working as an analyst, I can say it has the potential to save significant time and manpower. The amount of workforce needed to perform Taiwan-related activities can be reduced. These are the major improvements we have seen from the research we have conducted with the tool.

What needs improvement?

From our research and testing with the tool, we determined there need to be modifications and changes to train the LLM on the back end. It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet. It was unable to do that sort of classification. We concluded this tool would be more suitable for initial ticket management rather than security automation.

Regarding data handling, I would give preference to Torq. For case management, Cortex and its dashboards prove more useful. Cortex and Palo's solutions do not have as much capability as Torq provides with the same tools. However, Torq's dashboards could be improved, especially on the case management side.

For how long have I used the solution?

I have been using the solution for the past four months.

How was the initial setup?

The platform team from our company handled the setup. They managed everything from product testing to deploying it to members. As SOC analysts, we only managed what we could do with the data present.

What about the implementation team?

The implementation was handled by a team of three people.

Which other solutions did I evaluate?

Regarding tools, OpenSearch is something I have examined, which is similar to Elasticsearch but provided by AWS. We are also planning to look at Fellows exam because we are seeking a partner who could provide both hardware and software capabilities. We wanted a vendor who could provide an all-in-one solution.

Elasticsearch and Splunk are the tools I have used most extensively. While I do not have direct experience with Sentinel's query language, I believe it is similar to the SPL used in Splunk.

What other advice do I have?

One of our members uses AWS, and we receive their feed. This involves triaging AWS-related logs. While I do not have direct work experience with it, I am familiar with AWS-related services and data-related logs, especially with cloud red logs.

I have conducted this evaluation for four months. Beyond that, I have experience with SIEM and vulnerability management. I have worked on integrations between our case management system and the incident management system in ServiceNow, which we moved to Torq.

I found it particularly intuitive to use, as my previous experience with no-code tools helped me adjust to this software more quickly than my peers. The solution could improve its notification capabilities on the member side, particularly in notifying multiple people.

Since working with the demo version of the product, most scenarios and testing data provided the required use cases and results we were seeking with Torq.

I rate Torq an 8 out of 10.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2798670 - PeerSpot reviewer
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Real User
Top 20
Jan 22, 2026
Automation has transformed security workflows and still needs improvements in support and features
Pros and Cons
  • "What I appreciate most about Torq is that it is an essential part of our system."
  • "Torq's unified platform approach to AI, SOAR, automation, and case management is superior compared to my experience managing multiple point solutions."
  • "The initial deployment of Torq was not easy."

What is our primary use case?

We utilize Torq as our central hyperautomation hub to bridge the gap between detection and remediation. Our primary use case involves ingesting alerts from our SIEM and Cloud Detection & Response (CDR) tools via webhooks. Once an alert is received, Torq triggers automated end-user interviews using HyperAgents to validate the activity. If confirmed, the system automatically generates Jira tickets for tracking. Beyond basic alerting, we use Torq to correlate high-fidelity threat intelligence from CrowdStrike and AWS GuardDuty, and to automate critical IT workflows such as user deprovisioning and group management.

We have used Torq to automate triage, investigation, and remediation actions across multiple attack surfaces including endpoint security, identity, and cloud. The initial deployment of Torq was straightforward.

What is most valuable?

Torq's Agentic AI has increased alert handling capability and capacity for our SecOps staff. Torq's unified platform approach to AI, SOAR, automation, and case management is superior compared to my experience managing multiple point solutions. Torq has changed the day-to-day experience for our security team.

What needs improvement?

There are areas where Torq could improve, and the solution does have some downsides that could be addressed.

For how long have I used the solution?

I have been using Torq for approximately three years.

What do I think about the stability of the solution?

Torq has maintained good stability. I have not experienced lagging, crashing, or downtime with the solution.

How are customer service and support?

Torq's support team is responsive with a speed rating of seven out of ten. The quality of their answers is satisfactory.

How would you rate customer service and support?

Positive

Which other solutions did I evaluate?

I have used alternatives to Torq.

What other advice do I have?

I would rate my overall experience with Torq as a eight out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jan 22, 2026
Flag as inappropriate
PeerSpot user
Hiten Nandasana - PeerSpot reviewer
Angular developer at Flourish software
Real User
Top 5Leaderboard
May 22, 2026
Automation platform has transformed user onboarding and manages daily workflows efficiently
Pros and Cons
  • "Almost four or five hours of work is now completed in four or five minutes."

    What is our primary use case?

    Initially, we were using Slack for small automations, such as creating pipelines or shutting down servers. For example, I could shut down one of our Angular services on one of our servers through a slash command in Slack. To automate this process, we migrated everything from Slack to Torq. Currently, we are in the migration phase, with most of it completed, though some portions are still pending.

    We use Torq for identity management. For identity purposes, we create user accounts and have a workflow that creates a user account, adds that user into Slack, and grants Git access. This workflow handles user additions, deletions, and modifications related to identity, and it is working very well.

    We are not using Torq extensively for security purposes, as we have limited use cases for security. However, we are using it for day-to-day activities and general automations, which are also working well.

    What is most valuable?

    Feature-wise, I appreciate the Torq UI because of its drag-and-drop functionality. Everything is drag-and-drop, and I can accomplish whatever I want to do directly without writing any code. In Slack, there are many things that require writing code and familiarity with automation tools, but Torq is no-code. This is very good compared to all other solutions I have seen.

    The workload has been reduced quite a bit. Initially, onboarding a new user would take four or five hours for one person to create a user account everywhere, remember everything, and follow Confluence documentation. After implementing Torq, we only need to provide the name, user ID, and email, submit it, and then it creates everything. Almost four or five hours of work is now completed in four or five minutes. This represents a very good time saving.

    What needs improvement?

    I do not dislike anything about Torq because it has satisfied all of our use cases and requirements. We contacted support as well, and support is very good. I believe everything is good now. However, one thing I can mention is that if Torq provided more templates on the development side, that would be beneficial.

    As of now, Torq satisfies our use cases. A template would be helpful for someone who does not know anything about Torq and is starting to use it for the first time. After conducting a POC on Torq, I can implement solutions without needing templates as much, but templates would serve as a reference for new users. For example, templates would show what is possible with Torq. We faced this issue when we were new to Torq. We were considering use cases but wondering whether they were possible with Torq. At that time, we asked support if it was possible, and they explained how to implement it. If there were default templates available, we could see the templates and understand what is possible and doable with Torq.

    For how long have I used the solution?

    I have used Torq for about one and a half year.

    What do I think about the stability of the solution?

    I have not faced any issues until now. Torq is working very well without any problems and no downtime. Whenever I access the Torq URL, it is working. This is very good.

    There is no downtime at all. We have been using Torq for one and a half years, but we have experienced no downtime.

    What do I think about the scalability of the solution?

    Torq is very scalable. Whenever we require any new use cases, we simply need to create a new workflow. If we need to update something, we can update the workflow as well. Torq is fully scalable.

    How are customer service and support?

    The support team is very quick. Within 24 hours, they will send an email or come on a call if something is critical. Support is provided within 24 hours.

    Which solution did I use previously and why did I switch?

    We used Slack previously. I do not have experience with other tools. We used only Slack. However, Slack is used primarily for chatting and communication purposes in all organizations. While Slack is not similar to Torq, we were able to accomplish our automation through it somehow.

    How was the initial setup?

    The initial deployment was very easy. I did not face any issues. We purchased a SaaS product that is cloud-based, so there were no issues at all. The process was very straightforward with simple steps.

    What about the implementation team?

    At least one or two people are needed. One to two people are enough for this. It is a one-time setup where we create workflows based on our use cases. However, if we want to add more workflows, we need some support. For that purpose, one or two people who know Torq are more than enough.

    What was our ROI?

    After we created a workflow and tested it, we started using it, and the return was immediate. After creating the workflow, we were immediately getting results.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is cheap. Although I did not purchase the product myself, my manager and others were discussing it. This is a very cheap product, and it is very helpful.

    What other advice do I have?

    I have been working for five years with experience in the IT field. Torq is very good. It manages everything. I would rate this product 10 out of 10.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: May 22, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2866401 - PeerSpot reviewer
    Senior security analyst at a manufacturing company with 10,001+ employees
    Real User
    Top 5Leaderboard
    Jun 30, 2026
    Automation has streamlined incident handling and AI now summarizes and responds to threats
    Pros and Cons
    • "We have seen fewer failures of automations from the time Torq came into the picture, we've had a more streamlined process of handling incidents, and at the same time, we've learned to embed the AI into our incident types, and that is how it has helped us in the automation."
    • "Torq can probably use more ML and look at what can be closed and what cannot be closed in terms of data classification."

    What is our primary use case?

    My main use case for Torq is to handle the correct cases using it as a SOAR platform. We have created a work plan and we've used Torq as a SOAR platform to handle the incidents from start to closure.

    What is most valuable?

    In my opinion, the best features Torq offers are ease of navigation and good AI usage as Socrates. There are different stages of the incident when it comes into the queue, and we could easily navigate to the sections that we would want to update and work on. That is how it brings a lot of customization to the incidents navigation and all other stages of the incident. The good usage of AI is regarding Socrates, the AI that summarizes and can respond to the threats or the incidents on its own when it's assigned to the incident. Those are two of the strongest points of Torq.

    Torq is good in the reporting structure and showing metrics to the leadership. I think Torq plays a good role in that sense.

    What needs improvement?

    Torq can probably use more ML and look at what can be closed and what cannot be closed in terms of data classification. In terms of auto closure of incidents, it can do better when it uses ML. I choose that number because it's a great SOAR tool. It's not one of those existing SOAR platforms or just a pure SOAR. It has good incident handling, good UI, and a good user-friendly environment, but it can also improve its automation workbooks, work plans, and usage of ML to better cater to the market or consumers.

    For how long have I used the solution?

    I have used Torq for five months.

    What do I think about the stability of the solution?

    I did not see it buffer, take a lot of time to load, or be unresponsive. I haven't seen those issues in Torq. I think that's a good experience.

    What do I think about the scalability of the solution?

    If scalability is rated out of ten, I would rate it seven out of ten.

    Which solution did I use previously and why did I switch?

    It was Demisto XSOAR, and we shifted because we needed a more user-friendly SOAR platform.

    How was the initial setup?

    I would just make sure to replace the old or the previous solution with Torq point by point. If that is good, I think everything else will be taken care of.

    What about the implementation team?

    We were just consumers.

    What was our ROI?

    I can share the time saved from my work alone and cannot disclose or specify any other employees. I saved nearly roughly about ten hours of my time while I was working in Torq because it's much better than the previous tool.

    Which other solutions did I evaluate?

    I have heard Hyper Automate is pretty user-friendly and has less coding compared to other leaders in the market or other players in the market. Its drag and drop tasks or work plan building is what I heard.

    What other advice do I have?

    We have seen fewer failures of automations from the time Torq came into the picture. We've had a more streamlined process of handling incidents, and at the same time, we've learned to embed the AI into our incident types, and that is how it has helped us in the automation. I think Torq can really integrate other tools within the case management platform, and it can make the work a little more efficient. I would rate this review eight out of ten.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jun 30, 2026
    Flag as inappropriate
    PeerSpot user
    Software Engineer at Accenture
    Real User
    Top 10
    Jul 26, 2026
    Automation and ai integration have transformed incident response and reduced alert fatigue
    Pros and Cons
    • "Torq offers the best feature through integration with AI."
    • "Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I don't have to code for everything."

    What is our primary use case?

    My main use case for Torq is reviewing the incidents and responding to them. After that, I investigate them and take appropriate actions.

    For example, a user has logged in from a blacklisted country and it triggers an alert. I investigate the alert and contact the user through Torq.

    Another use case is when an IP from my client side has tried to connect to an external IP which is malicious. It may also trigger an alert, and if at the firewall it's not blocked, the action is not blocked. So that may trigger an alert and I will have to do further investigation and complete the required action.

    What is most valuable?

    Torq offers the best feature through integration with AI. I can use AI alongside Torq.

    AI helps me add work notes, resolve notes, and also assists in the investigation and checking of IPs, IP reputation, and more. AI helps me accomplish all of these things.

    Torq has minimized the alert fatigue and also reduced the time I need to work on the alerts. Runbooks are present for each use case that helps eliminate other tasks such as going through all of the alerts manually.

    The automation Torq provided for some use cases removed the false positives, which saved me time. The number of alerts is reduced after fine-tuning the false positives.

    Torq has changed my approach in many ways. It reduced the manual tasks and also helped me in resolving high volume alerts. I also work on the malware alerts more efficiently through Torq.

    Torq's ability to solve an operational security issue is commendable. It meets all the compliances and also helps me resolve threats. I also use runbooks to contain malware.

    What needs improvement?

    Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I don't have to code for everything.

    Torq could add API dependency and also on-premise connectivity. If on-premise connectivity is available, organizations wanting to work on Torq could implement it that way.

    For how long have I used the solution?

    I have been using Torq for three months now.

    What do I think about the stability of the solution?

    Torq is very stable.

    What do I think about the scalability of the solution?

    Regarding the scalability of Torq, I need to consider the elasticity as well. Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.

    How are customer service and support?

    I haven't had any issues using Torq so far, so I haven't contacted customer support. That is why I cannot comment on that.

    Which solution did I use previously and why did I switch?

    I used Splunk and I wanted to work on a different tool with more enhanced features. That is why I switched to Torq.

    What was our ROI?

    The standardized processes helped me guarantee identical incident response every time.

    Torq fortified my workflows and secured my cloud infrastructure.

    What's my experience with pricing, setup cost, and licensing?

    I am the end user. I don't have knowledge about pricing, setup cost, or licensing.

    Which other solutions did I evaluate?

    I also evaluated Azure Sentinel and QRadar. Those are the two options I evaluated before choosing Torq.

    What other advice do I have?

    I would definitely recommend others to use Torq as it is an all-rounder tool which even integrates AI. As we all know, it is the era of AI users, so we have to integrate AI into every tool. Torq is best suited for all the SOC analysts.

    Torq is a very scalable, elastic tool and also throttles integration of the tools, drops events, and creates message processing backlogs. It also shares back-end resources, so it is a good tool overall. I give Torq a rating of eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 26, 2026
    Flag as inappropriate
    PeerSpot user
    Maiko Svanidze - PeerSpot reviewer
    Information Technology Lecturer at a educational organization with 51-200 employees
    Real User
    Top 5
    Jun 30, 2026
    AI-driven automation has transformed incident response speed and boosted analyst confidence
    Pros and Cons
    • "According to positive outcomes, Torq reduced manual work and made incident response more efficient."

      What is our primary use case?

      For Torq, first of all, it's a hyperautomation and AI assistant usage. Our EDR SentinelOne is integrated in Torq and besides the vendor itself having hyperautomation abilities, Torq helps me to analyze incidents and to respond to incidents more quickly and more efficiently.

      Torq's AI SOC automation case management is much faster and more efficient compared to the manual tools I have used before. Torq is an ideal assistant for AI SOC in automation challenges.

      Torq changed the day-to-day experience for my security analysts. They are more confident and can test more approaches in the security operation center every day as workflows and routine.

      What is most valuable?

      I rely on Torq's AI assistant in most of my incident response and in building right and less complex workflows for automation.

      Torq helped me also in some infrastructure and ticketing challenges, for example, to organize the ticketing system in our company, but I am still in a process of learning about Torq and realizing different scenarios using Torq.

      The most valuable feature of Torq is hyperautomation and AI assistant because the quality of speed and recommendation from the AI assistant is really high. Another outstanding feature is that you don't need to write code. There is a library of prepared scripts or JSON scripts which can be right and adapted. You can face quite complex challenges without a programming background and can successfully solve these issues and challenges.

      Torq's no-code library helps me to be more efficient and respond to incidents more flexibly. The support of the AI assistant makes my actions more efficient and quicker.

      What needs improvement?

      The only thing is more out-of-the-box integrations. Torq already has a lot of supported integrations and adding new ones is not difficult, but for some customers, it's easier to have a plug and play interface to start onboarding.

      We didn't evaluate other options because we tested Torq and we liked it.

      At this stage, I have no additional suggestions. I will update my review several months later and maybe then I will have some suggestions to prove and to what in addition I would like to see in the solution.

      I can't evaluate Torq's agentic AI, but I think in my next review, I can provide more information.

      For how long have I used the solution?

      I have been using Torq for the last six months.

      What do I think about the stability of the solution?

      I haven't experienced any downtime or technical issues while running the platform.

      What do I think about the scalability of the solution?

      Torq can handle growth and increase easily without any downtime or lack of service.

      How are customer service and support?

      Customer support is responsive and helpful, but most of my questions were more how-to questions.

      Which solution did I use previously and why did I switch?

      I used online SIEMs with integrated SOARs, not online but on-premises, and we switched because it was too slow and too inefficient to use.

      How was the initial setup?

      From my point of view, Torq has excellent documentation and a support portal. You can find literally everything on the support portal. There are visual manuals and quite simple instructions for onboarding and for every use case you can imagine in your infrastructure.

      My advice would be to test Torq in your environment, ask as many questions as possible during POC and refer to documentation in cases you feel not confident about your new solution.

      What about the implementation team?

      At this stage, we are just customers of Torq.

      What was our ROI?

      Regarding Torq's pricing and license costs, as long as our existing team started to work more efficiently and quicker, I think we have quite a return of investment and we suppose to add more security management center tools. The return of investment is also the money we saved not adding another security tool. For me and for our security stack, it's about 30% return on investment.

      What's my experience with pricing, setup cost, and licensing?

      Torq is a standalone solution from Torq providers.

      Which other solutions did I evaluate?

      We didn't evaluate other options because we tested Torq and we liked it.

      What other advice do I have?

      I think I have told everything about Torq that I can share at this stage, but I am still in the process of learning the platform and I still think that there are many more features which can be adapted and can be used inside the company.

      According to positive outcomes, Torq reduced manual work and made incident response more efficient. From Torq workflows, I learn much more about my company ecosystem. This also reflects on the defensive side of the company. I see the gaps that I had according to incidents and I can fix and address the gaps relying on knowledge I get from automation results.

      I think the speed of work increased minimum by 50%, but I think with more automation and more optimization, we can make this result much better.

      The easiness of integration, good quality of support and good quality of documentation make this product easy to work with. From what I see, the vendor itself is oriented on improvement, which means that they will not stop at the level they reached by now.

      I am quite confident in Torq because I have checked, for example, compliance to ISO 27001 and this is the most relevant standard here in Georgia. I trust in Torq and I trust in the security compliance the platform provides.

      Torq's AI recommendations are consistently helpful. There was no case when the system provided me with a false recommendation or inaccurate response.

      Alert fatigue is something I would like Torq to help me address.

      My overall rating for this review is 10.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Jun 30, 2026
      Flag as inappropriate
      PeerSpot user
      Buyer's Guide
      Download our free Torq Report and get advice and tips from experienced pros sharing their opinions.
      Updated: August 2026
      Buyer's Guide
      Download our free Torq Report and get advice and tips from experienced pros sharing their opinions.