ORNA is an AI-guided platform for cyberattack response automation and incident case management. Its Scout agent detects infrastructure attacks and anomalies around the clock, groups findings by source, relevance, and criticality, and enriches them with threat intelligence from 28 public and private sources. AI analysis estimates severity and affected assets, with breakdowns by asset, attack type, technique, and time. Teams can escalate alerts into incidents; ORNA then generates and assigns attack-specific tasks based on team roles. Playbooks cover digital forensics and incident response as well as crisis work for HR, communications, and legal teams. It can produce executive or detailed reports with evidence analysis, and its Risk Dashboard supports NIST CSF management across five governance domains. ORNA lists more than 200 integrations and says it can be deployed on-premises or in the cloud. It also states that it encrypts data at rest and in transit, requires TOTP MFA, and segregates customer instances. A free self-managed plan is listed; managed and other self-managed plans require custom quotes.
Who it is for
ORNA is aimed at agile DFIR teams; the maker says free access is specifically for midsize businesses. Its playbooks also cover crisis activities involving HR, communications, and legal teams.
What is good
- Threat intelligence draws on 28 sources.
- Tasks are assigned based on team roles.
- Playbooks cover DFIR and other crisis work.
- Free 24/7 incident-resolution support is included.
What to know first
- Managed and other self-managed plans require custom quotes.
- Deployment and security details are stated by the maker.
Verdict
ORNA combines attack detection, incident workflows, reporting, and risk management, with cloud and on-premises deployment options. Pricing beyond the listed free self-managed plan is by custom quote.
ORNA plans and pricing
All plansCompared on incident response software
- Free plan
- Yes
- Case management
- Yes
- Evidence tracking
- Yes
- Responder collaboration
- Yes
- On-call scheduling
- Yes
- Audit log
- Yes
- API access
- Yes
- Deployment options
- hybrid



