ADR Security Tools
Compare the best ADR tools and vendors. Expert reviews, pricing, and feature comparisons on Latio.
Oligo Security offers application layer insights as part of a CADR platform. They baseline application library activities at a function level, and can detect either malicious deviation, or the execution of known vulnerable functions. This extends into AI, allowing them to see, detect, and respond to AI applications.
Aikido provides everything the average startup to mid-market company needs for security in a box - every code and cloud security scanner under the sun without much feature compromise, alongside a surprisingly robust runtime application solution for things like bot prevention. A no-nonsense replacement for a lot of more "specialized" solutions that tend to slow developers down.
Upwind has built CNAPP from the ground-up around runtime insights provided from a network focused endpoint agent. They provide unique features like API security, alongside vulnerability prioritization and scanning, and the more generic CNAPP feature sets.
The core of Sweet Security is powerful incident detection and response capabilities for cloud environments. They have since created a larger CNAPP platform expanding more into vulnerability management, posture, and identity capabilities
Raven has built a comprehensive runtime oriented ADR solution that can detect function executions from packages being exploited. This empowers them to detect application layer attacks, create prioritization based on what functions are being used, as well as virtual patching to prevent vulnerability exploitation.
Kodem offers runtime first code security solutions - from runtime function execution SCA to runtime detection for prioritizing SAST findings. They're also one of the few to offer ADR solutions.
Operant has focused their application defense solution on securing AI workloads, providing features like runtime detection and redaction for production applications. They excel at securing Kubernetes workloads, and are especially strong at network detections.
I think Edera is incredibly dope - they offer a simple deployment that offers robust runtime protection for your cloud environments. They introduce a hypervisor to kubernetes nodes that isolates containers as virtual machines instead of as processes. It provides an elegant solution to the specific problem of container isolation.
Via their oneagent, Dynatrace provides highly competitive ADR capabilities with function level reachability, RASP style blocking, and the ability to query most logs. Their agent also extends into processes and hosts. Their CADR offering has the complete offering from a feature perspective, but the UX struggles to tie it together for security.
Paraxial provides a unique combination of security tooling specializing in the Elixir language and Phoenix framework. They're a great choice for companies that use Elixir, and have unique runtime elements that them stand out from open source options.
Miggo is maximizing the value of your existing application performance monitoring, or offers an instrumentation of their own, that excels at building maps of distributed systems and real time attack detection and prevention. Miggo has no-code as well integration based implementations.
Acquired by Harness. Traceable has built some amazing API security capabilities thanks to starting with tracing as their beginning. They do a great job patching information together in a way that makes it relevant for investigations
Datadog offers a complete suite a security offerings that are a great fit for developer focused teams not looking for the most mature details in each area. They offer most scanning types, runtime detections, and a full SIEM, and you're probably already sending them your logs. It's a great runtime choice to meet developers where they work, but the UX is built primarily for developers.
Contrast wraps commonly exploited functions at runtime to detect and prevent application exploits, i.e. they scan the application once it's actually built and running for vulnerabilities, and preventing exploits. This makes Contrast a strong choice for enterprise application protection.
Acquired by Crowdstrike. Pangea provides an API and SDK to easily implement security features into your application - such as checking a user's password against a breach database, or checking a user's email against a spam database. They've expanded the capabilities of the SDK to focus on runtime AI protection.
Arcjet provides a simple RASP solution giving developers security features like bot protection, rate limiting, or sensitive data detection.
If you want to get your hands dirty with cutting edge ADR, Deepflow is an open source project that allows for agent based tracing, profiling, and more. It would be a lot of work to get it cooking for in house security, but it's an open source example for a lot of this technology.
Runtime-first CNAPP and CADR platform that uses eBPF sensors to validate which vulnerabilities are actually exploitable, detect app-layer attacks in real time, and reveal what AI workloads are doing in production.