CDR Security Tools
Compare the best CDR tools and vendors. Expert reviews, pricing, and feature comparisons on Latio.
Acquired by Google. Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, but their Code and Defend offerings are competitive in their own right.
Upwind has built CNAPP from the ground-up around runtime insights provided from a network focused endpoint agent. They provide unique features like API security, alongside vulnerability prioritization and scanning, and the more generic CNAPP feature sets.
The core of Sweet Security is powerful incident detection and response capabilities for cloud environments. They have since created a larger CNAPP platform expanding more into vulnerability management, posture, and identity capabilities
Every organization using AWS should absolutely turn on GuardDuty as their first cloud security step. They provide awesome base level protections and detections at a low price. An especially amazing check the box runtime protection tool.
Orca offers the standard suite of CNAPP features with a focus on agentless scanning. They're a good all around CNAPP offering mostly focused on the posture side.
Stream Security provides real time cloud context for enterprise security operations teams. The solution fills in the missing configuration gaps with most existing EDR and SIEM approaches to cloud security by providing real time information about how the cloud environment is changing to detect and respond to threats faster.
Acquired by Wiz. Gem is one of the first platforms to focus on cloud detection & response. Realizing the limitations of configuration scanning in the incident response process, they've built a tool primarily for the SOC to respond to cloud attack patterns. The lack of an agent for kubernetes context is the biggest gap.
Cortex Cloud is a security operations platform that integrates cloud and application security capabilities into their larger security operations offerings. This provides a single hub for managing first and third party findings across vulnerabilities and runtime events.
ARMO has all of the features of a CNAPP, but with a special emphasis on runtime security and Kubernetes. Their open source Kubescape is a great tool for scanning Kubernetes clusters, and their paid offering provides true CADR runtime protection and compliance features.
CrowdStrike's container runtime technically works, but deployment, maintenance, and usefulness do not compare to other tools at the time of testing. CrowdStrike's Windows offerings remain dominant in the space, but their CNAPP and container security solutions are difficult to recommend.
Sysdig created the first runtime cloud protection tool with the open source project Falco, and has since built a trusted, enterprise ready, runtime oriented CNAPP platform. The tool is strongest at runtime protection, but offers the standard suite of CNAPP features, and is especially a good choice for regulated industries.
GCP Security Command Center is a supplemental cloud security offering provided natively in the GCP platform. It has great vulnerability and posture scanning capabilities, but lacks a runtime agent for real-time protection. That said, it can be a great extension of cloud security capabilities especially for SOCs.
ClearVector has built identity focused runtime defense across workloads and clouds.
Plerion has built a competitive CNAPP offering for smaller teams who don't need all of the features, primarily on the posture side. Alongside CSPM, they provide attack maps, IaC scanning, Secret scanning, and vulnerability scanning. They link findings to assets in a clean and intuitive way. Currently there is no agent based runtime protection.
SkyHawk is betting big that they can provide just as much runtime response protection as agent based CDRs, but without an agent. This means that certain detection gaps exist, but in the examples I've seen from them, it makes me wonder if those gaps really matter.
Lacework built on top of an alert based approach rather than more traditional scanning models. That has the benefit of reduced noise and a faster reactive approach, but at the cost of surfacing a lot of alerts to security that they don't have the ability to fix.
Firemon has assembled a unique collection of cloud security features - CSPM, JIT AWS access, and alerting off cloudtrail events. While they don't have the full feature set of larger CNAPPs, they provide smart features at an aggressive price. They offer CSPM scanning for free.