AppSecNews

RASP

Runtime Application Self-Protection

Detect and block attacks from inside the running application process.

9 tools profiled

How it differs Runs inside the production app and blocks attacks as they happen. IAST finds bugs with similar instrumentation during testing; a WAF filters traffic in front of the app rather than inside it.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

5 tools match

  • Runtime application protection layered onto Datadog's existing APM tracing libraries, detecting and blocking attacks from inside the application and correlating them with traces.

    Commercial
    Growing
  • Dynatrace

    Dynatrace

    RASP

    Application security built on Dynatrace OneAgent instrumentation, identifying vulnerable libraries loaded in running processes and blocking injection attacks at execution points.

    Commercial
    Established
  • Imperva RASP

    Imperva

    RASP

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial
    Established
  • Oligo Security

    Oligo Security

    RASP

    Uses eBPF sensors to observe how application libraries actually behave at runtime, profiling normal activity to flag deviation and to show which vulnerable dependencies are genuinely in use.

    Commercial
    Emerging
  • RASP

    A next-generation WAF using in-path agents and modules that tag requests with attack signals locally and block sources once they cross a threshold, rather than dropping on a single pattern match.

    Commercial
    Established
  • Runtime application protection layered onto Datadog's existing APM tracing libraries, detecting and blocking attacks from inside the application and correlating them with traces.

    Commercial Growing
    RASP
  • Dynatrace

    Dynatrace

    Application security built on Dynatrace OneAgent instrumentation, identifying vulnerable libraries loaded in running processes and blocking injection attacks at execution points.

    Commercial Established
    RASP
  • Imperva RASP

    Imperva

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial Established
    RASP
  • Oligo Security

    Oligo Security

    Uses eBPF sensors to observe how application libraries actually behave at runtime, profiling normal activity to flag deviation and to show which vulnerable dependencies are genuinely in use.

    Commercial Emerging
    RASP
  • A next-generation WAF using in-path agents and modules that tag requests with attack signals locally and block sources once they cross a threshold, rather than dropping on a single pattern match.

    Commercial Established
    RASP
Tick up to 4 tools above.