AppSecNews

RASP

Runtime Application Self-Protection

Detect and block attacks from inside the running application process.

9 tools profiled

How it differs Runs inside the production app and blocks attacks as they happen. IAST finds bugs with similar instrumentation during testing; a WAF filters traffic in front of the app rather than inside it.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

4 tools match

  • Runtime application protection layered onto Datadog's existing APM tracing libraries, detecting and blocking attacks from inside the application and correlating them with traces.

    Commercial
    Growing
  • Dynatrace

    Dynatrace

    RASP

    Application security built on Dynatrace OneAgent instrumentation, identifying vulnerable libraries loaded in running processes and blocking injection attacks at execution points.

    Commercial
    Established
  • Imperva RASP

    Imperva

    RASP

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial
    Established
  • K2 Cyber Security

    New Relic

    RASP

    A runtime protection agent that models an application's expected execution flow and flags deviations, detecting injection and memory attacks without signatures; technology now part of New Relic.

    Commercial
    Growing
  • Runtime application protection layered onto Datadog's existing APM tracing libraries, detecting and blocking attacks from inside the application and correlating them with traces.

    Commercial Growing
    RASP
  • Dynatrace

    Dynatrace

    Application security built on Dynatrace OneAgent instrumentation, identifying vulnerable libraries loaded in running processes and blocking injection attacks at execution points.

    Commercial Established
    RASP
  • Imperva RASP

    Imperva

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial Established
    RASP
  • K2 Cyber Security

    New Relic

    A runtime protection agent that models an application's expected execution flow and flags deviations, detecting injection and memory attacks without signatures; technology now part of New Relic.

    Commercial Growing
    RASP
Tick up to 4 tools above.