AppSecNews

RASP

Runtime Application Self-Protection

Detect and block attacks from inside the running application process.

9 tools profiled

How it differs Runs inside the production app and blocks attacks as they happen. IAST finds bugs with similar instrumentation during testing; a WAF filters traffic in front of the app rather than inside it.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals

9 tools

  • Runtime application protection layered onto Datadog's existing APM tracing libraries, detecting and blocking attacks from inside the application and correlating them with traces.

    Commercial
    Growing
  • Dynatrace

    Dynatrace

    RASP

    Application security built on Dynatrace OneAgent instrumentation, identifying vulnerable libraries loaded in running processes and blocking injection attacks at execution points.

    Commercial
    Established
  • Imperva RASP

    Imperva

    RASP

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial
    Established
  • K2 Cyber Security

    New Relic

    RASP

    A runtime protection agent that models an application's expected execution flow and flags deviations, detecting injection and memory attacks without signatures; technology now part of New Relic.

    Commercial
    Growing
  • ModSecurity

    OWASP

    RASP

    An open source web application firewall engine that embeds in a web server or proxy and evaluates requests and responses against a rule language, most often the OWASP Core Rule Set.

    Open source
    Established
  • Runtime application protection layered onto Datadog's existing APM tracing libraries, detecting and blocking attacks from inside the application and correlating them with traces.

    Commercial Growing
    RASP
  • Dynatrace

    Dynatrace

    Application security built on Dynatrace OneAgent instrumentation, identifying vulnerable libraries loaded in running processes and blocking injection attacks at execution points.

    Commercial Established
    RASP
  • Imperva RASP

    Imperva

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial Established
    RASP
  • K2 Cyber Security

    New Relic

    A runtime protection agent that models an application's expected execution flow and flags deviations, detecting injection and memory attacks without signatures; technology now part of New Relic.

    Commercial Growing
    RASP
  • ModSecurity

    OWASP

    An open source web application firewall engine that embeds in a web server or proxy and evaluates requests and responses against a rule language, most often the OWASP Core Rule Set.

    Open source Established
    RASP
  • Oligo Security

    Oligo Security

    RASP

    Uses eBPF sensors to observe how application libraries actually behave at runtime, profiling normal activity to flag deviation and to show which vulnerable dependencies are genuinely in use.

    Commercial
    Emerging
  • OpenRASP

    Baidu

    RASP

    An open source runtime protection agent that hooks sensitive application functions and evaluates each call in context with JavaScript plugins rather than matching traffic signatures.

    Open source
    Growing
  • RASP

    A next-generation WAF using in-path agents and modules that tag requests with attack signals locally and block sources once they cross a threshold, rather than dropping on a single pattern match.

    Commercial
    Established
  • Waratek

    Waratek

    RASP

    Java-focused runtime protection that applies rule-driven fixes inside the JVM, letting teams neutralize known vulnerabilities without changing source code or rebuilding the application.

    Commercial
    Established
  • Oligo Security

    Oligo Security

    Uses eBPF sensors to observe how application libraries actually behave at runtime, profiling normal activity to flag deviation and to show which vulnerable dependencies are genuinely in use.

    Commercial Emerging
    RASP
  • OpenRASP

    Baidu

    An open source runtime protection agent that hooks sensitive application functions and evaluates each call in context with JavaScript plugins rather than matching traffic signatures.

    Open source Growing
    RASP
  • A next-generation WAF using in-path agents and modules that tag requests with attack signals locally and block sources once they cross a threshold, rather than dropping on a single pattern match.

    Commercial Established
    RASP
  • Waratek

    Waratek

    Java-focused runtime protection that applies rule-driven fixes inside the JVM, letting teams neutralize known vulnerabilities without changing source code or rebuilding the application.

    Commercial Established
    RASP
Tick up to 4 tools above.