AppSecNews

RASP

Runtime Application Self-Protection

Detect and block attacks from inside the running application process.

9 tools profiled

How it differs Runs inside the production app and blocks attacks as they happen. IAST finds bugs with similar instrumentation during testing; a WAF filters traffic in front of the app rather than inside it.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

6 tools match

  • Runtime application protection layered onto Datadog's existing APM tracing libraries, detecting and blocking attacks from inside the application and correlating them with traces.

    Commercial
    Growing
  • Imperva RASP

    Imperva

    RASP

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial
    Established
  • K2 Cyber Security

    New Relic

    RASP

    A runtime protection agent that models an application's expected execution flow and flags deviations, detecting injection and memory attacks without signatures; technology now part of New Relic.

    Commercial
    Growing
  • Runtime application protection layered onto Datadog's existing APM tracing libraries, detecting and blocking attacks from inside the application and correlating them with traces.

    Commercial Growing
    RASP
  • Imperva RASP

    Imperva

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial Established
    RASP
  • K2 Cyber Security

    New Relic

    A runtime protection agent that models an application's expected execution flow and flags deviations, detecting injection and memory attacks without signatures; technology now part of New Relic.

    Commercial Growing
    RASP
  • ModSecurity

    OWASP

    RASP

    An open source web application firewall engine that embeds in a web server or proxy and evaluates requests and responses against a rule language, most often the OWASP Core Rule Set.

    Open source
    Established
  • OpenRASP

    Baidu

    RASP

    An open source runtime protection agent that hooks sensitive application functions and evaluates each call in context with JavaScript plugins rather than matching traffic signatures.

    Open source
    Growing
  • Waratek

    Waratek

    RASP

    Java-focused runtime protection that applies rule-driven fixes inside the JVM, letting teams neutralize known vulnerabilities without changing source code or rebuilding the application.

    Commercial
    Established
  • ModSecurity

    OWASP

    An open source web application firewall engine that embeds in a web server or proxy and evaluates requests and responses against a rule language, most often the OWASP Core Rule Set.

    Open source Established
    RASP
  • OpenRASP

    Baidu

    An open source runtime protection agent that hooks sensitive application functions and evaluates each call in context with JavaScript plugins rather than matching traffic signatures.

    Open source Growing
    RASP
  • Waratek

    Waratek

    Java-focused runtime protection that applies rule-driven fixes inside the JVM, letting teams neutralize known vulnerabilities without changing source code or rebuilding the application.

    Commercial Established
    RASP
Tick up to 4 tools above.