AppSecNews

RASP

Runtime Application Self-Protection

Detect and block attacks from inside the running application process.

9 tools profiled

How it differs Runs inside the production app and blocks attacks as they happen. IAST finds bugs with similar instrumentation during testing; a WAF filters traffic in front of the app rather than inside it.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

3 tools match

  • Imperva RASP

    Imperva

    RASP

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial
    Established
  • ModSecurity

    OWASP

    RASP

    An open source web application firewall engine that embeds in a web server or proxy and evaluates requests and responses against a rule language, most often the OWASP Core Rule Set.

    Open source
    Established
  • Waratek

    Waratek

    RASP

    Java-focused runtime protection that applies rule-driven fixes inside the JVM, letting teams neutralize known vulnerabilities without changing source code or rebuilding the application.

    Commercial
    Established
  • Imperva RASP

    Imperva

    An in-application agent that parses payloads in their execution context using language grammars, blocking injection attacks without signatures, tuning or traffic learning.

    Commercial Established
    RASP
  • ModSecurity

    OWASP

    An open source web application firewall engine that embeds in a web server or proxy and evaluates requests and responses against a rule language, most often the OWASP Core Rule Set.

    Open source Established
    RASP
  • Waratek

    Waratek

    Java-focused runtime protection that applies rule-driven fixes inside the JVM, letting teams neutralize known vulnerabilities without changing source code or rebuilding the application.

    Commercial Established
    RASP
Tick up to 4 tools above.