Number 1: Datadog Application Security
by Datadog
Best for: adding attack detection to services already carrying Datadog APM tracing libraries
Top 9 · RASP
9 tools, ranked Last reviewed
A practitioner's guide to runtime application self-protection: true in-process agents, mobile hardening libraries, and the WAF-adjacent tools often filed alongside them.
The order follows the roundup The 10 Best RASP Tools, which explains each pick and where it falls short.
by Datadog
Best for: adding attack detection to services already carrying Datadog APM tracing libraries
Best for: runtime vulnerability prioritization across an estate already standardized on OneAgent
by Imperva
Best for: signature-free injection blocking inside Java and .NET applications
Best for: neutralizing known vulnerabilities in Java applications that cannot be rebuilt
Best for: proving the in-process protection model on Java or PHP before committing to a contract
by New Relic
Best for: teams whose previous runtime rollout died from false positives
Best for: determining which vulnerable dependencies are genuinely executing in production
by Fastly
Best for: blocking persistent attackers in front of applications no in-process agent supports
by OWASP
Best for: self-hosted rule-driven virtual patching at a web server or proxy you already operate
methodology
How entries are chosen. Every entry is a tool with a published profile in the catalog, in Runtime Application Self-Protection. Each note above says why it made this list, for the job in the title, separately from the tool's full profile.
Ranking is editorial. The order is a judgement by the editors about fit for this use case, not a score, a benchmark or a popularity count. A different job can produce a different order.
Advertising has no influence. Slots marked Sponsored are sold separately from the editorial. No vendor can pay to be included, to move up, or to be removed.