Get listed

Application Security

Best RASP Tools for Runtime Application Self-Protection in 2026

A WAF allow does not mean the query never executed.

Expertise: Application Security · Level: Intermediate · 13 min read

Picture a production checkout API that passed WAF review with 0 rule hits, then still executed a SQL injection the edge never understood in application context. Runtime Application Self-Protection instruments the running app so exploit attempts can be detected or blocked where the code actually runs.

Contrast Protect and peers sit inside the process or beside it with agents and sensors. The shortlist splits: classic in-process RASP, APM-coupled application security modules, JVM virtual patching specialists, and eBPF ADR that proves which vulnerable functions execute.

If you need design-to-runtime AppSec graphs more than in-app blocking, see ASPM tools. For human-led testing, use PTaaS tools.

How we evaluated

We read first-party RASP, ADR, and application security runtime pages on 19 Sep 2026. We asked whether protection runs in or beside the app, which languages are first-class, whether blocking is supported, and whether the product is still sold for new deployments. EOL products stay off the shortlist.

ToolBest forWhat to check
Contrast ProtectStandalone RASP with IAST kinshipCommercial · multi-language agents
Datadog ASMRASP-style protection in Datadog APMCommercial · Datadog estate
Dynatrace AppSecRuntime protection on OneAgentCommercial · Dynatrace estate
WaratekJVM virtual patching and RASPCommercial · Java-focused
Oligo SecurityeBPF ADR and runtime exploit blockingCommercial · ADR lane
KodemRuntime-powered AppSec evidenceCommercial · reachability focus
How the tools differ
Classic RASP
APM security
ADR / eBPF
1

Contrast Protect

Best established commercial RASP beside IAST

Contrast Security Protect RASP product page

Contrast Protect provides runtime application self-protection using instrumentation that shares DNA with Contrast Assess IAST, blocking exploit attempts in production without code changes.

It is the AppSec-first RASP pick when you do not want protection tied only to an APM purchase.

Key features:

  • In-process instrumentation across languages they support
  • Attack blocking for injection-class techniques they document
  • Shared agent story with Contrast Assess
  • Telemetry aimed at AppSec and operations

Why we like it:

Teams that already trust Contrast IAST can extend the same instrumentation story into production protection.

Limits:

Commercial. Agent performance and language coverage must be proven on your stack.

License or pricing: Commercial. Sales-quoted. Checked 19 Sep 2026.

2

Datadog Application Security

Best when Datadog APM is already deployed

Datadog Application Security monitoring product page

Datadog Application Security adds runtime application protection and vulnerability context on the Datadog agent path, including technology inherited from Sqreen.

Choose it to avoid a second agent fleet when Datadog already watches services.

Key features:

  • Runtime attack detection and blocking modes they publish
  • APM-correlated security signals
  • Broad language coverage in Datadog packaging
  • Unified dashboards with observability data

Why we like it:

Datadog shops get RASP-shaped controls without inventing a new install ritual.

Limits:

Commercial and strongest inside Datadog. Confirm ASM SKU versus APM-only contracts.

License or pricing: Commercial. Datadog product packaging; confirm on 19 Sep 2026.

3

Dynatrace Application Security

Best when Dynatrace OneAgent is already the observability layer

Dynatrace Application Security runtime protection page

Dynatrace Application Security uses OneAgent telemetry to detect vulnerabilities and block attacks in running applications with Davis AI prioritization they advertise.

It fits Dynatrace estates that want runtime AppSec without a separate RASP vendor.

Key features:

  • OneAgent-based runtime protection
  • Vulnerability detection plus attack blocking modes they list
  • Davis AI risk prioritization
  • Support across languages OneAgent covers

Why we like it:

Observability-led enterprises keep security next to traces they already trust.

Limits:

Commercial and Dynatrace-centric. Python-heavy stacks should verify language coverage carefully.

License or pricing: Commercial. Dynatrace packaging; confirm on 19 Sep 2026.

4

Waratek

Best for Java JVM virtual patching and RASP depth

Waratek Java RASP and virtual patching platform page

Waratek focuses on Java runtime protection with JVM-level controls and virtual patching aimed at known CVEs and injection classes without waiting on code changes.

Pick it when the painful estate is Java and virtual patching is the weekly queue.

Key features:

  • JVM instrumentation and data-tainting approaches they document
  • Virtual patching for vulnerable libraries
  • RASP controls for OWASP-class attacks on Java apps
  • SaaS or on-prem packaging options they list

Why we like it:

Java platform teams get specialist depth APM add-ons rarely match for virtual patching.

Limits:

Commercial and Java-first. Polyglot estates still need another RASP or ADR path.

License or pricing: Commercial. Sales-quoted. Checked 19 Sep 2026.

5

Oligo Security

Best for eBPF ADR that proves and blocks runtime exploitation

Oligo Security application detection and response page

Oligo Security markets application detection and response with eBPF sensors that show which vulnerable functions actually execute and can block exploit paths at the syscall layer.

It is the ADR pick when classic in-process RASP agents are hard to land.

Key features:

  • eBPF runtime sensing
  • Library and function execution evidence
  • Exploit blocking modes they publish
  • ADR workflows for AppSec and platform teams

Why we like it:

Platform teams allergic to JVM agents still get runtime proof of exploitability.

Limits:

Commercial. Kernel and workload support must match your OS mix.

License or pricing: Commercial. Sales-quoted. Checked 19 Sep 2026.

6

Kodem

Best for runtime-powered AppSec prioritization and evidence

Kodem runtime application security platform page

Kodem focuses on runtime-powered application security evidence so teams prioritize vulnerabilities that actually load and execute, not only exist in a lockfile.

It complements classic RASP when the painful week is false-positive SCA noise.

Key features:

  • Runtime reachability and execution evidence
  • AppSec prioritization workflows
  • Integration into developer and security tooling they list
  • Focus on reducing unreachable vulnerability noise

Why we like it:

AppSec leads drowning in SCA backlog get runtime truth before buying more scanners.

Limits:

Commercial. Confirm how blocking versus evidence-only modes are packaged.

License or pricing: Commercial. Sales-quoted. Checked 19 Sep 2026.

How to choose a RASP tool

Four questions before the quote. Names are the shortlist, not a scored bake-off.

Critical questionWhy it mattersWhat to evaluateRed flag
Do you already pay for Datadog or Dynatrace APM?Second agents are political.Datadog ASM or Dynatrace AppSec first.Ignoring the agent you already run.
Is the estate mostly JVM?Java specialists win virtual patching weeks.Waratek depth versus generalist RASP.Buying polyglot RASP then only protecting Tomcat.
Can you land in-process agents?Some platforms only allow eBPF ADR.Contrast for in-process; Oligo for eBPF.PoC on a lab JVM that production forbids.
Is the pain blocking or prioritization?Different products optimize differently.Protect/block modes versus Kodem-style evidence.Expecting SCA ranking from a pure block product.

What practitioners argue about RASP

Threads compare APM-coupled security modules and specialist RASP, not abstract OWASP slides.

Hacker News

“Hey I’m an engineer who worked at Sqreen and now Datadog. What kind of feature is still missing in Datadog ASM? To my knowledge everything is there except managing CSP and security headers now.”

Jan 2025 comment (linked in the Datadog entry). APM-coupled ASM is where many RASP evaluations land.

Waratek

“We are working on a specialised Cybersecurity Runtime Application Self-Protection (RASP) tooling.”

Waratek hiring note on HN (Apr 2025). Specialist JVM RASP remains an active product lane.

If the next gap is AppSec program graphs, read ASPM tools. For human-led testing programs, use PTaaS tools.

FAQs

Is RASP a WAF replacement?

No. WAFs sit at the edge. RASP instruments application runtime context. Most mature programs run both.

Is ADR the same as RASP?

ADR often uses eBPF or sensors beside the process to prove exploitability and block. RASP traditionally instruments inside the app. Overlap is real; packaging differs.

Can APM security modules replace specialist RASP?

Sometimes, if language coverage and blocking modes match. Java virtual patching specialists can still win JVM-heavy estates.

Is this a scored bake-off?

No. Order is editorial.

Application security resources