Cloud & App Security Product Insights

v1.20 Added vendors: Boundary-Breakers_Exaforce, Boundary-Breakers_Cytix, LLM_TrojAI, LLM_Marqus, ASPM_BlueFlag, ASPM_Rainforest, ASPM_FluidAttacks, Code-Fixers_ZeroPath, Mobile_appdome, Data_Formal, Data_Teleskope, Data_Cyera, MDM_Jamf, MDM_Kandji, MDM_Evren, Asset_JupiterOne, Asset_Axonius, CDR_Cortex, Remediation-Platforms_Mondoo, Remediation-Platforms_Conviso, Kubernetes_BiFrost, Kubernetes_Nirmata, SIEM_AIStrike, SIEM_Exaforce, RASP_Dynatrace, SaaS_Vorlon, SaaS_Nudge, SaaS_AppOmni, SaaS_Astrix, SaaS_Reco, IaC_Zest, IaC_Blast, IaC_Nirmata, Cloud-Identity_Lumeus, Cloud-Identity_Doppler, Cloud-Identity_BlueFlag, DAST_Bright, DAST_Ghost, MDR_Cyrebro, API_Ghost

High level changes:

  1. Added new categories: Asset Management, Data Security, SaaS Security
  2. Renamed Remediation Platforms to Vulnerability Management (CTEM)
  3. Added new “hands-on” tag to indicate which tools we’ve been hands on with, and ranked vendors more heavily weighted with this.
  4. Massive Javascript optimizations

Vendors added:

  1. Added Exaforce to boundary breakers - AI + SIEM is a step beyond AI + Logs
  2. Added Cytix to boundary breakers - monitors places where change happens for on demand pentesting of new endpoints
  3. Added TojAI to LLMs - runtime testing and protection for LLMs with on-prem hosting
  4. Added Marqus to LLMs - runtime security for LLMs
  5. Added Blueflag to ASPM and cloud identity - identity based ASPM and detection, JIT for git
  6. Added Rainforest to ASPM - code security with brand protection, hosted via on-prem vm
  7. Added FluidAttacks to ASPM - ASPM scanning + services
  8. Added Zeropath to Code-fixers - AI SAST = the next generation, no cap
  9. Added AppDome to Mobile - the most robust mobile app runtime protection
  10. Added Formal to the new data category - awesome runtime data aliasing
  11. Added Teleskope to the new data category - data access control for data stores and SaaS
  12. Added Cyera to Data - classical DSPM
  13. Added Jamf to new MDM category - the apple MDM king
  14. Added Kandji to the new MDM category - the strong jamf alternative
  15. Added Evren to the new MDM category - a smart developer MDM alternative to virtual machines
  16. Added JupiterOne to the new Asset Management category - great all in one queryable and customizable asset management
  17. Added Axonius to the new Asset Management category - Great asset and vulnerability management capabilities
  18. Added Cortex CDR to CDR - now it works with cloud
  19. Added Mondoo to Vuln Mgmt - ambitious all in one vulnerability scanning and management
  20. Added Conviso to Vuln Mgmt - vulnerability management + services
  21. Added Biforst to Kubernetes Security - automatic apparmor policy generation
  22. Added Added Nirmata to Kubernetes Security and IaC - policy as code enforcement
  23. Added AI-Strike and Exaforce to SIEM - AI first SIEMs
  24. Added Dynatrace to ADR - strong RASP like capabilities provided via their agent
  25. Added Vorlon to SaaS - SaaS discovery and runtime protection
  26. Added Nudge to SaaS - SaaS discovery and onboarding/offboarding automation
  27. Added AppOmni to SaaS - SaaS discovery and posture
  28. Added Astrix to SaaS - they don’t go to market as SaaS, but strong OAuth protection
  29. Added Reco to SaaS - Shadow IT discovery, threat detection, and posture management
  30. Added Zest to IaC - Remediation focused IaC and Cloud Posture
  31. Added Blast to IaC - IaC policy enforcement
  32. Added Lumeus to Cloud Identity - very strong developer workload access
  33. Added Doppler to Cloud Identity - secrets management for devs
  34. Added Bright to DAST - fully featured DAST solution
  35. Added Ghost to DAST and API security - API first dast and discovery leaning into AI capabilities
  36. Added Cyrebro to MDR - re-sellable EDR, SaaS, and SIEM security for MSSPs and MDRs

v1.19 Added vendors: Remediation-Platforms_AppSOC, LLM_Zenity, SCA_Kusari, Corporate_Identity_Axiad

v1.18 Added vendors: Boundary-Breakers_Edera, Remediation-Platforms_JupiterOne, Remediation-Platforms_Brinqa, LLM_Operant, Mobile_Quokka, PT_Doyensec, PT_Ethiack, CDR_KSOC, CDR_ARMO, CDR_ClearVector, Container-Runtime_Edera, Container-Runtime_ClearVector, RASP_Operant, RASP_Arcjet, Compliance_Zania, Compliance_Conveyor, SCA_Lineaje, Cloud-Identity_Clutch, Cloud-Identity_Permiso, Cloud-Identity_WhiteSwan, Cloud-Identity_Breez, Cloud-Identity_Procyon, DAST_Ethiack, DAST_Intruder, DAST_HCL_AppScan, MDR_Tamnoon, MDR_Cygnostic, API_AppSentinels, Compliance_SafeBase, Cloud-Identity_ClearVector

  1. Added Edera to Boundary Breakers and container runtime - a unique solution for isolating container workloads making them actually function like VMs instead of playing pretend like we do
  2. Added JupiterOne to Remediation Platforms - JupiterOne is easy data lake management, so you it can fit into really any category.
  3. Added Brinqa to Remediation Platforms - A good vulnerability management platform for enterprises with a lot of diverse workloads
  4. Added Operant to LLM - the team at operant has been busy applying their CADR tool to AI workloads
  5. Added Quokka to Mobile - a cool option for static and dynamic analysis of mobile app binaries
  6. Added Doyensec to Pentesters - smart team with great Javascript expertise
  7. Added Ethiack to DAST - DAST and pentesting combined, now featuring AI
  8. Added Rad and ARMO to CDR - an overdue update from when I kept CDR separate from needing an agent
  9. Added Clearvector to CDR, Container Runtime, and Cloud Identity - a holistic identity focused approach to detection and resposne
  10. Added Arcjet to ADR - okay okay this one is more a RASP but it does cool stuff for some easy security in JavaScript and I’m not making a separate category for RASP from ADR>
  11. Added Zania to GRC Automation - This tool is very cool and will uplift existing standards for compliance reporting since LLMs read better than humans do.
  12. Added Conveyor to GRC Automation - the leader in questionnaires and trust centers keeps doing that.
  13. Added Safebase to GRC automation - ez button for a security webpage and NDA request flows
  14. Added Lineaje to SCA - everything a nerdy SBOM and attestation lover could as for.
  15. Added Clutch to Cloud Identity - an extremely strong solution for NHI management and insights
  16. Added Permiso to Cloud Identity - they were under boundary breakers but now that I have this cloud identity category it’s a better fit - extremely strong ITDR platform
  17. Added Whiteswan to Cloud Identity - A great solution to grant and track access to Windows cloud workloads - you can even do stuff like require MFA for specific file access!
  18. Added Breez to Cloud Identity - Identity threat detection for cloud resources
  19. Added Procyon to Cloud Identity - JIT for cloud workloads
  20. Added Intruder to DAST - a strong web based network and application DAST scanner
  21. Added HCL Appscan to DAST - a desktop based DAST that’s aight.
  22. Added Tamnoon to MDR and Remediation Platforms - A unique approach to getting CNAPP findings resolved - is such a thing even possible??
  23. Added Cygnostic to MDR - a managed service offering for application and cloud security
  24. Added AppSentinels to API Security - an extremely strong and competitive offering for API security

v1.17 Added vendors: CNAPP_Uptycs, Boundary-Breakers_AIStrike, Boundary-Breakers_nanovms, Boundary-Breakers_Security_Runners, Boundary-Breakers_Dropzone, Boundary-Breakers_Cloudfence, Boundary-Breakers_Chaser, Boundary-Breakers_Kosli, Remediation-Platforms_Vicarius, CSPM_CodeShield, LLM_Aim, LLM_Unbound, LLM_AppSOC, ASPMs_Phoenix_Security, ASPM_Soos, ASPM_Codacy, ASPM_StartLeftSecurity, ASPMUptycs, PT_Kulkan, Container-Runtime_Uptycs, RASP_Deepflow, SCA_Soos, SCA_StartLeftSecurity, IaC_StartLeftSecurity, Container-Vulnerability_Autonomous, Container-Vulnerability_Soos, Container-Vulnerability_StartLeftSecurity, Cloud-Identity_Oasis, Cloud-Identity_Token, MDR_Fortra, API_Aikido, Corporate_Identity_BalkanID, SAST_Soos, SAST_StartLeftSecurity

v1.16 Added vendors: CSPM_Kloudle, PT_Include_Security, DAST_Nightvision, API_Traceable, API_Nightvision

v1.15 Added vendors: CNAPP_Tenable, Boundary-Breakers_Formal, Boundary-Breakers_HoundDog, Boundary-Breakers_Mimic, Remediation-Platforms_Zafran, Remediation-Platforms_Cyclops, CSPM_CheckRed, LLM_Mindgard, Code-Fixers_DryRun, Code-Fixers_Seezo, CDR_StreamSecurity, Container-Runtime_Sweet_Security, Kubernetes_Aqua_Security, RASP_Miggo, RASP_Oligo, SCA_Netrise, SCA_ReversingLabs, SCA_Coana, SCA_Contrast_Security, Container-Vulnerability_Endor, Cloud-Identity_Andromeda, API_42Crunch, API_Firetail, API_noname, API_SaltSecurity, SAST_Contrast_Security

v1.14 Added vendors: Boundary-Breakers_Ophion, Boundary-Breakers_Zenity, PT_Ophion, PT_Inspecitv, SCA_Scribe

v1.13 Added vendors: Boundary-Breakers_Bedrock_Systems, LLM_Noma, Mobile_Approov, Container-Runtime_Sternum, Container-Runtime_Bedrock_Systems, Container-Vulnerability_Oligo_Security

v1.12

v1.11 Added vendors: Boundary-Breakers_Seedata, Remediation-Platforms_SecOps_Solution, Code-Fixers_Infield, Cloud-Identity_Sonrai, Corporate_Identity_Push_Security

v1.10 Added vendors: Boundary-Breakers_VulnCheck, Remediation-Platforms_RevealID, CSPM_Aikido, MDM_Fleet, PT_Intigriti, Container-Vulnerability_Aikido, DAST_Aikido, DAST_EdgeScan

v1.8 Added vendors: Boundary-Breakers_Myrror, Code-Fixers_Nullify, SCA_Myrror

v1.7 Added vendors: Boundary-Breakers_Devici, SCA_Phylum, SCA_Tidelift, Cloud-Identity_InstaSecure, DAST_Akto, API_Akto

v1.6 Added vendors: Remediation-Platforms_Dependency_Track, Secret-Scanning_Legit_Security, Code-Fixers_Staris, PT_Staris, PT_MindPoint_Group, SCA_Socket, IaC_Legit_Security, Container-Vulnerability_Legit_Security, DAST_Staris, MDR_MindPoint_Group, SAST_Staris

v1.5 Added vendors: Boundary-Breakers_Seal, Boundary-Breakers_Grit, Secret-Scanning_Qwiet, ASPM_Qwiet, Code-Fixers_Seal, Code-Fixers_Grit, Code-Fixers_Amplify, SCA_Seal, SCA_Xigeni, SCA_Qwiet, SCA_Checkmarx, IaC_Qwiet, IaC_Checkmarx, Container-Vulnerability_Qwiet, Container-Vulnerability_Checkmarx, DAST_Pynt, DAST_Checkmarx, API_StackHawk, API_Escape, API_Pynt, SAST_Qwiet

v1.4 Boundary-Breakers_Xigeni, Code-Fixers_Latio, Container-Runtime_ARMO, Container-Runtime_Operant, Container-Runtime_Oligo_Security, API_Impart, API_Operant, API_Levo, API_AWS, API_Wallarm, API_Cloudflare, API_F5, API_Fortinet

v1.3 Added vendors: CSPM_Cycode, Container-Runtime_Upwind, IaC_Aqua_Security, Container-Vulnerability_Cycode, Container-Vulnerability_Mend, Container-Vulnerability_Apiiro, Container-Vulnerability_Veracode, SAST_Mend, SAST_Aqua_Security

v1.2 Added vendors: Secret-Scanning_Xigeni, LLM_Harmonic, ASPM_Xigeni, IaC_Xigeni, Cloud-Identity_Abbey, Corporate_Identity_Veza

v1.1 Added vendors: Cloud-Identity_P0_Security, Corporate_Identity_Crosswire, Corporate_Identity_ConductorOne, Corporate_Identity_Opal

v1.0

v0.9

v0.8

v0.7

v0.6

v0.5

v0.4

v0.3

v0.2

v0.1