# Which RASP vendors are considered leaders for runtime protection in cloud-native microservices where traditional perimeter defenses do not apply?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Which RASP vendors are considered leaders for runtime protection in cloud-native microservices where traditional perimeter defenses do not apply? In a containerized, distributed setup there's no single network edge to defend, so protection has to sit with the workloads themselves. These are the names from the <a class="a a--md" elv="true" href="https://www.g2.com/categories/runtime-application-self-protection-rasp-tools">Runtime Application Self-Protection (RASP) Tools</a> category that fit that model.</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/dynatrace/reviews"><strong>Dynatrace</strong></a> is built for cloud-native estates, and reviewers highlight automatic dependency mapping and deep, real-time visibility across containers and services from one console. Its runtime protection comes through the Application Security module, and since most reviews focus on observability, weigh that security layer on its own.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/falco/reviews"><strong>Falco</strong></a> is the cloud-native specialist here, a CNCF-born open-source tool that reviewers deploy as a DaemonSet across Kubernetes to watch container behavior at the system-call level, with customizable rules and real-time alerts. Though it leans toward detection and alerting rather than in-app blocking, and running on every node can consume noticeable resources on large clusters.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/imperva-runtime-application-self-protection-rasp/reviews"><strong>Imperva Runtime Application Self-Protection (RASP)</strong></a> is positioned squarely at the perimeter-less problem, protecting applications from threats that firewalls and intrusion detection miss and blocking attacks from inside the app.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For those of you running microservices, are you after something Kubernetes-native that watches the whole cluster, or an in-app agent that blocks per service? And how much of this are you handling at the mesh layer today?</p>

##### Post Metadata
- Posted at: 2 months ago
- Author title: Marketer
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;ASP works in the runtime, which is perfect for microservices where perimeter defenses don&#39;t apply. The real test is whether it catches attacks without creating false positives that trigger auto-remediation (circuit breakers, scaling up) for legitimate traffic.&lt;/p&gt;

##### Comment Metadata
- Posted at: 13 days ago
- Author title: Marketing Executive



### Comment 2

&lt;p&gt;The ownership distinction makes this more interesting than a straight vendor comparison. Cluster-level detection may be easier to standardize centrally, while in-app blocking gets closer to the actual service but asks every development team to participate. I’d be interested in whether teams successfully run both layers without creating duplicate alerts or unclear incident ownership.&lt;/p&gt;

##### Comment Metadata
- Posted at: 15 days ago
- Author title: Writer



### Comment 3

&lt;p&gt;One angle worth adding: whichever layer you pick, ownership matters as much as coverage. A cluster-wide tool sits naturally with the platform team, while an in-app agent has to be adopted by every service team shipping code. The second is a rollout conversation with far more people in it, which often decides what actually reaches the whole fleet.&lt;/p&gt;

##### Comment Metadata
- Posted at: 16 days ago
- Author title: Tech Consultant



### Comment 4

&lt;p&gt;These three actually sit at different layers rather than competing head to head: Falco watches at the node and system-call level across the cluster but is described as detection and alerting, not in-app blocking; Imperva RASP sits inside the application itself and blocks from there; and Dynatrace sits in between with cluster-wide visibility plus a security module worth evaluating separately from its observability reputation. That makes &quot;leader&quot; a layer-specific question rather than a single winner, since a team running Falco for cluster-wide detection would still need something like Imperva inside the app to actually block anything. Has anyone paired Falco&#39;s detection with an in-app RASP agent, and if so, how much overlap or noise did that create?&lt;/p&gt;

##### Comment Metadata
- Posted at: 2 months ago
- Author title: SEO Content Writer





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


