Buyer note
Runtime protection in CNAPPs: how nine vendors detect and block attacks
Cloud Security Compare editors · · Editorial assessment
The short version
CrowdStrike Falcon Cloud Security and Sysdig Secure lead our runtime protection criterion at 4.8, with Upwind at 4.7 and Palo Alto Networks Cortex Cloud at 4.6. The two agentless-first leaders overall, Wiz (4.2) and Orca Security (3.8), score lower here because their sensors were added to an agentless core. Most sensors in the category are now eBPF-based, so the differences are in blocking, investigation and how the sensor fits the rest of the platform.
What does our runtime criterion measure?
Runtime protection depth carries a 16% weight in our matrix. It covers detection and prevention inside running workloads: the sensor technology, whether it can block as well as alert, and the investigation and response tools around it. It does not cover posture findings or vulnerability scanning, which sit under agentless coverage and risk prioritization. A platform can lead one of those and trail on runtime, and that is the most common split in this market.
| Vendor | Runtime score | What the vendor lists |
|---|---|---|
| CrowdStrike Falcon Cloud Security | 4.8 | The Falcon sensor, the same agent CrowdStrike uses on endpoints, bringing its detection and response model to cloud workloads |
| Sysdig Secure | 4.8 | Sysdig agent with Falco-based runtime detection; runtime insight into which packages are in use |
| Upwind | 4.7 | eBPF sensors; baselines of cloud activity, network and application flows; forensic sequence of events; Upwind says it detects threats in 15 seconds |
| Palo Alto Networks Cortex Cloud (formerly Prisma Cloud) | 4.6 | Performance-optimized runtime agent that stops attacks as they execute; CDR from the merger of Prisma Cloud with Cortex CDR |
| SentinelOne Singularity Cloud | 4.5 | Cloud Workload Security detects and stops threats inside running containers, VMs and AI workloads |
| Aqua Security | 4.5 | Kernel-layer enforcement that blocks attacks without killing the container and preserves memory evidence |
| Wiz | 4.2 | Wiz Sensor, eBPF-based; Wiz states it blocks threats in real time on VMs, containers and serverless containers; Kubernetes file integrity and drift monitoring; Blue Agent AI investigation |
| Microsoft Defender for Cloud | 4.0 | Server runtime protection through Microsoft Defender for Endpoint (Defender for Servers Plan 1 and Plan 2) across Azure, AWS, GCP and on-premises machines |
| Orca Security | 3.8 | Orca Sensor, eBPF-based, on Linux, Kubernetes and Windows; can be configured to terminate processes; shows which vulnerable packages are executed |
Why do CrowdStrike and Sysdig lead?
Both start from the sensor. CrowdStrike brings the Falcon sensor it built for endpoint detection and response to cloud workloads, so teams that run Falcon on laptops and servers get the same agent, console and detection model in the cloud. Sysdig's runtime detection is built on Falco, the open-source project Sysdig created, which is now a CNCF graduated project. Falco 0.45.0, released on 21 September 2026, added raw byte matching in rule conditions and new rules that flag containers accessing GPU devices. The two tie at 4.8; see CrowdStrike vs Sysdig.
Where do Upwind and Cortex Cloud fit?
Upwind (4.7) is the runtime-first platform among the newer vendors. It combines eBPF sensors with baselines of cloud activity and network flows and a forensic timeline of events, and adds agentless scanning around that core. Its 15-second detection figure is Upwind's own claim, not our measurement. Palo Alto Networks Cortex Cloud (4.6) arrives at runtime from the security operations side: Prisma Cloud was merged with Cortex CDR to form Cortex Cloud, announced in February 2025, and its performance-optimized agent stops attacks as they execute.
Why do Wiz and Orca score lower on runtime?
Both built their platforms on agentless scanning and added an eBPF sensor later. The Wiz Sensor blocks threats, according to Wiz, and Wiz Defend adds Kubernetes file integrity monitoring, drift detection and AI-assisted investigation; we score it 4.2. The Orca Sensor runs on Linux, Kubernetes and Windows and can be configured to terminate processes, but it is an optional layer and less proven than runtime-first rivals; we score it 3.8, the lowest runtime score in the matrix. Both lead elsewhere, Orca on agentless coverage and Wiz on risk prioritization, code and ecosystem. For a buyer whose main requirement is runtime, those leads matter less than this row. See Orca vs Upwind and Upwind vs Wiz.
What about Defender for Cloud, SentinelOne and Aqua?
Microsoft Defender for Cloud (4.0) protects servers through Defender for Endpoint, which Defender for Servers extends across Azure, AWS, GCP and on-premises machines; it fits best where Microsoft's endpoint stack is already in place. SentinelOne Singularity Cloud (4.5) detects and stops threats inside containers, VMs and AI workloads through Cloud Workload Security. Aqua Security (4.5) uses kernel-layer enforcement that blocks attacks without killing the container and preserves memory evidence, which suits teams that cannot restart workloads to contain an incident.
What should you test?
- Install the sensor on one representative cluster and measure CPU and memory with your own monitoring.
- Run a planned, harmless test and record which detections fire, how long each takes to appear and what the investigation view shows.
- Check whether blocking is on by default, what it stops (a process, a container or a network connection) and who can release it.
- Check operating system and platform coverage against your estate. Windows hosts, serverless containers and managed Kubernetes are where vendor lists differ.
- Where the product builds on an open-source project, ask whether its managed rules follow the latest release.
Our lesson on rolling out a runtime sensor covers the staged rollout after purchase.
Sources
- Wiz Defend and Wiz Sensor wiz.io
- Orca Sensor orca.security
- Palo Alto Networks introduces Cortex Cloud paloaltonetworks.com
- Cortex Cloud paloaltonetworks.com
- Microsoft Defender for Servers learn.microsoft.com
- Upwind home upwind.io
- Upwind CDR upwind.io
- CrowdStrike Falcon Cloud Security crowdstrike.com
- SentinelOne Singularity Cloud sentinelone.com
- Sysdig Secure sysdig.com
- Falco falco.org
- Falco 0.45.0 falco.org
- Aqua platform aquasec.com
Related pages
- Rolling out a runtime sensorThe staged rollout after purchase
- Agentless vs agent-basedWhat each method sees
- CrowdStrike vs SysdigThe two runtime leaders head to head
- Comparison matrixThe runtime column next to the other six