Landscape / Vendor & product directory

Find the tool.
Understand the work.

Learn what each offering does, where it fits in a team's workflow, and what to verify before relying on it.

119 product profiles8 security segmentsResearch reviewed 19 September 2026

Explore established platforms, specialists, native controls, and open-source options. Profiles are scoped to offerings: a company can appear in several segments. This is an editorial selection, with documented capabilities and unassessed results.

Download the directory and source links ↓

119 product profiles across 8 segments

Start with the segment guides ↗

SIEM / 15 PROFILES

Security information & event management

Read the field guide ↗

Microsoft / Cloud SIEM

Microsoft Sentinel

Microsoft Sentinel is a cloud SIEM for collecting security records, finding suspicious activity and investigating incidents. A practitioner connects relevant sources and uses queries and analytics rules to turn those records into evidence.

Explore Microsoft Sentinel

Elastic / SIEM and search analytics

Elastic Security

Elastic Security provides SIEM investigation and detection over data stored in the Elastic platform. Analysts work with searchable events, rules and entity context; useful results still depend on sound collection and consistent field mappings.

Explore Elastic Security

CrowdStrike / Cloud SIEM and platform analytics

Falcon Next-Gen SIEM

Falcon Next-Gen SIEM combines security analytics with Falcon context and supported third-party data. The practical question is whether the organization’s required records can be collected, understood and investigated reliably within that workflow.

Explore Falcon Next-Gen SIEM

Palo Alto Networks / Converged SIEM and security operations

Cortex XSIAM

Cortex XSIAM combines SIEM-style analytics with adjacent detection, investigation and automation capabilities. It is best examined as an operations workflow whose components, data dependencies and action permissions need to be understood separately.

Explore Cortex XSIAM

Securonix / Cloud SIEM and behavior analytics

Unified Defense SIEM

Securonix Unified Defense SIEM combines cloud security analytics with user and entity behavior context. Its value in practice depends on whether the available identity and event data support an investigation that an analyst can explain.

Explore Unified Defense SIEM

IBM / Self-managed SIEM

IBM QRadar SIEM

IBM QRadar SIEM correlates security records into offenses that analysts investigate using event and asset context. This profile focuses on the continuing IBM self-managed offering and the operating work required to maintain its collection and correlation.

Explore IBM QRadar SIEM

Fortinet / SIEM with asset and operations context

FortiSIEM

FortiSIEM combines security event analytics with asset and operational context. It can help an analyst relate an alert to the systems involved, provided collection, discovery and source integration are configured for the actual environment.

Explore FortiSIEM

Rapid7 / Cloud SIEM and detection

SIEM (InsightIDR)

Rapid7 InsightIDR provides cloud security detection and investigation using collected event data and available endpoint and identity context. Practitioners use its search and alert workflows to connect activity that would be difficult to understand from a single source.

Explore SIEM (InsightIDR)

Logpoint / SIEM and normalized analytics

Logpoint SIEM

Logpoint SIEM collects and normalizes security records for detection and investigation. It illustrates the importance of understanding source coverage and operating responsibilities even when a vendor offers a simpler commercial or deployment model.

Explore Logpoint SIEM

Graylog / Security analytics over log management

Graylog Security

Graylog Security adds security detection and investigation capabilities to the Graylog platform. A practitioner can use its log-centric workflow to explore events and develop detections, but must distinguish the licensed security offering from Graylog Open.

Explore Graylog Security

Wazuh Inc. / Open-source security monitoring

Wazuh

Wazuh is an open-source security monitoring platform combining endpoint agents, central analysis and searchable security data. It gives learners a concrete way to connect collected host activity with rules, alerts and the operational work behind monitoring.

Explore Wazuh

EDR / 14 PROFILES

Endpoint detection & response

Read the field guide ↗

CrowdStrike / Endpoint detection and response

Falcon Insight XDR

Falcon Insight XDR is CrowdStrike’s endpoint detection and response offering within the Falcon platform. It combines endpoint investigation with supported cross-domain context, giving analysts a way to explore related activity and use licensed response functions during an investigation.

Explore Falcon Insight XDR

SentinelOne / Endpoint detection and response

Singularity Endpoint

Singularity Endpoint combines prevention with endpoint detection and response in SentinelOne’s platform. Its Storyline investigation model connects related activity, while remediation and rollback are advertised response capabilities whose availability must be checked against the chosen package and operating system.

Explore Singularity Endpoint

Palo Alto Networks / Endpoint detection and response

Cortex XDR

Cortex XDR connects endpoint detection and response with supported network, cloud, identity and other security signals. The endpoint agent contributes host evidence, while the wider analytics platform helps analysts investigate relationships that would be difficult to see in one isolated alert.

Explore Cortex XDR

Sophos / Endpoint detection and response

Sophos EDR

Sophos EDR adds investigation and response to Sophos Endpoint protection. It gives analysts endpoint evidence and documented options such as isolation and live shell, while related XDR and managed-service products broaden the portfolio without being interchangeable with the EDR license.

Explore Sophos EDR

Trend Micro / Endpoint detection and response

TrendAI Vision One Endpoint Security

TrendAI Vision One Endpoint Security connects endpoint protection and investigation to the wider Vision One platform. The offering is relevant when analysts need to understand endpoint events alongside supported server, email, cloud or network signals rather than treating every alert in isolation.

Explore TrendAI Vision One Endpoint Security

Trellix / Endpoint detection and response

Trellix EDR with Forensics

Trellix EDR with Forensics sits within an enterprise endpoint security portfolio with ePolicy Orchestrator management heritage. Its documented emphasis includes continuous monitoring and guided investigation, making it useful to study how endpoint evidence supports a repeatable investigation and evidence-handling process.

Explore Trellix EDR with Forensics

Bitdefender / Endpoint detection and response

GravityZone EDR

GravityZone EDR brings endpoint investigation into Bitdefender’s protection platform. Cross-endpoint incident correlation helps analysts connect related activity, while hunting and supported integrations provide ways to investigate beyond a single alert and share evidence with the wider security operations workflow.

Explore GravityZone EDR

ESET / Endpoint detection and response

ESET Inspect

ESET Inspect is the detection and response component in the ESET PROTECT ecosystem. It combines behavior and reputation information with investigation capabilities, providing a useful example of how endpoint rules, related activity and analyst judgment contribute to a security decision.

Explore ESET Inspect

WithSecure / Endpoint detection and response

Elements Endpoint Detection and Response

WithSecure Elements Endpoint Detection and Response organizes suspicious endpoint observations into broader investigation context. Guided response and an escalation-to-expert option illustrate a co-managed approach: software supports the investigation while the customer and any contracted specialists retain defined operational responsibilities.

Explore Elements Endpoint Detection and Response

Elastic / Endpoint detection and response

Elastic Defend

Elastic Defend provides endpoint protection and detection within Elastic Security through Elastic Agent and Fleet. It is a useful learning example of how a centrally managed endpoint integration supplies host evidence to a wider search and investigation platform that still requires operational ownership.

Explore Elastic Defend

Broadcom / Endpoint detection and response

Carbon Black Cloud Enterprise EDR

Carbon Black Cloud Enterprise EDR focuses on endpoint activity visibility, search and investigation. Its technical overview describes an evidence-oriented workflow in which analysts examine recorded behavior, connect related observations and use queries to investigate questions beyond the alert that started the case.

Explore Carbon Black Cloud Enterprise EDR

Arctic Wolf / Endpoint detection and response

Aurora Endpoint Defense

Aurora Endpoint Defense is an endpoint product in Arctic Wolf’s portfolio following its acquisition of Cylance assets. The offering brings prevention, detection and response capabilities into an endpoint technology discussion that should remain distinct from the company’s separately contracted managed security services.

Explore Aurora Endpoint Defense

Cisco / Endpoint detection and response

Cisco Secure Endpoint

Cisco Secure Endpoint combines endpoint protection and investigation within Cisco’s security portfolio. Device trajectory is a useful beginner concept: it helps an analyst follow activity associated with a host, while supported isolation and related security integrations provide options for an authorized response.

Explore Cisco Secure Endpoint

IAM / 15 PROFILES

Identity & access management

Read the field guide ↗

Microsoft / Workforce IAM

Microsoft Entra ID

Microsoft Entra ID is a cloud identity provider for workforce sign-in, multifactor authentication, and policy-based access to applications and cloud consoles. It issues tokens so employees, contractors, and partners can reach Microsoft 365 and connected software.

Explore Microsoft Entra ID

Okta / Workforce IAM

Okta Workforce Identity

Okta Workforce Identity is a cloud identity provider for employees, contractors, and partners. It offers single sign-on, adaptive multifactor authentication, a universal directory, and optional lifecycle, governance, and privileged-access modules across a large application catalog.

Explore Okta Workforce Identity

Auth0 / Customer identity

Auth0

Auth0 is Okta's customer identity platform for product teams that ship consumer or multi-tenant login. It handles business-to-consumer and business-to-business sign-in, social and enterprise federation, consent, and machine-to-machine client credentials rather than employee single sign-on.

Explore Auth0

Ping Identity / Workforce and customer federation

PingFederate / PingOne

PingFederate is a federation server for Security Assertion Markup Language, OpenID Connect, OAuth, and WS-Federation, with adapters and a policy editor. PingOne adds cloud multifactor authentication and identity services for hybrid or self-hosted deployments that mix workforce and partner identities.

Explore PingFederate / PingOne

Saviynt / Identity governance

Saviynt Identity Cloud

Saviynt Identity Cloud is a cloud identity governance platform that spans workforce access, application access governance, non-human identities, and privileged-access adjacency. It is often evaluated where enterprise-resource-planning or electronic-health-record connectors matter as much as single sign-on.

Explore Saviynt Identity Cloud

CyberArk / Privileged access

Idira Privileged Access Management

Idira Privileged Access Management is the current public PAM offering associated with CyberArk’s portfolio under Palo Alto Networks. It addresses privileged credentials and human administrative sessions. Adjacent machine and agent identity capabilities require separate product and deployment checks.

Explore Idira Privileged Access Management

BeyondTrust / Privileged access

BeyondTrust PAM Portfolio

BeyondTrust Pathfinder privileged access management combines password safe vaulting, privileged remote access, endpoint privilege management, and just-in-time elevation. It is aimed at least privilege on Windows and Unix, vendor remote access, and jump hosts rather than workforce single sign-on.

Explore BeyondTrust PAM Portfolio

Delinea / Privileged access

Delinea Secret Server

Delinea Secret Server is a credential vault for privileged secrets. It discovers accounts, encrypts stored credentials, supports check-in and check-out with rotation, and can monitor sessions. Platform claims that reach identity governance should be scoped separately from the vault.

Explore Delinea Secret Server

IBM / Identity fabric

IBM Verify

IBM Verify is a family of workforce, customer, governance, and privileged-identity products under one brand. It includes multifactor authentication, orchestration, consent, directory, identity governance, privileged identity, and an application gateway for legacy applications, including a government SKU.

Explore IBM Verify

Oracle / Cloud IAM and identity governance

Oracle OCI IAM / Identity Governance

Oracle Cloud Infrastructure Identity and Access Management provides identity domains for single sign-on, multifactor authentication, and lifecycle in Oracle Cloud. Oracle Identity Governance remains the adjacent on-premises heritage product for entitlements, with Access Governance for reviews.

Explore Oracle OCI IAM / Identity Governance

JumpCloud / Workforce directory and device management

JumpCloud Open Directory

JumpCloud Open Directory is a cloud directory that combines workforce identity, single sign-on, multifactor authentication, LDAP, RADIUS, and device management for mixed operating systems. It is often evaluated by smaller information-technology teams consolidating directory, single sign-on, and mobile device management.

Explore JumpCloud Open Directory

Cisco Duo / Multifactor authentication overlay

Cisco Duo

Cisco Duo is a multifactor authentication and device-trust overlay that often sits in front of an existing identity provider, virtual private network, or directory. It adds phishing-resistant methods, Duo Push, adaptive policy, and passwordless options without replacing identity governance or customer identity.

Explore Cisco Duo

Amazon Web Services / Cloud workforce IAM

AWS IAM Identity Center

AWS IAM Identity Center centralizes workforce access to AWS accounts and supported applications. It can connect an external identity provider and provision users through System for Cross-domain Identity Management, while account permission sets give users temporary AWS role credentials.

Explore AWS IAM Identity Center

VM / 14 PROFILES

Vulnerability & exposure management

Read the field guide ↗

Tenable / Exposure management platform

Tenable One

Tenable One is Tenable's exposure-management family. It gathers vulnerability, web application, identity, cloud, operational technology, and external-surface findings, then adds attack-path context so operators can inspect how weaknesses might combine rather than treating each scanner result as an isolated ticket.

Explore Tenable One

Qualys / Vulnerability management and TruRisk platform

Qualys VMDR

Qualys VMDR is a scanner-plus-agent vulnerability workflow on the Enterprise TruRisk Platform. It inventories assets, assesses missing patches and misconfigurations, and adds threat context and patch workflows. Enterprise TruRisk Management is described as aggregating Qualys and third-party findings rather than replacing the assessment layer.

Explore Qualys VMDR

Rapid7 / Hybrid exposure management

Rapid7 Exposure Command

Rapid7 Exposure Command is a hybrid exposure offering that keeps InsightVM as the scanner. Documentation distinguishes Surface Command inventory from vulnerability, cloud, and application findings plus third-party enrichment, so buyers are looking at layered products rather than a single unnamed console.

Explore Rapid7 Exposure Command

Microsoft / Exposure graph and Defender vulnerability management

Microsoft Security Exposure Management

Microsoft Security Exposure Management provides an exposure graph, attack paths, initiatives, and recommendations across supported endpoints, identities, and cloud signals. Related Defender Vulnerability Management and Defender External Attack Surface Management capabilities have separate requirements, so a Microsoft-heavy estate is still assembling more than one product boundary.

Explore Microsoft Security Exposure Management

Cisco / Legacy risk-based vulnerability management

Cisco Vulnerability Management

Cisco Vulnerability Management, formerly Kenna.VM, is a risk-based vulnerability-management product that ingests existing scanner findings, applies threat feeds, and supports service-level tracking by risk. It is in the sample as legacy context: Cisco published end of sale and a last-support date and did not name a replacement in the bulletin.

Legacy / migration contextExplore Cisco Vulnerability Management

Axonius / Cyber asset attack surface management

Axonius Cyber Assets and Exposures

Axonius is a specialist CAASM layer that sits above scanners and other sources. Cyber Assets normalizes and deduplicates many adapters. Exposures unifies vulnerabilities, misconfigurations, identity issues, coverage gaps, and owners so teams can see unscanned, unprotected, or unowned systems rather than only CVE lists.

Explore Axonius Cyber Assets and Exposures

runZero / Agentless discovery and exposure workflow

runZero

runZero is an agentless discovery and exposure product for information technology, operational technology, and Internet of Things environments. It combines active, passive, and integration inventory with hosted external engines, query-based vulnerability matching, and a 5.0 verified-remediation workflow. A Community Edition exists.

Explore runZero

Brinqa / Exposure orchestration

Brinqa Platform

Brinqa is an aggregation and orchestration platform rather than another scanner. It uses connectors and a Cyber Risk Graph to deduplicate findings, attribute owners, and apply business context. In August 2026 Brinqa acquired PlexTrac for offensive validation workflow and reporting; that combination is vendor-stated and should be tested rather than assumed mature.

Explore Brinqa Platform

XM Cyber / Attack-path analysis

XM Cyber

XM Cyber is an attack-path and choke-point specialist. It builds a digital-twin style graph of CVEs, misconfigurations, and identities across hybrid environments, with vendor-described expansion to cloud and artificial-intelligence related surfaces as of March 2026. The question it answers is how conditions chain toward crown-jewel assets, not how many CVEs exist.

Explore XM Cyber

Cymulate / Breach and attack simulation

Cymulate Exposure Validation

Cymulate Exposure Validation is a breach-and-attack-simulation centered product. It runs controlled simulations across attack vectors, supplies threat content, and offers remediation guidance so operators can see whether selected email, web, endpoint, or network controls behave as assumed. It validates controls; it does not inventory every CVE on its own.

Explore Cymulate Exposure Validation

Picus Security / Exposure validation and breach and attack simulation

Picus Autonomous Exposure Validation Platform

Picus offers an Autonomous Exposure Validation Platform that starts from breach-and-attack simulation and adds adjacent exposure, attack-path, and cloud validation modules. A threat library and vendor-specific mitigation content are part of the documented pitch. Module licensing versus need, and the boundary between attack-path validation and BAS, have to be confirmed per package.

Explore Picus Autonomous Exposure Validation Platform

Pentera / Automated security validation

Pentera Platform

Pentera is an agentless automated security-validation and automated-penetration-testing platform. Core, Cloud, and Surface assessment modules can attempt broader exploit chains than control simulation, and Resolve is described as remediation orchestration. Because tests may execute, change control, blast-radius limits, and cloud identity-and-access scope are part of the product boundary.

Explore Pentera Platform

Greenbone / Open-ecosystem vulnerability scanner

Greenbone OPENVAS SCAN

Greenbone OPENVAS SCAN is an open-ecosystem vulnerability scanner from Greenbone AG. Hardware and virtual scanning options exist, with an Enterprise Feed and a Community Feed and Community Edition. The company remains Greenbone AG; OPENVAS is the product brand. It is a useful comparison point for authenticated scanning without treating community coverage as equivalent to enterprise feed coverage.

Explore Greenbone OPENVAS SCAN

CNAPP / CSPM / 14 PROFILES

Cloud & workload security

Read the field guide ↗

Amazon Web Services / Native AWS security services

AWS Security Hub and Workload Security

AWS provides several services for understanding cloud exposure and workload threats. Security Hub CSPM assesses posture; the unified Security Hub correlates selected findings. Inspector examines supported workloads for vulnerabilities, while GuardDuty supplies threat detection. These services cooperate but are not interchangeable switches for complete cloud protection.

Explore AWS Security Hub and Workload Security

Microsoft / Native Azure and multicloud CNAPP

Microsoft Defender for Cloud

Microsoft Defender for Cloud combines cloud posture, development-related security and workload protection. Its AWS and Google Cloud connectors extend selected capabilities beyond Azure. For a beginner, the key lesson is that connecting a cloud account for configuration visibility does not automatically install or enable every workload protection component.

Explore Microsoft Defender for Cloud

Google Cloud / Native Google Cloud posture and detection

Google Security Command Center

Google Security Command Center collects security findings and supplies posture capabilities for Google Cloud. Posture policies and drift findings help teams compare deployed resources with an intended configuration. Tier and feature choices matter, particularly because published retirement notices affect selected offerings rather than the entire Security Command Center service.

Product transitionExplore Google Security Command Center

Wiz / Multicloud CNAPP

Wiz

Wiz connects cloud inventory, configuration, vulnerability and identity context to help teams understand exposure paths. Its platform includes agentless visibility and separate runtime capabilities. A graph can explain how conditions relate, but observing a process while it runs requires the relevant runtime component and supported deployment.

Explore Wiz

Palo Alto Networks / Application, posture and runtime security

Palo Alto Networks Cortex Cloud

Cortex Cloud brings application security, cloud posture and runtime security into Palo Alto Networks’ cloud portfolio. Prisma Cloud materials remain relevant to its lineage and existing deployments. A practitioner should connect development findings to deployed resources while verifying the precise modules behind the current product name.

Explore Palo Alto Networks Cortex Cloud

Orca Security / Agentless scanning and runtime CNAPP

Orca Security

Orca Security combines agentless cloud and workload scanning with exposure analysis and separate runtime sensing. Its SideScanning approach examines supported workload state without installing an agent on every scanned workload. That makes the distinction between recorded disk state and live process behavior a useful starting point for evaluation.

Explore Orca Security

CrowdStrike / Cloud posture and workload protection

CrowdStrike Falcon Cloud Security

Falcon Cloud Security extends CrowdStrike’s portfolio into cloud posture, workload protection and cloud detection. It combines agentless and sensor-based approaches across documented services. Existing endpoint deployment can simplify some operational familiarity, but it is not evidence that every cloud account, container or entitlement is already assessed.

Explore CrowdStrike Falcon Cloud Security

Sysdig / Runtime-focused cloud and Kubernetes security

Sysdig

Sysdig uses runtime information to support cloud threat detection and vulnerability prioritization, with a strong Kubernetes and Linux orientation. Knowing a package is present differs from knowing it is used by a running workload. Both kinds of evidence can inform a decision, without making unused software harmless.

Explore Sysdig

Fortinet / Posture, workload and development security

Fortinet FortiCNAPP

FortiCNAPP combines cloud configuration, identity, workload and development-security capabilities with Lacework lineage. Its behavioral analysis can add context to activity, while posture checks examine the configuration itself. The practical goal is to understand which signal supports a finding before deciding who should investigate or change the resource.

Explore Fortinet FortiCNAPP

Tenable / Cloud exposure and entitlement management

Tenable Cloud Security

Tenable Cloud Security brings cloud configuration, identity and workload context into an exposure-management portfolio. A learner can use it to examine why an exposed resource matters in its environment, rather than treating every misconfiguration or vulnerability as an isolated record with the same remediation priority.

Explore Tenable Cloud Security

Check Point / CNAPP transition and cloud network security

Check Point CloudGuard and Wiz CNAPP

Check Point’s current CNAPP path involves its Wiz partnership, while CloudGuard also names cloud network-security products. This is a useful example of why a product family cannot be treated as one lifecycle. A CNAPP transition can affect contracts and workflows without retiring the vendor’s firewall or web-application firewall.

Product transitionExplore Check Point CloudGuard and Wiz CNAPP

Aqua Security / Container and cloud workload security

Aqua Security

Aqua Security connects software and image assessment with cloud posture and runtime controls. Its container-oriented examples help explain the difference between preventing a risky image from entering a pipeline and observing behavior after deployment. Neither stage removes the need to identify who owns the application and its fixes.

Explore Aqua Security

Trend Micro / Cloud posture within a broader security platform

TrendAI Vision One Cloud Security

TrendAI Vision One provides cloud-account connections and security functions within Trend Micro’s wider platform. Supported clouds do not all expose the same features. For a learner, the essential task is reading the feature matrix and distinguishing account posture from image, disk, container and runtime protection.

Explore TrendAI Vision One Cloud Security

Upwind / Runtime-focused CNAPP

Upwind

Upwind combines runtime sensing with agentless cloud assessment to provide context about running applications and exposure. Live inventory and process evidence can help a team understand how a workload behaves. They also depend on sensor placement, supported environments and the quality of the signals actually collected.

Explore Upwind

APPSEC / 15 PROFILES

Application & software supply-chain security

Read the field guide ↗

Checkmarx / Application security platform

Checkmarx One

Checkmarx One is a commercial platform spanning application security testing and posture management. The vendor describes static and dynamic testing, composition analysis, infrastructure as code, containers, secrets, application programming interface checks, malicious-package detection, and ASPM analytics, with Developer Assist for the authoring loop.

Explore Checkmarx One

Veracode / Application risk management

Veracode ARM platform

Veracode's application risk management platform is a binary-analysis and software-as-a-service assurance path. The vendor describes static and dynamic testing, composition analysis, a package firewall after the 2025 Phylum acquisition, container and infrastructure-as-code scanning, Risk Manager after Longbow in 2024, and Fix assistance.

Explore Veracode ARM platform

Snyk / Developer-workflow application security

Snyk

Snyk is a developer-workflow suite covering open-source composition analysis, Snyk Code static analysis, secrets, containers, infrastructure as code, and API and web DAST. Official documentation describes editor, command-line, and source-control integrations. Public plan pages exist; regional hosting and enterprise governance still need confirmation.

Explore Snyk

GitHub (Microsoft) / Source-control native code and secret security

GitHub Code Security and GitHub Secret Protection

GitHub Code Security and GitHub Secret Protection are separate stock-keeping units in the Advanced Security family. Code Security covers code scanning, dependency review, Dependabot extras, and Copilot Autofix. Secret Protection covers secret scanning, push protection, and custom patterns. Several features remain free on public repositories; private and internal repositories require GitHub Team or Enterprise purchases of the relevant SKU.

Explore GitHub Code Security and GitHub Secret Protection

GitLab / Source-control and CI application security

GitLab SAST and dependency scanning

GitLab integrates application security with source control and continuous integration. Standard SAST analyzers are available across Free, Premium, and Ultimate. Dependency scanning and Advanced SAST require Ultimate under the reviewed documentation. Keep scanner availability distinct from the security views, policies, and vulnerability-management experience included in a tier.

Explore GitLab SAST and dependency scanning

Semgrep / Custom-rule static analysis and supply-chain platform

Semgrep AppSec Platform

Semgrep offers pattern-based static analysis in Community Edition and a commercial AppSec Platform. The platform adds a Pro engine, supply-chain reachability, secrets detection, and SBOM capabilities. Custom rules are the distinctive teaching point: teams can write patterns for local frameworks instead of waiting on a generic rule pack.

Explore Semgrep AppSec Platform

SonarSource / Quality platform with paid software composition analysis

SonarQube Advanced Security

SonarQube Advanced Security adds paid composition analysis and advanced static analysis to the quality platform. Dependency vulnerability and license-policy checks, SBOM import, and analysis modes have separate boundaries. The reviewed Enterprise-and-above requirement applies to the Advanced Security add-on on SonarQube Server, not to SonarQube Server itself.

Explore SonarQube Advanced Security

HCLSoftware / Application security testing

HCL AppScan

HCL AppScan is an IBM-heritage application-security testing family now under HCLSoftware. The vendor describes static, dynamic, and interactive testing, composition analysis, application programming interface checks, secrets, containers, and infrastructure as code, with cloud and self-managed 360° options including air-gap and sovereign deployments.

Explore HCL AppScan

OpenText / Static application security testing

OpenText Fortify Static Code Analyzer

OpenText Fortify Static Code Analyzer is a static-testing product known for legacy-language breadth, including COBOL and ABAP. The vendor describes broad language and framework support plus remediation assistance. A broader OpenText Application Security portfolio includes software-as-a-service and self-managed testing around that static core.

Explore OpenText Fortify Static Code Analyzer

Mend.io / Software composition analysis and developer remediation

Mend.io

Mend.io provides composition analysis alongside static analysis, container scanning, reachability, and Renovate-based dependency-update workflows. Evaluate each module separately on the codebase: strong dependency results do not establish how a static analyzer models first-party code, and an automated update still needs review and regression checks.

Explore Mend.io

Endor Labs / Reachability-first composition analysis

Endor Labs

Endor Labs is a reachability-first composition-analysis product with additional vendor-described controls: a package firewall, artificial-intelligence assisted static analysis, secrets, containers, and Model Context Protocol integration into coding agents. The teaching point is call-graph-based reachability plus intake control, not another undifferentiated CVE list.

Explore Endor Labs

Legit Security / Application security posture and SDLC discovery

Legit Security

Legit Security is an ASPM and software-development-lifecycle discovery product with vendor-described artificial-intelligence integrated-development-environment guardrails (VibeGuard). It can use native or ingested SAST and SCA, look for secrets beyond git, assess continuous-integration posture, and produce SBOMs. The distinctive choice is discovering the toolchain and correlating it, not replacing every engine.

Explore Legit Security

Chainguard / Hardened rebuilds and provenance

Chainguard

Chainguard supplies hardened open-source containers, libraries, and virtual machines rebuilt with component inventories and build-provenance evidence. Evaluate compatibility and the evidence accompanying each artifact. Replacing a base image still leaves first-party application code and added third-party dependencies for the team to assess.

Explore Chainguard

JFrog / Artifact-registry security

JFrog Xray, Advanced Security, and Curation

JFrog centers security on the artifact registry. Xray provides dependency analysis on artifacts already in Artifactory. Advanced Security is a documented add-on with Enterprise X or Enterprise+ that adds contextual analysis, SAST, secrets, and infrastructure as code. Curation addresses package intake. The teaching choice is registry admission and artifact context, not an IDE-first scanner.

Explore JFrog Xray, Advanced Security, and Curation

DLP / DSPM / 14 PROFILES

Data protection & posture

Read the field guide ↗

Microsoft / Classification, DLP and posture

Microsoft Purview Data Security

Microsoft Purview brings together tools for finding sensitive information, labeling it, examining exposure, and applying data loss prevention policies. For practitioners, the useful distinction is between identifying a sensitive document and enforcing a rule when someone shares that document.

Explore Microsoft Purview Data Security

Varonis / Data posture and access governance

Varonis Data Security Platform

Varonis examines sensitive information together with the permissions and activity around it. Its central teaching example is an ordinary file that becomes risky because a broad group or public link can access it, even when the storage service itself is configured correctly.

Explore Varonis Data Security Platform

Cyera / Data posture and DLP orchestration

Cyera Data Security

Cyera discovers sensitive data and relates it to exposure across supported cloud, software-as-a-service and other repositories. Its platform also describes DLP orchestration and identity capabilities, so a learner should ask which component finds risk, which changes access, and which inspects actual data movement.

Explore Cyera Data Security

BigID / Discovery, posture and privacy governance

BigID

BigID connects security and privacy work through an inventory of sensitive data. Discovery and classification help identify what is stored; posture analysis adds exposure and access context. A shared inventory can support several teams without making privacy workflow and DLP enforcement the same control.

Explore BigID

Securiti AI / Data discovery and governance

Securiti AI within Veeam

Securiti AI contributes data discovery, classification, posture and privacy governance to Veeam’s portfolio. These capabilities help explain where sensitive information resides and how it is handled. Their relationship to backup and recovery is useful to study, but a combined corporate portfolio is not automatically one integrated deployment.

Explore Securiti AI within Veeam

Forcepoint / Enterprise DLP across channels

Forcepoint DLP

Forcepoint DLP applies content policies across documented endpoint, email, web and cloud channels. The practical task is translating a data-handling rule into detection and an appropriate action, while preserving legitimate work. Its separate posture offering can inform that task by identifying sensitive information and exposure.

Explore Forcepoint DLP

Proofpoint / Email, cloud and endpoint DLP

Proofpoint Enterprise DLP

Proofpoint’s data loss prevention portfolio combines content inspection with user activity and threat context. An email sent to the wrong recipient and a departing employee’s unusual copying behavior illustrate different investigations. The same vendor’s email, cloud, endpoint and posture offerings still need separate coverage decisions.

Explore Proofpoint Enterprise DLP

Symantec Enterprise / Hybrid enterprise DLP

Symantec Data Loss Prevention

Symantec Data Loss Prevention, documented by Broadcom, uses a policy and detection architecture for discovering sensitive content and inspecting its movement. Matching a protected customer dataset is different from matching a generic pattern, so the detection method matters as much as the channel carrying the content.

Explore Symantec Data Loss Prevention

Netskope / Cloud, web and endpoint DLP

Netskope One DLP

Netskope One DLP inspects sensitive information across documented cloud, web and other channels. It can combine inline inspection with API-based examination of SaaS content. These are different observation points: a routed upload, a stored document and an offline endpoint do not have the same enforcement path.

Explore Netskope One DLP

Zscaler / Inline, endpoint and SaaS DLP

Zscaler Data Loss Prevention

Zscaler DLP applies content policy through cloud inspection, endpoint and supported SaaS controls. A practitioner needs to distinguish inspection of an outbound connection from scanning data already stored in an application. A shared policy interface does not eliminate differences in routing, clients or supported remediation actions.

Explore Zscaler Data Loss Prevention

Nightfall AI / SaaS, browser and AI DLP

Nightfall AI

Nightfall AI focuses on sensitive information in collaboration tools, browsers and AI workflows. Its useful learning scenario is a developer or analyst pasting synthetic sensitive content into an application. Discovery, classification and prevention depend on how the specific application and device are connected to the product.

Explore Nightfall AI

Rubrik / Data posture with recovery context

Rubrik Security Cloud DSPM

Rubrik’s data security posture management identifies sensitive information and exposure alongside a broader recovery portfolio. The educational value is connecting data importance to security and recovery decisions. Discovery, permission analysis, channel blocking and restoring a backup are distinct operations, even when one vendor supplies several of them.

Explore Rubrik Security Cloud DSPM

IBM / Database activity and data posture

IBM Guardium Data Security

IBM Guardium includes database activity monitoring, data protection and cloud posture products. Monitoring who queries a sensitive table teaches a different control from finding an exposed cloud dataset. The brand spans these jobs, so product names and deployment boundaries are important parts of an evaluation.

Explore IBM Guardium Data Security

Imperva / Data-store monitoring and protection

Thales Imperva Data Security Fabric

Thales Imperva Data Security Fabric examines activity and risk around data stores. The wider Thales portfolio also provides encryption, tokenization and key management through CipherTrust. These capabilities can complement one another, but observing a database query and controlling the encryption key are different security responsibilities.

Explore Thales Imperva Data Security Fabric

SOAR / MDR / 18 PROFILES

Response orchestration & managed operations

Read the field guide ↗

Palo Alto Networks / SOAR / automation software

Cortex XSOAR and XSIAM

Cortex XSOAR is standalone security orchestration software with playbooks, a war room, marketplace content, and case management. Cortex XSIAM is a separate converged operations platform that embeds SIEM, XDR, and SOAR, including playbooks, Quick Actions, and automation rules.

Explore Cortex XSOAR and XSIAM

Cisco / SOAR / automation software

Splunk SOAR

Splunk SOAR is licensed orchestration software, offered in cloud and on-premises forms, that automates playbooks and case management. Cisco owns Splunk. This profile is the software playbook plane, not a Cisco managed detection and response service.

Explore Splunk SOAR

Google / SOAR / automation software

Google Security Operations SOAR

Google Security Operations SOAR connects alerts, cases and response playbooks within Google’s security operations platform. Integrations and custom actions let analysts gather context and coordinate supported response steps, while the operating team remains responsible for permissions, workflow design and approvals.

Explore Google Security Operations SOAR

Tines / SOAR / automation software

Tines

Tines is a practitioner-oriented workflow platform used as security automation without a classic SOAR label. Analysts can build drag-and-drop or natural-language workflows with an audit trail, case templates, and vendor-agnostic APIs.

Explore Tines

Torq / SOAR / automation software

Torq

Torq sells workflow automation often marketed as AI SOC or hyperautomation. Documented building blocks include HyperAgents, a Socrates orchestrator, natural-language workflow building, and case handling. Outcome statistics on vendor pages are advertised, not independently tested here.

Explore Torq

Swimlane / SOAR / automation software

Turbine

Swimlane Turbine is a pure-play automation platform that claims SOC plus governance, risk, and vulnerability workflow uses. It offers a low-code canvas, case management, API connectors, and agentic routing of simple versus complex alerts.

Explore Turbine

Fortinet / SOAR / automation software

FortiSOAR

FortiSOAR is Fortinet's fabric-adjacent security orchestration product with SaaS and self-managed options. It documents playbooks, case management, expert agents, API and MCP connections, and multi-tenancy aimed at managed service providers. OT-oriented packs are advertised.

Explore FortiSOAR

Rapid7 / SOAR / automation software

Rapid7 Automation

Rapid7 Automation, documented under the InsightConnect name, provides security workflows that connect tools, enrich alerts and coordinate response. Analysts can combine plugins and human decision steps to make a repeatable process while retaining responsibility for its permissions and operation.

Explore Rapid7 Automation

CrowdStrike / Managed detection and response

Falcon Complete

Falcon Complete is CrowdStrike's native-platform managed detection and response service. Provider analysts detect, investigate, and, when contracted, remediate using Falcon telemetry across endpoint, identity, cloud, SaaS, and optional third-party sources through Next-Gen SIEM.

Explore Falcon Complete

Microsoft / Managed detection and response

Defender Experts MDR

Defender Experts MDR is Microsoft-staffed managed detection and response that augments a customer security operations center. It was renamed from Defender Experts for XDR. Neither plan is an incident-response engagement, and Plan 2 is not managed SIEM.

Explore Defender Experts MDR

Sophos / Managed detection and response

Sophos MDR

Sophos MDR is a staffed managed detection and response service with around-the-clock monitoring, hunting, containment, flexible response modes, and third-party telemetry options. Secureworks is not a second vendor; Sophos closed that acquisition.

Explore Sophos MDR

Arctic Wolf / Managed detection and response

Aurora MDR

Aurora MDR is Arctic Wolf's concierge managed detection and response service. It advertises around-the-clock detect, respond, and remediate guidance, a Concierge Experience, and open XDR integrations. Cylance is an acquired endpoint product, not a peer MDR company.

Explore Aurora MDR

Expel / Managed detection and response

Expel MDR

Expel MDR is a vendor-agnostic staffed service that investigates threats on the customer's existing endpoint, identity, and cloud tools. A workbench, around-the-clock SOC, and AI-assisted investigation (Ruxie) are advertised. Auto-remediation needs pre-authorization after analyst validation.

Explore Expel MDR

Zscaler / Managed detection and response

Zscaler MDR

Zscaler MDR provides staffed investigation of supported endpoint, cloud and identity threats. Its portal, automation and validation capabilities help customer teams understand provider findings and test the service. The Red Canary lineage is relevant when identifying current documentation and service entitlements.

Explore Zscaler MDR

eSentire / Managed detection and response

eSentire MDR

eSentire MDR is a multi-signal staffed service packaged as Atlas Essentials, Advanced, and Complete. It advertises around-the-clock hunt, investigate, and respond across endpoint, network, log, cloud, and identity packages, with Microsoft-ecosystem MXDR listed in Azure Marketplace.

Explore eSentire MDR

Huntress / Managed detection and response

Huntress

Huntress offers managed endpoint, identity and log-monitoring services supported by a staffed security operations center. Its portfolio is relevant to IT teams and managed service providers evaluating which operational responsibilities to delegate and which product layers they actually need.

Explore Huntress

Rapid7 / Managed detection and response

Rapid7 MDR

Rapid7 MDR combines a staffed security operations center, an advisor, hunting and exposure-informed investigations. The service works with customer teams under an agreed scope, so learners should distinguish provider investigation and response duties from the separate Rapid7 Automation software.

Explore Rapid7 MDR

SentinelOne / Managed detection and response

Wayfinder MDR

Wayfinder MDR is SentinelOne's current platform-linked managed detection and response service. It advertises continuous detection, investigation, response, and hunting using SentinelOne and Google threat intelligence, with Essentials and Elite service levels. Older Vigilance and Singularity MDR materials are lineage, not the current order form.

Explore Wayfinder MDR

Find your next idea.

Tip: press / to open search. Escape closes this window.