Cloud posture tools tell you what is misconfigured. CDR tools tell you when someone is actively abusing the environment. A compromised AWS identity calling RunInstances is a CDR problem, even if the account looked fine an hour earlier. That gap is Cloud Detection and Response. CDR is the live layer: cloud and control-plane logs, a runtime sensor on the host or cluster, identity anomalies, and now AI-agent tool calls. Posture inventories risk. CDR pages a SOC while the attack is still in flight.
That pitch hides two purchases in one line. A log plan bills CloudTrail-class events. It does not see execve. A runtime sensor sees the reverse shell, the miner, or the AI-CLI credential read. Some of those products are add-ons on a CNAPP you already pay for. Some are the runtime product itself. A SIEM pack that tails CloudTrail is a different product. If the product mainly shows cloud misconfigurations, it is still focused on posture management. CDR should also detect suspicious activity while workloads are running. We checked these names against first-party product pages, public prices, and recent product changes. Details are on How we review tools.
Ownership moved too. Google completed its acquisition of Wiz on 11 March 2026. Wiz joined Google Cloud, kept the Wiz brand, and remains a multicloud product - AWS, Azure, GCP, and Oracle. You are buying a Google Cloud company that still sells Wiz Defend as Wiz, not a disappearing independent.
We compared six tools on that split: cloud logs versus a runtime sensor, add-on versus the runtime product, and whether a public listing will predict the bill. If you already live in Wiz and want detection on that graph, start with Wiz Defend, and budget the Sensor as a second yes. If you want agentless coverage without a new sensor fleet, Orca is the argument. If the hole is containers and you will run their agent, Sysdig is the Falco feed. If the story is identity-to-workload in the cloud runtime, and you will accept a younger vendor, Sweet Security is the blocking console. If you already run Microsoft Defender, Defender for Cloud can hand cloud runtime alerts to Defender XDR without a second SOC platform. If you already run Cortex or want runtime block plus Unit 42 playbooks, Cortex Cloud CDR is the named Palo Alto product.
What usually goes wrong when buying cloud detection and response
The quote often names CDR. The proof is usually a different kind of detection.
| Problem | Solution |
|---|---|
| The walkthrough never leaves a CSPM heatmap | Ask for a vendor page that names detection while an attack is still in flight, not only posture of a public bucket |
| The quote is a log plan, but the proof is a reverse shell or a miner | Buy a runtime sensor. Cloud and control-plane logs will not see exec-time |
| The product only works if you already own that CNAPP | Check whether you can buy detection without the platform you already run, and which line is the add-on |
| Retention and ingest look cheap until the first noisy week | Ask how extra log volume, host-hours, or another 100-workload block is billed |
How we evaluated cloud detection and response tools
A tool had to name a current cloud detection and response product, make it clear whether detection is cloud logs, a runtime sensor, or both, say whether you can buy it without a CNAPP you already own, and show how extra volume is billed. Vendor pages that quote 10x MTTR or a 5/5/5 clock did not move a ranking. Neighbor products sit under What we left out.
TL;DR: The Six Compared
| Tool | Best For | Pricing Model | Highlights |
|---|---|---|---|
| Wiz Defend | Already on Wiz Advanced and want detection on that graph | AWS: Defend $18,000 / 300 GB of logs per month on Advanced. Sensor $28,000 / 100 sensors | Log ingest add-on. Sensor is a second add-on. You cannot buy Defend without Advanced |
| Orca Security | Lean multi-cloud teams that want log-and-context CDR without an agent everywhere | AWS 1-month packs: Small $7,000; Small-Medium $12,000; Medium $17,000; Large $30,000 / month | Agentless default: cloud logs plus SideScanning. Optional eBPF sensor. Host counts inside the packs are not printed |
| Sysdig | Kubernetes and containers, if you will run an agent and want a Falco feed | AWS: CNAPP Enterprise $72.00 / unit / month, min 20 units. Overages on host-hours and $2.50 / cloud-log event | Falco on hosts, containers, Kubernetes, and cloud logs. Dated rule changelog. A noisy trail can dwarf the $72 unit |
| Sweet Security | A runtime-first console that will block a rogue agent tool-call | AWS 12-month: Primary $50,000 / 100 workloads (log-based). Advanced $60,000 / 100 (comprehensive) | eBPF plus cloud logs. Blocking is the story. Six AWS Marketplace ratings |
| Microsoft Defender for Cloud | Azure-heavy SOCs that want cloud runtime detections inside Defender XDR | First 30 days free, then public Azure prices. Foundational CSPM is Free. Workload plans extra | Runtime sensor plus control-plane correlation. Alerts into Defender XDR. No single product named CDR |
| Palo Alto Cortex Cloud CDR | CloudSec plus SecOps teams that want runtime block on Cortex Cloud | Quote-only. Sold inside Cortex Cloud | Lightweight agent, 13,000+ detectors, Unit 42 intel, 1,000+ playbooks. Living name is Cortex Cloud CDR |
Wiz Defend

Wiz Defend is the detection-and-response add-on on top of Wiz Advanced. On the product page that means eBPF signals from the Wiz Sensor, analysis of cloud and SaaS logs, and agentless context from the Security Graph, with the Blue Agent doing AI triage. The runtime piece was not born in-house. In April 2024 Wiz bought Gem Security. Google then completed its acquisition of Wiz on 11 March 2026. Wiz joined Google Cloud, kept the brand, and still sells across AWS, Azure, GCP, and Oracle. The listing is still sold as Wiz.
The Sensor is a separate add-on to Defend. It watches VMs, containers, serverless containers, and, since 22 Jun 2026, Windows. Blue Agent went GA for all Defend customers on 30 Mar 2026. Agentless Workload Detection sits in Preview Hub for appliance logs that will not take an EDR agent. Wiz Sensor for Developer Workstations is Private Preview on Windows and macOS. You cannot buy Defend without Wiz Advanced. Full runtime is Advanced, then Defend, then the Sensor.
Best for: Teams already on Wiz Advanced that want control-plane and SaaS-log CDR plus an optional eBPF sensor, and that will pay the extra lines.
What you get:
- Defend as a log-ingest add-on, billed at 300 GB of logs per month per unit.
- The eBPF Sensor as a second add-on, on VMs, Kubernetes, serverless containers, and Windows.
- CIRA, ITDR, DDR, enriched by the Security Graph; Blue Agent GA 30 Mar 2026.
- AI runtime detections: prompt injection, model exfiltration, MCP server attacks. Agentless Workload Detection remains preview.
Why we like it: Defend writes live runtime edges - container-to-container, DNS to a database, an AI workload reaching an MCP server - back onto the same Security Graph the buyer already uses for attack paths. That is the reason to stay on Wiz instead of adding a second CDR console.
Limits:
- You cannot buy Defend without Wiz Advanced. Sensor is a second add-on.
- Defend is billed at 300 GB of logs per month per unit. Burst past a unit and you buy another. The listing does not say what happens mid-month.
- Agentless Workload Detection and the workstation Sensor are preview / private preview.
- Marketplace reviews flag cost-per-workload and incomplete vuln scanners.
Price: AWS Marketplace, 12-month table: Essential $24,000 / 100 workloads; Advanced $38,000 / 100; Sensor $28,000 / 100 sensors (Advanced add-on). Defend: $18,000 / 300 GB of logs per month, Advanced add-on. Wiz Code is on the same listing at $58,500 / 100 licenses and is not a CDR product. Private offers: marketplace@wiz.io.
Before buying
Ask whether Advanced is already on the contract. If it is not, the incremental quote is not the Defend line by itself. Ask what happens if you burst past 300 GB mid-month.
Orca Security

Orca’s CDR page does not hedge: detect, investigate, and respond to cloud attacks in progress. The default path is agentless: 24×7 cloud-provider logs and threat-intel feeds, correlated with SideScanning workload and configuration context, plus an optional Orca Sensor (eBPF) on critical workloads.
Alerts prioritize events that endanger crown-jewel assets. Investigation is cloud-agnostic event language plus SQL or a catalog query. Response is automated workflows, AI-written remediation text, and 50-plus integrations; the page names GuardDuty, Microsoft Defender for Cloud, GCP Security Command Center, Jira, ServiceNow, Splunk, Sumo Logic, and IBM QRadar. A published Marketplace reviewer ran the Sensor and then removed it. Budget a Sensor week. Do not assume you will keep it. Agentless CDR will not see a reverse shell the moment it execs. That is the Sensor.
Best for: Lean multi-cloud teams that want log-and-context CDR without an agent everywhere, and that will add the Sensor only where exec-time visibility is worth the rollout.
What you get:
- Agentless CDR: cloud logs + threat intel + SideScanning.
- Optional eBPF Sensor (process, file, DNS, network, fileless / memory).
- Unified investigation (SQL or catalog); 50-plus integrations including native-cloud detections.
- AI remediation text; Threat Investigation Agent since RSAC 2026.
Why we like it: Orca still argues that most detection signal is in cloud logs and the snapshot, and that a sensor is the exception you add on critical workloads. That is the lightest default rollout on this list if you will not run an agent everywhere.
Limits:
- Agentless CDR will not see a reverse shell the moment it execs.
- Marketplace list prices are the CNAPP platform. Extra licensing is Private Offer - the listing says so.
- The specified listing does not print host counts inside Small through Large.
Price: AWS Marketplace. 1-month packs (concurrent EC2): Small $7,000; Small-Medium $12,000; Medium $17,000; Large $30,000 / month. A 12-month tab is on the page. Extra licensing is Private Offer. Free trial offered.
Before buying
Ask how many concurrent EC2 the Small through Large packs actually cover. If the quote cannot name a host count, you are buying a pack name.
Sysdig

Sysdig is the Falco company, and the CDR page still sells that: customizable rules on the Falco engine across Linux and Windows servers, containers and Kubernetes, cloud logs and trails, and serverless / FaaS. On 26 Feb 2026 the Secure notes renamed the module Threat Detection. The public URL is unchanged. RFP language will drift.
The Falco Rules Changelog ran through 0.256.1 on 18 Aug 2026. Unauthorized writes to Gemini, Claude Code, and Codex CLI configuration directories are now a dated rule. That is evidence the category moved: CDR has to see an AI-agent tool call while it is still in flight. The 555 Benchmark (5 seconds to detect, 5 minutes to correlate, 5 minutes to respond) is still the header. Treat it as the vendor’s framework, not a clock you were handed.
Best for: Platform and SOC teams whose production is Kubernetes and containers, who already speak Falco or want the managed rule feed, and who will run an agent.
What you get:
- Falco detections on hosts, containers, Kubernetes, cloud logs, and FaaS.
- Identity correlation (exploit + privilege escalation / account compromise).
- A dated, rule-level changelog a SOC can read on a Tuesday. AI-CLI rules since 17 Mar 2026, still tuned through 0.256.1.
- Runtime Remediation Skill (public beta, 31 Jul 2026); Sysdig Secure AI (4 Aug 2026).
Why we like it: The dated Falco changelog is the product. Version 0.256.1 landed on 18 Aug 2026. If the write is an unauthorized AI-CLI config change, this is the shortlist, not a SIEM pack.
Limits:
- The public page still says CDR. The Secure notes renamed the module Threat Detection.
- Public Marketplace units start at 20 and then bill host-hours, serverless host-hours, and $2.50 per cloud-log event. Log-heavy CDR can dwarf the $72 unit.
- Agent deploy and policy tuning are the work. Reviewers on the listing say so.
- 555 and the “5-minute investigation” line are Sysdig’s framework and a product-page claim.
Price: AWS Marketplace. CNAPP Enterprise starts at $72.00 / unit / month (min 20 units). Custom and private-offer units are a sales conversation.
Before buying
Ask for a 30-day event-volume estimate before you lock a unit count into the budget. A noisy trail can dwarf the $72.00 floor.
Sweet Security

Sweet Security takes the most runtime-first approach in this comparison. Sweet Detection & Response unifies CDR, CWPP, and ADR on a lean eBPF sensor plus cloud logs, then sells an AI Storyline, impact scores, and playbooks that terminate a process without (they say) taking production down. Founded 2023. The 29 Jul 2026 release lists $120 million from Evolution Equity, Munich Re Ventures, Glilot, and Key1 Capital.
Agentic AI Blocking shipped 29 Jul 2026: unauthorized tool calls, secrets/PII leaving through an agent, live prompt-injection block. Investigator shipped 23 Jun 2026: one query, promote to a detection. The AWS listing splits log-based (Primary) from comprehensive (Advanced) runtime protection. That split is the buying question. AWS reviews are thin: 6 ratings, all AWS. Homepage 90 / 300 / 80 percent figures are marketing.
Best for: Teams that want a runtime-first CDR/ADR/CWPP console, especially if they also need to block rogue AI-agent behavior, and that will accept a younger vendor.
What you get:
- Unified CDR + CWPP + ADR over eBPF + cloud logs.
- AI Storyline; playbooks; optional process kill.
- Agentic AI Blocking, 29 Jul 2026.
- Investigator: one query, promote to a detection (23 Jun 2026).
Why we like it: Sweet will block a rogue agent tool-call as the default story, and you can choose log-based Primary or comprehensive Advanced on the same 100-workload block.
Limits:
- Six AWS Marketplace ratings. That is not a sample.
- Reviewers call out maturity versus larger CNAPP suites. Treat those as reviewer claims.
- Homepage percentage figures are marketing.
Price: AWS Marketplace. 12-month: Primary $50,000 / 100 workloads (log-based); Advanced $60,000 / 100 workloads (comprehensive). Private offers available. Support: support@sweet.security and a dedicated Slack channel.
Microsoft Defender for Cloud

Microsoft Defender for Cloud is Microsoft’s CNAPP with an explicit cloud detection and response story. A runtime eBPF sensor watches process, network, and Kubernetes activity. Those signals are correlated with control-plane and identity events, then mapped to MITRE ATT&CK and handed to Microsoft Defender XDR. The product page puts that detection inside the Microsoft Defender portal, across Azure, AWS, GCP, and Arc. First-party language also covers investigating container incidents and isolating compromised pods.
There is no single product named CDR. You buy Foundational CSPM (Free) plus workload plans such as Servers, Containers, SQL, and Storage, then use Defender XDR for the SOC console. Sentinel is the SIEM, not this product. The first 30 days are free. After that, Azure list prices apply. Foundational CSPM stays Free; runtime detection sits on the workload plans. Microsoft also publishes Defender CSPM as a paid posture plan. GuardDuty and Security Command Center remain single-cloud native feeds. They are not this row.
Best for: Azure-heavy SOCs that want cloud runtime detections inside Defender XDR, without introducing another security platform.
What you get:
- Runtime eBPF sensor for process, network, and Kubernetes, plus control-plane and identity correlation.
- MITRE-mapped alerts handed to Microsoft Defender XDR. Isolate compromised pods from the same story.
- Multicloud coverage on Azure, AWS, GCP, and Arc, next to CSPM, DevOps security, and workload plans.
- Public Azure prices after a 30-day trial. Foundational CSPM is Free.
Why we like it: Azure-heavy SOCs can combine cloud runtime detections with Defender XDR without introducing another security platform. The workload plans are on a public price list, so you can start a model before a sales cycle.
Limits:
- There is no single product named CDR. Confirm which workload plans are on the quote.
- Sentinel is the SIEM. Defender for Cloud is not a SIEM pack by itself.
- Foundational CSPM is posture. Runtime detection is on the paid workload plans.
- Malware scanning and some overages bill from day one, outside the 30-day free window.
Price: First 30 days free, then Azure list prices on Defender for Cloud pricing. Foundational CSPM is Free. East US retail on 25 Aug 2026 included Servers Plan 2 at $0.02/hour and Containers at $0.00941 per vCore-hour. Defender CSPM Standard listed at $0.007/hour per node. Confirm the current region price and which plans you need.
Before buying
Ask which workload plans are on the quote (Servers Plan 1 vs Plan 2, Containers, Storage) and whether the SOC will use Defender XDR or Sentinel. Free Foundational CSPM is not the runtime line.
Palo Alto Cortex Cloud CDR

Palo Alto Cortex Cloud CDR is the living Cloud Detection and Response product on Cortex Cloud, the current name for what buyers still call Prisma Cloud. A lightweight agent blocks malware, exploits, and fileless attacks in the cloud runtime. The page lists 13,000+ detectors infused with Unit 42 threat intelligence, and it names credential theft, cryptomining, reverse shells, suspicious tokens, and anomalous users as in-scope detections.
Incidents are risk-prioritized and mapped to MITRE ATT&CK. Response is autonomous agents plus more than 1,000 playbooks, aimed at CloudSec and SecOps working in the same Cortex Cloud console. Packaging sits inside Cortex Cloud, not a cheap standalone pack. There is no public dollar rate. Do not order this as Prisma Cloud CDR. CrowdStrike and SentinelOne are endpoint-first XDR. They are a different shortlist.
Best for: CloudSec plus SecOps teams that want runtime detection and blocking on Cortex Cloud, not a SIEM rule pack and not a second specialist console.
What you get:
- A named Cortex Cloud CDR product with a lightweight runtime agent that can block, not only alert.
- 13,000+ detectors plus Unit 42 threat intelligence on credential theft, cryptomining, reverse shells, and suspicious tokens.
- MITRE-mapped, risk-prioritized incidents for investigation.
- Autonomous response plus more than 1,000 playbooks inside Cortex Cloud workflows.
Why we like it: You get runtime detection, blocking, Unit 42 intelligence, and SecOps playbooks in the Cortex Cloud console you may already run, instead of adding a specialist CDR and a SIEM rule pack.
Limits:
- Quote-only. There is no public per-workload or per-sensor rate.
- Packaging sits inside Cortex Cloud. Ask whether the quote is CDR or a broader Cloud / CNAPP bundle.
- The living 2026 name is Cortex Cloud CDR. A Prisma Cloud CDR line on an old order form is the wrong label.
Price: Quote-only. There is no public per-workload or per-sensor rate. Order it as Cortex Cloud CDR, not Prisma Cloud CDR.
Before buying
Ask for Cortex Cloud CDR by that name, and whether the quote includes the runtime agent and playbooks or only posture. If the line still says Prisma Cloud CDR, you are ordering last year’s name.
How it detects attacks, and is it an add-on?
This grid plots two questions. Across is how it detects attacks: cloud and control-plane logs on the left, a runtime sensor on the right. Up is the commercial split: an add-on on a CNAPP you already buy at the top, the runtime product itself at the bottom.
Placement follows first-party product language: Defend as an Advanced log add-on, Orca’s agentless default on CNAPP packs, Sysdig’s Falco agent, Sweet’s Primary / Advanced split, Defender for Cloud’s runtime sensor plus XDR handoff, and Cortex Cloud CDR’s agent runtime. Wiz Sensor is a second add-on on Defend, so it is not a separate logo here. This is a map of the products, not a ranking.
Pricing and usage costs compared
| Tool | How pricing works | What extra usage costs |
|---|---|---|
| Wiz Defend | Log ingest add-on on Wiz Advanced. Sensor is a second add-on | Defend is the log add-on on Advanced. Another unit if you pass 300 GB. Sensor and Advanced are separate lines |
| Orca Security | Monthly CNAPP packs. Extra licensing, including the Sensor, is a private offer | $7,000 / $12,000 / $17,000 / $30,000 per month for Small through Large. Host counts inside the packs are not printed |
| Sysdig | Per-unit CNAPP fee, then host-hours and cloud-log events | $72.00 / unit / month, min 20 units. Extra usage after the unit is custom |
| Sweet Security | 12-month 100-workload blocks. Primary is log-based. Advanced is comprehensive runtime | Primary $50,000 / 100 workloads. Advanced $60,000 / 100. Another block if you grow past 100 |
| Microsoft Defender for Cloud | Public Azure prices after 30 days. Foundational CSPM is Free. Workload plans extra | Billed per plan and region. East US list on 25 Aug 2026 included Servers Plan 2 at $0.02/hour and Containers at $0.00941 per vCore-hour. XDR / Sentinel is a separate console |
| Palo Alto Cortex Cloud CDR | Quote-only inside Cortex Cloud | No public per-workload or per-sensor rate. Confirm Cortex Cloud CDR, not Prisma Cloud CDR |
What we left out
These are real products. We left each one off because it is a rule engine, a single-cloud native feed, an endpoint console, or a CNAPP module under a new name.
- Falco is CNCF graduated and was created at Sysdig. The right mention if you will write the rules yourself. It is a rule engine without the SOC console.
- GuardDuty and Security Command Center are the native single-cloud feeds. One cloud, one account, start there. They are not a multi-cloud CDR platform. Defender for Cloud is on this list as the Azure runtime-plus-XDR row.
- CrowdStrike and SentinelOne are endpoint-first XDR. Out of scope for this shortlist.
- Lacework / FortiCNAPP is not a living standalone Lacework product. FortiCNAPP is a CNAPP with a CDR module, not a dedicated CDR bake-off name.
- A SIEM pack that tails CloudTrail is a different product. It will not see execve.
Questions before you buy a CDR tool
A quote that cannot name these three is still a posture scan with a new badge.
- How does it detect the attack you will replay? A log plan bills CloudTrail-class events. It does not see
execve. If the replay is a reverse shell, a miner, or an AI-CLI credential read, you are buying a runtime sensor. - Is this an add-on on a platform you already pay for? Defend without Advanced is not on the public listing. A CNAPP pack is not automatically the Sensor.
- How does extra volume bill? 300 GB, host-hours, $2.50 cloud-log events, and 100-workload blocks all charge the noisy week. Ask for a 30-day volume estimate, not a 5/5/5 slide.
Which CDR tool should you pick
Already on Wiz Advanced: Defend on the 300 GB log add-on, then the Sensor as a second yes. Agentless coverage without a new fleet: Orca, and decide whether you keep the Sensor. Containers and a Falco feed you will run: Sysdig, knowing the $72.00 unit is not the bill. Runtime-first, and you will block a rogue agent tool-call: Sweet Security, on six AWS ratings. Azure runtime plus XDR: Microsoft Defender for Cloud, public Azure prices after 30 days. Agent runtime on Cortex Cloud: Cortex Cloud CDR, quote, not “Prisma Cloud CDR.” Replay one attack on the product you will pay for. If the proof cannot name logs versus a runtime sensor, it is not a CDR proof.
Frequently asked questions
Is CDR just XDR or CNAPP with a new badge?
No. CNAPP inventories posture and attack paths. XDR is typically endpoint telemetry with a cloud connector. CDR pages a SOC while a control-plane burst or a syscall is still in flight. If the walkthrough never leaves the posture graph, you are not in a CDR POC.
Do I need the sensor if I already buy the log plan?
Only if the POC attack is exec-time. The log plan bills CloudTrail-class events; it does not see execve. If the replay is a reverse shell, a miner, or an AI-CLI credential read, you are buying Wiz Sensor, Orca Sensor, Sysdig / Falco, or Sweet Advanced. One published Orca reviewer ran the Sensor and then removed it. Budget a week and decide.
Can I buy Wiz Defend without Wiz Advanced?
Not on the public AWS Marketplace listing. Defend is listed as an Advanced add-on. The Sensor is a second add-on. Full runtime is Advanced, then Defend, then the Sensor. If Advanced is not already on the contract, the incremental quote is not the Defend line by itself.




