Top Tools / August 18, 2026
StartupStash

The world's biggest online directory of resources and tools for startups and the most upvoted product on ProductHunt History.

Best Cloud Detection and Response Tools in 2026

A stolen API key or a console login without MFA does not wait for your next CSPM scan. Cloud Detection and Response is the live layer: control-plane logs, eBPF syscalls, identity anomalies, AI-agent tool calls.

It is not another name for XDR, MDR, or a CNAPP posture graph. Those products inventory risk. CDR pages a SOC while the RunInstances burst, the SES quota hike, or the reverse shell is still in flight.

Four products we would actually shortlist in 2026: Wiz Defend, Orca Security CDR, Sysdig (the page is still titled CDR; the Secure UI renamed the module Threat Detection on 26 Feb 2026), and Sweet Security.

We read the four product pages, the four AWS Marketplace listings, and blogs and changelogs from the last month. Vendor pages quote 10x MTTR, 90 percent faster resolve, and a 5/5/5 clock. Treat those as vendor claims. After that we stick to pages, marketplace rates, and dated changelogs.

Someone on HN watched 600 instances spin up in three hours before AWS sent a health event.

Wiz Defend

wiz-defend homepage

Wiz Defend is the detection-and-response add-on on top of Wiz Advanced. On the product page that means eBPF signals from the Wiz Sensor, analysis of cloud and SaaS logs, and agentless context from the Security Graph, with the Blue Agent doing AI triage.

The runtime piece was not born in-house. In April 2024 Wiz bought Gem Security, a CDR startup, for around $350 million — Reuters, quoted on HN when Google's $32 billion bid landed. The listing is still sold as Wiz.

The Sensor is a separate add-on to Defend. It watches VMs, containers, serverless containers, and — as of 22 Jun 2026 — Windows.

Wiz's FAQ Is Wiz a Runtime Security Tool? dates the rest: runtime network telemetry into the Security Graph (25 Jun 2026), Forensics GA (27 May), Cloud Run detection (19 May, after Fargate and Azure Container Apps), Blue Agent GA for all Defend customers (30 Mar), AI runtime detections (20 Mar). They say the Sensor ships with 2,000-plus built-in rules.

Inside the last 30 days, Agentless Threat Detection (next to a 20 Jul 2026 wp2shell post) puts Defend Agentless Workload Detection in Preview Hub for appliance logs that will not take an EDR agent — FortiGate, PAN-OS, BeyondTrust, Redis, WordPress.

Wiz Sensor for Developer Workstations is Private Preview on Windows and macOS; detections feed Wiz Defend Threats. No published-on date on that page.

Wiz publishes a Redis figure for Blue Agent on that same FAQ: Justin Lachesky, Director of Cyber Resilience, 431 cases since October 2025, 85.7 percent accuracy, false-negative rate below 2 percent. Vendor-blog, customer-reported.

Best for:
Teams already on Wiz Advanced that want control-plane and SaaS-log CDR plus an optional eBPF sensor, and that will pay the extra SKUs.

Key Features:

  • Wiz Defend sells the eBPF Sensor as an add-on, on VMs, Kubernetes, serverless containers, and Windows.
  • CIRA, ITDR, DDR, enriched by the Security Graph; Blue Agent GA 30 Mar 2026.
  • AI runtime: prompt injection, model exfiltration, MCP server attacks.
  • Agentless Workload Detection (Preview Hub) for appliance logs.

Why we like it:
The only SKU here priced as a log-ingest add-on on a public card, and the only one that writes runtime edges (live container-to-container, DNS to a database, an AI workload reaching an MCP server) back onto the same graph the buyer already uses for attack paths.

Notable Limitations:

  • You cannot buy Defend without Wiz Advanced. Sensor is a second add-on. Full runtime is a three-SKU stack.
  • Defend meters 300 GB of logs per month per unit. Burst past a unit and you buy another.
  • Agentless Workload Detection and the workstation Sensor are preview / private preview, not GA.
  • Marketplace reviews (Austin H., 4 Aug 2026; a government admin, 6 Aug 2026) flag cost-per-workload and incomplete vuln scanners. Syndicated listing reviews, not a G2 score.

Pricing:
AWS Marketplace, 12-month table: Essential $24,000 / 100 workloads; Advanced $38,000 / 100; Sensor $28,000 / 100 sensors (Advanced add-on). Defend: $18,000 / 300 GB of logs per month, Advanced add-on. Wiz Code ($58,500 / 100 licenses) is on the same card but is not a CDR SKU. Private Offer: marketplace@wiz.io. Marketplace rating 4.7 / 885 — not a G2 score.

Orca Security CDR

orca-cdr homepage

Orca's CDR page does not hedge: detect, investigate, and respond to cloud attacks in progress, not an EDR/XDR port. Schema last modified 16 Jul 2026.

The default path is agentless — 24×7 cloud-provider logs and threat-intel feeds, correlated with SideScanning™ workload and configuration context — plus an optional Orca Sensor (eBPF) on critical workloads. That page was last modified 16 Jul 2026 too.

Detect, investigate, respond. Alerts prioritize events that endanger crown-jewel assets. Investigation is cloud-agnostic event language plus SQL or a catalog query. Response is automated workflows, AI-written remediation text, and 50-plus integrations; the page names GuardDuty, Microsoft Defender for Cloud, GCP Security Command Center, Jira, ServiceNow, Splunk, Sumo Logic, and IBM QRadar.

Founded 1 Dec 2019 by Gil Geron and Avi Shua.

Last 30 days: both product pages on 16 Jul 2026, and on 21 Jul a Claude Compliance API integration (read-only org, identity, project, and chat metadata, not content).

AI-governance telemetry, not a new syscall pack — but it is the dated product post in the window. RSAC 2026 (16 Mar) added a Threat Investigation Agent; outside the window, kept as background.

A PeerSpot review on the AWS listing (Guilherme Ferreira Mury, 29 Jul 2026) is the Sensor caveat: "We had experience with the Orca Sensor, but we did not think it brings too much value to our current environment, so we decided to remove it." Budget a Sensor pilot. Do not assume you will keep it.

Best for:
Lean multi-cloud teams that want log-and-context CDR without an agent everywhere, and that will add the Sensor only where exec-time visibility is worth the rollout.

Key Features:

  • Agentless CDR: cloud logs + threat intel + SideScanning.
  • Optional eBPF Sensor (process, file, DNS, network, fileless / memory).
  • Unified investigation (SQL or catalog); 50-plus integrations including native-cloud detections.
  • AI remediation text; Threat Investigation Agent since RSAC 2026.

Why we like it:
The only one of the four that still argues, in 2026, that most CDR signal is in the control plane and the snapshot, and that the agent is the exception.

Notable Limitations:

  • Agentless CDR will not see a reverse shell the moment it execs. That is the Sensor, and at least one published reviewer removed it.
  • Marketplace list prices are the CNAPP platform, not a standalone CDR SKU. Extra licensing is Private Offer (the listing says so).
  • The specified listing does not print host counts inside Small through Large.
  • 14 Aug 2026 blogs (SOC automation, agentic AI) are not CDR changelogs.

Pricing:
AWS Marketplace. 1-month packs (concurrent EC2): Small $7,000; Small-Medium $12,000; Medium $17,000; Large $30,000 / month. A 12-month tab is on the page; we did not capture that table. Extra licensing is Private Offer (express path also listed). Free trial offered. Marketplace rating 4.7 / 344 (24 AWS, 320 external) — not a G2 score.

Sysdig CDR

sysdig-cdr homepage

Sysdig is the Falco company, and the CDR page still sells that: customizable rules on the Falco engine across Linux and Windows servers, containers and Kubernetes, cloud logs and trails, and serverless / FaaS.

The 555 Benchmark from the 27 Oct 2023 release is still the header: 5 seconds to detect, 5 minutes to correlate, 5 minutes to respond. On 26 Feb 2026 the Secure notes renamed the module Threat Detection. The public URL is unchanged.

Last 30 days: the Falco Rules Changelog ran from 0.254.3 (1 Jul 2026) through 0.256.1 on 18 Aug 2026. In-window: Azure / Entra rules (7 Jul), FP cuts on Execution from /tmp and IMDS-exfil (6–22 Jul), new "Unauthorized Process Manipulated {Gemini, Claude Code, Codex} CLI Configuration Directory" rules (31 Jul).

On 31 Jul the Runtime Remediation Skill entered public beta (human-gated, Sysdig MCP). On 4 Aug, Sysdig Secure AI.

A listing review (Syed Shahid A., 29 Apr 2026) called out "excellent real-time visibility into cloud-native and containerized environments." PeerSpot (Mumu Muhaemin, 27 Dec 2025): setup is complex if the team is new to Kubernetes.

Best for:
Platform and SOC teams whose production is Kubernetes and containers, who already speak Falco or want the managed rule feed, and who will run an agent.

Key Features:

  • Falco detections on hosts, containers, Kubernetes, cloud logs, and FaaS.
  • Identity correlation (exploit + privilege escalation / account compromise).
  • Managed Falco changelog; AI-CLI rules since 17 Mar 2026, still tuned in July–August.
  • Runtime Remediation Skill (public beta, 31 Jul 2026); Sysdig Secure AI (4 Aug 2026).

Why we like it:
The only vendor here with a dated, rule-level changelog a SOC can read on a Tuesday. Version 0.256.1 landed on 18 Aug 2026.

Notable Limitations:

  • CDR-the-page is Threat Detection-the-module. RFP language will drift.
  • Public Marketplace units start at 20 and then meter host-hours, serverless host-hours, and $2.50 per cloud-log event. Log-heavy CDR can dwarf the $72 unit.
  • Agent deploy and policy tuning are the work. Reviewers on the listing say so.
  • 555 and the "5-minute investigation" line are Sysdig's framework and a product-page claim.

Pricing:
AWS Marketplace. 1-month: CNAPP Enterprise $72.00 / unit / month (min 20 units); Monitor Enterprise Host $36.00 / unit / month (min 20). 12-month tab says "save up to 17%"; we did not capture that table. Overage that matters for CDR: CNAPP $0.13/host-hr, Cloud Logs $2.50/event, Secure D&R — CaaS $0.02/serverless host-hr (full overage table is on the listing). Private offers: salesops@sysdig.com. Marketplace rating 4.7 / 120 — not a G2 score.

Sweet Security

sweet-security homepage

Sweet is the runtime-first of the four. Sweet Detection & Response unifies CDR, CWPP, and ADR on a lean eBPF sensor plus cloud logs, then sells an AI Storyline, impact scores, and playbooks that terminate a process without (they say) taking production down.

Founded 2023; CEO Dror Kashti. The 29 Jul 2026 release lists $120 million from Evolution Equity, Munich Re Ventures, Glilot, and Key1 Capital.

Last 30 days: Agentic AI Blocking on 29 Jul 2026 (unauthorized tool calls, secrets/PII leaving through an agent, live prompt-injection block). The release also claims "over one billion" runtime events daily. On 17 Aug, Chris Lentricchia posted Policy Debt. Investigator shipped 23 Jun 2026, just outside the window.

Product-page quotes, not our interviews: Oded Blatman (CISO, Fireblocks), Nir Yizhak (CISO), Tal Hornstein (CIO & CISO). AWS reviews are thin — 6 ratings, all AWS.

Prajwal Chougale (15 Jul 2026) said it cut SIEM false positives versus Defender-for-Cloud + Sentinel. Filippos Malandrakis (27 Feb 2026) flagged the UI and would not bet it on "hundreds or thousands of Kubernetes clusters"; he measured the sensor at "around three hundred megabytes" RAM and "around three percent of one core." One reviewer, not an SLA.

Best for:
Teams that want a runtime-first CDR/ADR/CWPP console — especially if they also need to block rogue AI-agent behavior — and that will accept a younger vendor.

Key Features:

  • Unified CDR + CWPP + ADR over eBPF + cloud logs.
  • AI Storyline; playbooks; optional process kill.
  • Agentic AI Blocking, 29 Jul 2026.
  • Investigator: one query, promote to a detection (23 Jun 2026).

Why we like it:
The only listing that sells blocking as the default story, and the only AWS card that splits log-based (Primary) from comprehensive (Advanced) runtime protection. That split is the buying question.

Notable Limitations:

  • Six AWS Marketplace ratings. That is not a sample.
  • Reviewers (Malandrakis, 27 Feb 2026; a UK distributor, 10 Apr 2026) call out maturity versus Wiz / Palo Alto. The distributor wrote that production issues "resolved within about an hour or two." Reviewer claims.
  • Homepage 90 / 300 / 80 percent figures are vendor claims.

Pricing:
AWS Marketplace. 12-month: Primary $50,000 / 100 workloads (log-based); Advanced $60,000 / 100 workloads (comprehensive). Private offers available. Support: support@sweet.security and a dedicated Slack channel. Marketplace rating 4.3 / 6, all AWS — not a G2 score.

Someone else on HN already had prevention. Detection was the hole:

you learn that there's no intrusion detection, so if someone did gain access, it would be difficult to identify that such access had been obtained.

Honorable mentions, and what we left out

Falco (CNCF graduated, created at Sysdig) if you will write the rules yourself — not a CDR console. GuardDuty, Defender for Cloud, SCC are the native feeds Orca and Sysdig ingest; one cloud, one account, start there. CrowdStrike, Prisma Cloud, Defender XDR, SentinelOne, and generic CNAPP/XDR/MDR are out of scope: posture or endpoint-first XDR, not this list.

The remaining question is not which logo. It is which plane.

log CDR versus runtime sensor

Questions we would ask before a CDR POC

Is CDR just XDR or CNAPP with a new badge?

No. CNAPP inventories posture and attack paths. XDR is typically endpoint telemetry with a cloud connector. CDR pages a SOC while a control-plane burst or a syscall is still in flight.

If the walkthrough never leaves the posture graph, you are not in a CDR POC.

Do I need the sensor if I already buy the log SKU?

Only if the POC attack is exec-time. The log SKU meters CloudTrail-class events; it does not see execve. If the replay is a reverse shell, a miner, or an AI-CLI credential read, you are buying Wiz Sensor, Orca Sensor, Sysdig/Falco, or Sweet Advanced — not proving the log unit.

One published Orca reviewer ran the Sensor and then removed it; budget a week and decide.

Can I buy Wiz Defend without Wiz Advanced?

Not on the public AWS Marketplace card. Defend is listed as an Advanced add-on; the Sensor is a second add-on on Defend. Full runtime is a three-SKU stack.

If Advanced is not already on the contract, the incremental quote is not the Defend line by itself.

Why does Sysdig's $72 unit not predict the bill?

The $72 figure is CNAPP Enterprise per unit per month, with a 20-unit floor. Cloud-log CDR also meters $2.50 per event, and host-hours meter separately at $0.13. A noisy trail can dwarf the unit floor. Ask for a 30-day event-volume estimate before you put 20 × $72 in the budget.

AWS Marketplace list prices

Public AWS cards, checked this week. Private offers exist on all four. Orca and Sysdig have 12-month tabs; we did not capture those tables. Ratings on the cards are Marketplace scores, not G2.

Listing Public dimensions
Wiz Advanced $38,000 / 100 workloads / 12 mo. Defend $18,000 / 300 GB logs per month (Advanced add-on). Sensor $28,000 / 100 (Advanced add-on).
Orca 1-month concurrent-EC2 packs: Small $7,000; Small-Medium $12,000; Medium $17,000; Large $30,000. Extra licensing is Private Offer.
Sysdig CNAPP Enterprise $72 / unit / month (min 20). Overage that matters for CDR: $0.13 / host-hr, $2.50 / cloud-log event, CaaS $0.02 / serverless host-hr.
Sweet Primary $50,000 / 100 workloads / 12 mo (log-based). Advanced $60,000 / 100 / 12 mo (comprehensive).

Bottom Line on Cloud Detection and Response Tools

A CloudTrail burst and a reverse shell are not the same purchase, even when they sit on one vendor page. Buy the log unit for the first. Buy the sensor for the second. A CNAPP walkthrough is neither.

Wiz is a three-line add-on on an Advanced contract — Defend, then Sensor, each a separate yes. Orca will tell you the agent is the exception; one published reviewer agreed and pulled it. Sysdig is the Falco feed that still ships rules mid-week; the unit floor is not the bill. Sweet is the younger console that will kill a process and, as of 29 Jul 2026, an unauthorized agent tool-call, on six AWS ratings.

Replay one attack on the SKU you will pay for. If the POC cannot name the plane, stop the demo.

List your product on Startup Stash

A listing is not a paid rank on this page.
Get listed

About the author

How we review tools

Written by

StartupStash

Editorial team

The team behind Startup Stash. We write the Top Tools shortlists, check first-party product pages and dated changelogs, and put a date on the prices. Catalog counts on vendor sites stay vendor claims.

Reviewed by

Manaal

Content Manager, Startup Stash

Manaal is Content Manager at Startup Stash. She reviews the shortlist, the priced claims, and the sourcing before a Top Tools piece goes live.

Best Cloud Detection and Response...
StartupStash

The world's biggest online directory of resources and tools for startups and the most upvoted product on ProductHunt History.