Dynatrace
Publicly traded observability platform whose Application Security module uses runtime instrumentation, rather than standalone scanning, to detect and prioritize open-source and application vulnerabilities in production.
Visit Website ↗ + Add to CompareOverview
Dynatrace is a publicly traded (NYSE: DT) observability and application performance monitoring platform, founded in 2005 in Linz, Austria and now headquartered in Waltham, Massachusetts. Its Application Security module, Runtime Vulnerability Analytics, is built on top of the same OneAgent instrumentation the company already uses for performance monitoring: rather than running a separate static or dynamic scan, it continuously watches custom code, open-source libraries, and container and language runtimes as they actually execute in pre-production and production, flagging vulnerable code paths that are reachable and in use.
The distinguishing idea is context. Because Dynatrace already tracks data flows, dependency graphs, and execution paths for performance purposes, it can attach real runtime evidence to a CVE, telling a team whether a vulnerable library function is actually invoked, exposed to the internet, or handling sensitive data, rather than surfacing every match a dependency scan finds regardless of exploitability. That reachability-based prioritization is the module’s core pitch against traditional SAST/DAST and software composition analysis tools that scan code or artifacts without full runtime context.
As a module bolted onto a much larger observability suite, Application Security’s adoption and roadmap are tied to Dynatrace’s broader platform strategy rather than existing as a standalone security product; its main competitors are more purpose-built application and cloud security posture vendors. For organizations already running Dynatrace OneAgent at scale, though, it turns performance telemetry they are already collecting into a genuine, low-friction vulnerability prioritization signal.
Innovation Matrix Assessment
As a public company with roughly $2B in annual revenue, Dynatrace ships continuous platform updates and has extended Application Security with AI-driven (Davis AI) risk scoring; release cadence is well documented in its quarterly product release notes.
Runtime Vulnerability Analytics reuses the same OneAgent instrumentation already deployed for performance monitoring, so customers get vulnerability detection without deploying a separate scanning agent, though it only covers workloads already instrumented for observability.
Dynatrace has grown Application Security adoption alongside strong overall platform revenue growth (public SEC filings show continued double-digit ARR growth), though the company does not break out Application Security-specific revenue or customer counts.
Runtime-based, reachability-aware vulnerability prioritization is a genuinely different approach from static SCA/SAST scanning, but Dynatrace is applying an existing observability capability to security rather than introducing a new detection paradigm to the market.
The reachability analysis is grounded in real execution data rather than static heuristics, which should reduce false positives in principle, but no independent third-party benchmark of Application Security's detection accuracy was found; effectiveness claims are largely vendor-documented.
Runtime vulnerability prioritization addresses a well-documented pain point (alert overload from dependency scanners) that is increasingly acute for cloud-native and Kubernetes-heavy environments, which is exactly where Dynatrace's core observability install base already sits.
Why CISOs Should Care
Turns performance-monitoring instrumentation CISOs' engineering teams are likely already running into a vulnerability prioritization signal, cutting noise from dependency scanners without a new agent rollout.
What Makes It Different
Prioritizes vulnerabilities by actual runtime reachability and exposure rather than static dependency matching, using the same execution-path data Dynatrace collects for performance monitoring.
The Matrix Verdict
68/100 — INCREMENTAL INNOVATOR
A credible, low-friction vulnerability prioritization capability for organizations already standardized on Dynatrace's observability platform; it is not a standalone application security product and should be evaluated as a module within a larger platform decision rather than against dedicated AppSec vendors on feature parity alone.
Editorial Note: Claims vs. Verified Findings
Dynatrace's own product documentation and press materials describe the reachability-analysis mechanism; this is independently plausible given Dynatrace's established OneAgent architecture, but no independent third-party study benchmarking Application Security's false-positive or detection rates was found, so efficacy claims should be treated as vendor-reported.
Sources
Alternatives to Dynatrace
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…