Skip to content

Dynatrace

Publicly traded observability platform whose Application Security module uses runtime instrumentation, rather than standalone scanning, to detect and prioritize open-source and application vulnerabilities in production.

Visit Website ↗ + Add to Compare
68/100Incremental Innovator

Overview

Dynatrace is a publicly traded (NYSE: DT) observability and application performance monitoring platform, founded in 2005 in Linz, Austria and now headquartered in Waltham, Massachusetts. Its Application Security module, Runtime Vulnerability Analytics, is built on top of the same OneAgent instrumentation the company already uses for performance monitoring: rather than running a separate static or dynamic scan, it continuously watches custom code, open-source libraries, and container and language runtimes as they actually execute in pre-production and production, flagging vulnerable code paths that are reachable and in use.

The distinguishing idea is context. Because Dynatrace already tracks data flows, dependency graphs, and execution paths for performance purposes, it can attach real runtime evidence to a CVE, telling a team whether a vulnerable library function is actually invoked, exposed to the internet, or handling sensitive data, rather than surfacing every match a dependency scan finds regardless of exploitability. That reachability-based prioritization is the module’s core pitch against traditional SAST/DAST and software composition analysis tools that scan code or artifacts without full runtime context.

As a module bolted onto a much larger observability suite, Application Security’s adoption and roadmap are tied to Dynatrace’s broader platform strategy rather than existing as a standalone security product; its main competitors are more purpose-built application and cloud security posture vendors. For organizations already running Dynatrace OneAgent at scale, though, it turns performance telemetry they are already collecting into a genuine, low-friction vulnerability prioritization signal.

Innovation Matrix Assessment

Innovation Velocity 7/10

As a public company with roughly $2B in annual revenue, Dynatrace ships continuous platform updates and has extended Application Security with AI-driven (Davis AI) risk scoring; release cadence is well documented in its quarterly product release notes.

Operational Value 7/10

Runtime Vulnerability Analytics reuses the same OneAgent instrumentation already deployed for performance monitoring, so customers get vulnerability detection without deploying a separate scanning agent, though it only covers workloads already instrumented for observability.

Market Momentum 7/10

Dynatrace has grown Application Security adoption alongside strong overall platform revenue growth (public SEC filings show continued double-digit ARR growth), though the company does not break out Application Security-specific revenue or customer counts.

Category Disruption 6/10

Runtime-based, reachability-aware vulnerability prioritization is a genuinely different approach from static SCA/SAST scanning, but Dynatrace is applying an existing observability capability to security rather than introducing a new detection paradigm to the market.

Real-World Efficacy 6/10

The reachability analysis is grounded in real execution data rather than static heuristics, which should reduce false positives in principle, but no independent third-party benchmark of Application Security's detection accuracy was found; effectiveness claims are largely vendor-documented.

Enduring Relevance 8/10

Runtime vulnerability prioritization addresses a well-documented pain point (alert overload from dependency scanners) that is increasingly acute for cloud-native and Kubernetes-heavy environments, which is exactly where Dynatrace's core observability install base already sits.

Why CISOs Should Care

Turns performance-monitoring instrumentation CISOs' engineering teams are likely already running into a vulnerability prioritization signal, cutting noise from dependency scanners without a new agent rollout.

What Makes It Different

Prioritizes vulnerabilities by actual runtime reachability and exposure rather than static dependency matching, using the same execution-path data Dynatrace collects for performance monitoring.

The Matrix Verdict

68/100 — INCREMENTAL INNOVATOR

A credible, low-friction vulnerability prioritization capability for organizations already standardized on Dynatrace's observability platform; it is not a standalone application security product and should be evaluated as a module within a larger platform decision rather than against dedicated AppSec vendors on feature parity alone.

Editorial Note: Claims vs. Verified Findings

Dynatrace's own product documentation and press materials describe the reachability-analysis mechanism; this is independently plausible given Dynatrace's established OneAgent architecture, but no independent third-party study benchmarking Application Security's false-positive or detection rates was found, so efficacy claims should be treated as vendor-reported.

Sources