Oligo Security
Runtime application detection and response (ADR) that inspects live open-source library and function behavior to catch exploitable threats in production.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Oligo Security, founded in Tel Aviv in 2022, builds an Application Detection and Response (ADR) platform that uses eBPF to continuously inspect application and open-source library behavior at runtime in production environments. Rather than flagging every CVE found by static composition scanning, Oligo profiles which libraries and functions are actually executing and reachable, aiming to separate exploitable risk from theoretical risk and to detect live exploitation attempts and anomalous behavior as they happen.
The company has raised a reported $80M total, including a $50M Series B announced in January 2025 led by Greenfield Partners with participation from Ballistic Ventures, Lightspeed Venture Partners, Red Dot Capital Partners, Strait Capital, and TLV Partners. Oligo publishes customer case studies naming Cresta, Mural, OneTrust, OpenWeb, and Sage, citing large reductions in open-source vulnerability backlogs; these figures are vendor-published and have not been independently audited.
Oligo sits in a genuinely active segment — ADR/runtime application security — alongside other vendors approaching the same problem from different angles (e.g., RASP-style and cloud workload protection players), so it is an active contributor to an emerging category rather than its sole definer.
Innovation Matrix Assessment
Shipped a differentiated eBPF-based runtime inspection approach and has iterated from seed-stage (2023 coverage) to a Series B platform in ~3 years, positioning itself early in the ADR category as it formed.
Directly targets a known CISO pain point — SCA alert fatigue from non-exploitable CVEs — by surfacing which open-source code paths are actually reachable/running, which can meaningfully cut remediation workload if the detection holds up at scale.
Independently reported $50M Series B (Jan 2025, Greenfield Partners-led) on top of prior rounds totaling $80M, AWS Marketplace listing, and named customer case studies (Cresta, Mural, OneTrust, OpenWeb, Sage) are real, traceable signals of adoption.
ADR is a genuinely emerging category and Oligo is an early, well-funded mover in it, but runtime/behavioral application protection has adjacent incumbents and competitors, so it is a strong category participant rather than an outright category-definer.
Headline efficacy numbers (e.g., >99% vulnerability reduction, 90% backlog cut in under an hour) come from vendor-published case studies, not independent third-party testing or named analyst validation, so they are scored conservatively pending outside verification.
Runtime visibility into open-source/software supply-chain risk in production is a durable, growing requirement as cloud-native and AI-assisted codebases expand dependency surfaces.
Why CISOs Should Care
Helps security teams cut through open-source CVE noise by showing which vulnerable code is actually loaded and reachable at runtime, and flags live exploitation attempts, reducing both alert fatigue and mean time to detect in production.
What Makes It Different
Uses kernel-level eBPF instrumentation to observe real application and library behavior in production rather than relying on static manifest/SBOM scanning alone, aiming to prioritize the small fraction of findings that are truly exploitable.
The Matrix Verdict
65/100 — INCREMENTAL INNOVATOR
A credible, well-capitalized runtime application security player with real customer traction, but independent, third-party-verified efficacy evidence is still limited, so it lands in the Incremental tier pending more external validation.
Editorial Note: Claims vs. Verified Findings
Funding figures ($50M Series B, $80M total) are corroborated by press coverage (SecurityWeek, BusinessWire). Customer efficacy statistics (e.g., >99% vulnerability reduction) are drawn from vendor/aggregator-published case studies and have not been independently verified; treated as vendor claims, not confirmed facts.
Sources
Alternatives to Oligo Security
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Second Front Systems
A Wilmington, DE defense-tech company whose Game Warden platform deploys commercial SaaS into DoD classified networks in 90…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…