Security Stack Logo
Oligo Cloud Application Detection & Response (CADR) logo

Cloud Security

Oligo Cloud Application Detection & Response (CADR)

Runtime application security detecting exploits via eBPF library-level behavioral analysis.

Oligo Cloud Application Detection & Response (CADR) Overview

What it does

Oligo CADR is a Cloud Application Detection and Response (CADR) platform that detects and blocks application-layer and software supply chain exploitation in running cloud workloads. Its eBPF sensor watches library and function execution inside the Linux kernel, profiling each library's legitimate behavior and flagging deviations in real time. This surfaces zero-day exploits, malicious packages, shadow vulnerabilities, and exploitation caused by misuse or misconfiguration across software the organization builds, buys, and uses, including third-party commercial software.

How it works

The platform's patented eBPF sensor deploys in minutes with no code changes and less than 1% CPU overhead, covering Kubernetes and cloud-native environments as well as legacy on-premises applications. It builds a behavioral baseline for each library from that library's use in applications worldwide, then correlates deviations with call stacks and process trees across applications, workloads, hosts, and cloud environments. Technique-based protections block exploitation at the function and syscall level, with a single rule covering entire vulnerability classes, and generates a real-time bill of materials and Vulnerability Exploitability eXchange (VEX) evidence from the libraries that actually execute in production.

Credentials and traction

Oligo appears on the 2026 Fortune Cyber 60 list of top private cybersecurity companies, its second consecutive year, and on Fast Company's Most Innovative Companies of 2026 and the Rising in Cyber 2026 list. It was named a 2025 SINET16 Innovator, selected by more than 100 CISOs and risk executives, and recognized as both a Cloud Security Innovator and a CADR leader in the Latio 2025 Cloud Security Market Report; it also earned the SC Media Best Supply Chain Security Solution award in 2024. Customers include Salesforce, ServiceNow, Databricks, Instacart, and SoFi.

Key Capabilities

mapped to solution categories
Runtime Application Self-Protection (RASP)

Operate in monitor-only mode (log and alert), or active blocking mode (terminate request upon detection). Most deployments begin in monitor mode to establish a false positive baseline before enabling blocking.

Instruments runtimes to intercept database queries, command execution, and deserialization across Java, .NET, Python, Node.js, PHP, Ruby, and Go, with coverage depth varying by product.

Performs in-process interception and threat analysis with minimal latency impact, keeping the agent viable in production workloads with overhead varying by product.

Streams runtime attack evidence such as blocked exploit attempts and suspicious invocations to SIEM, SOAR, and APM platforms, commonly via OpenTelemetry.

Detects and blocks injection at the sink where untrusted input reaches dangerous operations, covering SQL and NoSQL injection, command injection, XXE, path traversal, and SSRF.

Detects exploitation of unknown vulnerabilities by analyzing runtime behavior rather than matching known attack signatures, protecting against vulnerabilities before CVE publication.

Blocks exploitation of known vulnerabilities at runtime without source code changes, reducing exposure during the gap before a deployed fix, especially on legacy or hard-to-patch applications.

Cloud Application Detection and Response (CADR)

Detects attacks at the application and API layer at runtime using behavioral signals such as unexpected process behavior, suspicious API calls, unusual service-to-service communication, and exploit activity across cloud apps, containers, and Kubernetes.

Blocks exploitation at the function and syscall level in running workloads using technique-based rules, so a single protection covers entire vulnerability classes including CVEs not yet discovered, without proxies or added latency.

Profiles the legitimate runtime behavior of each application library, using knowledge of that library's use in applications worldwide, and detects deviations that indicate exploitation, malicious packages, or dormant malicious code activating.

Generates a bill of materials and Vulnerability Exploitability eXchange (VEX) determinations from the libraries and functions that actually execute in production, updating the risk picture in real time as running applications change.

Cloud Workload Protection Platform (CWPP)

Monitors process execution, network connections and file system activity in running workloads through a kernel agent, eBPF sensor or sidecar container to detect behavioral anomalies and known attack patterns, including runtime privilege escalation, container escape attempts and unusual outbound network activity. This is the agent-based workload protection archetype; kernel-based versus non-kernel detection methods and Windows versus Linux coverage vary across products.

Captures a continuous record of workload events (process, network, file, syscall) for forensic investigation of incidents in running workloads.

Mitigates workload vulnerabilities in runtime through virtual patching, workload isolation and segmentation, and management of running services and processes.

Blocks the underlying attack technique (for example malicious syscalls or insecure deserialization paths) inside running workloads, so one rule mitigates entire CWE classes of CVEs, including undiscovered ones, without downtime or code patches.

Profiles the legitimate runtime behavior of individual application libraries (files, sockets, syscalls each library normally uses) and alerts when a library deviates, detecting compromise below the process level without file-based signatures.

Generates software bills of materials and VEX exploitability statements from what is observed executing in running workloads, rather than from static manifests, for compliance and vulnerability triage.

Determines which vulnerable libraries and functions are actually loaded and executed in running workloads, with call stacks and root cause analysis, to prioritize exploitable vulnerabilities over theoretical ones.

Detects and remediates malware and ransomware on running virtual machines and container hosts across Windows and Linux, combining file scanning with behavioral indicators such as mass encryption, with the option of automated quarantine or process termination. Distinct from memory protection: this covers malicious files and payloads rather than in-memory exploitation techniques.

Integrations

compatible tools
AWSAzureDockerGoogle CloudKubernetesSIEMSOARThreat Intelligence

Implementation & support

Deployment model
CloudEndpoint AgentOn-Premises
Support channels
DocumentationEmail SupportKnowledge Base

Info last updated on September 7, 2026

Buyers

Start a shortlist with Oligo Cloud Application Detection & Response (CADR)

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.