
Cloud Security
Oligo Cloud Application Detection & Response (CADR)
Runtime application security detecting exploits via eBPF library-level behavioral analysis.
Oligo Cloud Application Detection & Response (CADR) Overview
What it does
Oligo CADR is a Cloud Application Detection and Response (CADR) platform that detects and blocks application-layer and software supply chain exploitation in running cloud workloads. Its eBPF sensor watches library and function execution inside the Linux kernel, profiling each library's legitimate behavior and flagging deviations in real time. This surfaces zero-day exploits, malicious packages, shadow vulnerabilities, and exploitation caused by misuse or misconfiguration across software the organization builds, buys, and uses, including third-party commercial software.
How it works
The platform's patented eBPF sensor deploys in minutes with no code changes and less than 1% CPU overhead, covering Kubernetes and cloud-native environments as well as legacy on-premises applications. It builds a behavioral baseline for each library from that library's use in applications worldwide, then correlates deviations with call stacks and process trees across applications, workloads, hosts, and cloud environments. Technique-based protections block exploitation at the function and syscall level, with a single rule covering entire vulnerability classes, and generates a real-time bill of materials and Vulnerability Exploitability eXchange (VEX) evidence from the libraries that actually execute in production.
Credentials and traction
Oligo appears on the 2026 Fortune Cyber 60 list of top private cybersecurity companies, its second consecutive year, and on Fast Company's Most Innovative Companies of 2026 and the Rising in Cyber 2026 list. It was named a 2025 SINET16 Innovator, selected by more than 100 CISOs and risk executives, and recognized as both a Cloud Security Innovator and a CADR leader in the Latio 2025 Cloud Security Market Report; it also earned the SC Media Best Supply Chain Security Solution award in 2024. Customers include Salesforce, ServiceNow, Databricks, Instacart, and SoFi.
Key Capabilities
mapped to solution categoriesDetects exploitation of unknown vulnerabilities by analyzing runtime behavior rather than matching known attack signatures, protecting against vulnerabilities before CVE publication.
Verifies the integrity of application code, resources, and the execution environment at runtime, detecting repackaging, method hooking, and dynamic instrumentation such as Frida, and triggering a defensive response when tampering is detected.
Performs in-process interception and threat analysis with minimal latency impact, keeping the agent viable in production workloads with overhead varying by product.
Detects and blocks injection at the sink where untrusted input reaches dangerous operations, covering SQL and NoSQL injection, command injection, XXE, path traversal, and SSRF.
Streams runtime attack evidence such as blocked exploit attempts and suspicious invocations to SIEM, SOAR, and APM platforms, commonly via OpenTelemetry.
Operate in monitor-only mode (log and alert), or active blocking mode (terminate request upon detection). Most deployments begin in monitor mode to establish a false positive baseline before enabling blocking.
Instruments runtimes to intercept database queries, command execution, and deserialization across Java, .NET, Python, Node.js, PHP, Ruby, and Go, with coverage depth varying by product.
Blocks exploitation of known vulnerabilities at runtime without source code changes, reducing exposure during the gap before a deployed fix, especially on legacy or hard-to-patch applications.
Detects attacks at the application and API layer at runtime using behavioral signals such as unexpected process behavior, suspicious API calls, unusual service-to-service communication, and exploit activity across cloud apps, containers, and Kubernetes.
Triggers automated response actions (session revocation, account suspension, OAuth grant removal), in SaaS platforms in response to confirmed detections via platform APIs.
Monitors user, admin, and OAuth app activity within SaaS platforms (M365, Google Workspace, Salesforce, GitHub), for anomalies and policy violations using API-based log ingestion.
Detects misuse of OAuth access tokens granted to connected applications, including tokens being used outside expected scope, geographic anomalies, and post-compromise app persistence.
Captures a continuous record of workload events (process, network, file, syscall) for forensic investigation of incidents in running workloads.
Mitigates workload vulnerabilities in runtime through virtual patching, workload isolation and segmentation, and management of running services and processes.
Monitors process execution, network connections, and file system activity in running workloads using a kernel agent, eBPF sensor, or sidecar container to detect behavioral anomalies and known attack patterns.
Integrations
compatible toolsImplementation & support
Info last updated on August 23, 2026
Buyers
See how Oligo Cloud Application Detection & Response (CADR) fits your stack
Add Oligo Cloud Application Detection & Response (CADR) to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.