State of the space ·
All eight still price by coverage
From posture alerts to closed-loop response
Runtime detection in cloud environments started as an open-source project rather than a packaged agent: Sysdig released Falco in 2016 as a kernel-level runtime detection tool, and the company later layered its own investigation and response logic on top of it. Sysdig extended that engine in 2024 with Sysdig Sage, a runtime investigation agent that correlates cloud telemetry into an incident narrative for the analyst.
Wiz, which built its early business on cloud posture scanning, moved into live incident work in 2024 when it launched Wiz Defend at its RSA Conference announcement, adding runtime sensors and threat detection to the existing posture graph. Sweet Security and Upwind, both founded in 2022, and Stream.Security, founded in 2021, each shipped runtime detection and response agents between 2022 and 2023, arriving as purpose-built cloud detection and response products rather than posture tools extended into runtime.
Vendors in this category have converged on consumption-based pricing tied to the cloud resources under watch rather than to seat counts, reflecting a buyer base of cloud security engineers who already think in workload and account terms. Wiz folds Defend into its existing per-workload consumption model, so a customer already paying for posture coverage adds runtime detection against the same unit instead of negotiating a separate meter, according to Wiz's product materials.
Sysdig prices Sysdig Secure, which includes its runtime detection and the newer Sage investigation agent, on a per-node and per-container consumption basis common to cloud security tooling, with published list pricing not made public and quotes handled through sales. Sweet Security, Stream.Security, and Upwind have not published list pricing; pricing not public for all three as of this edition, with each vendor directing prospective buyers to a sales-led quote process anchored to cloud account or workload count. Sources: https://www.wiz.io/blog/wiz-defend; https://sysdig.com/blog/introducing-sysdig-sage/; https://sweet.security/; https://www.streamsecurity.ai/; https://www.upwind.io/
Sources:category analysis,NDR comparison,Vendr
May - Aug 2026 ·gold = a monetization move· grey = product, market, or capital
Procurement data published this year gives the clearest picture yet of how the category actually transacts.Darktrace lists 12 to 22% above Vectraand 8 to 18% above ExtraHop for the same NDR scope, and multi-module bundles routinely close 15 to 30% below list. Since the Thoma Bravo acquisition, buyers report that Darktrace discounts less on small deals and more on the large multi-module ones. The pricing model itself has not moved, and what has changed is how hard buyers push against it.
Source:VendorBenchmark,Vendr
A newer group of agentic SOC vendors has started selling directly against this category. Their argument, as they make it, is that detection quality has become similar across vendors and thatthe valuable work is the triage, investigation, and response after an alert fires. We report that as their sales claim, and we note that it is aimed at work the NDR vendors genuinely perform with AI and do not charge for as a separate item.
Source:market analysis
At RSAC 2026,CrowdStrike, Cisco, and Palo Alto all released agentic SOC productsthat take NDR data as input and sell the triage and investigation layer separately. The vendors on this map now share the alert pipeline with platform agents that charge for steps NDR includes in coverage.
Source:VentureBeat
The category's center of gravity keeps moving toward the cloud.The younger half of this map detects from cloud telemetry instead of network appliances, and all four established vendors now sell cloud sensors alongside their original deployments. Buying guides published this year treat cloud and OT coverage as standard evaluation criteria instead of extras.
Source:category review
2016 to 2026: from open-source runtime detection to closed-loop cloud response
Darktrace listed on the London Stock Exchange, and Bain Capital took ExtraHop private at about $900 million. The whole category priced by devices, sensors, and bandwidth in those years, largely because that is what security budgets were set up to buy.
Investors and buyers began questioning what "AI-powered" actually meant across the category, and vendors answered by competing on the quality of their signal instead of the volume of it. Vectra planted its flag on fewer, higher-confidence detections during this period. The pricing models came through the scrutiny untouched.
Ownership changed hands. Thoma Bravo took Darktrace private for about $5.3 billion, Cisco closed its $28 billion purchase of Splunk, and Corelight raised $150 million to keep building the evidence layer. The new owners tightened the existing coverage model instead of replacing it.
Darktrace bought Cado Security and folded cloud forensics into its autonomous investigation product, while generative assistants for summarizing and investigating alerts spread across the rest of the category. Product autonomy kept increasing while the pricing metrics stayed exactly where they were.
Autonomous SOC platforms now run triage and investigation on top of NDR signal and sell that layer as a product of its own. NDR pricing, for now, remains coverage-based.
Journalist first, analyst second
About this data
Everything on this page is a synthesis of public information: published reporting, analyst coverage, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.