State of the space ·

Cloud Defense Agents

The AMS Map plots five cloud defense agent vendors across agent independence, job width, and output to cost, with each chip carrying its pricing metric.
The quadrant, Aug 2026 ·open full page →· this file does not change after publish

All eight still price by coverage

Cloud Defense Agents detect, investigate, and contain incidents inside live cloud runtime environments, reading cloud-native telemetry such as API calls, workload identities, and container process activity against a model of the customer's own cloud footprint. The roster spans agents that surface a ranked alert for a human analyst to close and agents that trace a lateral-movement path across accounts and quarantine the workload without a ticket. Wiz priced its Defend module into the same per-workload consumption meter that already covers its posture scanning, tying detection revenue to a unit customers already budget against, according to Wiz's own product announcement.

1per-workload consumption pricingPositions: Monetizely analysisPublic data only
5 / 5
roster vendors versus tracked candidates in cloud runtime detection and response
3 of 5
vendors publishing consumption or workload-based pricing for cloud runtime agents
2024
year cloud detection and response shipped as a distinct, incident-closing product line

Who is on this map

No items found.
Two vendors on this roster carry established evidence: Sysdig, which built its runtime detection engine on the open-source Falco project it created in 2016 and has since scaled past $100 million in annual recurring revenue with hundreds of paying customers, and Wiz, whose Defend module extends a platform reportedly generating several hundred million dollars in annual recurring revenue and used across a large share of large enterprises. Three vendors sit in emerging territory on funding and named-customer traction: Sweet Security, Stream.Security, and Upwind, each shipping a runtime agent and each raising institutional rounds inside the last two years. All five seed candidates met the charter's minimum bar of a shipped detection-to-containment product plus verifiable funding or customer signal, so no seed dropped to the tracked-only list this edition. Vendors that scan cloud posture without acting on live incidents, or that route through network appliance and sensor work instead of cloud-native telemetry, stay out of this roster under the category's own routing rule and graduate in only once they ship an incident-closing agent.
No seed vendor fell short of the roster bar this edition; all five candidates named in the charter shipped a runtime detection-to-containment product with verifiable funding or customer evidence.

What this category does

Products in this category ingest cloud-native telemetry - API call logs, workload identity events, container and process traces, and configuration change feeds - and hold a live model of the customer's cloud accounts, identities, and network paths. Agents use that model to flag anomalous behavior, trace how far an intrusion has spread across accounts and services, and take a contas the case includes response action, from killing a process to revoking a credential to isolating a workload.
Security engineers still decide which flagged incidents warrant escalation to legal, customer notification, or law enforcement, and they still tune detection logic against each organization's normal traffic patterns to hold down false positives. SOC analysts covering cloud environments remain responsible for post-incident reporting, cross-team coordination during a live breach, and sign-off on any containment action that could disrupt production workloads.
The task list agents can take over
  1. Detect - flag anomalous cloud runtime behavior against a live model of the customer's own environment.
  2. Investigate - trace the blast radius of an alert across identities, workloads, and network paths.
  3. Contain - isolate or kill a compromised workload, revoke a credential, or quarantine a container.
  4. Correlate - link cloud-native telemetry, including API logs, kernel-level traces, and identity events, into a single incident timeline.

The agentic shift

From posture alerts to closed-loop response

Runtime detection in cloud environments started as an open-source project rather than a packaged agent: Sysdig released Falco in 2016 as a kernel-level runtime detection tool, and the company later layered its own investigation and response logic on top of it. Sysdig extended that engine in 2024 with Sysdig Sage, a runtime investigation agent that correlates cloud telemetry into an incident narrative for the analyst.

Wiz, which built its early business on cloud posture scanning, moved into live incident work in 2024 when it launched Wiz Defend at its RSA Conference announcement, adding runtime sensors and threat detection to the existing posture graph. Sweet Security and Upwind, both founded in 2022, and Stream.Security, founded in 2021, each shipped runtime detection and response agents between 2022 and 2023, arriving as purpose-built cloud detection and response products rather than posture tools extended into runtime.

Vendors in this category have converged on consumption-based pricing tied to the cloud resources under watch rather than to seat counts, reflecting a buyer base of cloud security engineers who already think in workload and account terms. Wiz folds Defend into its existing per-workload consumption model, so a customer already paying for posture coverage adds runtime detection against the same unit instead of negotiating a separate meter, according to Wiz's product materials.

Sysdig prices Sysdig Secure, which includes its runtime detection and the newer Sage investigation agent, on a per-node and per-container consumption basis common to cloud security tooling, with published list pricing not made public and quotes handled through sales. Sweet Security, Stream.Security, and Upwind have not published list pricing; pricing not public for all three as of this edition, with each vendor directing prospective buyers to a sales-led quote process anchored to cloud account or workload count. Sources: https://www.wiz.io/blog/wiz-defend; https://sysdig.com/blog/introducing-sysdig-sage/; https://sweet.security/; https://www.streamsecurity.ai/; https://www.upwind.io/

Sources:category analysis,NDR comparison,Vendr

Observed monetization patterns
  1. Consumption tied to workload count - Wiz bills Defend against the same per-workload meter used for its posture product.
  2. Module add-on to an existing platform - Sysdig Sage ships as an addition to Sysdig Secure rather than a standalone line item.
  3. Sales-led quoting with pricing not public - Sweet Security, Stream.Security, and Upwind route pricing through direct sales conversations tied to cloud account scale.

This quarter

May - Aug 2026 ·gold = a monetization move· grey = product, market, or capital

Pricing

Procurement data published this year gives the clearest picture yet of how the category actually transacts.Darktrace lists 12 to 22% above Vectraand 8 to 18% above ExtraHop for the same NDR scope, and multi-module bundles routinely close 15 to 30% below list. Since the Thoma Bravo acquisition, buyers report that Darktrace discounts less on small deals and more on the large multi-module ones. The pricing model itself has not moved, and what has changed is how hard buyers push against it.

Source:VendorBenchmark,Vendr

Competitive wedge

A newer group of agentic SOC vendors has started selling directly against this category. Their argument, as they make it, is that detection quality has become similar across vendors and thatthe valuable work is the triage, investigation, and response after an alert fires. We report that as their sales claim, and we note that it is aimed at work the NDR vendors genuinely perform with AI and do not charge for as a separate item.

Source:market analysis

Platform pressure

At RSAC 2026,CrowdStrike, Cisco, and Palo Alto all released agentic SOC productsthat take NDR data as input and sell the triage and investigation layer separately. The vendors on this map now share the alert pipeline with platform agents that charge for steps NDR includes in coverage.

Source:VentureBeat

Market

The category's center of gravity keeps moving toward the cloud.The younger half of this map detects from cloud telemetry instead of network appliances, and all four established vendors now sell cloud sensors alongside their original deployments. Buying guides published this year treat cloud and OT coverage as standard evaluation criteria instead of extras.

Source:category review

The long arc

2016 to 2026: from open-source runtime detection to closed-loop cloud response

2021
APPLIANCE PRICING

Darktrace listed on the London Stock Exchange, and Bain Capital took ExtraHop private at about $900 million. The whole category priced by devices, sensors, and bandwidth in those years, largely because that is what security budgets were set up to buy.

2023
AI SCRUTINY

Investors and buyers began questioning what "AI-powered" actually meant across the category, and vendors answered by competing on the quality of their signal instead of the volume of it. Vectra planted its flag on fewer, higher-confidence detections during this period. The pricing models came through the scrutiny untouched.

2024
CONSOLIDATION

Ownership changed hands. Thoma Bravo took Darktrace private for about $5.3 billion, Cisco closed its $28 billion purchase of Splunk, and Corelight raised $150 million to keep building the evidence layer. The new owners tightened the existing coverage model instead of replacing it.

2025
INVESTIGATION DEEPENS

Darktrace bought Cado Security and folded cloud forensics into its autonomous investigation product, while generative assistants for summarizing and investigating alerts spread across the rest of the category. Product autonomy kept increasing while the pricing metrics stayed exactly where they were.

2026
AGENTIC COMPETITION

Autonomous SOC platforms now run triage and investigation on top of NDR signal and sell that layer as a product of its own. NDR pricing, for now, remains coverage-based.

Vendor by vendor

Journalist first, analyst second

Method:we work journalist first and analyst second. We document the agentic products each vendor actually ships, with sources a reader can check, and the AMS placement follows from that documented capability. Vendors with no shipped agentic product stay on the quadrant and out of this section. We report how each vendor charges today, and we do not use this page to advise vendors on what to charge.
No items found.

Not covered

Corelight builds the evidence pipeline that most of the other tools on this page depend on, on top of  Zeek, one of the most widely used network analysis frameworks in security. When we went looking for a shipped  product that triages, investigates, or responds on its own, we did not find one, so Corelight stays on the quadrant and out of the breakdown section. The same finding applies to Netography, which provides flow observability at scale. If either company ships an agentic product, it enters this section in the edition that documents it.

About this data

Everything on this page is a synthesis of public information: published reporting, analyst coverage, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.