I have been using Sweet Security for approximately one and a half years. For our organization, Sweet Security blocks injection attacks and model manipulations in our production environment. With its help, we detect and respond to runtime errors that occur on our system. Most of the time, static scanners flag thousands of theoretical vulnerabilities, causing alert fatigue for our security operations team. Sweet Security helps us track execution memory and active process behaviors and system calls to catch live attacker movements from all parts of the world. I can provide a specific example. I observed a scenario where attackers discovered a flaw in our systems on our public website. The attacker was running malicious code snippets inside our container, our static container, because no files were written to the disk. With the help of Sweet Security runtime sensor, which hooks directly into the Linux kernel, we noticed a process inside the container calling system admin privileges, something a simple web server would never do. It also detects crypto miners via runtime reachability for us. My software has 100,000 old stacks with unpatched security vulnerabilities. One of the attackers discovered that Sweet Security does not let any attacker into our systems to run any Bitcoin miners in the background.
Sweet Security is evolved for the cloud native application protection platform. It focuses specifically on protecting cloud workloads by combining runtime telemetry with cloud security postures, identity, and data deployed in AWS, Azure, Kubernetes, or any cloud environment. Sweet Security plays a crucial role in providing runtime visibility and helping security teams prioritize real-time threats that are actively occurring in production. It provides dynamic runtime information for application security rather than just static analysis. Sweet Security gives runtime visibility into cloud workloads and Kubernetes environments, correlates cloud infrastructure, workloads, identities, and application activity into a single investigation. It combines all activities related to a single identity and correlates all those alerts to make one incident, which helps SOC teams get all alerts related to that entity in one place. For organizations moving towards cloud environments, Sweet Security provides a reliable solution to protect cloud resources and supports major cloud platforms including AWS, Azure, and Kubernetes environments. Before implementing Sweet Security, we did not have a solution specifically for cloud resources. We had a SIEM integrated Microsoft Azure and Defender. After incorporating Sweet Security, we observed a significantly higher number of alerts and more reliable alerts with greater visibility into what was happening at the cloud level in the runtime dynamic timeframe. We were able to get in-depth details about cloud resource sharing, uploads, and downloads, and our SOC team utilized it across a broad range of applications. Sweet Security reduced most of the false positive alerts that we were getting through our SIEM. It provided more real-time interaction data, allowing us to identify threats more effectively. The alert logics available in the platform are very helpful for conducting in-depth investigations.
My main use case for Sweet Security as a distributor is to distribute to our partners within the UK channel, and they then take it to their customers who are looking for a cloud-native platform that offers advanced threat detection and incident response capabilities to provide deep runtime context to security teams, enabling them to quickly extract actual attack narratives. Sweet Security is designed to protect sensitive data in cloud environments, understand the environment, and respond to any threats as they occur. The platform leverages runtime insights to deliver comprehensive protection across all layers of the security stack. I can provide a specific example of how one of my partners' customers has used Sweet Security in practice. Organizations primarily utilize Sweet Security for VM vulnerability management on cloud assets, particularly with AWS, which enhances runtime visibility and enables effective threat detection. Sweet Security is integrated for runtime protection and has evolved to support broader security ranges. It allows users to visualize cloud relationships, understand dependencies, and manage vulnerabilities from a code perspective. Sweet Security provides real-time security event response for security teams.
I'm mostly using Sweet Security for real-time infrastructure security. If there is any threat, I want to detect it in real time. That's the main use case. Vulnerability management is one other benefit I am getting from Sweet Security as well.
Director of Security Operations at a tech vendor with 501-1,000 employees
Real User
Top 10
Sep 30, 2025
We are cloud native and are using Sweet Security for call runtime protection. It is much bigger than just runtime protection, but the main use case was bringing Sweet Security for runtime protection services and it grew into a platform that we can utilize for many different things. We are using it instead of a CSPM and for visualizing what we call code-to-cloud, our code-to-cloud vision, to better understand the different packages and different dependencies that we have within the cloud runtime. It helps us a lot in understanding which vulnerabilities we should tackle from the code perspective.
Cloud and compute team leader at a manufacturing company with 1,001-5,000 employees
Real User
Top 10
Sep 4, 2025
We use Sweet Security primarily for vulnerability management on all of our cloud assets, mainly AWS, but we also use it for SOC, with the SOC integration getting the events and responding to them.
Sweet Security offers advanced cybersecurity measures designed to protect enterprise-level networks from complex threats, providing efficient monitoring and robust protection capabilities.
Focused on sophisticated threat detection and network security, Sweet Security provides an enterprise-grade solution for cybersecurity challenges. It integrates seamlessly with existing systems, offering real-time analytics and threat intelligence. Its comprehensive approach ensures high-level data...
I have been using Sweet Security for approximately one and a half years. For our organization, Sweet Security blocks injection attacks and model manipulations in our production environment. With its help, we detect and respond to runtime errors that occur on our system. Most of the time, static scanners flag thousands of theoretical vulnerabilities, causing alert fatigue for our security operations team. Sweet Security helps us track execution memory and active process behaviors and system calls to catch live attacker movements from all parts of the world. I can provide a specific example. I observed a scenario where attackers discovered a flaw in our systems on our public website. The attacker was running malicious code snippets inside our container, our static container, because no files were written to the disk. With the help of Sweet Security runtime sensor, which hooks directly into the Linux kernel, we noticed a process inside the container calling system admin privileges, something a simple web server would never do. It also detects crypto miners via runtime reachability for us. My software has 100,000 old stacks with unpatched security vulnerabilities. One of the attackers discovered that Sweet Security does not let any attacker into our systems to run any Bitcoin miners in the background.
Sweet Security is evolved for the cloud native application protection platform. It focuses specifically on protecting cloud workloads by combining runtime telemetry with cloud security postures, identity, and data deployed in AWS, Azure, Kubernetes, or any cloud environment. Sweet Security plays a crucial role in providing runtime visibility and helping security teams prioritize real-time threats that are actively occurring in production. It provides dynamic runtime information for application security rather than just static analysis. Sweet Security gives runtime visibility into cloud workloads and Kubernetes environments, correlates cloud infrastructure, workloads, identities, and application activity into a single investigation. It combines all activities related to a single identity and correlates all those alerts to make one incident, which helps SOC teams get all alerts related to that entity in one place. For organizations moving towards cloud environments, Sweet Security provides a reliable solution to protect cloud resources and supports major cloud platforms including AWS, Azure, and Kubernetes environments. Before implementing Sweet Security, we did not have a solution specifically for cloud resources. We had a SIEM integrated Microsoft Azure and Defender. After incorporating Sweet Security, we observed a significantly higher number of alerts and more reliable alerts with greater visibility into what was happening at the cloud level in the runtime dynamic timeframe. We were able to get in-depth details about cloud resource sharing, uploads, and downloads, and our SOC team utilized it across a broad range of applications. Sweet Security reduced most of the false positive alerts that we were getting through our SIEM. It provided more real-time interaction data, allowing us to identify threats more effectively. The alert logics available in the platform are very helpful for conducting in-depth investigations.
My main use case for Sweet Security as a distributor is to distribute to our partners within the UK channel, and they then take it to their customers who are looking for a cloud-native platform that offers advanced threat detection and incident response capabilities to provide deep runtime context to security teams, enabling them to quickly extract actual attack narratives. Sweet Security is designed to protect sensitive data in cloud environments, understand the environment, and respond to any threats as they occur. The platform leverages runtime insights to deliver comprehensive protection across all layers of the security stack. I can provide a specific example of how one of my partners' customers has used Sweet Security in practice. Organizations primarily utilize Sweet Security for VM vulnerability management on cloud assets, particularly with AWS, which enhances runtime visibility and enables effective threat detection. Sweet Security is integrated for runtime protection and has evolved to support broader security ranges. It allows users to visualize cloud relationships, understand dependencies, and manage vulnerabilities from a code perspective. Sweet Security provides real-time security event response for security teams.
I'm mostly using Sweet Security for real-time infrastructure security. If there is any threat, I want to detect it in real time. That's the main use case. Vulnerability management is one other benefit I am getting from Sweet Security as well.
We are cloud native and are using Sweet Security for call runtime protection. It is much bigger than just runtime protection, but the main use case was bringing Sweet Security for runtime protection services and it grew into a platform that we can utilize for many different things. We are using it instead of a CSPM and for visualizing what we call code-to-cloud, our code-to-cloud vision, to better understand the different packages and different dependencies that we have within the cloud runtime. It helps us a lot in understanding which vulnerabilities we should tackle from the code perspective.
We use Sweet Security primarily for vulnerability management on all of our cloud assets, mainly AWS, but we also use it for SOC, with the SOC integration getting the events and responding to them.