Intruder

APIyesOSS—FREEyesDOCS4/5
IN7.3#3 of 36
outWeboutWindowsoutMacoutLinux—Android—iOS

Ranked in Vulnerability Scanning Software ·Free plan

About

Intruder continuously scans infrastructure, web apps, APIs, cloud environments, and other supported targets for vulnerabilities, then prioritizes issues and provides remediation guidance. Prioritization draws on exploit likelihood and real-world threat intelligence. Emerging-threat scans check systems within hours of new risks appearing. Cloud scans assess AWS, Microsoft Azure, and Google Cloud for vulnerabilities, misconfigurations, and exposures; authenticated dynamic testing covers customer-controlled web apps and APIs, including OWASP Top 10 checks. Its API can manage targets, view issues, start scans, and retrieve results. Integrations include cloud platforms, code hosts, issue trackers, chat tools, Vanta, and Drata. Supported targets include external IP addresses and domains, internal Windows, macOS, and Linux devices, and container images. Intruder lists a free plan and a 14-day trial. Free includes five infrastructure targets and weekly external scans, but excludes web apps. Internal target scanning is limited to Pro and Enterprise. All customers receive live chat support; Enterprise customers also have access to dedicated security professionals.

Who it is for

Intruder suits teams that need continuous vulnerability scanning across infrastructure, APIs, web applications, and cloud environments. Its API and integrations are relevant to teams managing scan workflows alongside existing cloud, code, issue-tracking, and chat tools.

What is good

  • Emerging-threat checks run within hours of risks appearing.
  • Prioritization uses exploit likelihood and threat intelligence.
  • Authenticated testing covers apps and APIs.
  • API manages targets, scans, issues, and results.
  • All customers receive live chat support.

What to know first

  • Free plan excludes web apps.
  • Free plan limits scanning to five infrastructure targets.
  • Internal target scanning requires Pro or Enterprise.
  • Plan prices are not listed.

Inferse review

Intruder: the full review

Intruder combines continuous scanning with threat-based prioritization and remediation guidance across a broad set of target types. The free tier is limited to external infrastructure scans, so teams needing web app or internal scanning should note the plan restrictions.

Intruder is a continuous vulnerability-scanning service for infrastructure, cloud environments, web applications and APIs. It suits teams that need to cover several kinds of assets and prioritize remediation by threat, not just collect findings. Its clearest trade-off is a tightly capped free plan against broader coverage reserved for paid tiers.

Overview

Intruder combines continuous scanning with remediation guidance and risk ranking based on exploit likelihood and real-world threat intelligence. Emerging-threat scans check systems within hours of new risks appearing in the wild, which can help teams revisit exposure as threats change. The hybrid service supports authenticated scanning and targets ranging from external addresses and domains to internal devices, container images and cloud environments.

Intruder says it was founded in 2015 to address information overload in vulnerability management. That focus is reflected in its prioritization, although teams still need to decide how its plan boundaries map to their estate: internal target scanning is confined to Pro and Enterprise.

Key features

Prioritization and application testing

Intruder ranks issues using exploit likelihood and real-world threat intelligence, then provides remediation guidance. That is more useful for teams managing a large queue than a scan report that leaves every finding equally urgent. Authenticated dynamic application security testing covers customer-controlled web apps and APIs, including OWASP Top 10 checks; web testing is not part of Free.

Cloud and ecosystem coverage

Cloud scans assess AWS, Microsoft Azure and Google Cloud for vulnerabilities, misconfigurations and exposures. Integrations include GitHub, GitLab, Jira, Linear, ServiceNow, Slack, Microsoft Teams, Vanta and Drata, alongside the three cloud providers. Intruder's API can manage targets, view issues, start scans and retrieve results, giving teams a route to connect scanning with their own workflows.

Security and support

Intruder says it uses TLS for data in transit, logical separation between client datasets, and full-disk encryption on company devices and cloud volumes holding customer information. Intruder Systems Ltd says it completed an AICPA SOC 2 Type 2 audit. All customers receive live chat support; Enterprise adds access to dedicated security professionals. Supported compliance frameworks include SOC 2, ISO 27001, PCI DSS, HIPAA and Cyber Essentials.

Pricing

Intruder is freemium, with a free plan and a 14-day trial. The Free plan costs 0.00 USD per free, billed Forever. It covers five infrastructure targets, weekly external scans, one connected cloud account, two container images, ports 80 and 443, and three users. Web apps are excluded, and internal scanning is unavailable, so this tier is best for a small external-infrastructure footprint rather than a broad security program.

Cloud has custom pricing, billed monthly or annually, with annual billing saving 20%. Its base fee plus per-target fee buys three cloud accounts, daily cloud checks, web app and API testing, top 10 ports, five AI investigation credits and 15+ integrations. It fits teams focused on cloud and application coverage, but the per-target structure makes the total depend on the estate.

Pro has custom pricing, billed annually, with a base fee plus per-target fee. It adds ten cloud accounts, agent-based internal scanning, top 50 ports and ten AI investigation credits. That makes it the relevant tier for teams that need internal device coverage; those with larger or more varied needs may find the account and port caps restrictive.

Enterprise uses custom pricing, quoted separately. It includes unlimited cloud accounts, all ports, 1,000+ attack surface checks, 50 AI investigation credits and shadow IT discovery. Its dedicated security professionals make it the strongest fit for organizations needing wider coverage and specialist access, though the quoted model is less predictable than a fixed price.

Platforms

Intruder supports API, Linux, macOS, web and Windows. Its supported targets span external IP addresses, domains and subdomains; internal Windows, macOS and Linux devices; web applications, APIs, cloud environments and container images. The hybrid deployment model and authenticated scanning support teams covering both external and internal assets, subject to plan eligibility for internal scans.

Who it's for

Intruder is a strong fit for teams that need continuous coverage across infrastructure and applications, want threat-informed prioritization, and can match a paid tier to their cloud and internal scanning needs. Free is a narrow starting point for small external estates. Teams requiring internal scanning should plan for Pro or Enterprise, while those needing Enterprise's broader checks and support should account for custom pricing.

Pros and cons

  • Threat-based prioritization: exploit likelihood and real-world intelligence help teams distinguish urgent issues from the wider queue.
  • Broad target range: scanning spans cloud, applications, APIs, containers and internal devices, though internal scanning requires Pro or Enterprise.
  • Useful workflow access: the API can manage targets and scans and retrieve results, with integrations across cloud, development, ticketing and compliance tools.
  • Restrictive free tier: five targets, weekly external scans and ports 80 and 443 leave web app testing and internal coverage out of reach.
  • Paid costs depend on scope: Cloud and Pro use base-plus-per-target pricing, while Enterprise is quoted separately, making budget planning less straightforward than a fixed-price tier.

Alternatives

For Kubernetes-focused scanning with a self-hosted, Apache 2.0-licensed open-source CLI and operator, consider Kubescape. Mondoo CSPM is another free-forever open-source option, spanning cloud, Kubernetes, OS, SaaS and API scanning with an extensible provider system. Choose Prowler Cloud if a 15-day free trial with no cloud-account limit and every check and compliance framework is a better fit.

Qualys TotalCloud offers a free license with limited API calls for control evaluation. Astra Security may suit teams seeking a priced application-scanning plan: Scanner Lite is 69.00 USD per month for one target and three monthly scans, while Scanner is 199.00 USD per month for one target and unlimited scans. Cyscale CSPM is a paid CSPM alternative with Pro at 850.00 USD per month, billed annually, for up to 1000 assets and 10 connectors.

Google Artifact Analysis is relevant when the need is narrower: container or language package scanning is priced at 0.26 USD per once, with subsequent scans of the same image free. Cy5 Cloud-Native Vulnerability Management is another paid cloud-native option.

For category-level comparisons, browse Cloud Vulnerability Scanners, Vulnerability Management Software, Vulnerability Scanning Software and Network Vulnerability Scanners.

Verdict

Choose Intruder if your team needs ongoing infrastructure and application scanning with threat-informed prioritization and can budget for the tier that covers its assets. Its range of targets and workflow access are compelling; the free plan's external-only limits and custom paid pricing are the main reasons to look elsewhere.

Compared on vulnerability scanning software

Free plan
Yesintruder.io
Deployment model
hybridintruder.io

Facts

Product
Intruder provides continuous vulnerability scanning for infrastructure, web apps, and APIs, with prioritization and remediation guidance.intruder.io · 30 Sept 2026
Emerging threats
Emerging threat scans check systems within hours of new risks appearing in the wild.intruder.io · 30 Sept 2026
Prioritization
Intruder prioritizes issues using exploit likelihood and real-world threat intelligence.intruder.io · 30 Sept 2026
Cloud security
Cloud security scans assess AWS, Microsoft Azure, and Google Cloud environments for vulnerabilities, misconfigurations, and exposures.help.intruder.io · 30 Sept 2026
App scanning
Authenticated dynamic application security testing covers web apps and APIs controlled by the customer, including OWASP Top 10 checks.intruder.io · 30 Sept 2026
Integrations
Listed integrations include AWS, Azure, Google Cloud, GitHub, GitLab, Jira, Linear, ServiceNow, Slack, Microsoft Teams, Vanta, and Drata.help.intruder.io · 30 Sept 2026
API
Intruder's API can manage targets, view issues, start scans, and retrieve results.help.intruder.io · 30 Sept 2026
Security
Intruder says it uses TLS encryption for data in transit, logical data separation between client datasets, and full-disk encryption on company devices and cloud volumes storing customer information.intruder.io · 30 Sept 2026
Compliance
Intruder Systems Ltd says it successfully completed an AICPA SOC 2 Type 2 audit.intruder.io · 30 Sept 2026
Support
All customers receive live chat support, and Enterprise customers also have access to dedicated security professionals.intruder.io · 30 Sept 2026
Limits
Internal target scanning is available only on Pro and Enterprise plans.intruder.io · 30 Sept 2026
Company
Intruder says it was founded in 2015 to address information overload in vulnerability management.intruder.io · 30 Sept 2026

Best Intruder alternatives

See all 12