The Intruder homepage
Score7.3
Rank#1 of 31
PriceFree
Free planYes
Free trialYes
Runs onAPI, Linux, macOS, Web, Windows

Summary

Intruder provides continuous vulnerability scanning for infrastructure, web applications, APIs and cloud environments, with issue prioritization and remediation guidance. It ranks findings using exploit likelihood and real-world threat intelligence, and emerging-threat scans check systems within hours of new risks appearing. Cloud scans assess AWS, Microsoft Azure and Google Cloud environments for vulnerabilities, misconfigurations and exposures. Authenticated dynamic application testing covers customer-controlled web apps and APIs, including OWASP Top 10 checks. Supported targets include external IP addresses, domains and subdomains, internal Windows, macOS and Linux devices, and container images. Integrations include cloud platforms, code repositories, issue trackers, chat tools, Vanta and Drata. Its API can manage targets, view issues, start scans and retrieve results. Intruder offers a free plan and a 14-day trial. The free plan covers five infrastructure targets and weekly external scans, but excludes web apps. Internal target scanning is available only on Pro and Enterprise plans. All customers receive live chat support.

Who it is for

Intruder suits teams that need ongoing vulnerability checks across infrastructure, cloud environments, web apps or APIs. Teams requiring internal target scanning need Pro or Enterprise; Enterprise customers also have access to dedicated security professionals.

What is good

  • Continuous scanning covers infrastructure, web apps and APIs.
  • Prioritizes issues using exploit likelihood and threat intelligence.
  • Cloud scans cover AWS, Azure and Google Cloud.
  • API can start scans and retrieve results.
  • All customers receive live chat support.

What to know first

  • Free plan excludes web apps.
  • Free plan covers five infrastructure targets.
  • Internal scanning is limited to Pro and Enterprise.

Everything Xiaomi review

Intruder: the full review

Intruder combines continuous scanning with prioritization and remediation guidance across several target types. Its free tier is restricted to five infrastructure targets and excludes web apps, while internal scanning requires Pro or Enterprise.

Overview

Intruder is a vulnerability-management service for teams that need recurring checks across exposed infrastructure, cloud environments, applications and APIs. It suits security teams that want findings ranked by likely exploitability, rather than a flat list to triage themselves. Its strongest case is breadth with actionable prioritization; its free tier, however, is a narrow starting point rather than a full appraisal of the product.

Key features

Continuous scanning and prioritization

Intruder continuously scans supported targets and ranks issues using exploit likelihood and real-world threat intelligence, with remediation guidance to help teams decide what to fix first. That combination is useful where vulnerability backlogs compete for limited security time. Emerging-threat scans check systems within hours of new risks appearing in the wild, adding a rapid reassessment option alongside ongoing scans.

Application, cloud and internal coverage

Authenticated dynamic testing covers customer-controlled web applications and APIs, including OWASP Top 10 checks. Cloud scans assess AWS, Microsoft Azure and Google Cloud for vulnerabilities, misconfigurations and exposures. Supported targets also include external addresses and domains, internal Windows, macOS and Linux devices, and container images, although internal scanning is reserved for Pro and Enterprise.

Operations and safeguards

Integrations include AWS, Azure, Google Cloud, GitHub, GitLab, Jira, Linear, ServiceNow, Slack, Microsoft Teams, Vanta and Drata. The API can manage targets, view issues, start scans and retrieve results. Intruder says it uses TLS in transit, logical separation between customer datasets and full-disk encryption on company devices and cloud volumes holding customer information. Intruder Systems Ltd has completed an AICPA SOC 2 Type 2 audit; the product also names SOC 2, ISO 27001, PCI DSS, HIPAA and Cyber Essentials among supported compliance frameworks. All customers get live chat support, while Enterprise adds access to dedicated security professionals.

Pricing

Intruder is freemium, with a free plan and a 14-day trial. The free plan costs 0.00 USD per free, billed Forever, and allows three users, five infrastructure targets, one connected cloud account and two container images. It runs weekly external scans and checks ports 80 and 443; web apps are excluded. That is enough for a small, externally focused trial, but not for application testing, broad port coverage or internal scanning.

Cloud has custom pricing, billed monthly or annually, with annual billing saving 20%. Its base fee plus per-target fee covers three cloud accounts, daily cloud checks, web app and API testing, the top 10 ports, five AI investigation credits and 15+ integrations. It fits teams centered on cloud and application coverage, but the three-account and top-10-port limits are meaningful constraints.

Pro is custom pricing, billed annually, with a base fee plus per-target fee. It raises the cloud-account allowance to 10 and adds agent-based internal scanning, the top 50 ports and 10 AI investigation credits. This is the relevant step up for organizations that need internal checks; the annual-only term and per-target charge should factor into budgeting.

Enterprise uses custom pricing, quoted separately. It includes unlimited cloud accounts, all ports, 1,000+ attack surface checks, 50 AI investigation credits and shadow IT discovery. It is aimed at larger programs that need broader coverage and dedicated security professionals, rather than teams that can work within Pro's defined allowances.

Platforms

Intruder supports API, Linux, macOS, web and Windows, with a hybrid deployment model and authenticated scanning. The range of supported target types is broader than the free plan's infrastructure-only scope, so plan choice determines how much of that coverage is usable.

Who it's for

Intruder is a good fit for teams managing a mix of internet-facing systems, cloud accounts and customer-owned applications that need risk-based triage and remediation guidance. Cloud-focused teams may find Cloud's daily checks and app testing relevant; teams requiring internal device scanning need Pro or Enterprise. It is less compelling for individuals seeking a broad free scanner or teams unwilling to commit to custom-priced plans for expanded coverage.

Pros and cons

  • Pro: Prioritization combines exploit likelihood and threat intelligence, helping teams distinguish urgent issues from routine findings.
  • Pro: Coverage spans infrastructure, cloud, authenticated web apps and APIs, with emerging-threat checks within hours.
  • Pro: Live chat is available to all customers, and Enterprise adds dedicated security professionals.
  • Con: Free scanning is limited to five infrastructure targets, weekly external checks and ports 80 and 443; it excludes web apps.
  • Con: Internal scanning requires Pro or Enterprise, leaving a major target category outside the lower-cost entry point.
  • Con: Paid plan costs depend on custom pricing, and Cloud and Pro also charge a base fee plus per-target fee.

Alternatives

For a broader comparison, see Vulnerability Scanning Software, Network Vulnerability Scanners, Cloud Vulnerability Scanners and Vulnerability Management Software.

Choose ManageEngine Vulnerability Manager Plus if its freemium model and support for self-hosted deployment better suit your environment. OpenVAS offers a free virtual appliance with a community feed and limited enterprise features, but no default support. Nmap is the free option for users who need a standalone network-mapping tool, subject to its restriction on redistribution within commercial software or hardware products. NSAuditor AI is another freemium alternative. Choose Nuclei for an open-source, MIT-licensed CLI intended primarily as a standalone tool. Pentest-Tools Port Scanner is a narrower alternative for open-port and service discovery, with a free tier and a NetSec plan starting from 95.00 USD per month. Ivanti Neurons for Zero Trust Access is a paid alternative with named-user licensing. NSAuditor AI is also freemium and supports Windows, macOS and Linux.

Verdict

Choose Intruder if your team needs continuous, risk-prioritized scanning across infrastructure, cloud and authenticated applications, and can budget for the plan that unlocks its required coverage. Its main advantage is the combination of broad target support with threat-aware triage; look elsewhere if you need internal scanning on a free or entry-level plan, or want transparent paid pricing before engaging.

Intruder plans and pricing

All plans
Free Free Forever 5 infrastructure targets · web apps not included · weekly external scans · 1 connected cloud account · 2 container images · ports 80 and 443 · 3 users intruder.io · 30 Sept 2026
Cloud Not published Monthly or annually (annual saves 20%) Base fee plus per-target fee · 3 cloud accounts · daily cloud checks · web app and API testing · top 10 ports · 5 AI investigation credits · 15+ integrations intruder.io · 30 Sept 2026
Enterprise Not published Quoted separately Custom pricing · unlimited cloud accounts · all ports · 1,000+ attack surface checks · 50 AI investigation credits · shadow IT discovery intruder.io · 30 Sept 2026
Pro Not published Annually Base fee plus per-target fee · 10 cloud accounts · agent-based internal scanning · top 50 ports · 10 AI investigation credits intruder.io · 30 Sept 2026

Compared on vulnerability scanning software

Free plan
Yesintruder.io
Deployment model
hybridintruder.io

Facts

Product
Intruder provides continuous vulnerability scanning for infrastructure, web apps, and APIs, with prioritization and remediation guidance.intruder.io · 30 Sept 2026
Emerging threats
Emerging threat scans check systems within hours of new risks appearing in the wild.intruder.io · 30 Sept 2026
Prioritization
Intruder prioritizes issues using exploit likelihood and real-world threat intelligence.intruder.io · 30 Sept 2026
Cloud security
Cloud security scans assess AWS, Microsoft Azure, and Google Cloud environments for vulnerabilities, misconfigurations, and exposures.help.intruder.io · 30 Sept 2026
App scanning
Authenticated dynamic application security testing covers web apps and APIs controlled by the customer, including OWASP Top 10 checks.intruder.io · 30 Sept 2026
Integrations
Listed integrations include AWS, Azure, Google Cloud, GitHub, GitLab, Jira, Linear, ServiceNow, Slack, Microsoft Teams, Vanta, and Drata.help.intruder.io · 30 Sept 2026
API
Intruder's API can manage targets, view issues, start scans, and retrieve results.help.intruder.io · 30 Sept 2026
Security
Intruder says it uses TLS encryption for data in transit, logical data separation between client datasets, and full-disk encryption on company devices and cloud volumes storing customer information.intruder.io · 30 Sept 2026
Compliance
Intruder Systems Ltd says it successfully completed an AICPA SOC 2 Type 2 audit.intruder.io · 30 Sept 2026
Support
All customers receive live chat support, and Enterprise customers also have access to dedicated security professionals.intruder.io · 30 Sept 2026
Limits
Internal target scanning is available only on Pro and Enterprise plans.intruder.io · 30 Sept 2026
Company
Intruder says it was founded in 2015 to address information overload in vulnerability management.intruder.io · 30 Sept 2026

Best Intruder alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Intruder yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources