Intruder

7.9easy start · #1 of 36
in Vulnerability Scanning Software
  • Free to practise onyes
  • Free trialyes
  • Well documentedyes
  • Runs where you workyes

Runs on api, Linux, Mac, Web, Windows.

Intruder provides continuous vulnerability scanning for infrastructure, web applications, APIs, and cloud environments, with prioritization and remediation guidance. It ranks issues using exploit likelihood and real-world threat intelligence, while emerging-threat scans check systems within hours of new risks appearing. Cloud scans assess AWS, Microsoft Azure, and Google Cloud environments for vulnerabilities, misconfigurations, and exposures. Authenticated dynamic application testing covers customer-controlled web apps and APIs, including OWASP Top 10 checks. Other supported targets include external IP addresses, domains, subdomains, internal Windows, macOS, and Linux devices, and container images. Integrations include AWS, Azure, Google Cloud, GitHub, GitLab, Jira, Linear, ServiceNow, Slack, Microsoft Teams, Vanta, and Drata. The API can manage targets, view issues, start scans, and retrieve results. The free plan covers five infrastructure targets and weekly external scans, but does not include web apps. Internal target scanning is available only on Pro and Enterprise plans. All customers receive live chat support.

Who it is for

Intruder suits teams that need ongoing vulnerability scans across infrastructure, web apps, APIs, cloud environments, or container images. Its free plan may fit users starting with a small set of external infrastructure targets, while internal scanning requires Pro or Enterprise.

What is good

  • Prioritizes issues using exploit likelihood and threat intelligence
  • Emerging-threat scans run within hours of new risks
  • Tests customer-controlled web apps and APIs
  • API can start scans and retrieve results
  • All customers receive live chat support

What to know first

  • Free plan covers only five infrastructure targets
  • Free plan excludes web apps
  • Internal target scanning requires Pro or Enterprise

The Geeks Club review

Intruder: the full review

Intruder combines continuous scanning with issue prioritization and remediation guidance across infrastructure, applications, APIs, and cloud environments. Its free plan is limited to five infrastructure targets and weekly external scans, with no web app coverage.

Overview

Intruder is a vulnerability management product for teams that need to scan internet-facing assets and decide which findings deserve attention. Its risk-based prioritization and remediation guidance make it a stronger fit for teams managing recurring exposure than for anyone seeking only a basic port scanner.

Coverage spans external and internal devices, applications, APIs, cloud environments and container images. The main buying caveat is that meaningful coverage depends on the plan: the free tier is narrow, and internal scanning begins at Pro.

Key features

Prioritized, ongoing vulnerability scanning

Continuous scanning is paired with prioritization based on exploit likelihood and real-world threat intelligence. That can help teams focus limited remediation time on issues more likely to matter, rather than treating every alert as equally urgent. Intruder also provides remediation guidance, though it does not remove the work of deciding and carrying out fixes.

Emerging-threat scans check systems within hours after new risks appear in the wild. This is useful for organizations that need to reassess exposure as threats emerge, alongside their regular scanning.

Application, cloud and internal coverage

Authenticated dynamic testing covers customer-controlled web applications and APIs, including OWASP Top 10 checks. Cloud scans assess AWS, Microsoft Azure and Google Cloud for vulnerabilities, misconfigurations and exposures. These capabilities make Intruder more relevant to teams managing application and cloud risk together than a tool limited to network discovery.

Supported targets include external IP addresses, domains and subdomains, internal Windows, macOS and Linux devices, web applications, APIs, cloud environments and container images. However, internal target scanning is reserved for Pro and Enterprise, so the broad target list does not mean every plan covers every environment.

Operations and safeguards

Integrations include AWS, Azure, Google Cloud, GitHub, GitLab, Jira, Linear, ServiceNow, Slack, Microsoft Teams, Vanta and Drata. Its API can manage targets, view issues, start scans and retrieve results, giving teams options to connect scanning work with their own processes.

Intruder says it uses TLS for data in transit, logical separation between client datasets, and full-disk encryption on company devices and cloud volumes storing customer information. Intruder Systems Ltd says it completed an AICPA SOC 2 Type 2 audit. All customers receive live chat support; Enterprise also includes access to dedicated security professionals.

Pricing

Intruder has a free plan and a 14-day trial. Paid plans are billed monthly or annually where stated; Cloud annual billing saves 20%. Cloud and Pro use a base fee plus a per-target fee, while Enterprise has custom pricing.

PlanPrice and billingWhat it includes
Free0.00 USD per free; billed Forever5 infrastructure targets, weekly external scans, 1 connected cloud account, 2 container images, ports 80 and 443, and 3 users. Web apps are not included.
CloudCustom pricing; monthly or annually, with 20% savings on annual billing; base fee plus per-target fee3 cloud accounts, daily cloud checks, web app and API testing, top 10 ports, 5 AI investigation credits and 15+ integrations.
ProCustom pricing; billed annually; base fee plus per-target fee10 cloud accounts, agent-based internal scanning, top 50 ports and 10 AI investigation credits.
EnterpriseCustom pricing; quoted separatelyUnlimited cloud accounts, all ports, 1,000+ attack surface checks, 50 AI investigation credits and shadow IT discovery.

Free is a useful way to cover a small external footprint, but five targets, weekly scans and no web app testing make it a poor fit for teams needing broad or frequent assessment. Cloud is the paid tier that adds web app and API testing and daily cloud checks; Pro is the relevant step for agent-based internal scanning, though its annual billing and per-target fee matter for budgeting. Enterprise suits organizations needing the widest cloud and attack-surface scope, but requires a separate quote.

Platforms

Intruder supports API, Linux, macOS, web and Windows. Its hybrid deployment model and authenticated scanning support work across environments, while the plan restrictions still determine whether internal scanning is available.

Who it's for

Intruder is best suited to security and IT teams that need recurring vulnerability visibility across infrastructure, applications or cloud assets, and value help ranking findings. It is less suitable for a small team that needs web application coverage at no cost, internal scanning on a free tier, or a tool focused only on discovering open ports.

Pros and cons

  • Pros: Risk prioritization uses exploit likelihood and threat intelligence, helping teams direct remediation effort.
  • Pros: Authenticated web app and API testing, cloud assessment and infrastructure scanning cover several important asset types in one product.
  • Pros: Live chat is available to every customer, with dedicated security professionals for Enterprise.
  • Cons: Free excludes web app coverage, limits users to three and targets to five, and scans external assets weekly.
  • Cons: Internal scanning requires Pro or Enterprise, and Pro is annually billed with a per-target fee.
  • Cons: Paid prices are custom, so Cloud and Pro's base-plus-target pricing cannot be readily compared from the stated terms alone.

Alternatives

For another freemium vulnerability-management option, consider ManageEngine Vulnerability Manager Plus, which has a free edition and supports self-hosted deployment as well as API, web and desktop platforms. OpenVAS is a free-plan alternative with a community feed and limited enterprise features, but its free appliance has no default support. For a free tool with an end-user license, Nmap is worth considering if its redistribution restriction is acceptable.

Qualys External Attack Surface Management offers a 30-day no-cost period for CyberSecurity Asset Management 3.0 with EASM. Pentest-Tools Port Scanner includes open-port and service discovery on its free tier. NSAuditor AI is another freemium option. Nuclei is a free, MIT-licensed CLI intended primarily as a standalone tool, while OWASP Nettacker is free open-source software under Apache License 2.0.

Browse Vulnerability Scanning Software, Cloud Vulnerability Scanners, Network Vulnerability Scanners or Vulnerability Management Software for more options by category.

Verdict

Choose Intruder if your team needs continuous vulnerability scanning across infrastructure, cloud assets and authenticated applications, and wants prioritization to help focus remediation. Its clearest drawback is the gap between the free tier and the capabilities that require paid plans, especially internal scanning and broader application coverage. Teams with a tiny external footprint can start free; teams needing comprehensive coverage should compare the custom-priced paid tiers before committing.

Intruder plans and pricing

All plans
Free Free Forever 5 infrastructure targets · web apps not included · weekly external scans · 1 connected cloud account · 2 container images · ports 80 and 443 · 3 users intruder.io · 30 Sept 2026
Cloud Not published Monthly or annually (annual saves 20%) Base fee plus per-target fee · 3 cloud accounts · daily cloud checks · web app and API testing · top 10 ports · 5 AI investigation credits · 15+ integrations intruder.io · 30 Sept 2026
Enterprise Not published Quoted separately Custom pricing · unlimited cloud accounts · all ports · 1,000+ attack surface checks · 50 AI investigation credits · shadow IT discovery intruder.io · 30 Sept 2026
Pro Not published Annually Base fee plus per-target fee · 10 cloud accounts · agent-based internal scanning · top 50 ports · 10 AI investigation credits intruder.io · 30 Sept 2026

Compared on vulnerability scanning software

Free plan
Yes
Deployment model
hybrid

Best Intruder alternatives

See all 12