Intruder
Continuous vulnerability management and external attack-surface scanning for SMB and mid-market engineering teams.
Try Intruder Free
Start with the free plan and see if it fits your workflow — no credit card required.
TRY FOR FREE →Affiliate Disclosure: We may earn a commission if you sign up using this link, at no additional cost to you.
Our Verdict on Intruder
Intruder is a cloud-based vulnerability management platform built around continuous scanning of an organisation's internet-facing estate, combined with external attack-surface discovery so scanning covers the assets that exist rather than the ones someone remembered to add. Findings are prioritised with remediation guidance and can be routed into engineering workflows through documented integrations and an API.
Intruder sits in the privacy & security space and is best suited to engineering, platform and devops leads at technology companies that own security without a dedicated security team, and need evidence for soc 2, iso 27001 or customer security questionnaires.
Across our five rating lenses — ease of use, value, speed, accuracy and ROI — Intruder scores 8.4/10. That places it in the top tier of tools we've tested this year, and it comfortably earns its spot in our recommended stack.
- Continuous scanning combined with external attack-surface discovery
- Self-serve onboarding — no sales cycle before the first scan
- Findings arrive prioritised with remediation guidance rather than raw scanner output
- Emerging-threat scanning when a significant vulnerability becomes public
- Slack, Microsoft Teams, Jira, webhook and API integrations documented
- Reporting aimed at auditors and security questionnaires as well as engineers
- Automated scanning with human support is not a deeply scoped manual engagement
- Per-target pricing means cost tracks estate growth
- One layer only — no endpoint protection, dark web monitoring or awareness training
- Internal network validation is not the product's centre of gravity
- Not a managed service — remediation stays with your team
Intruder Pricing
Intruder publishes tiered plans (including Essential, Pro and Premium tiers) priced by the number of targets and applications in scope, with higher tiers adding scanning depth and human-led testing support. We do not reproduce figures because per-target pricing varies by scope and tier — confirm current pricing on intruder.io.
Not available. Look for a free trial instead.
Tiered plans, priced per target
For most users, the mid-tier paid plan delivers the best balance of features and cost.
What Intruder does well
Perfect for
The complete Intruder review
Intruder is a cloud-based vulnerability management platform built around continuous scanning of an organisation's internet-facing estate. Rather than selling a testing engagement, it sells ongoing visibility: you add targets — domains, IP addresses, web applications, APIs and cloud accounts — and the platform keeps scanning them, tells you what changed, and prioritises what actually matters. Its natural buyer is an engineering or DevOps team that has to own security without a dedicated security department behind it.
Intruder is bought by technical teams who need continuous, prioritised vulnerability data rather than a once-a-year report.
- SMB and mid-market engineering teams owning security without a security department
- SaaS companies asked for vulnerability scanning evidence in security questionnaires
- Teams that want external attack-surface discovery alongside scanning
- Organisations with cloud estates that change frequently
- Companies working towards or maintaining SOC 2 or ISO 27001 evidence
- DevOps teams who want findings routed into Slack, Jira or their own tooling
Intruder is a vulnerability management platform. Where the requirement is genuinely something else, we would rather point you away.
- Businesses that want a deeply scoped manual red-team engagement
- Organisations that need a fully managed SOC with human monitoring and response
- Teams looking for endpoint antivirus or device protection — that is a different layer
- Enterprises wanting adversary emulation across internal networks (see Pentera)
- Companies whose primary need is a researcher-powered bug bounty programme (see HackerOne)
- Buyers who need security awareness training and dark web monitoring bundled in
What Intruder actually is
It helps to separate the three things Intruder documents, because buyers frequently collapse them into "a scanner":
- Continuous vulnerability scanning: recurring authenticated and unauthenticated scanning of infrastructure, web applications and APIs, with results presented as prioritised issues rather than a raw scanner dump.
- External attack surface management: discovery of the internet-facing assets attached to your domains and cloud accounts — including subdomains and services you may not have known were exposed — so scanning covers what exists rather than what someone remembered to add.
- Emerging threat response: when a significant new vulnerability becomes public, Intruder documents proactively scanning customer targets for it rather than waiting for the next scheduled cycle.
That combination is the product's actual argument. A scanner tells you about the assets you point it at; attack-surface discovery tells you which assets you forgot. Most real-world exposure sits in the second category.
Key capabilities
- Continuous scanning of external infrastructure, with internal and authenticated scanning options documented.
- Web application and API scanning alongside network-layer checks.
- Attack-surface discovery and monitoring for newly exposed services and subdomains.
- Cloud connectors for major providers so new infrastructure is picked up as it appears.
- Issue prioritisation with remediation guidance, rather than an unranked CVE list.
- Downloadable reports intended for auditors, customers and internal stakeholders.
- Integrations documented for developer and alerting workflows — including Slack, Microsoft Teams, Jira and webhooks — plus an API for custom pipelines.
- Higher tiers documented as adding human-led testing support on top of automated scanning.
Deployment model and typical business size
Intruder is a SaaS platform: you sign in to a hosted portal, add targets, and scanning runs from Intruder's infrastructure. Internal scanning is documented as available via an agent or scanning appliance model, so on-premise-only deployment is not the shape of this product. Self-serve signup means a small team can be scanning the same day, which is a meaningful difference from platforms that require a sales cycle first.
In practice the sweet spot is a company with somewhere between a handful and a few hundred external assets: large enough that manual tracking has broken down, small enough that a full enterprise exposure-management programme would be over-buying.
Compliance support
Intruder's documentation positions its reporting as evidence for compliance programmes — SOC 2 and ISO 27001 are the frameworks most commonly cited by its own material, alongside customer security questionnaires. Read that the way we read every vendor's compliance page: the platform produces evidence supporting a control, it does not certify you against a framework. Your auditor decides whether the artefact satisfies your scope.
Pricing
Intruder publishes tiered plans with pricing that scales by the number of targets and applications in scope, with higher tiers unlocking additional scanning depth and human-led testing support. We deliberately do not reproduce figures here: per-target pricing changes, varies by scope and by tier, and a stale number in a review is worse than no number. Confirm the current position on Intruder's own pricing page, and price the number of assets you actually expect to have in twelve months rather than today.
Support
Support is documented as in-product and email-based, with the higher plans adding closer access to Intruder's security team and human-led testing input. We have not tested response times and do not publish a claim about them.
Strengths
- Continuous scanning plus attack-surface discovery in one subscription.
- Self-serve onboarding — a technical team can be scanning without a sales process.
- Findings arrive prioritised with remediation guidance rather than as raw scanner output.
- Emerging-threat scanning closes the window between disclosure and the next scheduled scan.
- Integrations and an API make findings actionable inside existing engineering workflows.
- Reporting is aimed at the audit and questionnaire use case, not just at engineers.
Limitations
- Automated scanning with human review is not the same as a deeply scoped manual engagement.
- Per-target pricing means cost tracks estate growth — model it before committing.
- No endpoint protection, dark web monitoring or awareness training: this is one layer, not a suite.
- Internal network validation is not the product's centre of gravity.
- Not a managed service — someone on your side still has to remediate.
Ideal customer
A twenty-to-three-hundred-person technology business with a cloud estate, no dedicated security hire, an engineering team willing to act on findings, and at least one external party — auditor, enterprise customer or insurer — asking for evidence that vulnerabilities are being found and fixed.
The Tool Money Lab verdict
On published documentation, Intruder is a credible continuous vulnerability management and external attack-surface platform for SMB and mid-market engineering teams. We have not commissioned scanning through it, so we make no claim about detection quality or false-positive rates, and we stop at this label rather than assert a stronger one we have not earned.
Alternatives to Intruder
These are the platforms buyers most often shortlist alongside Intruder. Cards activate automatically once the relevant TTML review is published.
SMB subscription bundling penetration testing as a service, dark web monitoring and security awareness training.
External attack-surface monitoring and application scanning built on crowdsourced researcher findings.
Automated security validation emulating attacks across internal and external environments for enterprise teams.
Researcher-powered bug bounty, vulnerability disclosure and scoped pentesting platform.
Where Intruder fits in our wider coverage
Intruder sits in the assurance layer of a business security stack, not the endpoint layer. If you are assembling that stack, start with our best business security software guide, then cover devices with the best antivirus software shortlist and credentials with best password managers. Network-layer options sit in best VPN tools, the full catalogue under privacy & security, and the software glossary defines the vulnerability-management and compliance terms used above. For a direct head-to-head, read CyberSuite vs Intruder.
Our reviews are based on vendor documentation, publicly available product information, independent testing where available, and ongoing editorial updates. We do not sell rankings. Where a page carries affiliate links we may earn a commission at no additional cost to you, and that relationship never changes the conclusion — see our affiliate disclosure and review methodology.
Evidence class: vendor-documentation-review. We have not run scans through Intruder and make no performance, detection-rate or customer-satisfaction claim. Specific price points are deliberately omitted because per-target pricing varies by scope and tier — confirm them on Intruder's own pricing page.
- Last reviewed
- Reviewed by
- The Tool Money Lab Editorial Team — independent software research
- Evidence sources
- Vendor Documentation · Official Product Pages · Official Integration Documentation · Official Compliance Pages
Frequently asked questions
Continuous vulnerability management: finding, prioritising and tracking security weaknesses across internet-facing infrastructure, web applications, APIs and cloud accounts, then producing reports you can hand to an auditor or customer.
Compare Intruder with alternatives
We're preparing detailed comparisons with CyberSuite, Detectify, Pentera, HackerOne and other tools in this category. In the meantime, you can explore the closest reviewed alternatives below.
These are individual reviews — not direct comparisons with Intruder.
Penetration testing, dark web monitoring and security awareness training sold as one SMB subscription instead of a consulting engagement.
External attack surface management and application scanning powered by a curated ethical hacker community.
Automated security validation that emulates attacks across internal, external and cloud environments for enterprise security teams.
Researcher-powered platform for vulnerability disclosure, bug bounty programmes and scoped penetration testing.
Intruder head-to-head
Understand the category before you buy
These guides are vendor-neutral and contain no product recommendations — they exist so you can judge the tools below on your own terms.
How subscription penetration testing differs from a once-a-year consulting engagement, what the platform layer actually adds, and where PTaaS still needs human testers.
Why a point-in-time test goes stale the moment you deploy, what "continuous" means in practice, and how to tell continuous testing apart from continuous scanning.
Discovery is the hard part of external security. EASM finds the internet-facing assets nobody wrote down, then keeps watching them as they change.
A scanner tells you what looks wrong. A penetration test tells you what an attacker could actually do with it. Auditors and buyers routinely conflate the two.
The Intruder knowledge graph
Every page connected to Intruder — comparisons, shortlists, alternatives and the wider Privacy & Security pillar. Follow any thread to keep learning.
Related Privacy & Security Tools
Explore similar tools, alternatives and comparisons before you decide.
Bitdefender
Category-leading malware detection with a light system footprint for home, family and business.
Proton Unlimited
The complete Proton bundle — Mail, VPN, Pass, Drive and Calendar in one plan.
Proton
Swiss-based privacy suite covering mail, VPN, password manager and cloud storage.
Proton VPN
Audited, open-source VPN with a genuinely usable free tier.
Norton 360
The broadest consumer security bundle — AV, VPN, password manager, cloud backup and (US) LifeLock identity.
Bitwarden
Open-source password manager with a strong free tier.
Where Intruder ranks
Intruder appears in 2 of our curated shortlists — each one ranks it against the direct alternatives for a specific use case.
Keep the Intruder research going
How we work
Every tool is used on real projects before we score it — no press-release rewrites.
Five lenses: ease of use, value, speed, accuracy, ROI. Averaged, not cherry-picked.
Some links pay us a commission at no cost to you. They never change our scores.
Editorial rankings are separate from partnership status. See our editorial policy.
Understand the terms behind this review in under a minute each.
Browse the Software Glossary →Stay Ahead of AI
Receive our weekly Intelligence Brief. Independent AI reviews, comparisons, new tools and practical recommendations delivered every Friday.
- ✓ New AI tools
- ✓ Honest reviews
- ✓ Best AI deals
- ✓ New comparisons
- ✓ Industry trends
- ✓ No spam.
Ready to try Intruder?
You've read the review. Now put it on real work.
Try Free →Disclosure: We may earn a commission if you purchase through links on this page. This never affects our reviews.
How to read our scores
This score includes direct product evaluation alongside our editorial research.
Calculated using product documentation, pricing analysis, interface review, verified customer reviews and independent evidence. A full long-term hands-on evaluation has not yet been completed.
Follow us for daily AI tools and reviews
New tools, tested honestly. Join the community on your favourite platform.