Intruder

Web · Windows · Mac · Linux · API

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely4 of 6 device platforms
  • DocumentedPlans, terms and facts published

Intruder provides continuous vulnerability scanning for infrastructure, web applications, APIs, cloud environments, and container images. It assesses external IP addresses, domains and subdomains, as well as internal Windows, macOS and Linux devices. Authenticated dynamic testing covers customer-controlled web apps and APIs, including OWASP Top 10 checks. Cloud scans look for vulnerabilities, misconfigurations and exposures in AWS, Microsoft Azure and Google Cloud. Issues are prioritized using exploit likelihood and real-world threat intelligence; scans for emerging threats check systems within hours of new risks appearing. The API can manage targets, view issues, start scans and retrieve results. Listed integrations include cloud services, code hosts, issue trackers and chat tools. Intruder has a free plan and a 14-day trial. The free plan covers five infrastructure targets and weekly external scans, but excludes web apps. Internal target scanning is available only on Pro and Enterprise plans. All customers receive live chat support; Enterprise customers can also access dedicated security professionals.

Who it is for

Intruder suits teams that need ongoing vulnerability scans across infrastructure, web apps, APIs or cloud environments. Its free plan may suit users with up to five infrastructure targets who do not need web app coverage.

What is good

  • Checks for emerging risks within hours of their appearance.
  • Prioritizes issues using exploit likelihood and threat intelligence.
  • Authenticated app testing includes OWASP Top 10 checks.
  • Integrates with cloud services, issue trackers and chat tools.
  • All customers receive live chat support.

What to know first

  • Free plan excludes web apps.
  • Free plan limits scans to five infrastructure targets.
  • Internal target scanning requires Pro or Enterprise.

Freedom251 review

Intruder: the full review

Intruder combines continuous scanning with prioritization and remediation guidance across several kinds of targets. Check the plan limits carefully, especially if you need web app or internal target scans.

Overview

Intruder is a continuous vulnerability-scanning service for organizations managing infrastructure, cloud environments, web applications or APIs. It is best suited to teams that need findings ranked by exploit likelihood and threat intelligence, rather than a flat list of issues. Its breadth is useful, but the free tier is narrow and the paid plans differ materially in target limits and scan coverage.

It supports external IP addresses, domains and subdomains, as well as internal devices, web apps, APIs, cloud environments and container images. The hybrid deployment model and authenticated scanning support a mix of public-facing and internal assessment needs.

Key features

Continuous scanning and prioritization

Intruder continuously scans infrastructure, web apps and APIs, then uses exploit likelihood and real-world threat intelligence to rank issues. That gives teams a practical way to focus remediation effort, although prioritization does not replace deciding how a finding affects their own environment. Remediation guidance is included to help move from detection to action.

Emerging-threat scans check systems within hours of new risks appearing in the wild. This is valuable for teams that need to reassess exposure quickly as new threats surface, in addition to ongoing scanning.

Application, cloud and internal coverage

Authenticated dynamic testing covers customer-controlled web applications and APIs, including OWASP Top 10 checks. Cloud scans assess AWS, Microsoft Azure and Google Cloud for vulnerabilities, misconfigurations and exposures. Internal target scanning, however, is reserved for Pro and Enterprise, so the free tier is not a route to internal-device coverage.

Supported targets also include container images and internal Windows, macOS and Linux devices. The API can manage targets, view issues, start scans and retrieve results, while integrations include major cloud providers, GitHub, GitLab, Jira, Linear, ServiceNow, Slack, Microsoft Teams, Vanta and Drata. These connections can fit the scanner into existing workflows; the plan determines which capabilities and quotas apply.

Security and support

Intruder says it uses TLS encryption in transit, logical separation between client datasets, and full-disk encryption on company devices and cloud volumes storing customer information. Intruder Systems Ltd says it completed an AICPA SOC 2 Type 2 audit. All customers receive live chat support; Enterprise adds access to dedicated security professionals.

Pricing

Intruder has a free plan and a 14-day trial. The Free plan costs 0.00 USD per free, billed Forever, and supports five infrastructure targets, weekly external scans, one connected cloud account, two container images, ports 80 and 443, and three users. Web apps are excluded. Those limits make it a reasonable starting point for a small external-infrastructure inventory, but not for teams needing application tests, internal scans or broader port coverage.

Cloud has custom pricing, billed monthly or annually, with annual billing saving 20%. It uses a base fee plus a per-target fee and includes three cloud accounts, daily cloud checks, web app and API testing, the top 10 ports, five AI investigation credits and 15+ integrations. It fits teams prioritizing cloud and application coverage, but the account count and port range are tighter than higher plans.

Pro has custom pricing, billed annually, with a base fee plus a per-target fee. It allows 10 cloud accounts, agent-based internal scanning, the top 50 ports and 10 AI investigation credits. This is the relevant tier for organizations that need internal target scanning, though its annual term and per-target pricing warrant checking against expected scope.

Enterprise has custom pricing, quoted separately. It includes unlimited cloud accounts, all ports, 1,000+ attack surface checks, 50 AI investigation credits and shadow IT discovery. Its broader scope and dedicated security professionals make it the fit for larger, more complex environments; it is likely unnecessary for teams covered by the narrower tiers.

Platforms

Intruder supports API, Linux, macOS, web and Windows platforms. Its supported targets span cloud services, containers, network assets and applications, making it suitable for mixed environments rather than a single operating system or asset type.

Who it's for

Intruder is a strong fit for security and IT teams that want recurring scans across exposed infrastructure and, on paid plans, cloud environments, web apps, APIs or internal devices. Its prioritization and remediation guidance help teams triage findings, while its integrations and API support operational workflows. It is less suitable for buyers seeking broad application and internal coverage at no cost, or those who need predictable pricing before scoping target counts.

Pros and cons

  • Pros: Continuous scanning across several target types, with emerging-threat checks within hours, helps teams respond to changing exposure.
  • Pros: Ranking based on exploit likelihood and threat intelligence, plus remediation guidance, helps direct attention toward consequential findings.
  • Pros: Cloud scans cover AWS, Azure and Google Cloud, and authenticated testing includes web apps and APIs with OWASP Top 10 checks.
  • Cons: The free plan excludes web apps and limits scans to weekly external checks, two ports and five infrastructure targets.
  • Cons: Internal scanning requires Pro or Enterprise, and the paid plans use custom pricing, including per-target fees on Cloud and Pro.

Alternatives

For a narrower or different approach, compare Vulnerability Scanning Software, Network Vulnerability Scanners, Cloud Vulnerability Scanners and Vulnerability Management Software.

ManageEngine Vulnerability Manager Plus is worth considering if its free edition or on-premises offering better fits your deployment needs. Nmap is a free option for users who want a standalone network scanning tool and can work within its end-user license terms. NSAuditor AI and NSAuditor AI are alternatives to compare for their supported platforms and free offerings. OpenVAS suits readers considering a free virtual appliance with a community feed and limited enterprise features. Nuclei is a free, MIT-licensed CLI intended primarily as a standalone tool. Pentest-Tools Port Scanner is a more focused option for open-port and service discovery, with a NetSec plan starting at 95.00 USD per month. Sirius is another free alternative to compare.

Verdict

Choose Intruder if your team needs continuous scanning across varied infrastructure and values risk-based prioritization, with paid tiers available for cloud, application and internal coverage. Its strongest case is the combination of broad target support and guidance on what to address first. Look elsewhere if you need web app or internal scanning on a free plan, or if custom and per-target pricing makes budgeting difficult.

Intruder plans and pricing

All plans
Free Free Forever 5 infrastructure targets · web apps not included · weekly external scans · 1 connected cloud account · 2 container images · ports 80 and 443 · 3 users intruder.io · 30 Sept 2026
Cloud Not published Monthly or annually (annual saves 20%) Base fee plus per-target fee · 3 cloud accounts · daily cloud checks · web app and API testing · top 10 ports · 5 AI investigation credits · 15+ integrations intruder.io · 30 Sept 2026
Enterprise Not published Quoted separately Custom pricing · unlimited cloud accounts · all ports · 1,000+ attack surface checks · 50 AI investigation credits · shadow IT discovery intruder.io · 30 Sept 2026
Pro Not published Annually Base fee plus per-target fee · 10 cloud accounts · agent-based internal scanning · top 50 ports · 10 AI investigation credits intruder.io · 30 Sept 2026

Compared on vulnerability scanning software

Free plan
Yes
Deployment model
hybrid

Best Intruder alternatives

See all 20