Security Stack Logo
Intruder logo

Vulnerability Management

Intruder

Exposure management uniting vulnerability scanning, ASM, cloud security, and AI pentesting.

Intruder Overview

What it does

Intruder is an exposure management platform combining continuous vulnerability scanning, attack surface management, cloud security, and on-demand AI pentesting for internet-facing systems and cloud infrastructure. The platform automatically discovers newly exposed services and scans them for the latest vulnerabilities shortly after public disclosure, customizing the output of multiple scanning engines to surface exposures that single-engine scanners miss across network infrastructure, web applications, and APIs. Pentesting agents built and trained by CREST-certified pentesters deliver web application pentest reports within hours.

How it works

The platform connects to AWS, Azure, Google Cloud, and Cloudflare accounts so newly exposed services become scan targets automatically, then runs scheduled and emerging threat scans within hours of critical vulnerability disclosures, drawing on more than 140,000 website security checks. Findings are ranked using the Exploit Prediction Scoring System (EPSS) and the CISA Known Exploited Vulnerabilities (KEV) catalog rather than severity alone, filtering false positives for lean security teams. GregAI, a built-in AI security analyst, validates issues, tailors remediation guidance to each environment, and drafts stakeholder reports, while daily cloud configuration checks, container image scanning, and secrets detection extend coverage.

Credentials and traction

Intruder is SOC 2 Type II certified. It ranked #38 on the 2023 Deloitte UK Technology Fast 50, the only cybersecurity company on that year's list of fastest-growing UK technology firms, and later earned a 2025 Cybersecurity Breakthrough Award and recognition as a 2025 Latio Cloud Security Innovator. More than 3,000 customers use the platform, including Drata, Virgin Active, Fujifilm, the NHS, and The Alan Turing Institute, spanning finance, healthcare, technology, higher education, and the public sector.

Key Capabilities

mapped to solution categories
Risk-Based Vulnerability Management (RBVM)

Scans cloud resource configurations and container image CVEs alongside traditional OS and application vulnerabilities in a unified risk view.

Enforces remediation deadlines by severity, reports on SLA compliance, and escalates overdue findings through configured approval chains.

Continuously discovers external-facing assets (domains, IPs, cloud services, APIs, certificates) including assets deployed outside the official inventory.

Recommends the minimum patch set that eliminates the highest-risk exposure (accounting for shared libraries and patch co-dependencies), rather than presenting a ranked CVE list.

Creates tickets, assigns owners, and tracks remediation progress in ITSM platforms (ServiceNow, Jira), closing the loop between finding and fix rather than producing a static report.

Cross-references the vulnerability inventory against live threat feeds tracking CVEs under active exploitation in the wild, surfacing vulnerabilities with confirmed attacker activity.

Aggregates and deduplicates findings from network scanners, endpoint agents, cloud scanners, and third-party tools into one normalized record for cross-estate risk ranking.

Assigns likelihood-of-exploitation scores using threat intelligence, vulnerability characteristics, and active exploit availability, independent of CVSS, which measures severity rather than exploitability.

Incorporates asset metadata (network exposure, business criticality, data classification) into vulnerability prioritization so that a critical CVE on an isolated internal test system ranks lower than a medium CVE on an internet-facing payment server.

Cloud Security Posture Management (CSPM)

Aggregates posture findings and policy enforcement across multiple cloud accounts, subscriptions, and projects from a single control plane, critical for organizations with 10+ cloud accounts.

Audits cloud service configurations across AWS, Azure, and GCP against security best practices and benchmarks, flagging misconfigurations such as public storage, permissive network rules, and disabled logging. Coverage breadth and per-service depth vary significantly across products.

Continuously discovers and inventories cloud resources across accounts, subscriptions, and projects so posture assessment runs against a current, complete picture of the environment rather than a stale or partial asset list. Coverage of newer and less common resource types varies across products.

Penetration Testing as a Service (PTaaS)

Manages asset scope definitions, scope change approvals, rules of engagement, and testing windows through a persistent platform interface rather than per-engagement documentation.

Delivers findings through a live client portal as testers discover them, with status, severity, and evidence, instead of a single static PDF at the end of the engagement.

Initiates penetration testing engagements through a platform interface without requiring a new statement of work for each test, enabling testing at the cadence of development releases.

Delivers findings directly into developer ticketing systems (Jira, GitHub Issues, Azure DevOps) alongside standard pentest reports, enabling developer remediation tracking within existing workflows.

Attack Surface Management (ASM)

Ranks discovered exposures by combining exploitability signals, asset business context, and active threat intelligence to produce an actionable remediation queue.

Identifies software stacks, versions, and components running on discovered assets through passive banner analysis and active probing, mapping CVE exposure without authenticated scanning.

Continuously enumerates internet-exposed assets (domains, IPs, subdomains, certificates, cloud storage, APIs) using passive DNS, certificate transparency logs, and active probing, including assets outside the official inventory.

Identifies cloud resources, SaaS applications, and exposed services deployed by business units without IT or security team visibility or approval.

Tracks SSL/TLS certificate expirations, newly registered lookalike domains, and subdomain takeover opportunities (dangling DNS records pointing to deprovisioned cloud services).

Compliance

certifications
SOC 2 Type II

Integrations

compatible tools
APIAWSAzureAzure DevOpsCloudflareDocker HubDrataGitHubGitLabGoogle CloudJiraLinearMicrosoft SentinelMicrosoft TeamsOktaPagerDutyServiceNowSlackSplunkVantaZapier

Implementation & support

Deployment model
Endpoint AgentSaaS
Support channels
Customer Success Manager (CSM)DocumentationEmail SupportKnowledge BaseLive Chat

Info last updated on August 23, 2026

Buyers

See how Intruder fits your stack

Add Intruder to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.