Vulnerability scanning and attack surface monitoring · Pricing guide
Intruder Pricing, Explained
Intruder is a rare case: the plans are documented in detail, but the numbers are not. The pricing page renders its figures from sliders based on how many targets you have, so there is no list price to quote, and the help centre states only that pricing is "a base fee plus a small fee-per-target". What Intruder does publish is more useful than most vendors manage — which scanning engine sits under each tier — and that gives you a way to sanity-check any quote.
Last verified: 2026-08-14
Intruder pricing at a glance
Why There Is No Price to Quote
Intruder's pricing page is interactive: you set your target count and it computes the number. Nothing is published as a list price, and the downloadable pricing table is an image rather than text, so no figure here can be sourced properly. Anyone quoting you a precise Intruder monthly price on a blog is estimating, and we would rather say so than join in.
What you can do is bound the estimate. Because cost is base fee plus per-target, your quote scales with how you count assets — and the definition is broad: every external IP, every domain and sub-domain, every container image, and every internal device with the agent installed is a target. A team with 40 sub-domains and 30 container images is a 70-target quote, not a 5-target one. Deduplicate and retire dead DNS records before you ask for pricing, because the slider does not know which of your sub-domains are abandoned.
The Engine Under Each Plan (The Useful Part)
Intruder documents which scanning engine powers each tier, which is unusually transparent and gives you a reference price. Free runs the open-source Nuclei engine with more than 79,000 external checks. Cloud combines OpenVAS and Nuclei (over 99,400 external checks). Pro runs the commercial Tenable Nessus engine, quoted at over 141,000 external and over 14,000 internal checks, with agent-based internal scanning. Enterprise combines Nessus with Nuclei and adds continuous network scanning, attack surface monitoring and a Rapid Response advisory service. Vanguard adds continuous human penetration testing on top: vulnerability chaining, false-positive investigation and impact review.
That matters commercially. If the Pro tier is Nessus underneath, then Nessus Professional's own published price — $4,790 a year — is your baseline for the same detection engine without the platform. What you pay Intruder above that buys the workflow: asset discovery, scheduling, emerging-threat scans, triage and reporting. Whether that wrapper is worth the delta is a real question, and it is much easier to answer once you know you are comparing against a $4,790 licence rather than an unknown.
What the Tiers Do Not Cover
Web application scanning is an add-on, and it runs OWASP ZAP with roughly 100 web-application checks: XSS, SQL and NoSQL injection and similar classes. That is signature-level web coverage, not application testing. No tier of a vulnerability scanner tests whether one of your users can read another user's records, because broken access control has no signature — it depends on what your application is supposed to allow.
So price Intruder for what it is good at: knowing what you have exposed and whether any of it carries a known vulnerability. Budget application-layer testing separately, and treat the Vanguard tier as the point where you are buying human pentest time rather than more scanning.
Intruder in Context (2026)
Only published figures appear here. Where a vendor does not publish, the cell says so rather than carrying an estimate.
| Option | Published price | Detection engine / model |
|---|---|---|
| Intruder Free | Free | Nuclei, >79,000 external checks, 5 web apps |
| Intruder Cloud / Pro / Enterprise | Not published (base fee + per target) | OpenVAS+Nuclei / Tenable Nessus / Nessus+Nuclei |
| Intruder Vanguard | Not published | Scanning plus continuous human pentesting |
| Intruder AI pentesting add-on | From $3,500 per test | Per test |
| Nessus Professional (same engine as Pro) | $4,790 / year | Tenable Nessus, licence only |
| Penetrify | From $100/month | AI penetration testing of web apps and APIs |
Plan engines, check counts and the target definition from help.intruder.io; the $3,500 AI pentesting figure and the 20% annual saving from intruder.io/pricing; Nessus price from tenable.com. All checked August 2026. Intruder's per-plan prices render client-side from a target-count slider and are therefore not quotable.
Scanning Your Estate vs Testing Your Application
Intruder is an attack-surface and vulnerability-scanning product: its job is to tell you what is exposed and whether it carries a known flaw, across IPs, domains, sub-domains, containers and internal hosts. Penetrify does the other job — it attacks the application itself, testing authentication, authorisation across roles and tenants, and business logic, then chains findings into exploit paths, from $100/month on every deploy. Teams with a broad infrastructure estate usually want both; teams whose entire risk is one multi-tenant web app usually find that per-target scanner pricing buys them the wrong coverage.
The bottom line
Intruder is a well-built scanner with unusually honest documentation about what powers each tier, and the free plan is a genuine way to see your external exposure. Budgeting takes work because pricing is per-target and unpublished: count your real targets first, deduplicate dead sub-domains, and use the fact that Pro runs Tenable Nessus — a $4,790-a-year licence on its own — as the yardstick for what the platform layer is costing you. Then price application-layer testing separately, because the ZAP-based web add-on is a scanner, not a pentest.
Frequently asked questions
How much does Intruder cost?
Intruder does not publish plan prices. The model is a base fee plus a per-target fee, computed from a slider on their pricing page, with annual billing saving 20%. The one published figure is the AI pentesting add-on, starting from $3,500 per test. Any precise monthly figure you see quoted elsewhere is an estimate.
What counts as a target in Intruder pricing?
Per Intruder's help centre: an external IP address, a domain, a sub-domain, a container image, or an internal device running their agent. That is a broad definition, so audit and retire unused sub-domains before requesting a quote — the count drives the price.
Is the free Intruder plan useful?
Yes, within its limits: 5 web apps, weekly external scans, 1 cloud account, 2 container images and 3 users, running the Nuclei engine with over 79,000 external checks. It is a real way to see your external exposure before paying anything.
What is the difference between the Intruder plans?
Mainly the scanning engine and scope. Free uses Nuclei; Cloud adds OpenVAS; Pro moves to the commercial Tenable Nessus engine with internal agent scanning; Enterprise combines Nessus and Nuclei with continuous network scanning and attack surface monitoring; Vanguard adds continuous human penetration testing on top.
Is Intruder cheaper than buying Nessus directly?
Not necessarily, and that is the useful comparison. The Pro tier runs the same Tenable Nessus engine that Nessus Professional licenses for $4,790 a year. Intruder adds asset discovery, scheduling, emerging-threat scans, triage and reporting on top. Get the quote, subtract the Nessus baseline, and decide whether the workflow is worth the difference.
Does Intruder replace a penetration test?
The scanning tiers do not: web application coverage is a ZAP-based add-on of roughly 100 checks, which finds signature-detectable classes and cannot test access control or business logic. The Vanguard tier adds human pentesting, which is where you are buying tester time rather than more scanning.