Security
Intruder
API integration
Ship Security features without building the integration. Full Intruder API access via Proxy and 30+ MCP-ready tools for AI agents — extend models and mappings to fit your product.
Talk to usUse Cases
Why integrate with Intruder
Common scenarios for SaaS companies building Intruder integrations for their customers.
Embed continuous vulnerability data in compliance platforms
Compliance and GRC tools can pull Intruder scan schedules, open issues, and remediation timestamps to automatically evidence SOC 2, ISO 27001, and HIPAA controls for their customers.
Power ASPM and risk aggregation dashboards
Security posture platforms can ingest Intruder issues, occurrences, and raw scanner output to unify DAST findings with SAST and cloud data into a single prioritized risk view.
Auto-provision scanning for developer platforms
Internal developer portals and cloud management tools can create Intruder targets, attach API schemas, and tag assets whenever a new service or environment is spun up, giving every microservice continuous coverage.
Sync vulnerabilities into ticketing workflows
Project management and ITSM tools can convert Intruder issues and occurrences into prioritized tickets based on severity and CVSS score, and close them automatically when the fix is detected.
Enable MSSP and multi-tenant security portals
Managed service providers can offer a branded portal to run on-demand scans, track license consumption per tenant, and collaborate with clients via comments on specific vulnerability occurrences.
What You Can Build
Ship these features with Truto + Intruder
Concrete product features your team can ship faster by leveraging Truto’s Intruder integration instead of building from scratch.
Vulnerability-to-ticket sync
Create tickets from Intruder issues and occurrences, mapping severity and CVSS score, and auto-close them when matching fixed occurrences appear.
Automated target provisioning
Bulk-create Intruder targets with tags whenever your platform detects a new IP, CIDR block, or web asset, so new infrastructure is scanned without manual setup.
Authenticated DAST scanning setup
Let users upload an OpenAPI schema and target authentication credentials from your UI so Intruder can scan behind login pages and against specific API routes.
On-demand and scheduled scan controls
Trigger scans, cancel in-progress runs, and manage recurring scan schedules — including Drata and Vanta upload flags — directly from your application.
Compliance evidence export
Surface scan schedules, open issues, and fixed occurrence timestamps as auditor-ready evidence of continuous vulnerability management SLAs.
Collaborative remediation comments
Allow analysts and developers to post and read comments on specific vulnerability occurrences without leaving your product.
SuperAI
Intruder AI agent tools
Comprehensive AI agent toolset with fine-grained control. Integrates with MCP clients like Cursor and Claude, or frameworks like LangChain.
list_all_intruder_health
Check that the Intruder API is running normally. Returns: status, authenticated_as, openapi, info, paths, components, servers.
list_all_intruder_issue_occurrences
List occurrences for an issue in Intruder. Returns: id, occurrence_id, target, display_address, port, protocol, extra_info, age, snoozed, snooze_reason, snooze_until, exploit_likelihood, cvss_score, first_seen_at, target_last_scanned_at, cves. Required: issue_id. occurrence_id is the stable ID that persists across scans; id may change between scans.
list_all_intruder_issues
List current issues in Intruder, with filters for severity, snoozing, tags, target addresses, and new occurrences since a timestamp. Returns: id, severity, title, description, remediation, snoozed, snooze_reason, snooze_until, occurrences, exploit_likelihood, cvss_score.
create_a_intruder_scan
Start a scan in Intruder. Returns the created scan including its id, status, scan_type, created_at, target_addresses, and start_time. Optionally pass target_addresses and/or tag_names in the body — with no body it scans all targets. Max 500 active and scheduled scans.
list_all_intruder_scans
List current scans in Intruder. Returns scan records including id, status, scan_type, schedule_period, and created_at; filter by scan_type, status, schedule_period, or tag_names.
intruder_scans_cancel
Cancel a running scan in Intruder. Returns the confirmation string "Scan was cancelled" on success. Required: scan_id.
get_single_intruder_scan_by_id
Get a single Intruder scan's details by id. Returns: id, status, created_at, target_addresses, scan_type, throttled, web_ports_only, schedule_period, start_time, completed_time, openapi, info, paths, components, servers. Required: id.
intruder_targets_bulk_create
Bulk add multiple targets in Intruder, including CIDR ranges. Returns the created target including id, address, display_address, target_status, license_type, and tags. Required: address for each target in the array.
create_a_intruder_target
Add a target in Intruder. Returns the created target including id, address, display_address, target_status, target_type, license_type, and tags. Required: address; type and url when target_authentication is supplied.
list_all_intruder_targets
List Intruder targets. Returns: id, address, display_address, has_api_schemas, has_authentications, last_scanned, license_type, waf_provider, waf_interference, tags, target_status, target_type. Filter by address, status, type, tags, or last scan date.
delete_a_intruder_target_by_id
Delete an Intruder target by id. Returns an empty 204 response on success. Required: id.
list_all_intruder_fixed_occurrences
List fixed occurrences in Intruder — vulnerabilities that have been resolved. Returns each occurrence with id, title, severity, cvss_score, affected_host, first_seen_at, and remediated_at.
list_all_intruder_licenses
List infrastructure and application license counts in Intruder. Returns: total_infrastructure_licenses, available_infrastructure_licenses, consumed_infrastructure_licenses, total_application_licenses, available_application_licenses, consumed_application_licenses.
create_a_intruder_occurrence_comment
Add a comment to an occurrence in Intruder. Returns the created comment including its id, content, commenter_type, user, and created_at. Required: issue_id, occurrence_id, content.
list_all_intruder_occurrence_comments
List comments on an occurrence in Intruder, newest first. Returns: id, content, commenter_type, user, created_at, edited_at. Required: issue_id, occurrence_id.
list_all_intruder_occurrence_scanner_output
List scanner output entries for an occurrence of an issue in Intruder. Returns: id, plugin, scanner_output. Required: issue_id, occurrence_id.
create_a_intruder_scan_schedule
Create a scan schedule in intruder that runs recurring scans on your targets. Returns: id, notice, openapi, info, paths, components, servers. Requires name, first_scan_time, and scan_frequency (monthly, daily, weekly, or quarterly); first_scan_time must be in the future and on the hour.
delete_a_intruder_scan_schedule_by_id
Delete a scan schedule in intruder by id, stopping its scheduled recurring scans. Returns an empty 204 response on success. Required: id.
list_all_intruder_scan_schedules
List all scan schedules in intruder. Returns: id, name, schedule_period, first_scan_time, next_scan_date, status, throttled, web_ports_only, latest_scan_id, latest_scan_status, last_scan_start_time, last_scan_end_time, targets, target_tags, upload_to_drata, upload_to_vanta.
update_a_intruder_scan_schedule_by_id
Update a scan schedule in intruder by id. All body fields (name, first_scan_time, scan_frequency, tags, targets, throttled, web_ports_only, upload_to_drata, upload_to_vanta) are optional for a partial update. Returns: notice, openapi, info, paths, components, servers. Required: id.
list_all_intruder_tags
List tags in Intruder. Returns the collection of tag records, each containing its name (up to 40 characters), which also serves as the tag's identifier when adding or removing it from targets. Default page size 25.
create_a_intruder_target_api_schema
Add an API schema to a target in Intruder by uploading a schema file. Returns the created schema including its id, name, base_url, and target_authentication_id. Required: target_id, name, base_url, file (multipart).
delete_a_intruder_target_api_schema_by_id
Delete an API schema from an Intruder target by id. Returns an empty 204 response on success. Required: id and target_id.
list_all_intruder_target_api_schemas
List API schemas attached to an Intruder target. Returns each schema's id, name, base_url, and target_authentication_id. Required: target_id.
update_a_intruder_target_api_schema_by_id
Update an API schema on an Intruder target, optionally replacing its schema file. Returns the updated schema including its id, name, base_url, and target_authentication_id. Required: id and target_id.
create_a_intruder_target_authentication
Add an authentication to a target in Intruder. Returns the created authentication object including its id, url, type, name, and enabled status. Required: target_id, type, url.
delete_a_intruder_target_authentication_by_id
Delete an authentication from a target in Intruder by id. Returns an empty 204 response on success. Required: target_id, id.
list_all_intruder_target_authentications
List the authentications configured for a target in Intruder. Returns each authentication's id, url, type, name, and enabled status. Required: target_id.
update_a_intruder_target_authentication_by_id
Update an authentication on a target in Intruder. Returns the updated authentication with id, url, type, name, and enabled status. Required: target_id, id. All cookies, headers, and additional_parameters key-value pairs you want present must be included in the request; omitted values are removed.
create_a_intruder_target_tag
Create a tag for a target in Intruder. Returns the created tag object including its name (up to 40 characters). Required: target_id, name.
intruder_target_tags_bulk_delete
Delete a tag from a target in Intruder by tag name. Returns an empty 204 response on success. Required: target_id, tag_name.
Why Truto
Why use Truto’s MCP server for Intruder
Other MCP servers give you a static tool list for one app. Truto gives you a managed, multi-tenant MCP infrastructure across 800+ integrations.
Auto-generated, always up to date
Tools are dynamically generated from curated documentation — not hand-coded. As integrations evolve, tools stay current without manual maintenance.
Fine-grained access control
Scope each MCP server to read-only, write-only, specific methods, or tagged tool groups. Expose only what your AI agent needs — nothing more.
Multi-tenant by design
Each MCP server is scoped to a single connected account with its own credentials. The URL itself is the auth token — no shared secrets, no credential leaking across tenants.
Works with every MCP client
Standard JSON-RPC 2.0 protocol. Paste the URL into Claude, ChatGPT, Cursor, or any MCP-compatible agent framework — tools are discovered automatically.
Built-in auth, rate limits, and error handling
Tool calls execute through Truto’s proxy layer with automatic OAuth refresh, rate-limit handling, and normalized error responses. No raw API plumbing in your agent.
Expiring and auditable servers
Create time-limited MCP servers for contractors or automated workflows. Optional dual-auth requires both the URL and a Truto API token for high-security environments.
How It Works
From zero to integrated
Go live with Intruder in under an hour. No boilerplate, no maintenance burden.
Link your customer’s Intruder account
Use Truto’s frontend SDK to connect your customer’s Intruder account. We handle all OAuth and API key flows — you don’t need to create the OAuth app.
We handle authentication
Don’t spend time refreshing access tokens or figuring out secure storage. We handle it and inject credentials into every API request.
Call our API, we call Intruder
Truto’s Proxy API is a 1-to-1 mapping of the Intruder API. You call us, we call Intruder, and pass the response back in the same cycle.
Unified response format
Every response follows a single format across all integrations. We translate Intruder’s pagination into unified cursor-based pagination. Data is always in the result attribute.
FAQs
Common questions about Intruder on Truto
Authentication, rate limits, data freshness, and everything else you need to know before you integrate.
How do end users authenticate their Intruder account?
Users connect their Intruder account through Truto's hosted auth flow using their API key. Truto securely stores and injects credentials on every request, so you don't handle secrets.
Can we create and manage scan schedules programmatically?
Yes. You can create, list, update, and delete scan schedules, including setting recurrence and the native upload_to_drata and upload_to_vanta flags for compliance workflows.
How fresh is the vulnerability data?
Data is fetched on-demand from Intruder's API when you call list endpoints for issues, occurrences, or fixed occurrences, so results reflect the current state at request time. You can poll on your own cadence to keep downstream systems in sync.
Can we scan authenticated web apps and APIs?
Yes. You can attach target authentications (cookies, headers, credentials) and upload API schemas to a target, enabling Intruder to perform DAST scans behind login pages and against defined API routes.
Does Truto handle pagination across large result sets?
Yes. Truto normalizes pagination for list endpoints like issues, occurrences, targets, and scans so you can iterate through full result sets without implementing Intruder's pagination logic yourself.
What target operations are supported?
You can create single or bulk targets, list all targets, delete targets by ID, and manage tags via create and bulk delete operations — enough to fully automate asset provisioning and organization.
Can we track license consumption for multi-tenant use cases?
Yes. The list_all_intruder_licenses endpoint lets MSSPs and multi-tenant platforms query infrastructure and application license usage for billing or capacity planning.
Intruder
Get Intruder integrated into your app
Our team understands what it takes to make a Intruder integration successful. A short, crisp 30 minute call with folks who understand the problem.