Intruder is a UK vulnerability scanner that looks at your attack surface from the outside: external perimeter, subdomains, cloud assets and web apps. monsys looks from the inside, with an agent on every host. Both position around CTEM. Honest comparison below.
| Dimension | monsys.ai | Intruder |
|---|---|---|
| Vantage point | ✓Inside-out: agent sees packages, kernel, services, auth logs | ✓Outside-in: external perimeter, subdomains, cloud assets |
| DAST / web app & API scanning | ✗Not present, only external uptime and TLS checks | ✓Built in: authenticated web app scans and API scanning |
| In-host CVE detection | ✓App dependencies + OS packages + kernel (backport-aware), plus SBOM/VEX | ~Agent-based internal scanning only in higher tiers, no kernel backport detection or SBOM |
| Remediation | ✓Controlled fix flow: operator approves with TOTP, with rollback and attestation chain | ~Ticket to Jira/Slack; execution and proof stay with you |
| Evidence for auditors | ✓Ed25519-signed audit packs, verifiable offline without trusting us | ~Audit-ready PDF reports and sync to Drata/Vanta, not cryptographically verifiable |
| Validation after a fix | ✓Verify step in the remediation loop: agent re-measures and attests the result | ✓Automatic external re-scan confirms the issue is closed |
| Monitoring, uptime and capacity | ✓Included: metrics, alerts, uptime checks, status pages, capacity prediction | ✗No operational monitoring, pure security scanning |
| Active attack detection | ✓Auth-log analysis, honeypots, GeoIP and lateral-movement correlation on the host | ✗No runtime detection; scans vulnerabilities, not attacks |
| Data residency | ✓EU: hosted in Belgium (GoTrust BV), no US SaaS in the critical path | ~United Kingdom: adequacy decision, but not an EU member state |
| Pricing model | ✓5 agents free forever, then €3 per server per month, public | ~Base fee plus per-target pricing; paid tiers quote-only |
Intruder and monsys overlap in positioning (CTEM, small security teams) but barely in technique: they look from the outside, we look from the inside. For many organisations the honest conclusion is that both make sense side by side: Intruder for the external attack surface and web apps, monsys for what lives inside your servers, the controlled fix and the signed evidence. If you pick only one and you run servers yourself, inside-out is usually the bigger blind spot.