Skip to content
← Back to documentation
Technical Reference

Intruder

Intruder is a powerful vulnerability management platform that helps businesses identify, assess, and remediate security risks across their digital assets. With its comprehensive scanning capabilities and user-friendly interface, Intruder enables organizations to stay ahead of potential threats and maintain a robust security posture.

CategoryDeveloper Tools
Authenticationcustom
Version0.1.0
Published scopes0 published scopes
Last updatedSeptember 19, 2026

Overview

Connect Intruder with Flows360

Intruder is a powerful vulnerability management platform that helps businesses identify, assess, and remediate security risks across their digital assets. With its comprehensive scanning capabilities and user-friendly interface, Intruder enables organizations to stay ahead of potential threats and maintain a robust security posture.

Use the Intruder connector to include its declared actions and events in Flows360 workflows without duplicating the integration logic inside each consuming system. This pinned connector version currently exposes 6 actions and no declared triggers.

Available actions

  • Add Target
  • Start Scan
  • Search For a Target
  • Search For an Issue
  • Search For an Issue Occurrence
  • Custom API Call

Available triggers

  • No triggers are declared in this pinned package.

The capability list above is generated from the exact reviewed connector package so the public description stays aligned with the version Flows360 operates.

Technical guide

Technical reference

Package identity

  • Connector: Intruder
  • Package: @activepieces/piece-intruder@0.1.0
  • Exact artifact digest: sha256:f55493621460e70a7b609e15f5df606d6d30321da611a599346aceb484a13671
  • Runtime: Activepieces-compatible deterministic worker
  • Source: the exact reviewed Activepieces source

Authentication

SECRET TEXT. Connection values are tenant-specific and remain in the consuming Studio instance; CDK stores definitions and field metadata, not customer credential values.

Action contracts

  • Add Target (addTarget), Add a new target to your Intruder account Classification: read.
  • Start Scan (startScan), Start a new scan. Optionally specify target addresses and/or tag names. If no targets or tags are provided, the scan will run on all targets. Classification: read.
  • Search For a Target (searchForATarget), Search for targets by address Classification: read.
  • Search For an Issue (searchForAnIssue), Search for issues with optional filters Classification: read.
  • Search For an Issue Occurrence (searchForAnIssueOccurrence), Search for occurrences of an issue by ID with optional snoozed filter Classification: read.
  • Custom API Call (custom_api_call), Make a custom API call to a specific endpoint Classification: read.

Trigger contracts

  • No trigger delivery contracts are declared.

Verification

Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.

Capability summary

Authenticationcustom
Supported objects6
Supported actions6
TriggersNone published

Authentication

Authentication method: custom

Authentication profiles

connection · custom
  • Intruder API Key Required · protected credential

Supported objects

ObjectReadWriteNotes
Add Target Yes No Add a new target to your Intruder account
Start Scan Yes No Start a new scan. Optionally specify target addresses and/or tag names. If no targets or tags are provided, the scan will run on all targets.
Search For a Target Yes No Search for targets by address
Search For an Issue Yes No Search for issues with optional filters
Search For an Issue Occurrence Yes No Search for occurrences of an issue by ID with optional snoozed filter
Custom API Call Yes No Make a custom API call to a specific endpoint

Supported actions

Add Target · Read

Add a new target to your Intruder account

add_target · Risk: low · Retry: safe

Inputs

  • address · string · Required, The address or domain of the target (e.g., example.com, 192.168.1.1)
  • tags · array · Optional, Tags to organize and filter targets
Start Scan · Read

Start a new scan. Optionally specify target addresses and/or tag names. If no targets or tags are provided, the scan will run on all targets.

start_scan · Risk: low · Retry: safe

Inputs

  • target_addresses · array · Optional, Target addresses to scan (e.g., example.com, 192.168.1.1). Leave empty to scan all targets.
  • tag_names · array · Optional, Tag names to filter targets. Leave empty to scan all targets.
Search For a Target · Read

Search for targets by address

search_for_atarget · Risk: low · Retry: safe

Inputs

  • address · string · Required, The address or domain to search for (e.g., example.com, 192.168.1.1)
Search For an Issue · Read

Search for issues with optional filters

search_for_an_issue · Risk: low · Retry: safe

Inputs

  • issueIds · array · Optional, Filter by specific issue IDs
  • targetAddresses · array · Optional, Filter by target addresses (e.g., example.com, 192.168.1.1)
  • tagNames · array · Optional, Filter by tag names
  • severity · string · Optional, Filter by severity level
  • snoozed · boolean · Optional, Filter for snoozed issues
Search For an Issue Occurrence · Read

Search for occurrences of an issue by ID with optional snoozed filter

search_for_an_issue_occurrence · Risk: low · Retry: safe

Inputs

  • issueId · string · Required, The ID of the issue to search for occurrences
  • snoozed · boolean · Optional, Filter for snoozed occurrences
Custom API Call · Read

Make a custom API call to a specific endpoint

custom_api_call · Risk: low · Retry: safe

Inputs

  • url · object · Required
  • method · string · Required
  • headers · object · Optional, Authorization headers are injected automatically from your connection.
  • queryParams · object · Optional, Appended to the URL as ?key=value.
  • body_type · string · Optional
  • body · object · Optional
  • response_is_binary · boolean · Optional, Enable for files like PDFs, images, etc.
  • failsafe · boolean · Optional, On a failed request, output the error instead of failing the step.
  • timeout · number · Optional, Seconds to wait for a response. Empty: up to the flow limit (10 min).
  • followRedirects · boolean · Optional, Follow 3xx redirects instead of returning them as the response.

Setup

Setup

  1. Add the Intruder connector to the workflow in the target Flows360 Studio instance.
  2. Create or select the tenant-specific connection required by the connector. Connection secrets remain in the Studio connection boundary and are not copied into CDK documentation.
  3. Provide the connection fields declared by the pinned package:
  • No provider credential fields are declared by the pinned package.
  1. Select the required action or trigger and complete its declared input fields. Required and optional inputs are defined by the exact package schema.
  2. Test the workflow in the appropriate environment before enabling production scheduling or event delivery.

Limitations

Limitations and operational notes

  • This content describes @activepieces/piece-intruder@0.1.0; provider behaviour can change independently and should be revalidated when the provider or connector version changes.
  • Only the 6 actions and 0 triggers declared by this pinned package are represented here.
  • Tenant credentials and connection values are not stored in the public connector record.
  • Provider-side permissions, account entitlements, quotas and rate limits remain subject to the connected provider account and are not inferred when the package does not declare them.
  • Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.

Troubleshooting

Why canu2019t the connector authenticate?

Check the tenant connection in Studio and confirm every required Intruder connection field is present. Re-authorise OAuth-based connections if the provider token or consent has expired. Do not place credential values in CDK content or logs.

Why is an action or trigger unavailable?

Confirm that the workflow is using @activepieces/piece-intruder@0.1.0 and compare the requested capability with the declared action and trigger list for this version. A capability that is not declared by the pinned package should not be presented as supported.

What should I check after a provider-side change?

Revalidate authentication, required fields, action/trigger behaviour and provider documentation before publishing refreshed connector content or moving a new package version into production.