Pricing overview

FullHunt provides an External Attack Surface Management (EASM) platform with a tiered pricing structure designed to accommodate individual researchers, small teams, and large enterprises. The pricing model primarily revolves around the number of monitored assets, which typically include domains, subdomains, IP addresses, and associated services. Users can start with a Free Community Account, which offers foundational capabilities for asset discovery and vulnerability intelligence. For more extensive requirements, FullHunt offers paid subscription plans that scale with additional features, higher asset limits, and dedicated support. The official FullHunt pricing page details the current plan offerings and their respective inclusions.

The platform's focus on continuous asset discovery and vulnerability monitoring means that pricing often reflects the ongoing computational resources required to scan and analyze an organization's digital footprint. As organizations grow or their attack surface expands, the need for higher tiers or custom enterprise solutions typically increases. This model is common among EASM providers, where the value scales with the breadth and depth of the security coverage provided. For context on broader security pricing models, resources like cloud security pricing comparisons can illustrate common cost drivers in the industry.

Plans and tiers

FullHunt's pricing structure is divided into several tiers, each designed to meet different operational scales and feature requirements. These tiers typically include a Free Community Account, a Team plan, and custom Enterprise solutions. Each tier builds upon the previous one, offering increased asset limits, advanced features, and enhanced support options.

Comparison Table: FullHunt Plans

Plan Price (Monthly) Key Limits / Features Best For
Free Community Account Free Limited asset discovery, basic vulnerability intelligence, community support. Individual researchers, students, small projects, evaluating core features.
Team From $199 Increased asset limits (e.g., 500 assets), API access, advanced vulnerability scanning, email support. Small to medium-sized security teams, startups, organizations with a defined attack surface.
Enterprise Custom Quote Unlimited assets, dedicated infrastructure, advanced integrations, custom reporting, 24/7 support, dedicated account manager, SLA. Large enterprises, managed security service providers (MSSPs), organizations with complex security needs and extensive attack surfaces.

The specific features and asset allowances for each plan are subject to change, and users should consult the official FullHunt pricing page for the most current details. The Team plan, for instance, offers a significant upgrade in terms of automated scanning capabilities and integration potential, which is crucial for teams looking to incorporate EASM into their existing security workflows. Enterprise plans are tailored to specific organizational needs, often including features like single sign-on (SSO), advanced role-based access control (RBAC), and compliance reporting.

Free tier and limits

FullHunt offers a Free Community Account, which serves as an entry point for users to explore the platform's core functionalities without a financial commitment. This free tier is designed for individual security researchers, students, and small teams who need basic asset discovery and vulnerability intelligence capabilities. While it provides a foundational understanding of an organization's external attack surface, it comes with specific limitations on usage and features.

Free Community Account Limitations:

  • Asset Discovery: Limited number of assets that can be monitored. For example, users might be restricted to a certain number of domains or IP ranges.
  • Vulnerability Intelligence: Access to basic vulnerability data and alerts, but potentially without the advanced correlation or historical data available in paid tiers.
  • API Access: Generally not included or severely restricted compared to paid plans, limiting automation capabilities.
  • Support: Primarily relies on community forums or documentation, without dedicated email or priority support.
  • Features: Core features are available, but advanced functionalities like continuous monitoring frequency, deep scanning, and integration options are typically reserved for paid subscriptions.

The Free Community Account is valuable for initial reconnaissance and understanding the scope of an attack surface. However, for continuous monitoring, comprehensive vulnerability management, and integration with other security tools, upgrading to a paid plan is generally necessary. The exact limits of the free tier are detailed on the FullHunt pricing page, which specifies the number of assets and features included.

Real-world cost examples

Understanding FullHunt's pricing involves considering typical use cases and how they align with the available plans. These examples illustrate potential monthly costs based on common organizational needs.

Example 1: Small Startup with a Basic Web Presence

  • Scenario: A startup with 5-10 primary domains, a few dozen subdomains, and a small number of public IP addresses. They need to monitor for newly exposed assets and critical vulnerabilities.
  • Plan Recommendation: FullHunt Team plan.
  • Estimated Monthly Cost: $199.
  • Rationale: The Team plan provides sufficient asset limits (e.g., 500 assets) and access to essential features like API integration and advanced vulnerability scanning, which are crucial for a growing startup to maintain a proactive security posture. The cost aligns with their need for more than basic free tier capabilities without the overhead of an enterprise solution.

Example 2: Medium-Sized Company with Multiple Business Units

  • Scenario: A company with 50-100 domains, hundreds of subdomains, and a dynamic cloud infrastructure. They require continuous monitoring, integration with their SIEM, and detailed reporting for compliance.
  • Plan Recommendation: FullHunt Enterprise plan (custom quote).
  • Estimated Monthly Cost: Varies, typically starting from several hundred to thousands of dollars, depending on asset count and custom features.
  • Rationale: The Enterprise plan offers unlimited assets, advanced integrations (e.g., with AWS SIEM solutions), dedicated support, and custom reporting necessary for a larger, more complex attack surface. The custom pricing allows for tailoring features like specific scanning frequencies or compliance-driven reporting.

Example 3: Individual Security Researcher or Bug Bounty Hunter

  • Scenario: An individual actively participating in bug bounty programs or conducting personal security research, focusing on a limited number of targets at a time.
  • Plan Recommendation: FullHunt Free Community Account.
  • Estimated Monthly Cost: Free.
  • Rationale: The Free Community Account provides sufficient capabilities for basic asset discovery and initial vulnerability checks, allowing researchers to identify targets and potential entry points without incurring costs. For more intensive or automated scanning, a temporary upgrade to the Team plan might be considered for specific projects.

These examples illustrate how the scale of an organization's digital footprint and its specific security requirements directly influence the appropriate FullHunt plan and associated costs. Prospective users are encouraged to contact FullHunt directly for a personalized quote, especially for Enterprise-level needs, to ensure accurate pricing based on their unique infrastructure.

How the pricing compares

FullHunt operates in the External Attack Surface Management (EASM) market, competing with other providers like Censys, Shodan, and Intrigue. The pricing models across these platforms often share common characteristics, primarily revolving around asset count, data access, and feature sets, but also present distinct differences.

Censys

Censys offers various plans, including a free tier for researchers and paid plans for enterprises. Like FullHunt, Censys's enterprise pricing is typically custom-quoted, based on factors such as the number of assets, search queries, and API usage. Censys is known for its extensive internet-wide scanning data, which can be a key differentiator in its value proposition and, consequently, its pricing structure. For smaller teams, Censys may offer more granular control over data access, potentially leading to different cost efficiencies compared to FullHunt's tiered approach.

Shodan

Shodan provides a free account with limited search credits and paid memberships that offer increased credits, API access, and additional features like network alerts. Shodan's pricing is often perceived as more accessible for individual researchers and small teams, with lifetime membership options available. While Shodan excels at identifying internet-connected devices and services, its focus is more on raw data collection and less on continuous, managed attack surface monitoring compared to FullHunt's EASM platform. This difference in core offering can lead to a lower entry price for Shodan, but potentially higher costs for comprehensive EASM capabilities.

Intrigue

Intrigue offers an open-source option alongside commercial offerings. Its pricing model for commercial use is generally based on factors like the number of projects, users, and the scale of the attack surface being monitored. Intrigue's strength lies in its highly customizable and extensible platform, which can be advantageous for organizations with specific integration needs. However, this flexibility might come with a higher initial setup cost or require more internal resources for deployment and management compared to FullHunt's more out-of-the-box EASM solution. The open-source component of Intrigue also provides a distinct cost advantage for those willing to self-host and manage the solution.

Overall Comparison

FullHunt's pricing is competitive within the EASM space, particularly for organizations seeking a managed solution with clear tiers for scaling. Its Free Community Account provides a solid entry point, similar to free tiers offered by alternatives. The Team plan offers a structured upgrade path for growing organizations. Enterprise pricing, while custom, aligns with industry standards for comprehensive EASM platforms that provide extensive asset discovery, vulnerability intelligence, and integration capabilities. The choice between FullHunt and its alternatives often comes down to the specific balance between cost, feature set, data depth, and the level of managed service required by the user.