Home / Security / NodeZero / Accounts with a subscription
NodeZero account with a paid subscription
Horizon3.ai
—
No offers yet
Nobody has listed this product yet. We do not invent prices: a displayed price is a public offer, and it only ever comes from a live seller.
Plans
NodeZero Flex
- Autonomous penetration tests on demand, whenever you need them
- Internal and external testing plus external asset discovery
- Cloud and Kubernetes cluster testing
- Active Directory audit and phishing impact testing
- Suggested fix actions with one-click verification and comprehensive reports
- MCP server and vulnerability management hub
NodeZero Core
- Everything in Flex, but testing runs continuously rather than as separate campaigns
- Scheduled runs without manual launches
- Testing from the perspective of current threat scenarios
- Assessment of whether your endpoint protection actually fires
- Fits environments that change faster than once a year
NodeZero Pro
- Everything in Core plus precision intrusion detection
- Honeytokens dropped automatically where an attacker would actually find them
- Rapid alerting on emerging vulnerabilities, including ones with no patch yet
- A check on whether the latest headline vulnerability affects you specifically, not a network in the abstract
- The vendor's own attack research team as the intelligence source
NodeZero Elite
- Everything in Pro plus risk management driven by test data
- High-value target discovery — what the business actually loses if an attack lands
- Verification of which data can genuinely be exfiltrated from the network
- Threat actor intelligence and vulnerability prioritization by real risk
- Executive reporting on how the organization's posture changes over time
Plan contents as published by the vendor; seller prices arrive at launch.
What you get
Ready access to the NodeZero portal with a paid package: deploy the lightweight agent inside your network, prove ownership of your external addresses and launch a run. The first thing to establish is whose organization it is: the product is sold under a contract with a specific legal entity, and on someone else's organization access can technically return to its owner along with the history of your tests. Penetration test reports are extremely sensitive material, so make sure you find out who else in that organization can see the results of your runs. Ask about the contract term and how much of the period is left: only the party the contract names can renew it.
About the service
An autonomous penetration test that runs against your own infrastructure without hiring a team of pentesters: the agent finds reachable hosts itself, picks and chains vulnerabilities together and drives the chain to a real outcome — a stolen credential, access to data that is not yours, a domain takeover. It covers the internal network, the external perimeter, cloud and Kubernetes clusters, with a separate directory service audit and phishing impact assessment. Every finding arrives not as "possibly vulnerable" but with the attack path shown, which makes it hard to argue with, and the fix is verified by a one-click re-run. Higher tiers add continuous scheduled runs, honeytokens for early detection of an attacker, rapid alerting on freshly exploited vulnerabilities and risk reporting for leadership. An MCP server is included, so the results can be worked through with your own AI assistant.
The same from another vendor