Buteo compared with Detectify, Intruder and Red Sift ASM

If you already run one of them, here is what Buteo adds, what it does not do, and when to keep what you have.

Detectify and Intruder test your exposed systems actively: they send payloads and crafted requests to find vulnerabilities, and both reach past the perimeter into web applications and APIs. Red Sift ASM, built on Hardenize, reads configuration instead, with TLS and certificate depth from the author of SSL Labs and a family of products that also fix what they find.

Buteo takes the passive road on purpose. It reads what your domain already tells the internet, never touches your systems, scores what it finds and tells you what changed since the last scan. That makes it safe to run against production at any hour, easy to approve, and precise where most attacks on a domain start: email posture, certificates, forgotten subdomains and lookalikes.

Reviewed on 26 September 2026. Every statement about another product cites the vendor's own page, read that day; the sources are at the end. "Not described on the pages we read" means exactly that, and not that the product cannot do it.

Question Buteo Detectify Intruder Red Sift ASM (Hardenize)
What it is The outside view of your domain as a service: DNS and email posture, TLS, headers, subdomains and ports, scored, tracked and compared scan to scan. Surface Monitoring finds exposed files, vulnerabilities and misconfigurations across your attack surface, continuously.[2] Vulnerability scanning and attack surface management, with automated and human penetration testing.[12][16] Attack surface management from Red Sift, which acquired Hardenize, the company of the SSL Labs author.[20][21]
How it tests Reads what the domain already publishes. No credentials tried, no paths probed, no weakness confirmed by exploiting it, so it is safe to point at production. Active: payloads sent to every discovered asset to test for CVEs.[1][2] Active: crafted requests from four engines, OpenVAS, Nuclei, Nessus and OWASP ZAP.[10][14] Configuration assessment rather than hunting for bad things, with scanning of the top 2,000 TCP and UDP ports.[22]
Before the first scan Ownership proven by a TXT record, a well-known file or an email challenge; until then the engine refuses to scan. Ownership verified by a DNS TXT record or an uploaded file.[5] The customer warrants in the terms that it holds the permissions needed; a technical check is not described.[17] Not described on the pages we read.
Email posture SPF resolved in full with its lookup count, DMARC checked for whether it actually rejects, and the DNSSEC chain followed to the root. Missing or insufficient SPF and DMARC records, and missing DKIM.[6][7] Not described on the pages we read. SPF, DMARC, MTA-STS, TLS-RPT, DNSSEC and DANE; the SPF lookup limit and BIMI in a separate product, OnDMARC, which also fixes them.[21][22][23]
TLS, headers and cookies Protocols and ciphers graded, the certificate chain and its time left, and each missing header with what its absence permits. Not described on the pages we read. Weaknesses in SSL/TLS implementations.[15] Connections simulated from popular clients, HSTS, CSP and SRI, secure cookies, and every certificate watched in real time as it is issued.[22]
Subdomains and takeover Subdomains discovered, and dangling CNAMEs open to takeover flagged. More than 600 subdomain-takeover tests, from the team that first researched the attack in 2014.[3] Discovery through connectors to AWS, Google Cloud, Cloudflare and Azure.[12] Dangling DNS that could be a takeover risk.[21]
Lookalike domains Lookalike domains registered by others, found and listed. Not described on the pages we read. Not described on the pages we read. Lookalike variants in ASM, and detection with takedown in Brand Trust.[22][24]
Vulnerabilities in exposed software Technologies fingerprinted on what is exposed; a weakness is reported from the evidence, never proven by exploiting it. Several thousand tests, fed by a crowdsourced community of more than 400 ethical hackers.[1][2][4] Checks from four engines, and emerging-threat scans within hours of a disclosure.[10][11] Not described on the pages we read.
What changed Every scan compared with the last; alertable change separated from recurring noise, with a history of events, and findings kept in a lifecycle from new to accepted risk. Alerts when a new subdomain appears, and custom rules for the changes you care about.[2][3] Scans triggered when the attack surface changes.[12] Real-time notifications of events, and certificate expiry alerts.[22]
Beyond the perimeter Nothing beyond what the domain publishes. The inside view is Ibex. Authenticated DAST, API scanning and internal scanning.[1] Authenticated web application scanning, and penetration testing by its own team.[13][16] Email authentication fixed in OnDMARC, and lookalike takedown in Brand Trust.[23][24]
Track record From DeltaCoders, which has built security software for regulated organisations since 2011. Founded in Stockholm in 2013; ISO 27001.[8][9] Founded in 2015; SOC 2 Type 2; more than 3,000 customers.[18][19] Red Sift holds ISO 27001 and a SOC 2 Type II attestation.[25]

When to pick them instead

If you need a vulnerability proven by exploiting it, pick Detectify or Intruder: Buteo never does that, by design. Pick Detectify for the deepest subdomain-takeover testing and new attack research that reaches the scanner through its crowdsourced community. Pick Intruder if you also want internal and cloud scanning, authenticated web application tests and penetration testers behind the tool. Pick Red Sift if you want the TLS and certificate depth of the SSL Labs lineage, or a product that fixes email authentication and takes lookalike domains down rather than reporting them.

When Buteo is the better fit

When the question is what your domain tells the internet, and you want it answered without anyone touching your systems. Buteo resolves SPF in full with its lookup count, checks whether DMARC actually rejects, follows DNSSEC to the root, grades TLS and headers, finds the subdomains and lookalikes you forgot, and tells you after every scan what changed. It runs as a service, with nothing to install, only on domains you have proven are yours, and reports in PDF and DOCX that someone outside the security team can read.

Buteo is the outside view; Ibex is the inside one. See how Buteo works.

Sources

  1. Detectify, home page, https://detectify.com/, read on 26 September 2026.
  2. Detectify, Surface Monitoring, https://detectify.com/product/surface-monitoring, read on 26 September 2026.
  3. Detectify, Prevent subdomain takeover, https://detectify.com/solutions/prevent-subdomain-takeover, read on 26 September 2026.
  4. Detectify, Crowdsource, https://detectify.com/crowdsource, read on 26 September 2026.
  5. Detectify support, Why do you require verification of domain ownership?, https://support.detectify.com/support/solutions/articles/48001049280-why-do-you-require-verification-of-domain-ownership-, read on 26 September 2026.
  6. Detectify support, Missing or insufficient SPF record, https://support.detectify.com/support/solutions/articles/48001048956-missing-insufficient-spf-record, read on 26 September 2026.
  7. Detectify support, Missing or insufficient DMARC record, https://support.detectify.com/support/solutions/articles/48001048963-missing-insufficient-dmarc-record, read on 26 September 2026.
  8. Detectify, About, https://detectify.com/about, read on 26 September 2026.
  9. Detectify support, Compliance, https://support.detectify.com/support/solutions/articles/48001060834-compliance, read on 26 September 2026.
  10. Intruder help, What scanning engine does Intruder use?, https://help.intruder.io/en/articles/2390040-what-scanning-engine-does-intruder-use, read on 26 September 2026.
  11. Intruder, Emerging threat scanning, https://www.intruder.io/use-cases/emerging-threat-scanning, read on 26 September 2026.
  12. Intruder, Attack surface management, https://www.intruder.io/platform/attack-surface-management, read on 26 September 2026.
  13. Intruder, home page, https://www.intruder.io/, read on 26 September 2026.
  14. Intruder help, Will Intruder's scans damage my systems?, https://help.intruder.io/en/articles/1763014-will-intruder-s-scans-damage-my-systems, read on 26 September 2026.
  15. Intruder help, What checks does Intruder run?, https://help.intruder.io/en/articles/7019918-what-checks-does-intruder-run, read on 26 September 2026.
  16. Intruder, Automated penetration testing, https://www.intruder.io/automated-penetration-testing, read on 26 September 2026.
  17. Intruder, Terms, https://www.intruder.io/legal/terms, read on 26 September 2026.
  18. Intruder, About us, https://www.intruder.io/about-us, read on 26 September 2026.
  19. Intruder, Security, https://www.intruder.io/security, read on 26 September 2026.
  20. Red Sift, Why we've acquired Hardenize, https://redsift.com/blog/why-weve-acquired-hardenize-and-what-this-means-for-our-customers, read on 26 September 2026.
  21. Red Sift, Red Sift ASM, https://redsift.com/pulse-platform/asm, read on 26 September 2026.
  22. Hardenize, Product, https://www.hardenize.com/product, read on 26 September 2026.
  23. Red Sift, OnDMARC, https://redsift.com/pulse-platform/ondmarc, read on 26 September 2026.
  24. Red Sift, Brand Trust, https://redsift.com/pulse-platform/brand-trust, read on 26 September 2026.
  25. Red Sift, ISO 27001 vs SOC 2, https://redsift.com/blog/navigating-the-information-security-landscape-iso-27001-vs-soc-2, read on 26 September 2026.

Detectify, Intruder, Red Sift, Hardenize, OnDMARC, Brand Trust, SSL Labs, Nessus, OpenVAS, Nuclei and OWASP ZAP are trademarks of their owners, named here only to compare. Something here out of date or wrong about your product? Tell us and we will correct it.

Already running one of them?

Tell us which, and which domains matter most, and we will say plainly whether Buteo adds anything.