Yes, Intruder can absolutely scan websites and servers hosted behind Cloudflare. However, it's important to set up your target correctly and allowlist Intruder's scanning IPs so our scanning engines can reach the intended target (website and/or underlying server).
What do I add as a target?
What do you want to scan | What to add as a target | Licenses required |
đ The website/web application only | The domain | 1 |
đ The underlying server only | The server's IP address | 1 |
đ Both the website and the server | The domain and the IP address | 2 |
How do I avoid scan interference?
You'll want to make sure our scanning IPs are added to your allowlist in Cloudflare.
Does this affect my network view?
Cloudflare can sometimes interfere with Attack Surface View, which is where we show you which ports and services you have open to the internet â and so we've outlined the expected behavior below.
Domains behind Cloudflare
When you scan a domain, the scanner automatically resolves its IP address. If a Content Delivery Network (CDN) like Cloudflare is in place, this IP will belong to the CDN.
IP addresses behind Cloudflare
If you add the IP address, the scanner will reach out to that IP address directly and report any open ports as normal:

