ProjectDiscovery
Security company behind the widely used open-source Nuclei vulnerability scanner, now offering a commercial cloud platform for AI-assisted pentesting and attack surface management.
Visit Website ↗ + Add to CompareOverview
ProjectDiscovery was founded in 2020 and is headquartered in San Francisco. The company began as the team behind a suite of widely adopted open-source security tools — including the Nuclei vulnerability scanner, Subfinder, HTTPX and Naabu — that became staples of the bug bounty and offensive security research community, with Nuclei alone maintaining a library of 10,000+ community-contributed detection templates.
Building on that open-source foundation, the company now offers a commercial Cloud Platform for vulnerability scanning and attack surface management, plus a newer AI-powered pentesting and security agent product. ProjectDiscovery reports more than 100,000 security professionals using its tools and cites customers including Elastic, ConnectWise and Paddle, and the company was recognized at both the RSA Conference Innovation Sandbox and Black Hat in 2025.
Innovation Matrix Assessment
A prolific open-source release cadence (Nuclei, Subfinder, HTTPX, Naabu) plus rapid expansion into an AI pentesting agent shows fast, community-validated product iteration.
Widely adopted open-source scanning tooling embedded in many security teams' existing workflows reduces friction in adopting the commercial platform built on top of it.
Recognition at RSA Innovation Sandbox and Black Hat 2025, plus a reported 100,000+ tool users, indicate strong community and industry momentum, even without disclosed funding figures.
Open-sourcing core scanning infrastructure and layering a commercial AI agent on top is a notable go-to-market model, though the scanning techniques themselves build on established approaches.
Nuclei's broad, community-vetted adoption in bug bounty and pentest workflows is a meaningful real-world efficacy signal, though this is community usage rather than a controlled benchmark.
Open-source-backed vulnerability scanning and AI-assisted attack surface testing sit squarely in the direction the broader security tooling market is moving.
Why CISOs Should Care
ProjectDiscovery gives CISOs access to attack surface and vulnerability scanning built on the same open-source engine already trusted and battle-tested by a huge global community of independent security researchers and bug bounty hunters.
What Makes It Different
Its open-source-first model, with a massive community-contributed detection template library, differentiates ProjectDiscovery from closed, proprietary-only scanning vendors and gives its commercial platform an unusually large and transparent detection-content base.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
A technically well-regarded company with genuine grassroots credibility from its open-source tools, now converting that community trust into a commercial AI-assisted attack surface and pentesting platform; strong technical reputation, still building out enterprise commercial scale.
Editorial Note: Claims vs. Verified Findings
User counts, customer names and award recognition are drawn from ProjectDiscovery's own site; specific funding details could not be independently verified in this research pass and are marked undisclosed.
Sources
Alternatives to ProjectDiscovery
CybelAngel
External attack surface management and digital risk protection platform that scans the open, deep, and dark web for…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Armis (a ServiceNow company)
Agentless asset intelligence platform discovering and assessing every connected IT, OT, IoT and medical device, now part of…
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
Doppel
San Francisco AI-native digital risk protection platform that detects and automatically takes down phishing sites, impersonation accounts, and…