XHack Logo
XHack
Home
Features
Services
BlogPricingContact
Sign upLogin
XHack Logo
XHackOffensive Security

Certified cybersecurity firm delivering enterprise-grade security solutions. VAPT, Red Teaming, SOC, and AI-powered security tools.

OSCP+OSCPC-AI/MLPenCASA
Services
  • VAPT Services
  • Red Teaming
  • SOC Services
  • Threat Intelligence
  • GDPR Compliance
  • Incident Response
Quick Links
  • About Us
  • VAPT
  • Services
  • XHack AI
  • Docs
  • Pricing
  • Services Pricing
  • Blog
  • Case Studies
  • Documents
  • Team
  • Certifications
Comparison
  • XBOW vs XHack
  • Horizon3 vs XHack
Contact
support@xhack.io

24/7 SOC Operations

XHack Status
Under attack? Get help nowGet a Quote

© 2026 XHack. All rights reserved.

Security & TrustVulnerability DisclosurePrivacy PolicyTerms of ServiceRefund Policy
Blog/Security

Horizon3 vs XHack: An Honest 2026 Buyer’s Comparison

XHack

XHack

Author

September 12, 2026

19 min read

Horizon3 vs XHack: An Honest 2026 Buyer’s Comparison

Table of contents

23

Horizon3 vs XHack at a Glance

What NodeZero Does

What Horizon3 gets right

Where it falls short

What XHack Does

It works inside the network

What it covers that NodeZero doesn’t

Horizon3 vs XHack Pricing, Three Ways

Buying a subscription for a company

Buying one test with humans on it

Buying as one person

Horizon3 vs XHack Scope: Where They Overlap

Who Is Allowed to Buy

The Proof Gap

Horizon3 vs XHack: How to Choose

FAQ: Horizon3 vs XHack Questions Answered

Can XHack replace NodeZero for Active Directory testing?

What does Horizon3 NodeZero actually cost?

Can one person buy NodeZero?

Is XHack’s free trial actually free?

Does Horizon3 have a Gartner Magic Quadrant ranking?

Which should a startup or small security team pick?

The Bottom Line

By Salman Khan, OSCP+, Founder of XHack, SRT (Synack Red Team member)

Read this in 30 seconds: Both products break into internal networks and both work Active Directory. What you are really choosing between is a proven, expensive platform and a cheaper, broader one.

  • NodeZero starts at $15,000. That buys one test against 1,000 assets. XHack’s company plan is $560 a month, and a solo researcher pays $20.
  • Horizon3 has proof XHack does not. It says NodeZero solved the Game of Active Directory range in 14 minutes, and it sells a deception product built only for AD.
  • XHack does the same AD work. Privilege escalation paths, lateral movement, credential testing, pivoting between machines, up to taking a domain admin account.
  • Horizon3 has FedRAMP High. XHack has nothing like it. If you sell to the federal government, that ends the conversation before price comes up.
  • Only one of them will sell to a single person. NodeZero has no individual plan at any price.

I run XHack. Keep that in mind for the next four thousand words.

If you are weighing Horizon3 vs XHack, the price tags make it look simple. NodeZero opens at $15,000. XHack opens at $560 a month for a company, or $20 for one person. That is a real gap, and it is close to the least useful thing about this decision.

Here is what actually matters. Both platforms attack internal networks. Both do Active Directory, lateral movement and post-exploitation. Horizon3 can prove its version works and can sell to the federal government. XHack covers more ground for less money and will sell to one person with a credit card.

Neither of those cancels the other out, so the rest of this is about which one fits the situation you are actually in.

Horizon3 vs XHack AI pentesting platforms compared side by side for pricing and scope
Horizon3 NodeZero vs XHack: comparing autonomous pentesting platforms in 2026

Horizon3 vs XHack at a Glance

Horizon3 (NodeZero)XHack
Cheapest way in$15,000, one time, one test$560/mo company, $20/mo individual
Can you see the price?Only on its AWS Marketplace listing, not its own siteYes, published
Annual tiers$25,000, $32,500, $42,500 (500 assets)$6,720, $13,188, $36,000
Test volumeUnlimited runs, 500 to 1,000 assets2, 5 or 12 asset scans a month
Internal network and ADYes, its specialityYes
AD proofGOAD solved in 14 minutes, plus AD TripwiresNone published
MobileNoYes: jadx, androguard, ADB, Frida
AI and LLM testingNoYes: AI Probe, OWASP LLM Top 10
Supply chainNoYes: GitGuard
Sells to individualsNoYes
Trial30 days, company email, then read-only7 days, no card, ID check first
ComplianceFedRAMP High“SOC 2 ready,” which is not certified
Size~7,000 customers, $250M raised at $2B+6 clients, team of eight
Air-gapped optionNoYes, local agent

Two rows decide most cases: AD proof and price. If you want the wider market instead of a head-to-head, 12 AI pentest tools ranked for 2026 covers it.

What NodeZero Does

NodeZero attacks your network the way an intruder would. It maps what is there, then chains steps together, pivoting from a weak machine to a better one, rather than working down a list of known CVEs like a scanner.

It runs without installing an agent on every host, and Horizon3 is refreshingly specific about the AI inside it. NodeZero “never uses GenAI to create or execute exploits.” The exploit code is fixed and pre-tested. The AI does the reasoning about where to go next. That is a deliberate safety trade, and it separates NodeZero from a fully generative autonomous penetration testing agent.

What Horizon3 gets right

FedRAMP High. NodeZero Federal earned it in May 2025. You can check it yourself on the FedRAMP marketplace, which makes it one of the few vendor claims in security you do not have to take on faith. Without it you cannot touch high-impact federal systems. XHack does not have it, and no discount substitutes for it.

A benchmark nobody else can point at. GOAD is a deliberately nasty Active Directory range that security teams use to test themselves. Horizon3 says NodeZero solved it completely in 14 minutes. Then it built AD Tripwires, decoys that sit inside Active Directory and fire when someone touches them. Base Tripwires shipped in September 2024, the AD version a year later. That is a company putting years into the hardest surface in enterprise security.

Mileage. More than 300,000 production-safe tests, 310,000 by its August 2026 raise. The number has climbed steadily across years of announcements instead of appearing fully formed, which makes it easier to believe.

Money. A $250M round in August 2026 at over $2 billion, roughly triple what the company was worth 14 months earlier. Around 7,200 customers and $100M in recurring revenue, growing near 120% a year. They are not going anywhere.

Grown-up product lines. Tripwires and Insights, a dashboard tracking how fast teams actually fix things, are what you build after the core product works. Small competitors rarely have them.

Good reviews, thin numbers. 4.8 out of 5 on G2, from 24 reviews. 4.7 on Gartner Peer Insights from 73, the largest sample anywhere. Gartner named it a Customers’ Choice in October 2025 and put it in a Market Guide. To be precise about that last one: Gartner publishes no Magic Quadrant for this category, so nobody leads one, whatever a sales deck implies.

The federal traction makes sense once you know who built it. Snehal Antani was the first CTO of Joint Special Operations Command. Anthony Pillitiere spent 21 years in the Air Force. They met inside US Special Operations Command. Horizon3 does appear alongside the NSA, but as a Black Hat co-presenter, not as anyone’s former employer.

Where it falls short

You cannot dip a toe in. The entry price is $15,000 for a single test. Horizon3 will not put a number on its own site and routes you to a demo instead. The real figures live on its AWS Marketplace listing, which most buyers never think to check: $15,000 for Flex, then $25,000, $32,500 and $42,500 a year.

“Unlimited” is not unlimited. You get unlimited test runs. You do not get unlimited scope. Every tier stops at 500 or 1,000 assets, and the only published route past that is a $100,000 support package covering 25,000.

One person cannot buy it. No plan exists for an individual, a freelancer or a bug hunter. The only self-serve door is a 30-day trial that needs a company email address, and when it expires the account freezes into read-only rather than closing.

A customer who did the math and left. Karrie Westmoreland, a senior security engineer, gave it three stars in July 2026 after about 18 months. She flagged results landing outside her scope and, as reported, too much cost for too few real attacks, and did not renew. I could not confirm her exact wording, so treat it as reported rather than quoted. It is also the only detailed criticism I could find anywhere, which cuts both ways.

Nobody will go on record. The case studies are anonymous: a North American manufacturer, a major social media company. Horizon3 says it works with Fortune 10 firms, the NSA and CISA. No named customer confirms it publicly.

No mobile, no AI testing. Horizon3 sells neither. If you ship an app or run an LLM in production, you are buying a second tool for those.

The web app product is brand new. NodeZero WebApp Pentesting launched on 29 July 2026 and was still behind an early-access waitlist on day one.

One thing I noticed and cannot explain: for a product with thousands of customers, there is almost nothing about NodeZero on Reddit or Hacker News. Make of that what you will.

What XHack Does

XHack sells three things on one contract that usually come from three vendors: human penetration testers, an autonomous AI agent, and a security operations platform that keeps watching after the test ends.

It works inside the network

This is the part people get wrong, so plainly:

The agent does port scanning and service enumeration, Active Directory assessment, privilege escalation path discovery, lateral movement, credential testing and network segmentation checks. It moves through an enterprise network on its own, pivoting from machine to machine.

Once it has a foothold it keeps going: escalating privileges, harvesting credentials, moving sideways, finding data worth stealing. On the human side, XHack’s testers exploit what they find to prove real impact, up to taking control of a domain administrator account, inside agreed rules of engagement.

What XHack cannot do is show you a benchmark. Horizon3 can. That is a gap in evidence, not in ability, and if your board wants a number on a slide it is a gap that matters.

What it covers that NodeZero doesn’t

  • Mobile apps. jadx and androguard to pull APKs and IPAs apart, ADB for exported components, Frida for hooking a running app.
  • AI and LLM systems. AI Probe throws over 350 attack payloads at the OWASP LLM Top 10, so prompt injection and the rest.
  • Supply chain. GitGuard reads pull requests for vulnerable dependencies, exposed CI tokens and leaked .env files before they merge.
  • Cloud misconfiguration. Open buckets, over-privileged IAM roles, exposed Kubernetes.

Cloud is the one place both compete head on, because Horizon3 sells cloud and Kubernetes testing too. The other three it does not sell at all.

XHack also runs offline. There is a desktop agent on Ollama or llama.cpp for air-gapped and classified environments where nothing may leave the building. NodeZero is hosted, with no offline mode. For most buyers that is irrelevant. For a defence contractor it decides everything.

Three ways to buy: $20 a month as an individual, $560 a month as a company, or $2,500 for a scoped engagement where XHack’s testers work alongside the agent. The 7-day trial takes no card, though your ID has to clear first. It is agentic pentesting with a human signing the report, an AI VAPT model rather than a machine left alone with your network.

Horizon3 vs XHack Pricing, Three Ways

Setting $20 against $15,000 would be a cheap trick, because they are not the same purchase. Three fair comparisons instead. For how this market prices in general, AI penetration testing costs has the full range.

Buying a subscription for a company

XHack is $560 a month for Starter, $1,099 for Premium, $3,000 for Elite. Over a year: $6,720, $13,188, $36,000.

NodeZero is $15,000 once for Flex, or $25,000 a year for Core. Vendr, a procurement brokerage that earns its living being trusted on software pricing, puts the median real deal at $18,600 a year and the top end near $59,720. Useful, but their numbers point in a direction rather than close a case.

XHack’s middle tier at $13,188 for a year still costs less than one NodeZero test. Before treating that as settled, the cheapest AI pentest tools is worth reading, because cheap and good are separate questions.

Buying one test with humans on it

XHack’s Essential engagement is $2,500: one unauthenticated web app or up to 50 host IPs, four days, retest included, scope agreed before anyone starts. Real testers working with the agent.

Horizon3 sells human compliance testing as well, staffed with OSCP-certified people. It publishes no price, so there is nothing honest to compare it against.

Buying as one person

This is not about which number is smaller. It is about whether you are allowed through the door. XHack sells to a single researcher for $20 a month. NodeZero has no individual plan at any price.

Horizon3 (NodeZero)XHack
Company subscription$15,000 once, or $25,000/yr$560/mo, $6,720/yr
Typical real deal$18,600/yr, up to $59,720 (Vendr)Too small to appear in pricing trackers
One human-led testSold, price not published$2,500, four days, retest included
IndividualNot available$20/mo
Pricing comparison table for Horizon3 NodeZero company tiers versus XHack company and individual plans
Horizon3 vs XHack pricing: company subscriptions, scoped engagements, and individual tiers side by side

Before you quote those numbers at anyone: they do not buy the same thing. NodeZero’s price buys unlimited runs against 500 to 1,000 assets, pointed at internal networks and Active Directory. XHack’s tiers are metered, 2, 5 or 12 asset scans a month with a cap on log volume, pointed wider. This compares what it costs to start, not what you get. An enterprise wanting continuous testing across thousands of assets should buy NodeZero, because XHack has no tier for that.

Horizon3 vs XHack Scope: Where They Overlap

The tidy version of Horizon3 vs XHack would be that NodeZero owns networks and XHack owns everything else. That is not true. Both work internal networks and Active Directory. The difference is where each spent its effort.

Attack surfaceHorizon3 (NodeZero)XHack
Internal networkYes, its flagshipYes
Active Directory, lateral movementYes, with GOAD and AD TripwiresYes, no benchmark published
ExternalYesYes
Cloud and KubernetesYesYes
Web app and APIYes, launched July 2026Yes
MobileNoYes
AI and LLM systemsNoYes
Supply chainNoYes
Comparison chart of Horizon3 NodeZero and XHack attack surface coverage across network, Active Directory, mobile, and AI
Horizon3 vs XHack attack surface comparison: where coverage overlaps and where it diverges

The overlap is the ground where real breaches happen. Somebody gets a foothold, escalates, moves sideways, reaches a domain controller. Both products do that autonomously. Horizon3 has years of published results behind its version and XHack has none, which is the whole argument for paying more.

The divergence is everything past the network. Mobile, AI systems and supply chain sit inside XHack’s plans from Premium up. Horizon3 does not sell them.

For a wider view, XHack’s ranked comparison of AI pentesting agents and the field of autonomous AI hacking agents put this pairing in context.

Who Is Allowed to Buy

Scope and price are half of a Horizon3 vs XHack decision. Who each company will actually sell to is the other half.

Individuals. XHack sells plans at $20, $49 and $150 a month to one person with a card. NodeZero has no individual tier. If you are a freelancer or a bug hunter, that is the entire comparison and you can stop reading.

Trials. NodeZero gives 30 days but wants a company email, which locks out anyone without a business domain, and the account drops to read-only when time runs out. XHack gives 7 days with no card, but a government ID has to be approved first, and companies submit business documents too. Free, and not anonymous.

A solo researcher can be running XHack this afternoon. An enterprise with a procurement team can work with either.

The Proof Gap

This is the part of Horizon3 vs XHack that explains the price difference, more than any feature list.

Horizon3 can point to a dated result on a public test range, a product line built around Active Directory, 300,000 logged tests, a federal authorization and two Gartner mentions. Every one of those is checkable by someone who does not work there.

XHack’s side is short and I am not going to dress it up. Six clients secured. Thirty-two assessments done. Fourteen written up. Three separate counts, not one number wearing three hats. Compliance is “ISO 27001, SOC 2 ready,” which means preparing for an audit, not passing one. There is no SOC 2 report, no ISO certificate number and no auditor named anywhere.

The one hard result for the agent is a redacted YesWeHack case. It found live OAuth client credentials hardcoded into a Flutter web bundle in about 25 minutes with almost no human help, and the programme paid out. That happened, and it is one finding. It is not a track record sitting next to 300,000 tests.

One distinction I want to make cleanly, because it would be easy to blur. My Synack Red Team membership and the vulnerabilities I have reported are manual work I did with my own hands. The AI agent inherits none of that, and I am not going to let it borrow my CV.

Horizon3 vs XHack: How to Choose

Buy NodeZero if:

  • You sell into federal or high-impact government systems and need a FedRAMP High vendor.
  • Your board or your auditor wants a dated benchmark, not a capability description.
  • You are an enterprise running continuous tests across 500 to 1,000 assets.
  • A multi-week sales process is fine and you have $15,000 to $25,000 a year.

Buy XHack if:

  • You need mobile, AI and supply-chain testing alongside network and AD work, from Premium up.
  • Your budget is $6,000 to $15,000 a year, or you want one scoped test instead of a subscription.
  • You are one person, or a small team nobody enterprise will sell to.
  • You need an air-gapped deployment.
  • You will trade a shorter track record for lower cost and wider coverage.

Before signing with either of us, how to choose a pentest provider lists the questions worth asking and the answers that should worry you.

Decision framework diagram for choosing between Horizon3 NodeZero and XHack based on budget, scope, and compliance needs
Horizon3 vs XHack decision framework: which buyer fits which platform

FAQ: Horizon3 vs XHack Questions Answered

Can XHack replace NodeZero for Active Directory testing?

For the work itself, yes. XHack’s agent handles Active Directory assessment, privilege escalation path discovery, lateral movement and live exploitation up to taking a domain admin account. What it cannot hand you is a benchmark. Horizon3 solved the GOAD range in 14 minutes and has sold AD Tripwires since September 2025. So the capability matches and the evidence does not, which matters a lot if someone above you needs convincing and not at all if they do not.

What does Horizon3 NodeZero actually cost?

Horizon3 will not say without a demo, but its AWS Marketplace listing will: $15,000 once for Flex covering 1,000 assets, then $25,000, $32,500 and $42,500 a year for 500 assets. Vendr, a procurement brokerage rather than an auditor, puts the median real deal at $18,600 a year and the ceiling near $59,720. The detail most buyers miss is the asset cap. Every tier stops at 500 or 1,000, and the only listed way past it is a $100,000 support package covering 25,000.

Can one person buy NodeZero?

No. There is no plan priced for an individual, a freelancer or a solo hunter. Whether Horizon3 would refuse such a sale is not something anyone outside the company can answer, but there is no door to walk through. The cheapest entry is $15,000, and the 30-day trial needs a company email. When it ends the account goes read-only rather than closing, so your results stay visible but frozen.

Is XHack’s free trial actually free?

Yes, no credit card. The catch is identity, not money. An individual needs a government ID approved before touching any tooling, and a company submits business documents too. So it costs nothing and it is not instant. If it matters: those documents are held while the account is open and deleted 30 days after you close it.

Does Horizon3 have a Gartner Magic Quadrant ranking?

No, and neither does anyone else, because Gartner does not publish a Magic Quadrant for this category. Horizon3 was named a Customers’ Choice in Gartner Peer Insights in October 2025 and appears in a Gartner Market Guide. Both are real. Both sit a step below a Magic Quadrant, so treat any vendor who blurs that line accordingly.

Which should a startup or small security team pick?

Price the smallest real piece of work each one will sell you. XHack’s Essential engagement is $2,500 with the scope written down and four-day delivery, so you know the cost and the date before committing. Horizon3 sells human testing too but publishes no price, so you learn both numbers at the end of a sales cycle. If you need FedRAMP High, or a benchmark an auditor will accept, NodeZero is the safer buy even at several times the money.

The Bottom Line

Horizon3 vs XHack comes down to this. Both products do much of the same work, and what separates them is proof and scale, not capability.

Horizon3 earned its price with years of published results, a federal authorization we cannot match, and a balance sheet most companies never see. XHack earned its price with a company plan costing less than half of one NodeZero test, a plan a single person can buy, three attack surfaces Horizon3 does not sell, and a human-led engagement from $2,500.

If you need FedRAMP High or a benchmark for an auditor, buy NodeZero and do not let the price argue you out of it. If your budget stops well short of $15,000, or you need more than the network without signing a second contract, our pricing is on the site and the trial costs nothing but a verification step.

If XBOW is also on your shortlist, XBOW vs XHack runs the same numbers against a very different competitor: web and API only, billed per test.

Do not buy on price alone, and do not buy on one benchmark alone. Horizon3 vs XHack really comes down to what your auditor, your budget and your actual attack surface need. For everything else in this market, the honest comparison of AI pentesting tools is the next stop.


Categories

Security

Previous

AI vs Human Penetration Testing: What Each One Actually Catches in 2026

Next

XBOW vs XHack

On this page

Horizon3 vs XHack at a Glance

What NodeZero Does

What Horizon3 gets right

Where it falls short

What XHack Does

It works inside the network

What it covers that NodeZero doesn’t

Horizon3 vs XHack Pricing, Three Ways

Buying a subscription for a company

Buying one test with humans on it

Buying as one person

Horizon3 vs XHack Scope: Where They Overlap

Who Is Allowed to Buy

The Proof Gap

Horizon3 vs XHack: How to Choose

FAQ: Horizon3 vs XHack Questions Answered

Can XHack replace NodeZero for Active Directory testing?

What does Horizon3 NodeZero actually cost?

Can one person buy NodeZero?

Is XHack’s free trial actually free?

Does Horizon3 have a Gartner Magic Quadrant ranking?

Which should a startup or small security team pick?

The Bottom Line

Related articles

Continue reading

AI Penetration Testing Compliance: Will Your Auditor Accept an AI-Run Test?

Security

AI Penetration Testing Compliance: Will Your Auditor Accept an AI-Run Test?

Which frameworks accept an AI-run pentest, what CREST’s new accreditation requires, and the one report field an agent ca...

Read article
AI vs Human Penetration Testing: What Each One Actually Catches in 2026

Security

AI vs Human Penetration Testing: What Each One Actually Catches in 2026

What AI catches, what a human catches, and what the research actually shows. Benchmarks, live head-to-heads, compliance ...

Read article
XBOW vs XHack

Security

XBOW vs XHack

XBOW and XHack compared on real pricing, scope, HackerOne proof and honest limits on both sides, so you pick the tool th...

Read article