ASM Comparison

HailBytes ASM vs runZero

runZero excels at internal asset discovery. HailBytes ASM is built for external attack-surface monitoring with white-label deliverables. They’re often complementary; this page helps you decide which (or both).

TL;DR

runZero (formerly Rumble Network Discovery) is best in class for internal active asset discovery: agentless network scans that find IT, OT, and unmanaged devices on your corporate networks. HailBytes ASM is an external attack-surface management platform that runs the recon pipeline on internet-facing assets inside your own AWS or Azure account.

  • Pick HailBytes ASM if you need continuous external recon, white-label deliverables for clients, or AI-agent orchestration over the scan pipeline.
  • Stay with runZero if your priority is unmanaged-device discovery on internal networks and OT/IoT visibility.
  • Run both if you need full internal + external coverage; the products don’t overlap meaningfully.

Pricing & Cost Model

HailBytes ASM starts at 4 vCPU, ASM’s documented minimum, at $5,880/year on a 1-year commitment ($8,400 at list). 8 vCPU, the size ASM’s hardening guide names Production (recommended), is $11,760 committed ($16,800 at list). runZero Professional is cheaper than our floor on a small surface, and the two products are not substitutes anyway: external recon of an unknown internet-facing surface is a different job from authenticated internal asset discovery. Treat the table below as a budgeting reference, not a scorecard.

DimensionHailBytes ASMrunZero
Pricing axisInfrastructure ($0.24/vCPU/hour)Per asset (Professional / Enterprise tiers)
Annual cost (small surface)$5,880 (4 vCPU, ASM’s documented minimum; $8,400 list), all-in $8,520 committed and $11,040 at list: runZero Professional still undercuts us outright, though by less than it did against 8 vCPU; we lose this band~$5,000 (Professional)
Annual cost (mid surface)$11,760–$23,520 (8–16 vCPU; $16,800–$33,600 list), all-in this overlaps runZero’s range at 8 vCPU and exceeds its top at 16$15,000–$30,000
Annual cost (large surface)$23,520–$47,110 (16–32 vCPU; $33,600–$67,300 list), all-in, below runZero Enterprise at 16 vCPU and above it at 32$50,000+ (Enterprise)
Free trial30 days via AWS / Azure Marketplace21-day Community / Pro trial
Procurement pathCloud marketplace (counts toward EDP / MACC)Direct subscription

HailBytes figures are the 1-year commitment price (delivered as an AWS or Azure private offer, not a discount on the published meter) with list alongside, so the comparison sits on the same annual-contract basis as the competitor column. The meter covers software only; the VM, storage, and networking run in your own cloud account and are billed separately at roughly $35/vCPU/month, $220/month at 4 vCPU, $280 at 8, $560 at 16, and $1,120 at 32, so scale that line to the size on the row you are reading.

Our cost steps with the size of the surface rather than scaling per asset, so every comparison on this page is calculated all-in against the rung that fits. 4 vCPU is ASM’s documented minimum and suits a small, stable surface (about $8,520/year all-in on a 1-year commitment, $11,040 at list). 8 vCPU is the size ASM’s own hardening guide names Production (recommended) and covers 10 to 50 scheduled scans a day ($15,120 / $20,160). 16 vCPU covers 50+ scans a day ($30,240 / $40,320). Quote 4 vCPU only where the surface genuinely is small and stable; 8 vCPU is the size we recommend for production. Full pricing.

Sizing above 8 vCPU: ASM sizes its scan worker from the host, so a larger instance scans proportionally faster: a 16 vCPU deployment gives the scan engine twice the cores an 8 vCPU one does. Instances deployed before August 2026 pick this up on the next update, when the installer rewrites the worker limits to match the machine.

Architecture & Control

DimensionHailBytes ASMrunZero
DeploymentSelf-hosted in your AWS / Azure accountSaaS console + on-prem Explorer scanners
Source code accessShips with the deployment; auditable under NDAClosed source
Primary scan targetExternal attack surface (internet-facing)Internal corporate networks (agentless)
Custom scan logic / wordlists✅ Full control🟡 Probe customization
Per-tenant isolationOne VM per tenantMulti-tenant SaaS console

Capability Comparison

CapabilityHailBytes ASMrunZero
External subdomain enumeration✅ Multi-source❌ Not the use case
Internet-facing port & service scanning✅ Built-in🟡 If targeted
Internal network active discovery❌ Not the use case✅ Best in class
OT / IoT / ICS device discovery✅ runZero’s real moat
CVE matching
Custom wordlists✅ Unlimited🟡 Probe-level
AI-powered analysis✅ OpenAI + Ollama (local GPU)
MCP server / AI-agent tooling✅ Built-in (Claude / Cursor / Windsurf)
SIEM integrationSplunk, Sentinel, Elastic, Chronicle✅ Webhook + connectors
Government cloud (GovCloud / Azure Gov)✅ Both🟡 FedRAMP-pursuing
White-label for client deliverables✅ Built-in

See It in the Product

runZero is excellent at the internal network. ASM is built for the external surface and the OT protocols exposed on it.

HailBytes ASM vulnerability list filtered to exposed industrial protocols, showing MODBUS and Siemens S7 findings
MODBUS, Siemens S7, DNP3 and BACnet as first-class findings.
HailBytes ASM cloud connectors page with AWS, Azure, GCP and Cloudflare asset-discovery integrations
Cloud accounts inventoried alongside the domains.

Captured from a running instance. See all 48 screens →

When HailBytes ASM Wins

  • External attack-surface monitoring is the use case. runZero’s strength is on the inside; for external recon, HailBytes is the right primitive.
  • Pen-test firms and MSSPs. Fixed per-instance cost combined with white-label output is what makes resold continuous external monitoring profitable.
  • Government and regulated industries. Deploy in AWS GovCloud or Azure Government and the scan data stays inside your own tenancy.
  • AI-agent recon workflows. A built-in MCP server lets Claude, Cursor, and Windsurf drive scans and finding triage directly.

When runZero Wins

  • Unmanaged internal-device discovery is your real problem. runZero’s agentless internal scans are best in class and widely respected.
  • OT/IoT/ICS environments. runZero handles fragile and proprietary protocols that pure recon-tooling won’t.
  • Asset-management for compliance on the internal side, like PCI scoping, HIPAA inventory, and similar work.

Most teams running both products treat HailBytes ASM as the external-facing layer and runZero as the internal-facing one.

Try HailBytes ASM

Both marketplace listings come with a 30-day trial that covers the VM as well.

Deploy from Marketplace ASM Product Details Full Comparison Matrix

Related Comparisons

Other discovery and ASM platforms usually evaluated alongside runZero:

See HailBytes ASM in Action

Skip the slide deck. Watch the product run end-to-end before you book a call.

HailBytes ASM product demo video thumbnail

Try HailBytes ASM Free

Get a free trial deployment on AWS or Azure. Our team walks you through setup and your first steps, whether that’s a single organization or a multi-client rollout.

  • 30-day free trial on AWS or Azure
  • Guided onboarding from our security team
  • No credit card required to start
  • 40+ security tools pre-configured

Request a Free Trial

We’ll respond within one business day.