AppSecNews
DAST Commercial Established

Acunetix

by Invicti Security

Commercial dynamic application security scanner that crawls web apps with a headless browser engine and confirms many injection findings by exploiting them.

Visit acunetix.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Acunetix in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Current integration list: confirm against vendor documentation
  • Exact scope of the sensor agent language support: verify

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Acunetix drives a target application from the outside. Its crawler loads pages in a headless browser so that client side routing, single page application views and DOM generated links are discovered rather than missed, then it builds a site map of reachable endpoints, forms and parameters. Against that map it runs an attack library covering injection classes, cross site scripting, insecure deserialization indicators, misconfiguration checks, exposed files and known component weaknesses.

The part that distinguishes it from a generic scanner is proof based reporting. For several high severity classes, notably SQL injection and command execution, the scanner does not stop at a suspicious response signature. It sends a follow up payload designed to produce an unambiguous artifact and marks the finding as confirmed only when that artifact appears. Acunetix also offers an optional server side sensor that runs inside the application runtime and feeds back stack level context, turning some findings into file and line references instead of URL and parameter pairs.

Where it fits

This is a security team tool that scales to an estate rather than a single app. It commonly runs on a schedule against staging or production, with results routed to issue trackers so developers receive tickets rather than PDF reports. Pipeline triggering is supported, but full scans are too slow for per commit gating. To be useful it needs working authentication and an exclusion list so the crawler does not fire destructive requests at real data.

Strengths

  • Confirmation logic for injection classes cuts triage time substantially compared with signature only scanners.
  • The browser based crawler handles JavaScript heavy applications that defeat older link extraction approaches.
  • Scan configuration is granular: scope rules, excluded paths, custom headers and authentication recording are all first class.
  • Reporting includes compliance oriented views that satisfy audit requests without extra work.

Limitations

  • Business logic flaws, broken access control between user roles and multi step workflow abuse remain largely invisible to it, as with all automated DAST.
  • Authenticated scanning is fragile: session handling changes, MFA and token rotation break recorded logins and need ongoing maintenance.
  • Coverage is only as good as the vendor check library, with limited room for you to write your own checks.

Who it suits

Good fit for a security team responsible for many externally facing applications that needs repeatable, low noise coverage of common vulnerability classes and a paper trail for auditors. Less suitable for a small engineering team who want scanning inside every pull request, or for anyone whose primary risk is authorization logic rather than injection.

Used Acunetix? Recommend it under your own name and title.

Recommend this tool