AppSecNews
DAST Commercial Established

Invicti

by Invicti Security

Enterprise dynamic scanner, formerly Netsparker, that confirms many injection findings by safely exploiting them before reporting.

Visit invicti.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Invicti in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Current integration list and edition naming: confirm against vendor documentation
  • IAST sensor language coverage: verify

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Invicti, previously sold as Netsparker, crawls a web application and attacks what it finds. The crawler renders pages in a browser engine so script-driven navigation, single-page application routes and dynamically written forms enter the site map, and it ingests OpenAPI, WSDL and Postman definitions to reach API endpoints that no link points at. It also runs discovery across your domains to surface applications nobody registered, which matters once an organization is past a few dozen sites.

The mechanism the product is built around is proof-based scanning. For classes where exploitation can be made safe and unambiguous, notably SQL injection, command injection, local file inclusion and remote code execution, the scanner does not report on a response heuristic. It follows up with a payload designed to extract a specific harmless artifact, such as a database version string, and marks the result confirmed only when that artifact comes back. Confirmed findings can then be auto-assigned to developers without a human triage step. An optional runtime sensor adds server-side context, turning some findings into file and line references.

Where it fits

This is a platform for a security team managing an application portfolio, not a developer's local tool. It typically runs on a schedule against staging or production with findings pushed into an issue tracker, and it can be triggered from a pipeline for release gating. Self-hosted scan agents cover internal applications without exposing them. Prerequisites are the usual ones: reliable authentication configuration, scope and exclusion rules, and a non-production data set if the scanner will be submitting forms.

Strengths

  • Proof-based confirmation removes most false positives for the injection classes it covers, the single biggest driver of DAST triage cost.
  • Discovery finds applications outside the known inventory, which is often where the real exposure is.
  • Spec-driven API scanning means REST and SOAP endpoints get tested rather than silently skipped.
  • Confirmed issues can go straight to a developer queue with reproduction steps attached.

Limitations

  • Confirmation applies only to a subset of classes. Cross-site scripting, access control and configuration findings still need human review.
  • Broken authorization between roles, business logic abuse and multi-step workflow flaws remain outside what automated dynamic testing can see.
  • Authenticated scanning breaks when login flows change, and maintaining sessions across many applications is real ongoing work.
  • Heavy scans are slow and load-generating, so they do not belong in a per-commit pipeline stage.

Who it suits

Well matched to an enterprise security team with many web applications, a mandate to reduce triage effort, and the capacity to maintain scan configuration and authentication. A poor fit for a small team wanting scanning inside every pull request, and not the right instrument if your dominant risk is authorization logic rather than injection.

Used Invicti? Recommend it under your own name and title.

Recommend this tool