TrustRadius: an HG Insights company

Invicti Web + API (Acunetix)

Score8 out of 10

18 Reviews and Ratings

What is Invicti Web + API (Acunetix)?

Invicti Web + API (formerly Acunetix) is a cloud-based and on-premises Dynamic Application Security Testing (DAST) and API Security platform engineered to automatically scan running web applications and web services for security vulnerabilities. Positioned as an enterprise application security testing alternative to platforms such as Veracode, Checkmarx, and Rapid7 InsightAppSec, the software combines black-box dynamic scanning with Interactive Application Security Testing (IAST) agents to identify vulnerabilities across complex single-page applications (SPAs), JavaScript frameworks, and Representational State Transfer (REST), GraphQL, and SOAP web services. Invicti Web + API utilizes Proof-Based Scanning technology, which automatically executes safe exploitation attacks against detected vulnerabilities—such as Cross-Site Scripting (XSS) and SQL Injection (SQLi)—to extract non-sensitive proof data and confirm exploitability without manual penetration testing. The platform integrates into Continuous Integration/Continuous Deployment (CI/CD) pipelines, ticketing platforms like Jira, and Vulnerability Management software to automate issue assignment, re-testing, and remediation tracking across software development lifecycles.

Read more details.

Media

Screenshot of Dashboard
Screenshot of Filtering
Screenshot of scan results

1 / 3

Screenshot of Dashboard

Who Buys & Uses Invicti Web + API (Acunetix)

Best tool for Application Security

Use Cases and Deployment Scope

I had use case from one of our customers to establish security testing automation in DevSecOps pipeline. I was looking for such a tool and after lot of evaluations found Acunetix perfectly suited to the requirements. After initial PoC of few days with little configuration support from Invicti we decided to go for it and establish a platform for our end customers

Pros

  • Integration of tool with different IDE is great
  • Easy to scan code and identify vulnerabilities
  • Dashboard is easy to customise

Cons

  • Configuration of DevSecOps can be improved for ease
  • Dashboard can have API integration
  • Broaden the scope of vulnerabilities

Most Important Features

  • Vulnerabilities scanning
  • DevSecOps interested testing
  • Visibility and remedial action recommendation

Return on Investment

  • It helped improve ROI by 30%
  • Helped reduced manpower by 15%
  • Improved churn out of applications by 50%

Alternatives Considered

Rapid7 AppSpider

Other Software Used

Checkmarx, Rapid7 AppSpider, Coverity Static Analysis (SAST)

Squash OWASP vulnerabilities with Acunetix

Use Cases and Deployment Scope

We are not a big web development shop but we occasionally do have new code that we need to test against OWASP type web application vulnerabilities. There are many tools that can do this. But most of them have a fairly decent rate of false positives. Also, they don't really help address the issues that they find. Acunetix has had a low false-positive rate for us. The developer reports provide a lot of contexts to help the people who need to fix the issues know what to fix.

Pros

  • Low rate of false positives
  • Good reporting options
  • Authenticated scans

Cons

  • User management

Most Important Features

  • Low rate of false positives
  • Detailed developer reports
  • Support for a sufficient number of assets

Return on Investment

  • It has aided audit compliance
  • It has allowed for deployment of secure code

Application Vulnerability Scanner with a great ROI

Pros

  • Fast.
  • Easy-to-use.
  • Great customer support.
  • Reporting features.
  • Supports importing state files from other popular application testing tools.
  • Has other features built-in beyond just scanning for vulnerabilities.

Cons

  • Does not support multiple endpoints well (e.g. apps and services that do not reside at the same URL).
  • Has authentication problems with modern enterprise apps which involve a lot of redirects to unrelated endpoints, federated IDs, SSO, etc. This is related to the first point.
  • The vulnerability detection capability is not as robust as Burp Suite Pro + extensions, Metasploit + auxiliary modules, Nmap + scripts, etc.

Return on Investment

  • Saved money compared to other commercial scanners, especially over the long run.
  • Scan speed seems to be pretty good compared to some of the bulkier commercial products out there. However, that largely has to do with proper configuration.
  • A downside is that is requires a bit of extra work just to get it set up to scan APIs, web services, etc.

Other Software Used

Nessus