Invicti Web + API

Invicti Web + API

Invicti Security
+
+

Related Products

  • Aikido Security
    239 Ratings
    Visit Website
  • Astra Pentest
    295 Ratings
    Visit Website
  • ESET PROTECT Advanced
    2,304 Ratings
    Visit Website
  • Orca Security
    606 Ratings
    Visit Website
  • DriveStrike
    24 Ratings
    Visit Website
  • Rocket z/Assure VAP
    1 Rating
    Visit Website
  • Criminal IP ASM
    21 Ratings
    Visit Website
  • ManageEngine Endpoint Central
    3,286 Ratings
    Visit Website
  • NinjaOne
    6,035 Ratings
    Visit Website
  • Kitecyber
    82 Ratings
    Visit Website

About

Crashtest Security is a SaaS-based security vulnerability scanner allowing agile development teams to ensure continuous security before even hitting Production. Our state-of-the-art dynamic application security testing (DAST) solution integrates seamlessly with your dev environment and protects multi-page and JavaScript apps, as well as microservices and APIs. Set up Crashtest Security Suite in minutes, get advanced crawling options, and automate your security. Whether you want to see vulnerabilities within the OWASP Top 10 or you want to go for deep scans, Crashtest Security is here to help you stay on top of your security and protect your code and customers.

About

Invicti Web + API, formerly Acunetix, is a dynamic application security testing (DAST) platform for identifying and validating vulnerabilities across web applications, APIs, and other runtime assets. The platform automatically discovers applications, APIs, shadow assets, unlinked pages, and undocumented endpoints while supporting modern JavaScript applications and authenticated workflows. Its scanning engine detects more than 7,000 types of security issues, including vulnerabilities covered by the OWASP Top 10 and OWASP API Top 10 as well as business logic flaws. Invicti combines AI-driven risk scoring with runtime reachability, exploitability, and business context to help security teams prioritize vulnerabilities that represent demonstrable risk.

Platforms Supported

Windows Not Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Supported
Mac Not Supported
Linux Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

Companies of all sizes

Audience

Application security teams, security engineers, penetration testers, DevSecOps teams, developers, CISOs, vulnerability management teams, and enterprises that need automated DAST, API security testing, vulnerability validation, prioritization, and remediation across modern web applications and APIs

Support

Phone Support Supported
24/7 Live Support Not Supported
Online Supported

Support

Phone Support Supported
24/7 Live Support Supported
Online Supported

API

Offers API Supported

API

Offers API Supported

Screenshots and Videos

Screenshots and Videos

Pricing

€35 per month
Free 14 Day Trial with Flexible Pricing to suit your requirements
Free Version Supported
Free Trial Supported

Pricing

No information available.
Free Version Not Supported
Free Trial Supported

Reviews/Ratings

Overall 4.6 / 5
ease 4.6 / 5
features 4.2 / 5
design 4.2 / 5
support 5.0 / 5

Reviews/Ratings

Overall 4.0 / 5
ease 5.0 / 5
features 5.0 / 5
design 4.0 / 5
support 4.0 / 5

Pros & Cons from Real Users

Pros

  • As Information security/Data Privacy manager we wanted a product that would help us identify security vulnerabilities and provide recommendations on how to eliminate them. Crashtest does that on several levels, from scanning the requests to checking the headers and then trying to actually penetrate systems change/destroy data in a very clever way. Support staff very helpful, responsive and friendly. This product can be integrated with so many CI/CD tools and with a bit of configuration it is easy to automate and integrate to almost any system and Notify/prevent security vulnerabilities from reaching areas they should not.
  • Crashtest Security provides a great vulnerability detection while it is very easy to setup and use. It detects vulnerabilities such as SQL Injections or Code Execution from a blackbox point of view. So I can really see, how attackers view my web applications from the outside. We have integrated it our processes and get Mattermost notifications regarding our scan results.
  • - Very easy setup - Provides solutions for findings with the help of a wiki - Generates an easy to read scan result (even for non tech people) - Very friendly support
  • The solution is easy to setup. The UI is mostly clean. The solution provides a helpful findings wiki.
  • - Easy to set up and integrate. - Performs a wide range of scans and scanning scenarios. - User friendly scan results.

Cons

  • As a new system, Crashtest had some issues when we started using it, but the support team was very responsive in fixing any issues we encountered. If I have to be picky, the one thing I would raise is that there is a bit of room to improve performance.
  • Some features (such as configuring scanning for networks not reachable from the internet) are not yet available as self service functionality using the web frontend. However, the Crashtest Security support was very friendly and eager to support us with the setup.
  • - many pages cant be opened in a new tab - sometimes the scanner cant login to our application, a manual restart fixes the problem
  • Product is not 100 % stable yet. Sometimes duplicated findings occur. The JavaScript-built UI is not always easy or reliable to navigate (open in new tab is not possible for many pages).
  • As of today, I couldn't observe any disadvantages.

Pros & Cons from Real Users

Pros

  • It is the most advanced automated web scanner. The vulnerability management feature works very well. The results are very accurate.

Cons

  • I have not found any cons until now. It works great.

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Not Supported

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Not Supported

Company Information

Crashtest Security
Founded: 2017
Germany
crashtest-security.com

Company Information

Invicti Security
Founded: 2018
United States
acunetix.com

Alternatives

Alternatives

Astra Pentest

Astra Pentest

Astra Security
PT Application Inspector

PT Application Inspector

Positive Technologies
AppTrana

AppTrana

Indusface
Invicti

Invicti

Invicti Security
Invicti

Invicti

Invicti Security
Acunetix

Acunetix

Invicti Security
PT Application Inspector

PT Application Inspector

Positive Technologies

Categories

Categories

Vulnerability Management Features

Asset Discovery Not Supported
Asset Tagging Not Supported
Network Scanning Not Supported
Patch Management Not Supported
Policy Management Not Supported
Prioritization Not Supported
Risk Management Not Supported
Vulnerability Assessment Supported
Web Scanning Supported

Vulnerability Scanners Features

Asset Discovery Not Supported
Black Box Scanning Supported
Compliance Monitoring Supported
Continuous Monitoring Supported
Defect Tracking Not Supported
Interactive Scanning Not Supported
Logging and Reporting Supported
Network Mapping Not Supported
Perimeter Scanning Not Supported
Risk Analysis Supported
Threat Intelligence Supported
Web Inspection Not Supported

Endpoint Protection Features

Activity Log Not Supported
Antivirus Not Supported
Application Security Supported
Behavioral Analytics Not Supported
Device Management Not Supported
Encryption Not Supported
Signature Matching Not Supported
Web Threat Management Supported
Whitelisting / Blacklisting Not Supported

Vulnerability Management Features

Asset Discovery Supported
Asset Tagging Supported
Network Scanning Supported
Patch Management Not Supported
Policy Management Not Supported
Prioritization Supported
Risk Management Supported
Vulnerability Assessment Supported
Web Scanning Supported

Vulnerability Scanners Features

Asset Discovery Supported
Black Box Scanning Supported
Compliance Monitoring Supported
Continuous Monitoring Supported
Defect Tracking Supported
Interactive Scanning Supported
Logging and Reporting Supported
Network Mapping Supported
Perimeter Scanning Supported
Risk Analysis Supported
Threat Intelligence Supported
Web Inspection Supported

Application Security Features

Analytics / Reporting Supported
Open Source Component Monitoring Not Supported
Source Code Analysis Not Supported
Third-Party Tools Integration Supported
Training Resources Supported
Vulnerability Detection Supported
Vulnerability Remediation Supported

Computer Security Features

Anti Spam Not Supported
Antivirus Not Supported
Audit Trail Supported
Compliance Management Supported
Database Security Audit Supported
File Access Control Supported
Financial Data Protection Not Supported
Maintenance Scheduling Not Supported
Real Time Monitoring Not Supported
Security Event Log Not Supported
Virus Definition Update Not Supported
Vulnerability Protection Supported

Cybersecurity Features

AI / Machine Learning Not Supported
Behavioral Analytics Not Supported
Endpoint Management Not Supported
Incident Management Not Supported
IOC Verification Supported
Tokenization Not Supported
Vulnerability Scanning Supported
Whitelisting / Blacklisting Not Supported

IT Security Features

Anti Spam Not Supported
Anti Virus Not Supported
Email Attachment Protection Not Supported
Event Tracking Not Supported
Internet Usage Monitoring Not Supported
Intrusion Detection System Not Supported
IP Protection Not Supported
Spyware Removal Not Supported
Two-Factor Authentication Not Supported
Vulnerability Scanning Supported
Web Threat Management Supported
Web Traffic Reporting Not Supported

Network Security Features

Access Control Not Supported
Analytics / Reporting Not Supported
Compliance Reporting Not Supported
Firewalls Not Supported
Internet Usage Monitoring Not Supported
Intrusion Detection System Not Supported
Threat Response Supported
VPN Not Supported
Vulnerability Scanning Supported

Integrations

GitHub Supported
Jenkins Supported
Jira Work Management Supported
ArmorCode Not Supported
Azure DevOps Supported
Bitbucket Supported
Bizzy Not Supported
CodeShip Supported
DefectDojo Supported
Dradis Not Supported
GitLab Supported
Google Cloud Build Supported
Imperva CDN Not Supported
Jira Not Supported
NAVEX IRM Not Supported
Nucleus Not Supported
Scuba Database Vulnerability Scanner Not Supported
SecurityHQ Not Supported
ThreadFix Not Supported

Integrations

GitHub Supported
Jenkins Supported
Jira Work Management Supported
ArmorCode Supported
Azure DevOps Not Supported
Bitbucket Not Supported
Bizzy Supported
CodeShip Not Supported
DefectDojo Not Supported
Dradis Supported
GitLab Not Supported
Google Cloud Build Not Supported
Imperva CDN Supported
Jira Supported
NAVEX IRM Supported
Nucleus Supported
Scuba Database Vulnerability Scanner Supported
SecurityHQ Supported
ThreadFix Supported
Claim Crashtest Security and update features and information
Claim Crashtest Security and update features and information
Claim Invicti Web + API and update features and information
Claim Invicti Web + API and update features and information