Invicti Web + API

Invicti Web + API

Invicti Security
+
+

Related Products

  • Aikido Security
    239 Ratings
    Visit Website
  • Astra Pentest
    295 Ratings
    Visit Website
  • Feroot
    32 Ratings
    Visit Website
  • Cloudflare
    2,042 Ratings
    Visit Website
  • Rocket z/Assure VAP
    1 Rating
    Visit Website
  • Reflectiz
    33 Ratings
    Visit Website
  • Criminal IP ASM
    21 Ratings
    Visit Website
  • Orca Security
    606 Ratings
    Visit Website
  • Bitdefender Ultimate Small Business Security
    5 Ratings
    Visit Website
  • DriveStrike
    24 Ratings
    Visit Website

About

Invicti Web + API, formerly Acunetix, is a dynamic application security testing (DAST) platform for identifying and validating vulnerabilities across web applications, APIs, and other runtime assets. The platform automatically discovers applications, APIs, shadow assets, unlinked pages, and undocumented endpoints while supporting modern JavaScript applications and authenticated workflows. Its scanning engine detects more than 7,000 types of security issues, including vulnerabilities covered by the OWASP Top 10 and OWASP API Top 10 as well as business logic flaws. Invicti combines AI-driven risk scoring with runtime reachability, exploitability, and business context to help security teams prioritize vulnerabilities that represent demonstrable risk.

About

Nessus is trusted by more than 30,000 organizations worldwide as one of the most widely deployed security technologies on the planet - and the gold standard for vulnerability assessment. From the beginning, we've worked hand-in-hand with the security community. We continuously optimize Nessus based on community feedback to make it the most accurate and comprehensive vulnerability assessment solution in the market. 20 years later and we're still laser focused on community collaboration and product innovation to provide the most accurate and complete vulnerability data - so you don't miss critical issues which could put your organization at risk. Today, Nessus is trusted by more than 30,000 organizations worldwide as one of the most widely deployed security technologies on the planet - and the gold standard for vulnerability assessment.

Platforms Supported

Windows Supported
Mac Not Supported
Linux Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

Application security teams, security engineers, penetration testers, DevSecOps teams, developers, CISOs, vulnerability management teams, and enterprises that need automated DAST, API security testing, vulnerability validation, prioritization, and remediation across modern web applications and APIs

Audience

IT professionals searching for a Vulnerability Assessment solution

Support

Phone Support Supported
24/7 Live Support Supported
Online Supported

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

API

Offers API Supported

API

Offers API Not Supported

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version Not Supported
Free Trial Supported

Pricing

No information available.
Free Version Not Supported
Free Trial Supported

Reviews/Ratings

Overall 4.0 / 5
ease 5.0 / 5
features 5.0 / 5
design 4.0 / 5
support 4.0 / 5

Reviews/Ratings

Overall 4.8 / 5
ease 5.0 / 5
features 4.8 / 5
design 5.0 / 5
support 4.4 / 5

Pros & Cons from Real Users

Pros

  • It is the most advanced automated web scanner. The vulnerability management feature works very well. The results are very accurate.

Cons

  • I have not found any cons until now. It works great.

Pros & Cons from Real Users

Pros

  • Customizable Scans Wide Platform Support Pre-built policies and Templates like PCI DSS and HIPAA Frequent Plugin Updates Active and Passive Detection Comprehensive Vulnerability Coverage
  • Nessus supports a wide range of operating systems and devices, making it versatile for diverse IT environments. Nessus benefits from an active community of users and professional support, ensuring that users can find solutions and best practices when needed. Nessus provides the flexibility to perform both agent-based scans for systems that require persistent monitoring and agentless scans for systems where installing an agent is impractical.
  • Nessus excels at identifying vulnerabilities in systems across a wide range of platforms, including operating systems, databases, network devices, and web applications. It checks for known vulnerabilities using both signature-based and heuristic-based scanning techniques Nessus can perform configuration audits by comparing system settings against industry best practices (e.g., CIS Benchmarks, DISA STIGs). This allows organizations to enforce security policies and ensure that systems are configured securely By providing Nessus with valid credentials (such as admin-level access), it can perform more in-depth scans and accurately identify vulnerabilities that require elevated privileges. Nessus can integrate with other security solutions such as SIEMs (Security Information and Event Management systems), ticketing systems (e.g., ServiceNow, Jira), and other vulnerability management tools. This helps automate workflows and streamline vulnerability remediation. Nessus offers an intuitive user interface with a simple setup process, making it accessible even to organizations without a dedicated security team. The interface provides easy access to scan configurations, reports, and plugin management.
  • 1) Nessus provides in-depth vulnerability scanning across a wide range of systems, applications, and devices, helping identify potential security risks quickly and thoroughly. 2) The vulnerability database is constantly updated, ensuring that the scanner detects the latest threats and vulnerabilities, which is crucial for maintaining up-to-date security. 3) The interface is intuitive and easy to navigate, even for users who aren’t security experts. It’s simple to run scans, view results, and take action based on the findings. 4) Nessus offers flexibility with customizable scanning profiles, allowing users to tailor scans to specific needs, whether it’s targeting particular systems, vulnerabilities, or compliance requirements. 5) The reports generated by Nessus are detailed and clear, offering actionable insights and prioritizing vulnerabilities based on severity. This helps teams address the most critical issues first.
  • In depth vulnerability scanning with very usable results in easy to read formats and reports that you can drill down into. Very detailed information for how quick the scan is.

Cons

  • Limited Automation Custom Scripting Complexity No Built-In Patch Management Limited Cloud Integration False Positives
  • The basic version of Nessus is free for limited use, accessing advanced features like compliance checks and extended reporting in Nessus Professional requires a subscription, which may not suit smaller organizations with tight budgets. Nessus scans can consume significant network and system resources, potentially slowing down operations or affecting the performance of critical systems during scans.
  • Nessus can be resource-heavy, especially when performing in-depth scans or scanning large environments. High network bandwidth and processing power are required to perform large-scale scans without negatively impacting system performance. In environments with limited resources, this could slow down network operations or impact system stability While Nessus does offer some web application scanning capabilities (e.g., detecting SQL injection, XSS, etc.), it is not as specialized or comprehensive as dedicated web application security testing tools like Burp Suite or OWASP ZAP. Organizations with a heavy focus on web applications may find Nessus lacking in depth for these specific needs
  • 1) While Nessus does integrate with some third-party tools, its integration options are more limited compared to some other vulnerability management platforms, which might be a drawback for larger organizations with complex IT environments. 2) Nessus can struggle with scaling up for very large, complex environments or enterprise-level networks, where more robust vulnerability management platforms might be better suited.
  • The free trial sucked. Not only is it limited to 7 days, but you can't even try the full feature set for that 7 days. It's limited to reporting on the first 16 devices it detects. Unfortunately on my network, it didn't make it to any servers before hitting that limit, so I only got info on workstations, a printer and a credit card reader. At least give me 1 full scan of my network so I can compare workstations to servers, or give me the ability to go back and pick certain IP addresses to scan, maybe via csv file upload?

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Not Supported

Training

Documentation Not Supported
Webinars Not Supported
Live Online Not Supported
In Person Not Supported

Company Information

Invicti Security
Founded: 2018
United States
acunetix.com

Company Information

Tenable
Founded: 2002
United States
www.tenable.com/products/nessus

Alternatives

Astra Pentest

Astra Pentest

Astra Security

Alternatives

Astra Pentest

Astra Pentest

Astra Security
AppTrana

AppTrana

Indusface
Invicti

Invicti

Invicti Security
Tenable One

Tenable One

Tenable
PT Application Inspector

PT Application Inspector

Positive Technologies
ESOF

ESOF

TAC Security

Categories

Categories

IT Security Features

Anti Spam Not Supported
Anti Virus Not Supported
Email Attachment Protection Not Supported
Event Tracking Not Supported
Internet Usage Monitoring Not Supported
Intrusion Detection System Not Supported
IP Protection Not Supported
Spyware Removal Not Supported
Two-Factor Authentication Not Supported
Vulnerability Scanning Supported
Web Threat Management Supported
Web Traffic Reporting Not Supported

Network Security Features

Access Control Not Supported
Analytics / Reporting Not Supported
Compliance Reporting Not Supported
Firewalls Not Supported
Internet Usage Monitoring Not Supported
Intrusion Detection System Not Supported
Threat Response Supported
VPN Not Supported
Vulnerability Scanning Supported

Vulnerability Management Features

Asset Discovery Supported
Asset Tagging Supported
Network Scanning Supported
Patch Management Not Supported
Policy Management Not Supported
Prioritization Supported
Risk Management Supported
Vulnerability Assessment Supported
Web Scanning Supported

Vulnerability Scanners Features

Asset Discovery Supported
Black Box Scanning Supported
Compliance Monitoring Supported
Continuous Monitoring Supported
Defect Tracking Supported
Interactive Scanning Supported
Logging and Reporting Supported
Network Mapping Supported
Perimeter Scanning Supported
Risk Analysis Supported
Threat Intelligence Supported
Web Inspection Supported

Application Security Features

Analytics / Reporting Supported
Open Source Component Monitoring Not Supported
Source Code Analysis Not Supported
Third-Party Tools Integration Supported
Training Resources Supported
Vulnerability Detection Supported
Vulnerability Remediation Supported

Computer Security Features

Anti Spam Not Supported
Antivirus Not Supported
Audit Trail Supported
Compliance Management Supported
Database Security Audit Supported
File Access Control Supported
Financial Data Protection Not Supported
Maintenance Scheduling Not Supported
Real Time Monitoring Not Supported
Security Event Log Not Supported
Virus Definition Update Not Supported
Vulnerability Protection Supported

Cybersecurity Features

AI / Machine Learning Not Supported
Behavioral Analytics Not Supported
Endpoint Management Not Supported
Incident Management Not Supported
IOC Verification Supported
Tokenization Not Supported
Vulnerability Scanning Supported
Whitelisting / Blacklisting Not Supported

Vulnerability Management Features

Asset Discovery Supported
Asset Tagging Not Supported
Network Scanning Supported
Patch Management Not Supported
Policy Management Supported
Prioritization Supported
Risk Management Not Supported
Vulnerability Assessment Supported
Web Scanning Supported

Integrations

ArmorCode Supported
Bizzy Supported
Centraleyezer Supported
Dradis Supported
Hexway Pentest Suite Supported
Kondukto Supported
Nucleus Supported
Phoenix Security Supported
ThreadFix Supported
ThreatAdvisor Supported
Axonius Supported
CertSecure Manager Not Supported
CnSight Not Supported
Conviso Platform Not Supported
Core Impact Not Supported
Imperva WAF Supported
ManageEngine Endpoint Central Not Supported
SQUAD1 Not Supported
Swimlane Not Supported
ThreatAware Not Supported

Integrations

ArmorCode Supported
Bizzy Supported
Centraleyezer Supported
Dradis Supported
Hexway Pentest Suite Supported
Kondukto Supported
Nucleus Supported
Phoenix Security Supported
ThreadFix Supported
ThreatAdvisor Supported
Axonius Not Supported
CertSecure Manager Supported
CnSight Supported
Conviso Platform Supported
Core Impact Supported
Imperva WAF Not Supported
ManageEngine Endpoint Central Supported
SQUAD1 Supported
Swimlane Supported
ThreatAware Supported
Claim Invicti Web + API and update features and information
Claim Invicti Web + API and update features and information
Claim Tenable Nessus and update features and information
Claim Tenable Nessus and update features and information