For the complete documentation index, see llms.txt. This page is also available as Markdown.

Invicti Enterprise

Note: This capability is currently in Early Access (EA) and is not generally available. To request access, please contact OX technical support.

You can connect OX to your Invicti Enterprise instance to import Dynamic Application Security Testing (DAST) results.

This lets you view Invicti Enterprise findings alongside your other security findings in the OX platform.

Invicti Enterprise runs proof-based DAST scans against your running web applications and APIs. OX reads those results through the Invicti API, maps them to your applications, and presents them in one place for triage, prioritization, and reporting.

Notes:

  • Some advanced Invicti Enterprise capabilities, such as automatic crawling of subdomains, depend on your Invicti configuration and may affect what data is shown in OX.

  • The Invicti Enterprise connector does not support automatic discovery of credentials from the Invicti UI. You must obtain the required credentials manually.

  • If your Invicti Enterprise instance requires a token instead of a username and password, consult your Invicti administrator.

Terminology mapping

Invicti Enterprise and OX use different labels for similar concepts. Use this map while you work.

Invicti Enterprise
OX Security

Websites, Targets

Applications

Vulnerabilities

Issues

Scans

Scans

Severity

Severity

Prerequisites

  • Invicti Enterprise account: An account that can open API Settings and generate an API token.

  • OX permissions: Permission to configure connectors.

Note: If your organization uses single sign-on (SSO), the API Settings page may open without a password prompt. If SSO is enabled but you are still prompted for a password, go to Settings > Single Sign-On and select Enforce to authenticate only with single sign-on.

Connect Invicti Enterprise to OX

  1. In the OX platform, go to the Connectors page.

  2. Select Add Connector and search for Invicti Enterprise.

  1. In the Configure your Invicti credentials box, provide the following details:

Field
Description

Invicti host URL

The base URL of your Invicti Enterprise instance, for example https://www.netsparkercloud.com. On-premises deployments use your own instance URL.

User Name

Your Invicti username.

Password

Your Invicti password.

  1. Select CONNECT.

  2. To select specific Invicti projects to import, click the gear icon next to the DELETE button.

  1. Select the Invicti projects and select SAVE.

When connected, OX starts pulling DAST data from Invicti.

Last updated