For the complete documentation index, see llms.txt. This page is also available as Markdown.

Invicti Platform

You can connect OX to your Invicti Platform tenant to import Dynamic Application Security Testing (DAST) results.

This lets you view Invicti Platform findings alongside your other security findings in the OX platform.

Invicti Platform is the unified Invicti application security offering. OX reads its DAST findings through the Platform API, maps them to your applications, and presents them in one place for triage, prioritization, and reporting.

Terminology mapping

Invicti Platform and OX use different labels for similar concepts. Use this map while you work.

Invicti Platform
OX Security

Targets

Applications

Findings, Vulnerabilities

Issues

Scans

Scans

Severity

Severity

Prerequisites

  • Invicti Platform account: An account that can open User settings and generate an API key.

  • OX permissions: Permission to configure connectors.

Step 1: Get an Invicti Platform API key

Invicti Platform authenticates API requests with a personal API key generated from your user settings.

  1. Sign in to Invicti Platform.

  2. Select your initials in the upper-right corner, then select User settings.

  3. Select API key.

  4. Select Generate new API key.

  5. Select Copy and store the key in a secure location. You cannot view it again after you leave the page.

Important: Invicti Platform is served from regional hosts. Note the host you sign in to, for example:

  • https://app.invicti.com

  • https://platform-eu.invicti.com

You enter this host in OX in Step 2.

Step 2: Connect Invicti Platform to OX

  1. In the OX platform, go to Connectors.

  2. In the search box, enter Invicti. The Invicti connector appears under Dynamic App Security.

  3. Select the Invicti card to open the credentials dialog.

  1. On the User Name & Password tab, provide the following details.

Field
Value

Host URL

The base URL of your Invicti Platform tenant, for example https://app.invicti.com or https://platform-eu.invicti.com.

User Name

Your Invicti Platform user name.

Password

The API key you generated in Step 1.

  1. Select Connect.

  2. To choose which Invicti targets OX imports, select the gear icon next to Delete, select the targets you want, then select Save.

Note: The gear icon becomes active after the connection succeeds. Select it to limit the import to specific Invicti targets.

Last updated