Listing Thumbnail

    Invicti

     Info
    Deployed on AWS
    Invicti Security leads in modern application security with best in class DAST at the core of a platform built for risk posture management. Proof based scanning delivers 99.98 percent accuracy by validating real exploitable vulnerabilities cutting false positives and streamlining remediation. AI innovations and engine upgrades make the worlds best DAST even better helping teams uncover more critical issues across web apps and APIs faster and with less noise keeping security focused on what matters most.

    Overview

    Invicti merged DAST market leaders Netsparker and Acunetix into a new scalable Application Security Platform. By combining both solutions with AI enhancements and expanded capabilities the industrys leading DAST solutions are now a powerful complete AppSec platform featuring:

    Dynamic interactive and static security testing within a single platform

    Web app shadow API and LLM discovery and scanning

    Detection of more high and critical vulnerabilities with the help of AI

    All vulnerabilities in a single view with remediation orchestration for complete risk posture management

    Invicti combines its industry leading coverage accuracy and speed with visibility and orchestration integrated into every step of your SDLC at the scale you need. With DAST at the center you are not just getting another security tool you are getting a runtime force multiplier for your entire AppSec program.

    For Enterprise customers with custom pricing EULA or a private offer please contact tackle@invicti.com .

    Highlights

    • AI-powered proof-based scanning verifies over 94% of direct-impact vulnerabilities with 99.98% accuracy, eliminating false alarms and enabling teams to fix issues without wasting time on verification.

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (7)

     Info
    Dimension
    Description
    Cost/12 months
    Acunetix Online Premium
    QTY 5 Targets (FQDN = website, web application, API, or web services)
    $7,000.00
    Acunetix MSSP License
    Acunetix Managed Security Service Provider License
    $15,960.00
    Invicti Ent On Demand
    QTY 50 Targets (FQDN = website, web application, API, or web services)
    $37,000.00
    Invicti Ent On Premise
    QTY 50 Targets (FQDN = website, web application, API, or web services)
    $37,000.00
    Premium Support
    Premium Support
    $150,000.00
    Prem SPT & Guided Suc
    Premium Support and Guided Success
    $300,000.00
    Invicti ASPM
    License for Invicti ASPM offering. 150 Users and Targets.
    $60,000.00

    Vendor refund policy

    Fees will be due and payable as set forth on the Order Form, and Customer agrees to timely pay all fees. Payment obligations are non-cancelable, and fees paid are non-refundable.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Testing
    Top
    100
    In Monitoring

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Dynamic Application Security Testing
    Advanced DAST scanning capabilities with AI-powered vulnerability detection across web applications and APIs
    Vulnerability Verification
    Proof-based scanning methodology that validates real exploitable vulnerabilities with 99.98% accuracy
    Multi-Layer Security Testing
    Integrated dynamic, interactive, and static security testing within a single platform
    API and LLM Discovery
    Comprehensive scanning and discovery of web application shadow APIs and Large Language Model vulnerabilities
    AI-Enhanced Vulnerability Detection
    AI-driven technology to detect more high and critical vulnerabilities with advanced algorithmic analysis
    Web Application Firewall
    Advanced protection against OWASP Top 10 threats using machine learning and behavioral analytics
    Bot Protection
    Proactive defense using fingerprinting, challenge/response techniques, and behavioral analysis to block automated attacks
    Threat Intelligence
    IP Intelligence threat feed with regular updates to block malicious IP traffic and threat campaign signatures
    Traffic Management
    Load balancing functionality supporting 1 VIP and up to 3 virtual servers with per-app deployment model
    Automation Integration
    Supports integration with automation and CI/CD tools through Automation Toolchain, CloudFormation Templates, and Quick Start Guides
    Vulnerability Scanning
    Integrated vulnerability scanning with comprehensive network and system assessment capabilities
    Penetration Testing
    Advanced penetration testing functionality with multiple scanning approaches and methodologies
    Compliance Reporting
    Supports multiple compliance standards including PCI, FISMA, HIPAA, NERC CIP, and SOX through predefined report templates
    Scan Policy Management
    Configurable scan policies with 20 built-in policies and support for custom policy creation
    Asset Discovery
    Automated asset tagging and discovery with powerful dashboards and analytics for comprehensive security management

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    1 AWS reviews
    |
    115 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Rahul Kumar

    Identifies vulnerabilities across bulk web applications but needs better support and cleaner reports

    Reviewed on Nov 16, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I have been using Acunetix  for more than five years, as I used it in both my previous company and my current company.

    My day-to-day use of Acunetix  involves scanning web applications, scanning multiple files, and conducting gray-box scanning of the applications to identify any automated issues related to outdated libraries.

    I rely primarily on Acunetix for bulk scanning of multiple web applications, which includes gray-box and white-box assessments as well as black-box assessments of web applications in terms of security.

    One specific example of a recent assessment I did with Acunetix involved a large customer-facing application with many modules and functionalities that cannot be done manually, so it was very efficient; we included active scanning of Acunetix through gray-box credentials and identified a few vulnerabilities that were not found manually.

    What is most valuable?

    The best feature Acunetix offers is the centralized dashboard and the quality of reports it generates, which includes various options for selecting reports and developer options for directly sharing the reports with developers.

    The centralized dashboard of Acunetix gives visibility into the security aspects of mass applications; for instance, with more than 200 applications, it provides a valuable overview of findings and necessary fixes, along with a high-level summary that helps us achieve compliance through monthly and sometimes weekly scanning.

    In terms of reporting, Acunetix is excellent because it can generate different types of reports, such as an executive summary report, detailed reports, and developer reports that can be shared directly with developers.

    Acunetix positively impacts my organization by helping identify outdated libraries and applications, including legacy applications vulnerable to old attacks based on OWASP Top 10, thus aiding in compliance checks for PCI DSS and OWASP.

    Acunetix provides a centralized report with compliance-related aspects and a vulnerability timeline, effectively helping reduce vulnerabilities and save time.

    What needs improvement?

    I believe Acunetix can improve customer support, as the dedicated support staff are often unfamiliar with problems and troubleshooting, leading to communication gaps that delay issue resolution.

    Regarding the needed improvements, I find that there are too many duplicate findings in reports; for example, if there are numerous XSS vulnerabilities reported, they are shown individually instead of being grouped together.

    For how long have I used the solution?

    I have been working in my current field for more than eight years.

    What do I think about the stability of the solution?

    Acunetix is pretty stable in my experience.

    What do I think about the scalability of the solution?

    Acunetix can handle increasing workloads and more applications easily.

    How are customer service and support?

    Acunetix customer support responds on time, but resolution can take longer due to involving stakeholders who are not relevant and the support staff not being familiar with the problem.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    Before Acunetix, we used a different solution called ImmuniWeb , which did not provide good findings or customer support, prompting the switch.

    What was our ROI?

    I have seen a return on investment, as Acunetix helps reduce the man-days and effort needed for scanning bulk applications through automated assessments, allowing good dashboard visualization that can be reported easily to management, providing complete visibility on vulnerability metrics.

    What's my experience with pricing, setup cost, and licensing?

    In terms of pricing, setup cost, and licensing, I find it good and not overpriced, plus there are discounts offered.

    Which other solutions did I evaluate?

    We evaluated several options, including Checkmarx, Acunetix, Burp  Suite, and ImmuniWeb  before making our choice.

    What other advice do I have?

    My advice for those looking into using Acunetix is to utilize it effectively due to its good features, especially its APIs and other functionalities. My company does not have a business relationship with this vendor beyond being a customer. I would rate this review as a seven out of ten.

    Kaushal D.

    Comprehensive and Reliable Web Vulnerability Scanner

    Reviewed on Nov 08, 2025
    Review provided by G2
    What do you like best about the product?
    Acunetix delivers precise and rapid vulnerability scanning through an intuitive interface. The platform generates comprehensive reports and offers prompt remediation guidance, ensuring thorough coverage for both web applications and APIs. This makes the process of conducting security assessments efficient and dependable.
    What do you dislike about the product?
    At times, scans can be quite resource-intensive and may take longer to complete when working with large applications. Additionally, I feel that the pricing structure could be more accommodating, especially for smaller teams or projects with a limited scope.
    What problems is the product solving and how is that benefiting you?
    Acunetix assists in detecting and addressing security vulnerabilities such as SQL injection, XSS, and misconfigurations early in the development process. By automating routine web application scans, it enhances our overall security posture and helps us save time.
    Computer Software

    Powerful Scanning, But Setup Can Be Complex for Beginners

    Reviewed on Nov 05, 2025
    Review provided by G2
    What do you like best about the product?
    Acunetix by Invicti provides accurate and fast vulnerability scanning with minimal false positives. I like how easy it is to integrate into CI/CD pipelines for automated security testing.
    What do you dislike about the product?
    While Acunetix is a powerful tool, the initial setup and scan configuration can feel a bit complex for first-time users.
    What problems is the product solving and how is that benefiting you?
    Acunetix by Invicti helps us identify and remediate web application vulnerabilities early in the development cycle. It automates vulnerability scanning for issues like SQL injection
    Mitul S.

    User-Friendly and Accurate, But Room for Further Impressions

    Reviewed on Nov 05, 2025
    Review provided by G2
    What do you like best about the product?
    This is a very good product that is also user-friendly. Its accuracy in finding vulnerabilities is impressive.
    What do you dislike about the product?
    Nothing as of now, no any issue on the product
    What problems is the product solving and how is that benefiting you?
    Need to work to reduce the false positives and need a integration or inbuilt Gen AI for latest threats
    Ranit D.

    Effortless Vulnerability Detection That Fits Seamlessly into DevSecOps

    Reviewed on Nov 04, 2025
    Review provided by G2
    What do you like best about the product?
    What I like best about Acunetix by Invicti is how seamlessly it combines powerful vulnerability detection with ease of use. It’s not just another security scanner — it’s an intelligent, automated tool that feels built for both developers and security professionals. The way it quickly identifies and prioritizes critical vulnerabilities like SQL injection, XSS, and misconfigurations across websites and APIs saves a huge amount of manual effort. The clean, intuitive dashboard makes interpreting scan results straightforward, and the detailed remediation guidance helps teams actually fix issues rather than just list them. Plus, its integration with CI/CD pipelines and issue trackers like Jira fits perfectly into a modern DevSecOps workflow, making security testing feel like a natural part of development instead of a separate burden.
    What do you dislike about the product?
    What I dislike about Acunetix by Invicti is that, despite its powerful capabilities, it can sometimes feel resource-intensive and time-consuming, especially during deep scans of large or complex web applications. The scans can slow down systems or take longer than expected, which might interrupt normal workflows. Additionally, while the tool provides a lot of valuable data, the volume of findings can be overwhelming, and filtering out false positives requires manual effort and experience. The pricing can also be on the higher side for smaller organizations or startups, which limits accessibility. Lastly, although it integrates well with other tools, setting up and fine-tuning these integrations for the first time can take some technical know-how and patience.
    What problems is the product solving and how is that benefiting you?
    Acunetix by Invicti is solving the critical problem of identifying and mitigating web application vulnerabilities before attackers can exploit them. In today’s digital landscape, where websites and APIs are prime targets, Acunetix helps by automatically scanning for weaknesses like SQL injections, cross-site scripting (XSS), insecure server configurations, and outdated components. What makes it especially beneficial is how it provides accurate, actionable insights rather than just raw data — helping security teams and developers understand where the issues lie and how to fix them efficiently. For me, this translates to saved time, stronger security posture, and peace of mind, knowing that potential threats are caught early in the development cycle. Its integration with DevOps tools also ensures that security becomes part of the continuous delivery process, reducing the risk of vulnerabilities making it into production and helping maintain compliance with security standards.
    View all reviews