Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Invicti

Invicti Security

Reviews from AWS customer

2 AWS reviews

External reviews

118 reviews
from and

External reviews are not included in the AWS star rating for the product.


3-star reviews ( Show all reviews )

    sai kiran narayana .

Excellent Security Tool with Continuous Improvements

  • November 24, 2025
  • Review provided by G2

What do you like best about the product?
This is one of the best security tools available on the market today. It continues to evolve and improve. By using it, web applications become more secure. Additionally, it helps identify most hidden pages on any website, especially those concealed through cookies.
What do you dislike about the product?
The vulnerability detection is inconsistent, and the scanning process tends to be slow.
What problems is the product solving and how is that benefiting you?
The process of identifying probable vulnerabilities is crucial for maintaining security. It allows for early detection of potential risks, helping to prevent issues before they become serious problems.


    Himanshu_Tyagi

Saves significant assessment time with automated scans but requires manual effort to filter false positives

  • November 24, 2025
  • Review from a verified AWS customer

What is our primary use case?

Acunetix has primarily been used for application security, and it has also been used for vulnerability management, though not as extensively because Qualys Guard Total Cloud solution was being used for scanning cloud assets.

Qualys Total Cloud was used to scan cloud assets. Earlier, when using CLI tools like Troller, there was not much visibility because the reporting section from the CLI tool was not that helpful. However, when using Qualys Guard, the Total Cloud offered advanced reporting features and had the option to share vulnerability reports directly via email, allowing the end participant's email address to be entered for automatic report delivery.

What is most valuable?

The crawling option in Acunetix is really good because whenever a scan is initiated, the crawling option provides good coverage about the vulnerabilities identified in the application. The attack option that comes after crawling is quite good. When the application is configured in authenticated scan mode with Acunetix, it provides good visibility about the security vulnerabilities in the application.

The experience with Qualys Total Cloud was really good, as when Qualys Guard was used to scan cloud security assets, it identified the vulnerabilities and helped differentiate between valid findings and invalid findings. Qualys Guard is called Total Cloud, which means cloud assets are scanned regardless of any environment, whether it is GCP, AWS, or Azure.

What needs improvement?

Improving the handling of false positives would be beneficial because it can be challenging to trust the findings flagged by Acunetix, and those findings must be manually validated. Sometimes the scanner shows a vulnerability count exceeding 100, and manually assessing the findings can be quite a challenge.

The main concern is related to false positives; Acunetix needs to work on identifying valid and invalid findings. While Checkmarx has very good coverage, its pricing is quite high. If Acunetix improves in handling false positives, it will make a significant impact in the security world.

For how long have I used the solution?

Acunetix has been used for a long time, about five to six years, along with Netsparker and other automated scanners.

What do I think about the stability of the solution?

The experience has been pretty smooth without crashes, downtimes, or performance issues with Acunetix.

What do I think about the scalability of the solution?

Acunetix is quite scalable.

How are customer service and support?

The tech support from Invicti for Acunetix is really good. Whenever a support ticket is raised, their SLA is quite nice. For high-severity issues, they reach out within two to three hours, and for critical issues, a response is received within 15 minutes.

The tech support would be rated an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

As far as experience is concerned, only Checkmarx SAST tool has been worked on, and no other Checkmarx products like Checkmarx One are used.

Rapid7 Nexpose has been used, but no other Rapid7 products have been explored. Additionally, Qualys Guard and Qualys VMDR Vulnerability Management Detection Response solution have been worked on.

How was the initial setup?

The setup process for Acunetix is not that complicated, and Acunetix support can always be reached out to. Whenever Acunetix is onboarded in the environment, the Acunetix team assists with the installation, making the setup quite easy.

What's my experience with pricing, setup cost, and licensing?

The pricing cost is affordable for small and mid-sized organizations, and when compared to Checkmarx, it is significantly affordable, as Checkmarx is quite expensive.

The cost-effectiveness is really good because it comes under the budget of organizations looking to use automated scanners, which really helps and saves time.

What other advice do I have?

Currently, work is being done with AWS cloud security and application security tools such as Burp Suite, and various automated scanners such as Netsparker and Acunetix are also being used, along with vulnerability scanning tools such as Nessus Professional and Rapid7 Nexpose.

Acunetix is good, even though there have been some issues related to false positives. Whenever an automated scanner like Netsparker or Acunetix is used, it takes time to run the scan. Once the scan is completed, the false positives flagged by the scan need to be identified. Acunetix is a good tool because if there is less time and the team needs to perform the security assessment, a manual assessment will take almost a week to assess a large application. However, when an automated scanner like Acunetix is used, the same task can be done within three to four days. Authenticated scans are usually preferred with any automated scanner like Acunetix because it provides much visibility about the application on which the scan is initiated, and the results from authenticated scans are very good compared to unauthenticated scans.

Acunetix was used recently, about three months ago.

Acunetix was not used for AWS because various other AWS solutions are available to determine the vulnerabilities for cloud, primarily using AWS Inspector to scan the AWS cloud. Security Hub is also used to measure cloud security posture management, so when it comes to scanning the cloud, AWS Inspector is primarily used.

Acunetix was hosted on the AWS cloud because when the application was scanned, it was not an on-premises solution; the applications hosted in AWS cloud were scanned using Acunetix.

The integration part has not been explored much because other tools are available, but Acunetix supports YAML files that can be used to integrate those scans into the CI/CD pipeline. However, Acunetix scans have not been integrated into the CI/CD pipeline.

The Acunetix network security component has not been used.

If there is less time to perform manual security assessments, Acunetix is a good option because if a manual security assessment takes almost a week, the same task with Acunetix can be completed within three to four days, which really saves time for the entire team. The results are faster and interactive reports generated by the dashboard can be shared. This helps improve the overall security posture.

The features present in Acunetix are quite good and serve the purpose well.

Acunetix is definitely recommended for scanning, and if someone asks whether they should use Acunetix to mitigate the threats identified in their applications hosted in AWS cloud, it would definitely be recommended.

When the continuous scan approach is used for security compliance, it really helps because the scan is not paused for any reason, like if the application goes down. With the continuous scan operation, the application is continuously assessed by the scan engine of Acunetix, and the results from the continuous scan feature are quite good. The continuous scanning feature has been used.

If an organization has 100 plus applications and wants to use an automated scanner, they should definitely go ahead with Acunetix because it is very cost-effective and will save time compared to focusing on other solutions and performing manual security assessments.

The recommendation for other organizations considering Acunetix depends upon their requirements.

This review has been given a rating of 7 out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)


    Rahul Kumar

Identifies vulnerabilities across bulk web applications but needs better support and cleaner reports

  • November 16, 2025
  • Review provided by PeerSpot

What is our primary use case?

I have been using Acunetix for more than five years, as I used it in both my previous company and my current company.

My day-to-day use of Acunetix involves scanning web applications, scanning multiple files, and conducting gray-box scanning of the applications to identify any automated issues related to outdated libraries.

I rely primarily on Acunetix for bulk scanning of multiple web applications, which includes gray-box and white-box assessments as well as black-box assessments of web applications in terms of security.

One specific example of a recent assessment I did with Acunetix involved a large customer-facing application with many modules and functionalities that cannot be done manually, so it was very efficient; we included active scanning of Acunetix through gray-box credentials and identified a few vulnerabilities that were not found manually.

What is most valuable?

The best feature Acunetix offers is the centralized dashboard and the quality of reports it generates, which includes various options for selecting reports and developer options for directly sharing the reports with developers.

The centralized dashboard of Acunetix gives visibility into the security aspects of mass applications; for instance, with more than 200 applications, it provides a valuable overview of findings and necessary fixes, along with a high-level summary that helps us achieve compliance through monthly and sometimes weekly scanning.

In terms of reporting, Acunetix is excellent because it can generate different types of reports, such as an executive summary report, detailed reports, and developer reports that can be shared directly with developers.

Acunetix positively impacts my organization by helping identify outdated libraries and applications, including legacy applications vulnerable to old attacks based on OWASP Top 10, thus aiding in compliance checks for PCI DSS and OWASP.

Acunetix provides a centralized report with compliance-related aspects and a vulnerability timeline, effectively helping reduce vulnerabilities and save time.

What needs improvement?

I believe Acunetix can improve customer support, as the dedicated support staff are often unfamiliar with problems and troubleshooting, leading to communication gaps that delay issue resolution.

Regarding the needed improvements, I find that there are too many duplicate findings in reports; for example, if there are numerous XSS vulnerabilities reported, they are shown individually instead of being grouped together.

For how long have I used the solution?

I have been working in my current field for more than eight years.

What do I think about the stability of the solution?

Acunetix is pretty stable in my experience.

What do I think about the scalability of the solution?

Acunetix can handle increasing workloads and more applications easily.

How are customer service and support?

Acunetix customer support responds on time, but resolution can take longer due to involving stakeholders who are not relevant and the support staff not being familiar with the problem.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Before Acunetix, we used a different solution called ImmuniWeb, which did not provide good findings or customer support, prompting the switch.

What was our ROI?

I have seen a return on investment, as Acunetix helps reduce the man-days and effort needed for scanning bulk applications through automated assessments, allowing good dashboard visualization that can be reported easily to management, providing complete visibility on vulnerability metrics.

What's my experience with pricing, setup cost, and licensing?

In terms of pricing, setup cost, and licensing, I find it good and not overpriced, plus there are discounts offered.

Which other solutions did I evaluate?

We evaluated several options, including Checkmarx, Acunetix, Burp Suite, and ImmuniWeb before making our choice.

What other advice do I have?

My advice for those looking into using Acunetix is to utilize it effectively due to its good features, especially its APIs and other functionalities. My company does not have a business relationship with this vendor beyond being a customer. I would rate this review as a seven out of ten.


    Mitul S.

User-Friendly and Accurate, But Room for Further Impressions

  • November 05, 2025
  • Review provided by G2

What do you like best about the product?
This is a very good product that is also user-friendly. Its accuracy in finding vulnerabilities is impressive.
What do you dislike about the product?
Nothing as of now, no any issue on the product
What problems is the product solving and how is that benefiting you?
Need to work to reduce the false positives and need a integration or inbuilt Gen AI for latest threats


    Srinivas Walikar

Identifies vulnerabilities effectively while needing partner collaboration improvements

  • March 17, 2025
  • Review provided by PeerSpot

What is our primary use case?

I typically use Acunetix to identify vulnerabilities for clients.

What is most valuable?

The features of Acunetix have proved most effective in identifying vulnerabilities. I find the false positives to be a notable aspect. Additionally, with its impressive capabilities, Acunetix offers several options for deployment. I can use it both on the cloud and on-premises, which provides flexibility. Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.

What needs improvement?

Acunetix should focus more on partners for improvement.

For how long have I used the solution?

I have used Acunetix for approximately 30 minutes.

What was my experience with deployment of the solution?

There were no major issues during deployment, and it takes about 30 minutes to deploy.

What do I think about the stability of the solution?

I rate its stability six out of ten.

What do I think about the scalability of the solution?

The scalability of Acunetix is rated seven out of 10.

How are customer service and support?

The technical support from Acunetix is quite good, and I rate it eight out of 10.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of Acunetix is quite straightforward.

What was our ROI?

There have been improvements in security posture since using Acunetix.

What's my experience with pricing, setup cost, and licensing?

The pricing of Acunetix is pretty expensive and could be improved.

What other advice do I have?

I would recommend Acunetix to others. Overall, I rate this solution seven out of ten.


    Kamil Matusik

Easy to use and helps scan for vulnerabilities, but the deployment process is difficult, and the support must be improved

  • June 25, 2024
  • Review provided by PeerSpot

What is most valuable?

The product is really easy to use. It is a useful product. If you are a security engineer and don't have experience in the tool, you can learn it quickly. We are using Acunetix on our XDR process. We use it to scan applications and create reports for the developers. We use the scheduler to schedule scans. We can use a scan simulation to see whether the connection is established correctly. We can see where the issue is. It is great because we can find the bugs. We can create authenticated scans.

What needs improvement?

The deployment process must be improved. It is difficult to create a proxy connection.

For how long have I used the solution?

I have been using the solution for five years.

How are customer service and support?

The support is not perfect. The support could be improved. I often have to write to managers to push things.

How would you rate customer service and support?

Neutral

How was the initial setup?

I work with on-premise and on-the-cloud products. I faced a huge problem when I tried to install cloud agents. We needed a proxy connection, but Acunetix had a problem creating the connection. I worked with the support for a month. It started working, but the agent caused the bug.

Which other solutions did I evaluate?

I have used Snyk, Qualys, and Tenable. I have worked with other tools that are more helpful and have more functionality than Acunetix. Acunetix is suitable for small companies.

What other advice do I have?

We use Acunetix via API with our bucket. When developers try to push some part of the code, Acunetix is used to analyze the vulnerabilities. The integration of Acunetix with Jira and other buckets is easy. Acunetix is not very different from the other vulnerability scanners. It is not the best solution. The connection is via API. We get the link and change the token between the connections. The integration is not easy, but it's not hard. Bigger companies with a lot of developers can get better tools. Overall, I rate the tool a six or seven out of ten.


    Government Administration

Basic Website Security Analyze Tool

  • June 01, 2023
  • Review provided by G2

What do you like best about the product?
Created custom reports and scan profiles are very useful.
What do you dislike about the product?
You can not include all subdomains in your license.
What problems is the product solving and how is that benefiting you?
Pentest and security harding


    Roy A.

Decent performance, outdated UI

  • November 26, 2021
  • Review provided by G2

What do you like best about the product?
It does good crawling of the website, easy scan scheduling, and simple vulnerabilities view
What do you dislike about the product?
The vulnerabilities POC sometimes not intuitive and slightly complexed. The UI looks old. To add users, you need to set the password for them.
What problems is the product solving and how is that benefiting you?
Automatic dynamic scans for prod websites. Adding another layer of vulnerability discovery, in addition to manual pentesting


    muhammet furkan .

good example of app scan market

  • April 02, 2020
  • Review provided by G2

What do you like best about the product?
Acunetix have a user friendly interface. I have been using for 4 years. You don't need complex configuration.
What do you dislike about the product?
Latest version interface good but sometimes getting some error.
What problems is the product solving and how is that benefiting you?
Web application scanning.


    Computer & Network Security

Good tool for Penetration testing

  • June 21, 2019
  • Review provided by G2

What do you like best about the product?
One of the best tool for penetration testing on web application . It has very good scanner which scan application through out completely
What do you dislike about the product?
It will dephase the website with the script execution. It will provide some false positive Vulnerabilities
What problems is the product solving and how is that benefiting you?
Web application security and web services related Vulnerability