Best Software for 2025 is now live!
Save to My Lists
Paid
Claimed

Invicti (formerly Netsparker) Reviews & Product Details - Page 2

Invicti (formerly Netsparker) Overview

What is Invicti (formerly Netsparker)?

Invicti is an automated application and API security testing solution that allows enterprise organizations to secure thousands of websites, web apps, and APIs and dramatically reduce the risk of attack. By empowering security teams with the most unique DAST + IAST scanning capabilities on the market, Invicti allows organizations with complicated environments to confidently automate their web application and API security. With Invicti, security teams can: - Automate security tasks and save hundreds of hours each month - Gain complete visibility into all your applications — even those that are lost, forgotten, or hidden - Automatically give developers rapid feedback that trains them to write more secure code — so they create fewer vulnerabilities over time - Feel confident that you are equipped with the most powerful application security scanning tool on the market You have the most demanding security needs, and Invicti is the best-in-class application security solution you deserve.

Invicti (formerly Netsparker) Details
Product Website
Languages Supported
English
Show LessShow More
Product Description

Invicti (formerly Netsparker) is an automatic and easy-to-use web application security scanner to automatically find security flaws in websites, web applications and web services.

How do you position yourself against your competitors?

Application Security with Zero Noise


Seller Details
Company Website
Year Founded
2018
HQ Location
Austin, Texas
Twitter
@InvictiSecurity
2,568 Twitter followers
LinkedIn® Page
www.linkedin.com
312 employees on LinkedIn®
Description

Invicti Security is a cybersecurity company specializing in web application security solutions. Their flagship product, AppSec, offers automated vulnerability scanning and management to help organizations identify and remediate security risks in their web applications. With a focus on improving security workflows and compliance, Invicti aims to empower development teams to build secure applications efficiently. For more information, visit their website at [invicti.com](https://www.invicti.com/).


Peter A.
PA
Overview Provided by:

Recent Invicti (formerly Netsparker) Reviews

Dhanarjun M.
DM
Dhanarjun M.Mid-Market (51-1000 emp.)
4.0 out of 5
"User friendly API Testing"
It is very user friendly and gives you detailed view of the API requests and the response forms and vulnerabilities
Harshit S.
HS
Harshit S.Enterprise (> 1000 emp.)
5.0 out of 5
"Invicti (formerly Netsparker) Amazing tool for Dynamic Application Security Testing (DAST)"
Good amount of True positive issues. the Good amount of information is provided for the issue (captures complete request and response for the repor...
BK
Bala K.Small-Business (50 or fewer emp.)
5.0 out of 5
"All in one vulnerability scanner"
Invicti which is Netsparker provided me major vulnerability database to find remote execution vulnerability, domain invalidation and manay vulnerab...
Security Badge
Invicti (formerly Netsparker) Security
Get security information from Invicti (formerly Netsparker) to help you buy the right software. View Security Information

Invicti (formerly Netsparker) Media

Invicti (formerly Netsparker) Demo - Detailed vulnerability scans reports
The detailed reports allow you to monitor the security state of a target web application or web API through the different scans.
Invicti (formerly Netsparker) Demo - Viewing issues in Netsparker Enterprise
The Issues window displays lists of vulnerabilities detected in scans run by your entire team. You can get an overview of Issues that have been assigned to you, those that are awaiting a Retest, and those that are Addressed. Find out more https://www.netsparker.com/support/viewing-issues-netsp...
Invicti (formerly Netsparker) Demo - How to run a group scan in Netsparker Enterprise
Netsparker is very easy to use and starting a new security scan is as easy as 1, 2, 3. From the main menu, click Scans, then New Group Scan. The New Website Group Scan window is displayed. From the Website Group dropdown, select the website group you want to scan. Complete the remainder of the fi...
Invicti (formerly Netsparker) Demo - A SQL Injection vulnerability report
Netsparker reports all the vulnerability details the developers need to fix the vulnerability including the vulnerable URL, parameter and payload. It also reports a Proof of Exploit, proving the vulnerability is real and not false positive.
Using Invicti for vulnerability scanning has allowed Channel 4 to improve security while also spending less on manual Penetration Testing.
Play Invicti (formerly Netsparker) Video
Using Invicti for vulnerability scanning has allowed Channel 4 to improve security while also spending less on manual Penetration Testing.
Find and test your APIs faster and more efficiently than ever before with API Security and new API Discovery from Invicti.
Play Invicti (formerly Netsparker) Video
Find and test your APIs faster and more efficiently than ever before with API Security and new API Discovery from Invicti.

Official Downloads

Answer a few questions to help the Invicti (formerly Netsparker) community
Have you used Invicti (formerly Netsparker) before?
Yes

59 Invicti (formerly Netsparker) Reviews

4.6 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
59 Invicti (formerly Netsparker) Reviews
4.6 out of 5
59 Invicti (formerly Netsparker) Reviews
4.6 out of 5

Invicti (formerly Netsparker) Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for Invicti (formerly Netsparker)Question

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Verified User in Telecommunications
AT
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Invicti (formerly Netsparker)?

Netsparker is a digitalized online web application security scanner, which is entirely configurable, which enables users to scan websites, web applications, and web services and detect security flaws.

You have a lot of options to select options to select security policies.

Also, it has support to start multiple scans at a given time based on agents installed or configured in the Netsparker enterprise server. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

No support for 2FA or MFA applications. We have more than 50% of Applications with 2FA in our organization. I heard it's getting published soon.

When using Netsparker to scan or detect vulnerabilities in web applications with larger web applications, users can notice slowness in the web scanning processes. Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

False Positives reported

Starting security assessments more than 5-6 at a time because of the agents installed. Review collected by and hosted on G2.com.

Volodymyr S.
VS
Senior Information Security Engineer
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Invicti (formerly Netsparker)?

A lot of security checks, that are easily customizable. You can make the exact scat profile\type that you want.

Really good support that answering fast and giving you proper recommendations. Every time when we reported false positives - the reaction was fast and adequate. It is the best solution that you can find on a market. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

Sometimes you need a lot of time and RAM to scan big applications, but it is an understandable disadvantage. Also, there are not so many options for scheduling, so in most cases, you will be running scans in real time. Review collected by and hosted on G2.com.

Recommendations to others considering Invicti (formerly Netsparker):

Go to the settings and spent dome hours diving in. It will give you a much better understanding of a product and will increase value from the scanning activity.

Also, not install it on the servers that already have other roles - it can ruin your life.

If you have a lot of applications, you should go for the cloud. Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

Closing the most popular vulnerabilities with minimum time investments. We don't need to check every application with our hands - the scanner will make the most of the important checks automatically. Review collected by and hosted on G2.com.

JL
Analyste - Sécurité TI
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Invicti (formerly Netsparker)?

Netsparker is an intuitive software to use even so it has a lot of options under the hood to help you tweak the configuration.

The technologie dashboard, shows you in a click all the informations about the sofwares versions used in your web applications. It makes it easy to see the states of your applications.

The number of false positive is low and it is able to detect a wide range of vulnerabilities. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

The Kenna integrations need's work, it is not proprely sending CVE'S at the moment.

And there is no metrics to compare ourself to the industries, e.g remediations time. Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

We are securing our web applications by detecting security issues, before they are exploited.

Compare to the solution we had before, we lowered our false positive by a high margin and improved the detections of security issue.

They missed a few times CVE's related to an oudated software version, support has fixed it quickly, still an area that would need more attention. Review collected by and hosted on G2.com.

Damien S.
DS
Sr. Application Security Architect / Penetration Tester / vCISO / Instructor
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Invicti (formerly Netsparker)?

NetSparker integrates with so many technologies in such an efficient manner it makes complete CI/CD coverage possible from a DAST perspective. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

The licensing tied to URLs is very strict. Once you have attached a root URL to a website for scanning, it is challenging to retrieve that license if you or the development team made a mistake. This disconnect has happened several times with us due to initiating the development teams into the scanning process. Each time we have had to work with NS support to retrieve licenses. Review collected by and hosted on G2.com.

Recommendations to others considering Invicti (formerly Netsparker):

Consider NetSparker if your development lifecycle includes a lot of cutting-edge technologies that must be assessed quickly. Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

We were looking for a DAST solution that would integrate into the software development lifecycle. The use of NetSparker has relieved us of scanning manually and not maintaining a proper cadence for each scan cycle. Review collected by and hosted on G2.com.

Mustafa A.
MA
Senior Security Engineer
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
Business partner of the seller or seller's competitor, not included in G2 scores.
What do you like best about Invicti (formerly Netsparker)?

Netsparker support gets back to you so fast that it looks like you are on a chat with them

always available for meet and screen share to resolve any problem even if it takes 2hrs(which they are way faster in solving)

a very friendly support team that can escalate any matter quickly if needed Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

Nothing pretty much

all is great with their team Review collected by and hosted on G2.com.

Recommendations to others considering Invicti (formerly Netsparker):

I don't want to name any other application that does a similar job to Netsparker but I need to tell you, based on my experience in Security for over 8 years, I see that Netsparker, by far, is the best Web Application Security tool I have worked with Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

variety of problems, like scanner, cannot reach the websites, verifying XSS, Environment Migration, and etc. Review collected by and hosted on G2.com.

Verified User in Insurance
EI
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
What do you like best about Invicti (formerly Netsparker)?

Netsparker is intuitive to use. I don't have to understand much about the web platform that I am assessing nor the various options to customize the software—knowing those simply provides a quicker and more in-depth experience. Out of the box, Netsparker quickly provides the function I need. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

I would offer a wider variety of subscription models. I felt that some of the flexibility I would have liked to have regarding "registering" the domains that I will test with Netsparker felt prohibitive. It removed flexibility to do specific ad-hoc examinations and tests. I would suggest some additional offerings in a subscription. I would also recommend offering a one-year subscription model. Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

Netsparker allows me to integrate security assurance into the software development lifecycle in my organization. I can periodically validate secure coding practices during development and after deployment. I can also validate the functionality of some of my other security features, such as my web application firewall. Netsparker is an excellent tool to have in my security toolbox. Review collected by and hosted on G2.com.

Verified User in Banking
AB
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Invicti (formerly Netsparker)?

The interface is user extremely user-friendly, easy to grab, even a new-beginner can manage it quickly. Reports are visually satisfactory, they are not complex but are reflecting the all vulnerabilities at the same time, therefore providing the reader a good summary of the relative scan(s). Automatically sent notification emails are useful on the other hand, for instance, if an agent is down you are being warned just at that time so you can fix and load the balance on agents again before any crashes. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

Both the web and desktop apps are instable during custom script writing and verification of login/logout. Here, there are other factors rather than Netsparker of course, such as the health websites you are scanning or internet connection, but there are some situations that 'Test script' button works for some time and doesn't for a few times after. These pop-out pages(custom script and verification) are being loaded very slow generally. Review collected by and hosted on G2.com.

Recommendations to others considering Invicti (formerly Netsparker):

If you are looking for a perfect software, probably you won't be able to find it. Netsparker is close to perfect and it delivers a great support both in Turkish and English (maybe also in other languages I don't know). You don't feel lost and waste huge time and effort on accomplishing your expectations from this app so I find it clever to invest on a good support. Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

We are using Netsparker for dynamically scanning different styles of websites we own; with Captcha, without Captcha, when logging in requires one or multiple pages, does not matter for this application. For the beginning, it feels hard to configure but the support team always respond quickly and they are really helpful about all problems whether they are easy or hard to solve. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
II
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: Seller invite
Incentivized Review
What do you like best about Invicti (formerly Netsparker)?

Netsparker can provide proof of concept/exploitation of web applications to give customers Reports that are visually pleasing, comprehensible put together in an easy to read but not overtaxing format. It explains the vulnerabilities in detail, plus also giving you a mitigation/road map on how to resolve the vulnerability.

I love the way I can craft authenticated and unauthenticated scans on different web applications. These can be a simple website to a complex fresh from the developers' web application that highlights vulnerabilities that developers had missed in beta testing. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

Some recent upgrades have left bugs in the system which can be annoying. The NET4.8 one on the last upgrade was not highlighted until customer found that using the API the Netsparker scanner would stall just before the initiation of the scan. Other than that nothing else has troubled us. Review collected by and hosted on G2.com.

Recommendations to others considering Invicti (formerly Netsparker):

The best web application scanner around - why bother with the rest when this hits every spot in vulnerability and penetration testing. Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

The number of security holes left open by developers that netsparker discovers in DAST scanning, which helps the developers to re-focus and implement the necessary mitigation or upgrades to make the correct changes. A handy tool in our penetration testing in our continuous testing platform with scanning every week to ensure continuity and any changes in the web application that would alert us in our BOT network. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
EI
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
Business partner of the seller or seller's competitor, not included in G2 scores.
What do you like best about Invicti (formerly Netsparker)?

Very little false positive and relatively easy to use. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

Can always make it even easier to use . Review collected by and hosted on G2.com.

Recommendations to others considering Invicti (formerly Netsparker):

Try it out Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

Web vulnerability scanning in a quick manner Review collected by and hosted on G2.com.

TW
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Invicti (formerly Netsparker)?

The best element if NetSparker Appsec tooling is the ease of use. You can get up and running in a matter of minutes. Their default scan policies are very powerful and easy to modify as needed. I also like the local scan agents for applications that we cannot whitelist through our firewall. If there are challenges their Support staff is also VERY responsive and knowledgeable. They are more than happy to get on a call and walk through any issues and work it through to a resolution. Review collected by and hosted on G2.com.

What do you dislike about Invicti (formerly Netsparker)?

Scanning API's is a little cryptic and requires good understanding of the specific commands within it. It would be helpful if the setup of them was a little more dynamic based on the API type and content. Review collected by and hosted on G2.com.

Recommendations to others considering Invicti (formerly Netsparker):

After review over a dozen other products available, after seeing the demo of NetSparker it was an easy decision. Some of the other products available seem to expect their users to have a PhD. Most IT professionals do not have the time to invest into overly complex tools. NetSparker provides out of the box, thorough scanning tools which allow users to produce results quickly. Review collected by and hosted on G2.com.

What problems is Invicti (formerly Netsparker) solving and how is that benefiting you?

Our organization did not have any AppSec tools or policies in place. As a result this was a substantial area of risk which was unknown in scope. NetSparker helped us understand the risks, how to mitigate them before they are deployed and provides ongoing incremental scans to ensure compliance. Review collected by and hosted on G2.com.