Support
Scan Policies

Creating a new scan policy

This document is for:
Invicti Enterprise On-Demand, Invicti Enterprise On-Premises

A scan policy is a set of settings for web application security scans. It determines the security tests to be conducted when initiating a scan. You can choose pre-defined policies, customize them based on your target's characteristics, or create new ones. Additionally, you can share policies within a group or duplicate them from a group.

How to create a new scan policy in Invicti Enterprise

  1. Log in to Invicti Enterprise.
  2. From the main menu, select Policies  > New Scan Policy.
  3. Fill in the Name and Description fields.
  4. Select the Shared checkbox, if required (refer to Sharing Scan Policies).
  5. Complete the remaining fields. (Each tab is explained in the Scan Policy Fields tables below.)
  6. Click Save when you have finished configuring your scan policy.

108

How to share Scan Policies

There are four types of Scan Policies:

  • Default: Unless set as Shared, these are exclusively for your use.
  • Share: These policies are available for others to utilize.
  • Private: Reserved solely for your own use, these policies cannot be accessed by others.
  • Mine: Referring to the policies you have personally created.

When you share your Scan Policy, other users gain access to it for use and cloning. Scan Policies that you create and do not share with your team members are labeled as "Mine" and "Private" in the Type column.

NOTE: The user who has the Account Administrator role can see the private policies of the team members.

  1. Navigate to the New Scan Policy window.
  2. Enable the Shared field. A new section, Website Groups, is displayed.
  3. Select all the Website Groups the Scan Policy should be shared with. This means that anyone who has access to those groups can use your Scan Policy. 

NOTE: By default, authentication verifier agents use incognito mode on Chromium browsers.