Managing Authentication Verifier Agents
You can download and install authentication verifier agents to verify that you run authenticated scans in your local environment.
- To scan a website located on your internal network, and not accessible from the internet, you need to install and configure a scan agent on your network. The agent will conduct the actual scan job and then report the results back to Invicti Enterprise.
- You can download and install an internal verifier agent to perform the authentication, so you can make sure that your scan is authenticated.
For further information about the internal authentication verifier, see Streamline authenticated scanning with Invicti’s verifier agents.
This topic explains how to manage authentication verifier agents in Invicti Enterprise. Downloading authentication verifier agent? See Installing Authentication Verifier Agents.
Manage Authentication Verifier Agents fields
This table lists and explains the fields on the Authentication Verifier Agents page.
Field | Description |
Name | This is the name of the authentication verifier agent. |
Launch Verification Date | This is the date when the authentication verifier agent was first available. |
Last Heartbeat | This is the last time the authentication verifier agent communicated with the web application. |
Auto Update Enabled | This is whether the Agent is configured to update itself when there is a new release. |
Agent Version | This is the version number of the authentication verifier agent. |
VdB Version | This is the Vulnerability Database Version running on the Authentication Verifier Agent. |
Operating System | This is the operating system on which the Authentication Verifier Agent is installed. |
Starting with the 7 December 2022 dated release, internal agents are bundled with the required .NET framework. So, you don’t need to install .NET into your environment. Also, the installed framework version and your .NET version can be different.
Managing authentication verifier agents
This page lists authentication verifier agents installed on your machine. From this page, you can download the required files to install your verifier agents, delete your agents, and request agent logs.
How to access the Manage Authentication Verifier page
- Log in to Invicti Enterprise.
- From the main menu, select Agents > Manage Verifiers.
Accessing verifier agent logs
The Invicti Enterprise Authentication Verifier Agent stores the application logs in the Logs folder in the installation path.
The last three days’ logs can be downloaded from the Manage Authentication Verifier page. These logs are especially useful for troubleshooting.
How to access authentication verifier agent logs
- From the main menu, select Agents > Manage Verifier.
- Next to the relevant Agent, select the Command drop-down, then Request Agent Logs.
- From the Request Verifier Logs dialog, select Yes. Wait.
- In the Save As window, choose a location and select Save.
Then, Invicti downloads the log to your preferred location.
Deleting authentication verifier agent using the UI
You can delete an authentication verifier agent using Invicti Enterprise’s user interface.
How to delete an authentication verifier agent using the UI
- Log in to Invicti Enterprise.
- From the main menu, select Agents > Manage Verifiers.
- Next to the relevant agent, select Delete.
- From the Delete Agent dialog, select Yes, Delete to delete the verifier agent.
This action only deletes the agent from the user interface and stops the service in your machine.
Verifying form authentication with a verifier agent
After the installation, you can use your agent to authenticate forms.
How to verify form authentication with a verifier agent
- Log in to Invicti Enterprise.
- From the main menu, select Scans > New Scan.
- In the Target URL field, enter the URL.
- From the Scan Options section, select Form Authentication.
- Select the Form Authentication checkbox.
- In the Login Form URL field, enter the URL of the login form whose credentials you want to configure.
- In the Personas section, select New Persona. Then, enter a username and password.
- Select Verify Login & Logout so the verifier agent can test the login.
If there is more than one authentication verifier agent installed in your machine, Invicti shows a drop-down to select the verifier agent you want to use.
Scanning your website with an internal scan agent? See Defining and Scanning an Internal Website in Invicti Enterprise.