Add target
In Invicti Platform, an asset can be either a target or a project. This document guides you through adding a new target, configuring its details, and preparing it for accurate and secure scanning. Targets—typically websites or web applications—can be added either from the Website Discovery page or directly from the Targets page. If you want to create multiple targets, refer to the linked document.
Steps to add a new target
- Select Inventory > Targets from the left-side menu.
- Click Create new target.
- Enter a name and the URL of the target.
- By default, new targets use the Invicti Cloud Agent, which can scan any publicly available site without additional configuration. Choose the agent that best matches your scan environment and security requirements.
- Invicti Cloud agent (default): This is Invicti’s managed cloud-based agent, suitable for scanning publicly accessible websites. It requires no setup and is ideal for most internet-facing applications.
- Private agent: You can also use your own installed scan agent to scan internal or restricted environments not accessible from the public internet.
- Assign the target to an environment (e.g., development, staging, production) to help organize and manage scans. Environments are defined in Settings > Environments and must be created there before use.
- Select a parent application to group the target with related assets. Applications serve as central units for managing vulnerabilities and improving analysis across connected targets.
- Choose a collection to organize the target based on business context or custom criteria. Collections support tailored security management and reporting.
- Add tags to further group and filter targets. Submit each tag by pressing Enter after typing. Tags assist with quick identification, categorization, and filtering in reports and views.
- Confirm the target creation by pressing Create target.
Before running your first scan, make sure to read our authorized target scan policy. To get started safely with the Invicti Platform, you can use our testing website, which allows you to explore scanning features without using your own FQDNs or affecting live environments. |
- The Targets page is updated with your new target.
Once your target is setup, you can run the first scan. |