Security Settings

This document is for:
Invicti Enterprise On-Premises

In the Security Settings window, you can enable, add and set security measures while scanning. You can also make user sessions IP restricted, prevent internal scanning, enable localhost scanning, and add new authorized IP addresses.

Security Settings is available in the Invicti Enterprise On-Premises Edition only.

For further information, see Overview of Settings in Invicti Enterprise and Invicti Editions.

Security Settings Fields

This table lists and explains the fields in the Security Settings window.



Prevent Internal Scanning

Enable this option to prevent Invicti from scanning internal IP address blocks.

Enable Localhost Scanning

Enable this option to allow Invicti to scan localhost. For example, if you’ve already built your website on localhost:95, please enable it for scanning.

Authorized IP Addresses

This is a list of IP Addresses that have been specifically authorized to access Invicti Enterprise.

If you want to serve the application behind a load balancer, you must add its IP address to this list. Otherwise, IP Based Cookies will not work.


This is the name of the IP Address.

Regex Pattern

This is the Regex Patterns of the IP Address.

How to Enable Security Settings

  1. Log in to Invicti Enterprise.
  2. From the main menu, select Settings > Security

Invicti Enterprise On-Premises Security Settings

    • Enable the Prevent Internal Scanning checkbox.
    • Enable the Enable Localhost Scanning checkbox.
  1. Select Save.

How to Add an Authorized IP Address

  1. From the main menu, select Settings > Security
  2. In the Authorized IP Addresses panel, select New.
  3. Complete the Authorized IP Addresses, Name, and Regex Pattern fields.
  4. Select Save.

How to Delete an Authorized IP Address

  1. From the main menu, select Settings > Security
  2. In the Authorized IP Addresses panel, select the Delete button () next to the relevant IP address.
  3. Select Save.

