Skip to main content
availability

This integration is configured through the Invicti ASPM product.

Infrastructure overview

What is infrastructure scanning?

Infrastructure scanning identifies vulnerabilities in running infrastructure, including servers, network devices, operating systems, and cloud resources. Unlike IaC scanning (which checks configuration files before deployment), infrastructure scanning assesses the actual state of deployed systems to find known vulnerabilities, missing patches, and misconfigurations.

note

Invicti AppSec Core includes a preconfigured Invicti SCA scanner that is automatically activated with your package. The integrations on this page are for teams using Invicti ASPM who want to connect their own SCA tools instead. See AppSec Core scanners overview for details on the built-in scanner.

How it works

Infrastructure scanners connect to your environment and assess running systems by:

  • Vulnerability assessment — scans hosts and network devices for known CVEs, missing patches, and outdated software.
  • Configuration auditing — checks system configurations against security benchmarks and hardening standards.
  • Network scanning — discovers open ports, exposed services, and network-level vulnerabilities.
  • Compliance checks — evaluates infrastructure against frameworks such as CIS Benchmarks, PCI DSS, and NIST.

What it can discover

Infrastructure scanning detects risks across the following categories:

CategoryExamples
Missing patchesUnpatched operating systems, outdated software with known CVEs
Exposed servicesOpen ports, unnecessary services running, publicly accessible management interfaces
Configuration weaknessesDefault credentials, weak encryption settings, disabled security features
Network vulnerabilitiesUnencrypted protocols, insecure DNS configurations, weak firewall rules
Compliance gapsDeviations from CIS Benchmarks, PCI DSS, HIPAA, and other standards

Infrastructure scanning vs. CSPM

Infrastructure scanning and CSPM are complementary but distinct:

Infrastructure scanningCSPM
TargetRunning hosts, servers, network devicesCloud service configurations
ApproachActive vulnerability scanningContinuous configuration assessment
Use caseFind CVEs and missing patches on deployed systemsFind misconfigurations in cloud resources

For cloud infrastructure coverage, consider using both infrastructure scanning and CSPM integrations together.

Supported infrastructure scanning tools

The following infrastructure scanning integrations are available through Invicti ASPM:

ToolFocus
Nessus ProfessionalVulnerability assessment and compliance auditing
Tenable.io VMCloud-based vulnerability management
Tenable.scOn-premise vulnerability management
Qualys VMDRVulnerability management and compliance
Rapid7 InsightVMVulnerability assessment and risk prioritization
Rapid7 InsightVM CloudCloud-based vulnerability management
Rapid7 NexposeOn-premise vulnerability management
Lacework InfraCloud infrastructure security
CrowdStrike InfraEndpoint and infrastructure security

Need help?

The Invicti Support team is ready to provide technical assistance. Go to Help Center

Was this page useful?