Skip to main content

Invicti OOB and Verified Badge

Invicti OOB enhances the reliability and precision of vulnerability scans by accurately detecting out-of-band vulnerabilities. The Verified badge is displayed for vulnerabilities with a 100% confidence rating.

This document explains how to identify vulnerabilities found by Invicti OOB and those marked with the Verified badge in the vulnerability results.

Invicti OOB

Invicti OOB enables Invicti to improve the accuracy and reliability of vulnerability scans by identifying out-of-band vulnerabilities (exploits reported back to the scanner). It integrates seamlessly with out-of-band checks and requires no installation or configuration; however, it does need internet access to bxss.me.

Refer to the trustlisting guidelines for more information:

By default, all scans use Invicti OOB service, unless specific checks are excluded or the service is turned off. Without Invicti OOB, out-of-band detection isn't possible. Vulnerabilities verified through out-of-band testing are marked with the Invicti OOB label. Vulnerabilities detected with Invicti OOB are never false positives.

How to identify Invicti OOB-detected vulnerabilities

  1. Select Vulnerabilities from the left-side menu.
  2. In the View by Vulnerability list, look for the Invicti OOB icon.
Invicti OOB icon in the vulnerability list.
  1. Click the selected vulnerability to display its details on the right-hand side. The information appears in the details.
Example of the vulnerability discovered by Invicti OOB in Invicti Platform.

Verified badge

The Verified badge indicates vulnerabilities detected with 100% certainty during a scan, confirming their existence in the scanned web application and eliminating the need for manual verification.

Vulnerabilities not marked with the verified badge are generally valid; however, the detection method may prevent Invicti from being completely certain of their existence. Nonetheless, Invicti maintains a very low false positive rate.

How to identify vulnerabilities with the Invicti Verified badge

  1. Select Vulnerabilities from the left-side menu.
  2. Check the Confidence column for a value of 100% to identify the vulnerabilities.
Example of confirmed vulnerabilities with 100% confidence and Verified badge.
  1. Click the selected vulnerability to display its details on the right-hand side. The Verified badge appears within the vulnerability details.
Example of the confirmed vulnerability with the Verified badge in the details pane.

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?