Skip to main content
availability

Deployment: Invicti Platform on-demand, Invicti Platform on-premises

Target definition

Before Invicti Platform can scan a website, API, or web application for vulnerabilities, you add it as a target. This document explains what a target is, the asset types you can choose, and how targets count toward your license - so you can plan your coverage and keep license usage predictable.

A target can be almost any web asset, including websites, APIs, web applications, servers, and network devices. Typically, each domain or web application uses one target license.

Configure target settings page.

Target types

When you add a target, you select its asset type, which determines how Invicti scans it:

  • Webapp: A website or web application. Invicti crawls the target in a browser to discover links and pages, then scans what it finds.
  • API-only target (asset type API): An API endpoint that Invicti scans only against the operations defined in its API specification. Invicti doesn't crawl the target in a browser, and any endpoints or links discovered outside the specification are ignored. Creating API-only targets requires the API discovery add-on.
Related documents

Licensing rules for targets

When determining how targets are counted for licensing, the following rules apply:

tip

For more information about managing your license usage and viewing FQDN consumption, refer to License management.

  • localhost and 127.0.0.1 consume 1 licensed target
  • example.com and www.example.com together consume 1 licensed target
  • The protocol (http vs. https) doesn't affect target count and consumes 1 licensed target
  • Subdomains are considered separate targets: for example, www.example.com and api.example.com consume 2 licensed targets
  • Different paths within the same domain consume 1 licensed target: for example, example.com and example.com/blog/
  • Different ports for the same domain consume 1 licensed target: for example, example.com:8080 and example.com:8888
  • Invicti test sites with Demo status (visible in the Settings > License > Licensed FQDNs used drawer) don't consume any target licenses; for example, vulnweb.com

Target variations and licensing

Target variations refer to different configurations of the same FQDN. You can create multiple variations such as:

  • http://example.com
  • https://example.com
  • http://www.example.com
  • https://www.example.com
  • http://example.com/blog
  • http://example.com:888
  • http://example.com:777

All these variations use only one licensed FQDN.

Important licensing behavior:

  • Invicti doesn't immediately count targets against your license when you add them
  • You can remove a target without penalty if you make a mistake in the address
  • Invicti counts a target as licensed only after you scan it

Subdomain licensing rules

Invicti counts each subdomain as a separate FQDN, with the exception of www:

  • http://www.example.com and http://api.example.com use 2 licensed targets
  • invicti.com:80 and invicti.com:443 count as 1 licensed target
  • invicti.com/home and invicti.com/site count as 1 licensed target

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?