Skip to main content
this document is for:

Deployment: Invicti Platform on-premises

Invicti Platform on-premises trustlist requirements

To ensure the proper functioning of internal agents and integrations, configure inbound and outbound traffic rules to allow access to the URLs specified in this document. Correctly configuring network access is a prerequisite for successful and accurate scans of your targets.

Registry access requirements

  • Primary registry: platform-registry.invicti.com (requires an active internet connection).
  • Additional sources: Some images are pulled from Docker Hub (registry-1.docker.io).
  • Trustlist guidance for Docker: You can allow access to Docker Hub by following the Docker allowlist guide.

Inbound and outbound connections

ScopeSourceDestination
Using Invicti Platform GUIYour browserIP address or URL of your Invicti Platform main installation on (default) port
Using Invicti Platform APIYour API clientIP address or URL of your Invicti Platform main installation on (default) port
DAST scansThe main installation scan enginesYour target
Zero configuration API discoveryThe main installation scan enginesIP address/URL for your targets including ports being checked (the default port list is: 80, 81, 443, 3000, 5000, 7000, 8000, 8008, 8080, 8081, 8083, 8088, 8090, 8181, 8443, 8888)
Engine calls to the Invicti OOB service for out-of-band vulnerability checkingIP address of your Invicti Platform main installationhttps://bxss.me
Engine calls to the safe browsing serviceIP address of your Invicti Platform main installation or Invicti Internal Scanning Agenthttps://sb.bxss.me (port 443)
Engine calls to the software composition analysis serviceIP address of your Invicti Platform main installation or Invicti Internal Scanning Agentsca.invicti.com
Invicti OOB S3 bucket for out-of-band vulnerability checkingIP address of your Invicti Platform main installation or Invicti Internal Scanning Agenthttps://poll.bxss.me
Access Token for the Invicti Discovery ServiceIP address of your Invicti Platform main installationhttps://jwtsigner.invicti.com
API calls to the Invicti Discovery ServiceIP address of your Invicti Platform main installationhttps://discovery-service.invicti.com
Check for software updatesIP address of your Invicti Platform main installationhttps://static-platform.invicti.com
License activation and license updatesIP address of your Invicti Platform main installationhttps://activation.invicti.com
API discovery for Apigee API hub, Mulesoft, AWS API Gateway, etcIP address of your Invicti Platform main installationIP ranges or URLs for your target API integrations (including port number)
Using IAST
  • IP address of your Invicti Platform main installation
  • Scanned target
IP address or URL of your Invicti IAST Bridge. If using IAST Bridge in your installation the default port is 7880. If using online IAST bridge, https://iast.invicti.com

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?