Integrate Invicti scans to Autobahn Fit

This tutorial describes how to integrate your Invicti account in the Autobahn Fit

Table of content

Why integrate Invicti with Autobahn Fit

Prerequisites to integrate Invicti

Integrate your Invicti account

View your Invicti data

Delete your Invicti account configuration

Enable or disable Invicti integration

Why integrate Invicti with Autobahn Fit

Invicti is an automated, yet fully configurable, web application security scanner that enables you to scan websites, web applications, and web services, and identify security flaws
Integrating your Invicti account enable Autobahn to automatically export your scan reports to your Autobahn Fit. The exported data will the reprioritized and mapped into Autobahn Workouts.

Prerequisites to integrate Invicti

To enable the integration, you need to:

  • User ID of your Invicti API
  • Token of your Invicti API

Collect Invicti User ID and API

An API Key associated with a user account that has permissions to fetch data.
To obtain the Client ID and API Token:

1 - Log in to Invicti Enterprise.

2 -Select [Your Name] (top right of the window) and navigate to API Settings.

3 - In the Current Password field, enter your current password.

4 - Select Submit to view your User ID and API Token.  Further details are available in Invicti API Overview.

5 - Copy your User ID and API Token, and paste them on Autobahn Fit integration page.

Integrate your Invicti account

1 - Sign in to your account and on the side menu, click on ‘Integrations’. Click on the ‘Configure’ button on the Invicti card.

 If you already have Invicti configured, this means that someone in your organization has already configured the Invicti account, and this applies organization-wide.

2 - You will be directed to a form asking you to fill in your Invicti credentials. Fill in your Invicti account credentials accordingly.

3 - Fill in the timespan of your Invicti scan data that you want to pull from the past.

4 - Fill in the frequency of how you want Autobahn to pull data from your Invicti account. This could be daily, weekly, monthly or quarterly.

5 - Once you have completed the form, the test and save button on the bottom-right of the page will be activated. Click on it to configure your Invicti account.

6 - If the credentials are correct, there will be a pop-up notification on the top-right corner of your screen, saying that Invicti has been configured successfully. Please note that at this point, Autobahn will start fetching your historical scan data. This may take a couple of hours until the data is fully visible in the all scan page. Once everything is processed, they should receive a notification e-mail.

View your Invicti data

1 - Go to your All Scans page or Scan Overview page and view your scan list. Based on the frequency of data pulled from Invicti, you should see your Invicti scans in the scan list. You can differentiate where scans come from by referring to the ‘Origin’ column on the scan table.

2 - You can filter scan origin by ‘Invicti'.

3 - To view the result, click on the scan and you will be taken to the scan report page, originated from your Invicti scan.

Delete your Invicti account configuration

1 - On the side menu, click on ‘Integrations’.

2 - Refer to the Invicti card and click Edit.

Note that you need to have Invicti configured first to be able to delete the configuration.

3 - You are redirected to the configuration page. Notice that you are not able to edit the configuration (disabled fields). Click on Delete this configuration button on the bottom-left side of the screen.

4 - A pop-up on the top-right corner will show, saying that your Invicti configuration has been successfully deleted.

5 - You will be directed to the same configuration page, however this time you are able to fill in the form.

5 - If you go back to the integrations page, you should see that Invicti is not yet configured.

Enable or disable Invicti integration

1 - On the integrations page, refer to the Invicti card that you would like to deactivate or reactivate.

2 - Click on the toggle. Note that clicking this toggle when the integration is active does not mean the configuration is cancelled. You can reactivate it by clicking on the toggle again.