Managing Authentication Verifier Agents

You can download and install authentication verifier agents to verify that you run authenticated scans in your local environment.

  • To scan a website located on your internal network, and not accessible from the internet, you need to install and configure a scan agent on your network. The agent will conduct the actual scan job and then report the results back to Acunetix 360.
  • You can download and install an internal verifier agent to perform the authentication, so you can make sure that your scan is authenticated.

This topic explains how to manage authentication verifier agents in Acunetix 360. Downloading authentication verifier agent? See Installing Authentication Verifier Agents.

Manage Authentication Verifier Agents fields

This table lists and explains the fields on the Authentication Verifier Agents page.

Field

Description

Name

This is the name of the authentication verifier agent.

Launch Verification Date

This is the date when the authentication verifier agent was first available.

Last Heartbeat

This is the last time the authentication verifier agent communicated with the web application.

Auto Update Enabled

This is whether the Agent is configured to update itself when there is a new release.

Agent Version

This is the version number of the authentication verifier agent.

VdB Version

This is the Vulnerability Database Version running on the Authentication Verifier Agent.

Operating System

This is the operating system on which the Authentication Verifier Agent is installed.

Information

Starting with the 7 December 2022 dated release, internal agents are bundled with the required .NET framework. So, you don’t need to install .NET into your environment. Also, the installed framework version and your .NET version can be different.

Managing authentication verifier agents

This page lists authentication verifier agents installed on your machine. From this page, you can download the required files to install your verifier agents, delete your agents, and request agent logs.

How to access the Manage Authentication Verifier page
  1. Log in to Acunetix 360.
  2. From the main menu, select Agents > Manage Verifiers.

Accessing verifier agent logs

The Acunetix 360 Authentication Verifier Agent stores the application logs in the Logs folder in the installation path.

The last three days’ logs can be downloaded from the Manage Authentication Verifier page. These logs are especially useful for troubleshooting.

How to access authentication verifier agent logs
  1. From the main menu, select Agents > Manage Verifier.
  2. Next to the relevant Agent, select the Command drop-down, then Request Agent Logs.

  1. From the Request Verifier Logs dialog, select Yes. Wait.
  2. In the Save As window, choose a location and select Save.

Then, Acunetix 360 downloads the log to your preferred location.

Deleting authentication verifier agent using the UI

You can delete an authentication verifier agent using Acunetix 360's user interface.

How to delete an authentication verifier agent using the UI
  1. Log in to Acunetix 360.
  2. From the main menu, select Agents > Manage Verifiers.
  3. Next to the relevant agent, select Delete.
  4. From the Delete Agent dialog, select Yes, Delete to delete the verifier agent.

Tips

This action only deletes the agent from the user interface and stops the service in your machine.

Verifying form authentication with a verifier agent

After the installation, you can use your agent to authenticate forms.

How to verify form authentication with a verifier agent
  1. Log in to Acunetix 360.
  2. From the main menu, select Scans > New Scan.
  3. In the Target URL field, enter the URL.
  4. From the Scan Options section, select Form Authentication.
  5. Select the Form Authentication checkbox.

  1. In the Login Form URL field, enter the URL of the login form whose credentials you want to configure.

Information

If there is more than one authentication verifier agent defined in your system, Acunetix 360 shows a drop-down menu to select the verifier agent you want to use.

  1. In the Personas section, select New Persona. Then, enter a username and password.
  2. Select Verify Login & Logout so the verifier agent can test the login.

If the Verify Login & Logout button has a check mark, this means the Acunetix 360 Authentication Verifier Agent verified the login form successfully.

Scanning your website with an internal scan agent? See Defining and Scanning an Internal Website in Acunetix 360.


 
« Back to the Acunetix Support Page