What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
- Current product naming under OpenText: verify
- Supported application server and framework list: confirm with vendor docs
- Whether the agent ships with the base WebInspect license: verify
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
The WebInspect Agent is a companion to Fortify's dynamic scanner rather than an independent product. It is deployed into the application runtime, as a Java agent in the servlet container or as a .NET profiler, and instruments security relevant methods so that when WebInspect sends a request from the outside, the agent records what that request did on the inside. The two halves are correlated, producing a finding that carries both the attacking request and the server side evidence: the SQL statement executed, the file path resolved, the command constructed, and the stack trace leading to it.
Beyond confirmation, the agent widens what the scanner knows about. It can enumerate routes and parameters registered by the framework that the crawler never reached, so the dynamic scan attacks endpoints it would otherwise miss, which is often where the interesting authorization and injection problems live. It also surfaces categories a black box scanner is structurally blind to, such as weak cryptographic calls and insecure file handling that produce no observable difference in an HTTP response.
Where it fits
This sits in a controlled pre-production environment, since it requires modifying a running application. In practice it is operated by a security testing team who already run WebInspect on a schedule, with results pushed into Fortify Software Security Center so dynamic findings sit next to static ones for the same application. Its value depends on you already owning the Fortify stack and on having a test environment that mirrors production closely enough for the scan to be meaningful.
Strengths
- Turns a URL and parameter finding into a file, line and stack trace a developer can act on immediately.
- Framework route enumeration materially improves crawl coverage on applications with dynamic or client side routing.
- Correlation into Software Security Center gives one governance view across static, dynamic and runtime results.
- Detects classes of weakness that leave no trace in an HTTP response.
Limitations
- Only useful inside the Fortify ecosystem, and its ownership has moved between vendors more than once, which is worth weighing on a long procurement horizon.
- Java and .NET only, so polyglot estates get partial coverage at best.
- Requires deploying and maintaining an agent in the test environment, a step that quietly goes stale and leaves you scanning without it.
- The surrounding tooling is enterprise weight: installation, licensing and configuration are not a developer self-service exercise.
Who it suits
A reasonable addition for large enterprises already committed to Fortify with significant Java and .NET applications and a dedicated testing team. Not appropriate for small teams, for modern polyglot microservice estates, or for organizations that want security testing owned and run by developers.
Used Fortify WebInspect Agent (IAST)? Recommend it under your own name and title.
Recommend this tool