โ† All cheat sheets

NESSUS-ADVANCED

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Advanced vulnerability scanning with Nessus and OpenVAS/Greenbone.
Covers credentialed scanning, policy tuning, API automation, and
compliance auditing.

NESSUS ADVANCED#


    

SCAN POLICIES#

# Built-in templates
  Basic Network Scan          # General-purpose
  Advanced Scan               # Full control over settings
  Credentialed Patch Audit    # Authenticated patch check
  Web Application Tests       # Web app scanning
  PCI-DSS Quarterly Scan      # PCI compliance
  SCADA                       # ICS/SCADA systems
  Malware Scan                # Known malware detection
  Host Discovery              # Network discovery only
  Internal PCI Network Scan   # Internal PCI compliance

CREDENTIALED SCANNING#

# Windows (SMB)
  Authentication: Windows
  Username: domain\admin (or admin for local)
  Password: P@ssw0rd
  Domain: CORP (optional)

  # Enable: Remote Registry service must be running
  # Or: WMI access required
  # GPO: Computer Config > Admin Templates > Network >
  #      Network Connections > Windows Defender Firewall >
  #      Allow inbound remote administration exception

# Linux (SSH)
  Authentication: SSH
  Username: root (or sudo user)
  Password: or SSH key file (.pem/.ppk)
  Elevate privileges with: sudo
  sudo user: username
  sudo password: password

  # SSH key auth (recommended)
  Upload private key file
  Passphrase if key is encrypted

# Database scanning
  Oracle, SQL Server, MySQL, PostgreSQL
  Provide DB credentials in scan policy

# VMware/ESXi
  Username: root
  Password: ESXi password
  Port: 443

ADVANCED SCAN SETTINGS#

# Discovery
  Ping Methods: ARP, TCP, ICMP, UDP
  Port Range: 1-65535 (or specific ports)
  Port Scanner: SYN, TCP, UDP
  Network Type: Private LAN, Mixed, Public WAN

# Assessment
  Override normal accuracy: Enable
  Perform thorough tests: Enable (slower but more accurate)
  Scan for known web vulns: Enable
  Brute force credentials: Enable/Disable

# Performance
  Max concurrent hosts: 30 (default)
  Max concurrent checks per host: 5
  Network timeout: 5 seconds
  Max retries: 3
  Reduce parallel connections on congestion: Enable
  Throttle scan on network congestion: Enable

# Report
  Show missing patches that have been superseded: Enable
  Hide results from dead hosts: Enable

PLUGIN FAMILIES#

# Enable/disable by category
  CGI abuses              # Web application vulns
  Databases               # Database vulns
  Default Unix Accounts   # Default cred checks
  Denial of Service       # DoS checks (disable for production)
  Firewalls               # Firewall config checks
  FTP                     # FTP vulnerabilities
  General                 # General checks
  Misc                    # Miscellaneous
  Netware                 # Novell checks
  Peer-To-Peer            # P2P software
  SCADA                   # ICS/SCADA checks
  Service Detection       # Service/version detection
  SMTP                    # Email server checks
  SNMP                    # SNMP checks
  Web Servers             # Web server vulns
  Windows                 # Windows-specific checks
  Windows: Microsoft Bulletins  # MS patch checks

NESSUS CLI (NASL)#

# nessuscli commands (run on Nessus server)
/opt/nessus/sbin/nessuscli lsuser                 # List users
/opt/nessus/sbin/nessuscli adduser admin           # Add user
/opt/nessus/sbin/nessuscli chpasswd admin          # Change password
/opt/nessus/sbin/nessuscli rmuser admin            # Remove user
/opt/nessus/sbin/nessuscli fetch --register XXXX   # Register license
/opt/nessus/sbin/nessuscli update --all            # Update plugins
/opt/nessus/sbin/nessuscli fix --reset-all         # Reset config
/opt/nessus/sbin/nessuscli fix --list              # List settings

# Service management
systemctl start nessusd
systemctl stop nessusd
systemctl restart nessusd
systemctl status nessusd

NESSUS API#

# API base: https://NESSUS_IP:8834

# Authenticate
curl -k -X POST https://localhost:8834/session \
  -d '{"username":"admin","password":"pass"}'
# Returns: {"token":"SESSION_TOKEN"}

# List scans
curl -k -H "X-Cookie: token=TOKEN" \
  https://localhost:8834/scans

# Launch scan
curl -k -X POST -H "X-Cookie: token=TOKEN" \
  https://localhost:8834/scans/SCAN_ID/launch

# Get scan results
curl -k -H "X-Cookie: token=TOKEN" \
  https://localhost:8834/scans/SCAN_ID

# Export scan report
curl -k -X POST -H "X-Cookie: token=TOKEN" \
  -d '{"format":"nessus"}' \
  https://localhost:8834/scans/SCAN_ID/export
# Formats: nessus, csv, html, pdf

# Download export
curl -k -H "X-Cookie: token=TOKEN" \
  https://localhost:8834/scans/SCAN_ID/export/FILE_ID/download \
  -o report.nessus

# Create scan
curl -k -X POST -H "X-Cookie: token=TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"uuid":"TEMPLATE_UUID","settings":{"name":"My Scan","text_targets":"10.10.10.0/24"}}' \
  https://localhost:8834/scans

NESSUS AUTOMATION (PYTHON)#

# pyTenable library
pip install pytenable

from tenable.nessus import Nessus

nessus = Nessus('https://localhost:8834',
                access_key='ACCESS_KEY',
                secret_key='SECRET_KEY')

# List scans
for scan in nessus.scans.list():
    print(f"{scan['id']}: {scan['name']}")

# Launch scan
nessus.scans.launch(scan_id)

# Export results
with open('report.nessus', 'wb') as f:
    nessus.scans.export(scan_id, fobj=f)

========================================================================

OPENVAS / GREENBONE ADVANCED#


    

GVM ARCHITECTURE#

# Greenbone Vulnerability Management (GVM) stack:
  gvmd            # Greenbone Vulnerability Manager daemon
  ospd-openvas    # OSP scanner wrapper for OpenVAS
  openvas         # Scanner engine
  gsad            # Greenbone Security Assistant (web UI)
  gvm-tools       # CLI and Python API tools
  notus-scanner   # Local security check scanner
  pg-gvm          # PostgreSQL extension

GVM-CLI COMMANDS#

# Install gvm-tools
pip install gvm-tools

# Connect via Unix socket
gvm-cli socket --gmp-username admin --gmp-password pass \
  --xml '<get_version/>'

# Connect via TLS
gvm-cli tls --hostname localhost --port 9390 \
  --gmp-username admin --gmp-password pass \
  --xml '<get_version/>'

# List targets
gvm-cli socket --gmp-username admin --gmp-password pass \
  --xml '<get_targets/>'

# List tasks (scans)
gvm-cli socket --gmp-username admin --gmp-password pass \
  --xml '<get_tasks/>'

# Get results
gvm-cli socket --gmp-username admin --gmp-password pass \
  --xml '<get_results task_id="TASK_UUID"/>'

GVM PYTHON API#

from gvm.connections import UnixSocketConnection
from gvm.protocols.gmp import Gmp
from gvm.transforms import EtreeTransform

connection = UnixSocketConnection()
transform = EtreeTransform()

with Gmp(connection, transform=transform) as gmp:
    gmp.authenticate('admin', 'password')

    # Get version
    version = gmp.get_version()

    # Create target
    target = gmp.create_target(
        name='My Target',
        hosts=['10.10.10.0/24'],
        port_list_id='PORT_LIST_UUID'
    )

    # Create task
    task = gmp.create_task(
        name='Full Scan',
        config_id='CONFIG_UUID',       # Scan config
        target_id=target.get('id'),
        scanner_id='SCANNER_UUID'
    )

    # Start task
    gmp.start_task(task.get('id'))

    # Get results
    results = gmp.get_results()

SCAN CONFIGS#

# Built-in configs:
  Discovery                 # Host/service discovery only
  Full and fast             # Most NVTs, optimized (recommended)
  Full and fast ultimate    # All NVTs including destructive
  Full and very deep        # Slow, thorough, all ports
  Full and very deep ult.   # Everything including DoS
  Host Discovery            # Ping/ARP discovery only
  System Discovery          # OS and service detection

# Custom config:
  1. Configuration > Scan Configs > New
  2. Base on existing config
  3. Edit NVT families (enable/disable)
  4. Tune preferences per NVT

CREDENTIALED SCANNING (OPENVAS)#

# SSH credentials
  Credentials > New Credential
  Type: Username + Password (or SSH key)
  Login: root
  Password: or upload private key

# SMB credentials
  Type: Username + Password
  Login: DOMAIN\admin
  Password: P@ssw0rd

# Assign to target
  Configuration > Targets > Edit
  SSH Credential: select
  SMB Credential: select

COMPLIANCE AUDITING#

# Both Nessus and OpenVAS support:
  - CIS Benchmarks (Windows, Linux, etc.)
  - DISA STIGs
  - PCI DSS
  - HIPAA
  - SOX compliance checks

# Nessus: use Compliance templates
# OpenVAS: use Policy compliance NVT families

REPORT FORMATS#

# Nessus: HTML, PDF, CSV, Nessus XML
# OpenVAS: HTML, PDF, CSV, XML, LaTeX, TXT, Anonymous XML

# Export via API for integration with:
  - DefectDojo (vulnerability management)
  - Faraday (collaborative pentest)
  - Splunk/ELK (SIEM integration)
  - Jira (ticket creation)

PERFORMANCE TUNING#

# Nessus
  - Reduce concurrent hosts for large scans
  - Use port lists instead of 1-65535
  - Schedule scans during off-hours
  - Use agent-based scanning for remote assets

# OpenVAS
  - Tune max_hosts and max_checks in openvas.conf
  - Use dedicated scan server for large networks
  - PostgreSQL tuning for large result sets
  - Feed sync: greenbone-feed-sync

TIPS#

  - Credentialed scans find 10x more vulnerabilities
  - Always test credentials before full scan
  - Use agent-based scanning for remote/mobile assets
  - Schedule scans to avoid production impact
  - Compare scan results over time for trending
  - Export to CSV for custom analysis
  - Nessus .nessus files can be parsed with Python/XML tools
  - OpenVAS is free but requires more setup than Nessus
  - Use pyTenable/gvm-tools for automation
  - Disable DoS plugins for production environments