NESSUS-ADVANCED
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Advanced vulnerability scanning with Nessus and OpenVAS/Greenbone. Covers credentialed scanning, policy tuning, API automation, and compliance auditing.
NESSUS ADVANCED#
SCAN POLICIES#
# Built-in templates Basic Network Scan # General-purpose Advanced Scan # Full control over settings Credentialed Patch Audit # Authenticated patch check Web Application Tests # Web app scanning PCI-DSS Quarterly Scan # PCI compliance SCADA # ICS/SCADA systems Malware Scan # Known malware detection Host Discovery # Network discovery only Internal PCI Network Scan # Internal PCI compliance
CREDENTIALED SCANNING#
# Windows (SMB) Authentication: Windows Username: domain\admin (or admin for local) Password: P@ssw0rd Domain: CORP (optional) # Enable: Remote Registry service must be running # Or: WMI access required # GPO: Computer Config > Admin Templates > Network > # Network Connections > Windows Defender Firewall > # Allow inbound remote administration exception # Linux (SSH) Authentication: SSH Username: root (or sudo user) Password: or SSH key file (.pem/.ppk) Elevate privileges with: sudo sudo user: username sudo password: password # SSH key auth (recommended) Upload private key file Passphrase if key is encrypted # Database scanning Oracle, SQL Server, MySQL, PostgreSQL Provide DB credentials in scan policy # VMware/ESXi Username: root Password: ESXi password Port: 443
ADVANCED SCAN SETTINGS#
# Discovery Ping Methods: ARP, TCP, ICMP, UDP Port Range: 1-65535 (or specific ports) Port Scanner: SYN, TCP, UDP Network Type: Private LAN, Mixed, Public WAN # Assessment Override normal accuracy: Enable Perform thorough tests: Enable (slower but more accurate) Scan for known web vulns: Enable Brute force credentials: Enable/Disable # Performance Max concurrent hosts: 30 (default) Max concurrent checks per host: 5 Network timeout: 5 seconds Max retries: 3 Reduce parallel connections on congestion: Enable Throttle scan on network congestion: Enable # Report Show missing patches that have been superseded: Enable Hide results from dead hosts: Enable
PLUGIN FAMILIES#
# Enable/disable by category CGI abuses # Web application vulns Databases # Database vulns Default Unix Accounts # Default cred checks Denial of Service # DoS checks (disable for production) Firewalls # Firewall config checks FTP # FTP vulnerabilities General # General checks Misc # Miscellaneous Netware # Novell checks Peer-To-Peer # P2P software SCADA # ICS/SCADA checks Service Detection # Service/version detection SMTP # Email server checks SNMP # SNMP checks Web Servers # Web server vulns Windows # Windows-specific checks Windows: Microsoft Bulletins # MS patch checks
NESSUS CLI (NASL)#
# nessuscli commands (run on Nessus server) /opt/nessus/sbin/nessuscli lsuser # List users /opt/nessus/sbin/nessuscli adduser admin # Add user /opt/nessus/sbin/nessuscli chpasswd admin # Change password /opt/nessus/sbin/nessuscli rmuser admin # Remove user /opt/nessus/sbin/nessuscli fetch --register XXXX # Register license /opt/nessus/sbin/nessuscli update --all # Update plugins /opt/nessus/sbin/nessuscli fix --reset-all # Reset config /opt/nessus/sbin/nessuscli fix --list # List settings # Service management systemctl start nessusd systemctl stop nessusd systemctl restart nessusd systemctl status nessusd
NESSUS API#
# API base: https://NESSUS_IP:8834
# Authenticate
curl -k -X POST https://localhost:8834/session \
-d '{"username":"admin","password":"pass"}'
# Returns: {"token":"SESSION_TOKEN"}
# List scans
curl -k -H "X-Cookie: token=TOKEN" \
https://localhost:8834/scans
# Launch scan
curl -k -X POST -H "X-Cookie: token=TOKEN" \
https://localhost:8834/scans/SCAN_ID/launch
# Get scan results
curl -k -H "X-Cookie: token=TOKEN" \
https://localhost:8834/scans/SCAN_ID
# Export scan report
curl -k -X POST -H "X-Cookie: token=TOKEN" \
-d '{"format":"nessus"}' \
https://localhost:8834/scans/SCAN_ID/export
# Formats: nessus, csv, html, pdf
# Download export
curl -k -H "X-Cookie: token=TOKEN" \
https://localhost:8834/scans/SCAN_ID/export/FILE_ID/download \
-o report.nessus
# Create scan
curl -k -X POST -H "X-Cookie: token=TOKEN" \
-H "Content-Type: application/json" \
-d '{"uuid":"TEMPLATE_UUID","settings":{"name":"My Scan","text_targets":"10.10.10.0/24"}}' \
https://localhost:8834/scans
NESSUS AUTOMATION (PYTHON)#
# pyTenable library
pip install pytenable
from tenable.nessus import Nessus
nessus = Nessus('https://localhost:8834',
access_key='ACCESS_KEY',
secret_key='SECRET_KEY')
# List scans
for scan in nessus.scans.list():
print(f"{scan['id']}: {scan['name']}")
# Launch scan
nessus.scans.launch(scan_id)
# Export results
with open('report.nessus', 'wb') as f:
nessus.scans.export(scan_id, fobj=f)
========================================================================
OPENVAS / GREENBONE ADVANCED#
GVM ARCHITECTURE#
# Greenbone Vulnerability Management (GVM) stack: gvmd # Greenbone Vulnerability Manager daemon ospd-openvas # OSP scanner wrapper for OpenVAS openvas # Scanner engine gsad # Greenbone Security Assistant (web UI) gvm-tools # CLI and Python API tools notus-scanner # Local security check scanner pg-gvm # PostgreSQL extension
GVM-CLI COMMANDS#
# Install gvm-tools pip install gvm-tools # Connect via Unix socket gvm-cli socket --gmp-username admin --gmp-password pass \ --xml '<get_version/>' # Connect via TLS gvm-cli tls --hostname localhost --port 9390 \ --gmp-username admin --gmp-password pass \ --xml '<get_version/>' # List targets gvm-cli socket --gmp-username admin --gmp-password pass \ --xml '<get_targets/>' # List tasks (scans) gvm-cli socket --gmp-username admin --gmp-password pass \ --xml '<get_tasks/>' # Get results gvm-cli socket --gmp-username admin --gmp-password pass \ --xml '<get_results task_id="TASK_UUID"/>'
GVM PYTHON API#
from gvm.connections import UnixSocketConnection
from gvm.protocols.gmp import Gmp
from gvm.transforms import EtreeTransform
connection = UnixSocketConnection()
transform = EtreeTransform()
with Gmp(connection, transform=transform) as gmp:
gmp.authenticate('admin', 'password')
# Get version
version = gmp.get_version()
# Create target
target = gmp.create_target(
name='My Target',
hosts=['10.10.10.0/24'],
port_list_id='PORT_LIST_UUID'
)
# Create task
task = gmp.create_task(
name='Full Scan',
config_id='CONFIG_UUID', # Scan config
target_id=target.get('id'),
scanner_id='SCANNER_UUID'
)
# Start task
gmp.start_task(task.get('id'))
# Get results
results = gmp.get_results()
SCAN CONFIGS#
# Built-in configs: Discovery # Host/service discovery only Full and fast # Most NVTs, optimized (recommended) Full and fast ultimate # All NVTs including destructive Full and very deep # Slow, thorough, all ports Full and very deep ult. # Everything including DoS Host Discovery # Ping/ARP discovery only System Discovery # OS and service detection # Custom config: 1. Configuration > Scan Configs > New 2. Base on existing config 3. Edit NVT families (enable/disable) 4. Tune preferences per NVT
CREDENTIALED SCANNING (OPENVAS)#
# SSH credentials Credentials > New Credential Type: Username + Password (or SSH key) Login: root Password: or upload private key # SMB credentials Type: Username + Password Login: DOMAIN\admin Password: P@ssw0rd # Assign to target Configuration > Targets > Edit SSH Credential: select SMB Credential: select
COMPLIANCE AUDITING#
# Both Nessus and OpenVAS support: - CIS Benchmarks (Windows, Linux, etc.) - DISA STIGs - PCI DSS - HIPAA - SOX compliance checks # Nessus: use Compliance templates # OpenVAS: use Policy compliance NVT families
REPORT FORMATS#
# Nessus: HTML, PDF, CSV, Nessus XML # OpenVAS: HTML, PDF, CSV, XML, LaTeX, TXT, Anonymous XML # Export via API for integration with: - DefectDojo (vulnerability management) - Faraday (collaborative pentest) - Splunk/ELK (SIEM integration) - Jira (ticket creation)
PERFORMANCE TUNING#
# Nessus - Reduce concurrent hosts for large scans - Use port lists instead of 1-65535 - Schedule scans during off-hours - Use agent-based scanning for remote assets # OpenVAS - Tune max_hosts and max_checks in openvas.conf - Use dedicated scan server for large networks - PostgreSQL tuning for large result sets - Feed sync: greenbone-feed-sync
TIPS#
- Credentialed scans find 10x more vulnerabilities - Always test credentials before full scan - Use agent-based scanning for remote/mobile assets - Schedule scans to avoid production impact - Compare scan results over time for trending - Export to CSV for custom analysis - Nessus .nessus files can be parsed with Python/XML tools - OpenVAS is free but requires more setup than Nessus - Use pyTenable/gvm-tools for automation - Disable DoS plugins for production environments