← All cheat sheets

OPENVAS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

OpenVAS (Open Vulnerability Assessment Scanner) is a full-featured
vulnerability scanner. Part of the Greenbone Vulnerability Management
(GVM) framework, it uses a regularly updated feed of Network
Vulnerability Tests (NVTs) with 50,000+ checks.

INSTALLATION#

# Kali Linux:
sudo apt install openvas
sudo gvm-setup                   # Initial setup
sudo gvm-start                   # Start services

# Check setup:
sudo gvm-check-setup             # Verify installation

WEB INTERFACE#

# Default URL: https://127.0.0.1:9392
# Default credentials set during gvm-setup
# Change password after first login

CLI MANAGEMENT#

gvm-start                        # Start all GVM services
gvm-stop                         # Stop all GVM services
sudo greenbone-feed-sync         # Update vulnerability feeds
sudo gvm-check-setup             # Verify installation

# Service management:
systemctl start ospd-openvas     # Start scanner
systemctl start gvmd             # Start manager
systemctl start gsad             # Start web interface
systemctl status gvmd            # Check manager status

SCAN WORKFLOW (WEB UI)#

# 1. Create Target
# Configuration → Targets → New Target
# - Name, Host(s), Port List
# - Credentials (optional, for authenticated scans)

# 2. Create Task
# Scans → Tasks → New Task
# - Name, Target, Scanner, Scan Config

# 3. Start Scan
# Click play button on the task
# Monitor progress in real-time

# 4. View Results
# Scans → Reports → Select report
# Filter by severity, host, or vulnerability type

SCAN CONFIGURATIONS#

# Built-in scan configs:
# Full and fast          - Most common, good balance
# Full and fast ultimate - Includes destructive tests
# Full and deep          - Thorough but slow
# Full and deep ultimate - Most comprehensive
# Host Discovery         - Quick host/port discovery
# System Discovery       - OS and service detection

PORT LISTS#

# All IANA Assigned TCP         - ~5000 ports
# All IANA Assigned TCP and UDP - ~10000 ports
# All TCP                       - Ports 1-65535
# All TCP and Nmap top 100 UDP  - Comprehensive
# OpenVAS Default               - Top ~4500 ports

CREDENTIALS#

# Authenticated scans provide deeper results:
# SSH credentials   - Linux/Unix authenticated scanning
# SMB credentials   - Windows authenticated scanning
# ESXi credentials  - VMware scanning
# SNMP credentials  - Network device scanning
# Database          - Database-specific checks

SEVERITY LEVELS#

# Critical  (CVSS 9.0-10.0)  - Immediate remediation
# High      (CVSS 7.0-8.9)   - Urgent remediation
# Medium    (CVSS 4.0-6.9)    - Planned remediation
# Low       (CVSS 0.1-3.9)    - Risk acceptance possible
# Log       (CVSS 0.0)        - Informational

FILTERS & OVERRIDES#

# Filters: Customize report views
# - Severity ranges
# - Host groups
# - Vulnerability categories
# - QoD (Quality of Detection)

# Overrides: Adjust severity for your environment
# - False positive marking
# - Custom severity adjustment
# - Notes and justifications

SCHEDULING#

# Schedule recurring scans:
# Configuration → Schedules → New Schedule
# - First run date/time
# - Recurrence (daily, weekly, monthly)
# - Duration limit
# - Timezone

REPORT FORMATS#

# Available export formats:
# - PDF         - Professional reports
# - HTML        - Web-viewable reports
# - XML         - Machine-readable
# - CSV         - Spreadsheet import
# - ITG         - IT-Grundschutz format
# - TXT         - Plain text
# - Verinice    - Compliance tool format

GMP CLI (ADVANCED)#

# GVM Management Protocol for automation:
gvm-cli --gmp-username admin --gmp-password <pass> \
  socket --socketpath /run/gvmd/gvmd.sock \
  --xml "<get_tasks/>"

# List tasks:
gvm-cli ... --xml "<get_tasks/>"

# Start scan:
gvm-cli ... --xml '<start_task task_id="<uuid>"/>'

# Get results:
gvm-cli ... --xml '<get_results task_id="<uuid>"/>'

EXAMPLES#

# Quick unauthenticated scan:
# 1. Targets → New: 192.168.1.0/24
# 2. Tasks → New: "Network Scan", Full and fast
# 3. Start task
# 4. Export PDF report

# Authenticated Windows scan:
# 1. Credentials → New: SMB, domain\admin
# 2. Targets → New: Windows servers, with credential
# 3. Tasks → New: Full and deep, with target
# 4. Schedule weekly

TROUBLESHOOTING#

# Feed sync issues:
sudo greenbone-feed-sync --type GVMD_DATA
sudo greenbone-feed-sync --type SCAP
sudo greenbone-feed-sync --type CERT

# Service restart:
sudo gvm-stop && sudo gvm-start

# Check logs:
tail -f /var/log/gvm/gvmd.log
tail -f /var/log/gvm/openvas.log

NOTES#

- Free and open-source (GPLv2)
- 50,000+ vulnerability tests
- Regular feed updates required
- Authenticated scans find more vulnerabilities
- Initial feed sync can take hours
- Resource intensive (recommend 4GB+ RAM)
- Greenbone Enterprise available for commercial use
- Pair with Metasploit for exploitation validation