OPENVAS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
OpenVAS (Open Vulnerability Assessment Scanner) is a full-featured vulnerability scanner. Part of the Greenbone Vulnerability Management (GVM) framework, it uses a regularly updated feed of Network Vulnerability Tests (NVTs) with 50,000+ checks.
INSTALLATION#
# Kali Linux: sudo apt install openvas sudo gvm-setup # Initial setup sudo gvm-start # Start services # Check setup: sudo gvm-check-setup # Verify installation
WEB INTERFACE#
# Default URL: https://127.0.0.1:9392 # Default credentials set during gvm-setup # Change password after first login
CLI MANAGEMENT#
gvm-start # Start all GVM services gvm-stop # Stop all GVM services sudo greenbone-feed-sync # Update vulnerability feeds sudo gvm-check-setup # Verify installation # Service management: systemctl start ospd-openvas # Start scanner systemctl start gvmd # Start manager systemctl start gsad # Start web interface systemctl status gvmd # Check manager status
SCAN WORKFLOW (WEB UI)#
# 1. Create Target # Configuration → Targets → New Target # - Name, Host(s), Port List # - Credentials (optional, for authenticated scans) # 2. Create Task # Scans → Tasks → New Task # - Name, Target, Scanner, Scan Config # 3. Start Scan # Click play button on the task # Monitor progress in real-time # 4. View Results # Scans → Reports → Select report # Filter by severity, host, or vulnerability type
SCAN CONFIGURATIONS#
# Built-in scan configs: # Full and fast - Most common, good balance # Full and fast ultimate - Includes destructive tests # Full and deep - Thorough but slow # Full and deep ultimate - Most comprehensive # Host Discovery - Quick host/port discovery # System Discovery - OS and service detection
PORT LISTS#
# All IANA Assigned TCP - ~5000 ports # All IANA Assigned TCP and UDP - ~10000 ports # All TCP - Ports 1-65535 # All TCP and Nmap top 100 UDP - Comprehensive # OpenVAS Default - Top ~4500 ports
CREDENTIALS#
# Authenticated scans provide deeper results: # SSH credentials - Linux/Unix authenticated scanning # SMB credentials - Windows authenticated scanning # ESXi credentials - VMware scanning # SNMP credentials - Network device scanning # Database - Database-specific checks
SEVERITY LEVELS#
# Critical (CVSS 9.0-10.0) - Immediate remediation # High (CVSS 7.0-8.9) - Urgent remediation # Medium (CVSS 4.0-6.9) - Planned remediation # Low (CVSS 0.1-3.9) - Risk acceptance possible # Log (CVSS 0.0) - Informational
FILTERS & OVERRIDES#
# Filters: Customize report views # - Severity ranges # - Host groups # - Vulnerability categories # - QoD (Quality of Detection) # Overrides: Adjust severity for your environment # - False positive marking # - Custom severity adjustment # - Notes and justifications
SCHEDULING#
# Schedule recurring scans: # Configuration → Schedules → New Schedule # - First run date/time # - Recurrence (daily, weekly, monthly) # - Duration limit # - Timezone
REPORT FORMATS#
# Available export formats: # - PDF - Professional reports # - HTML - Web-viewable reports # - XML - Machine-readable # - CSV - Spreadsheet import # - ITG - IT-Grundschutz format # - TXT - Plain text # - Verinice - Compliance tool format
GMP CLI (ADVANCED)#
# GVM Management Protocol for automation: gvm-cli --gmp-username admin --gmp-password <pass> \ socket --socketpath /run/gvmd/gvmd.sock \ --xml "<get_tasks/>" # List tasks: gvm-cli ... --xml "<get_tasks/>" # Start scan: gvm-cli ... --xml '<start_task task_id="<uuid>"/>' # Get results: gvm-cli ... --xml '<get_results task_id="<uuid>"/>'
EXAMPLES#
# Quick unauthenticated scan: # 1. Targets → New: 192.168.1.0/24 # 2. Tasks → New: "Network Scan", Full and fast # 3. Start task # 4. Export PDF report # Authenticated Windows scan: # 1. Credentials → New: SMB, domain\admin # 2. Targets → New: Windows servers, with credential # 3. Tasks → New: Full and deep, with target # 4. Schedule weekly
TROUBLESHOOTING#
# Feed sync issues: sudo greenbone-feed-sync --type GVMD_DATA sudo greenbone-feed-sync --type SCAP sudo greenbone-feed-sync --type CERT # Service restart: sudo gvm-stop && sudo gvm-start # Check logs: tail -f /var/log/gvm/gvmd.log tail -f /var/log/gvm/openvas.log
NOTES#
- Free and open-source (GPLv2) - 50,000+ vulnerability tests - Regular feed updates required - Authenticated scans find more vulnerabilities - Initial feed sync can take hours - Resource intensive (recommend 4GB+ RAM) - Greenbone Enterprise available for commercial use - Pair with Metasploit for exploitation validation