Best FREE Vulnerability Scanner: Nessus Vs OpenVAS (Greenbone)

preview_player
Показать описание
Hackers are experts at finding gaps in your security, but what if you could find them first? This is what vulnerability scanners do. They automatically scan your devices and find the weaknesses that hackers might try to exploit.
Two of the most well-respected vulnerability scanners are Tenable's Nessus and OpenVAS aka Greenbone Vulnerability Management. Both of them have free versions, but which is the best?

💬 *Follow* *Me*

🌐 Nessus Essentials

🌐 Greenbone Enterprise Trial (OpenVAS)

Kali Linux (for Greenbone Source/Community Edition)

Video timestamps:
0:00 - Vulnerability Scanners, Patch Scanners, and Penetration Tests
2:06 - Tenable Nessus, Greenbone OpenVAS, and Competitors
3:05 - Free Version Limitations
6:29 - User Experience Comparison
7:26 - Detecting Vulnerabilites in Unsupported Software
9:53 - Detecting Insecure Configurations: Test Setup
14:17 - Detecting Insecure Configurations: Results
18:54 - Conclusion

#CyberSecurity #Nessus #OpenVAS #Greenbone #VulnerabilityScanner
Рекомендации по теме
Комментарии
Автор

Well Nessus can also do Web Application Tests and OpenVAS is just a vunrability scanner, so we have to add that into the picture as Nessus even can log into the web app using web form or basic authentication. I am not saying that OpenVAS is bad but it depends if you just need a vunrability scanner or also to test a web application.

Nikoolayy
Автор

Deeper dive into a framework that can help less experienced individuals understand findings -Your review in plain language really helped understand me understand some common detections

rdladr
Автор

I'm curious about your scan approach. I don't have Nessus, but with GVM/openvas, you have two scan approaches: Outside scan, Internal System scan. The outside scan, meaning being outside the host and scanning for vulnerabilities and the Internal System scan being one where you setup a Root user, pass the access to GVM and it logs in to the system to find libraries installed and their current vulnerability status (any CVE's listed on them.) From the penetration tester/red team point of view, you're taking on the role of an outsider, seeing what's open, what's broadcasting, etc. From a Blue Team perspective, you probably want to know what libraries are out of date, what CVEs are reported for what is running and installed on the system. A scan of the system, as root, is preferable to finding these issues. In GVM setting up that Root scan is not simple and isn't the default, but when done it is the most powerful aspect of GVM (imo).

ffeorg
Автор

Excellent overview. Thank you for such an in-depth review.

john.walley
Автор

This explanation is just a masterpiece, really helpful!

MochAzkal
Автор

Great video! Many thanks for making it. I especially appreciated that you included info on false positives and gave a brief description on some of the findings. Just wondering if you know of any good resource online that breaks down the Nessus scan finding better than what is provided by Nessus. Basically a better description of the configuration-type issues found and remediation advice etc?

VideoGigs
Автор

i tried the nessus essentials solution, but whenever i try to go to the 'credentials' tab to configure an authenticated scan it never loads. the result is that i can't do an authenticated scan and only detect external facing vulnerabilities. has anyone else experienced this?

denson
Автор

The reason Nessus is still ahead is the greenbone ui is so freaking ugly and not at all intuitive. Change that horrible ui and you might make great strides

xelerated
Автор

Could make a video on Windows Server hardening tutorial? And also Ubuntu/CentOS if you will. Thanks.

rafaelhengky
Автор

Where can I find the video mentioned at 19:29?

ruipereira-cihm
Автор

How about the docker version? " mikesplain/openvas "

aprendainformaticagratis
Автор

Wait - Nessus are doing a free version limited at 16 hosts again?

grover-
Автор

I wonder how Wazuh would do in this scenario. It might be a little overkill though.

leek
Автор

Hi there, Awesome work, Im a student in Cyber but I can learn much more from you. Do you have any mentor programs I can pay you for to teach me? I want to download videos so I can put on a USB to watch when I want, Can you help me out with a wat to accomplish this? ethecal hacking is what im trying to sprcialize in with mobile forensics? THanks Jay hope to hear from you. thanks you

JAYSF
Автор

You're not listened to - from around min 5:00 you are getting lost in too many details - you're video seems to be made for a noob, but one needs to be a pentester to actually understand what the heck you are talking about. And a pentester knows already ...

sintaklaas
Автор

Lol both of these are paid not, and none of them have a free version

zeprii