image1
image2

An open-source framework of several services and tools offering vulnerability scanning and vulnerability management.

I don't want to read all that. Show me tests!

What is OpenVAS?

OpenVAS stands as a comprehensive vulnerability scanning tool offering both unauthenticated and authenticated testing, along with support for a wide array of internet and industrial protocols. It is designed to handle large-scale scans efficiently and features an advanced internal scripting language for crafting custom vulnerability tests. The vulnerability tests, sourced from a feed with a longstanding history of daily updates, enable the scanner to detect a range of security weaknesses.

Since its inception in 2006, OpenVAS has been actively developed by Greenbone. It is an integral component of the Greenbone Enterprise Appliance—a commercial suite for vulnerability management. Within this suite, OpenVAS joins with other open-source modules to constitute the Greenbone Community Edition.

Range of functions

User-friendliness

What OpenVAS is missing?

OpenVAS is a comprehensive open-source vulnerability scanner, notable for its depth of scanning capabilities. However, it may present challenges for some users and organizations. Its user interface, while fully functional, lacks the polished ease of commercial alternatives, potentially steepening the learning curve. Technical proficiency is needed for setup and maintenance, as commercial support is absent, with reliance instead on community-driven assistance. The plug-in database is expansive, yet it may not be as current as those from proprietary tools with dedicated teams. OpenVAS's less commercial nature might affect its adoption in organizations that favor established brand recognition, especially where compliance is concerned. While OpenVAS offers a wide array of features, it might not match the cutting-edge analytics and user management features of paid solutions. It could underperform in large network environments and may require extra steps to optimize for high-volume scans. OpenVAS's detection accuracy is generally reliable, but users may encounter a higher rate of false positives, (as reported in some articles and posts) increasing the workload for security teams. Integrating OpenVAS with other tools is feasible but not always straightforward, lacking the plug-and-play integration of its commercial counterparts.

“In theory... but is it ? Let's TEST it!”

Nessus in practice

Review

User-friendliness:

Installation and setup: Error feedback:

Conclusions

In Theory OpenVAS is very promising but it fell completely flat when we tried to run it. We've tried multiple troubleshooting steps and a different VM, which yield the same results.

Where to get OpenVAS?

Official documentation: Link