Nessus Guide Tutorial
Nessus Guide Tutorial
Introduction 3
Get Started 4
Navigate Nessus 9
Settings 10
Scans 11
Create a Scan 12
Scan Templates 13
Scan Results 17
View Vulnerabilities 18
Conclusion 22
References 23
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their -2-
respective owners.
Introduction
Congratulations on starting your trial of Nessus Professional, the de-facto industry standard vul-
nerability assessment solution for security practitioners! Nessus Professional is the most com-
prehensive vulnerability assessment solution on the market today, designed to simplify assessments,
save time, and provide accurate visibility into your networks.
This guide will assist you to ensure you get the most out of your trial. This guide is intended to be a
starting point as you familiarize yourself with the interface, features, and capabilities of Nessus Pro-
fessional. For an in-depth guide into all the options available in Nessus Professional, see the full Nes-
sus User Guide.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their -3-
respective owners.
Get Started
Trial Email
After signing up for a Nessus trial, you should receive an email with instructions for how to activate
your Tenable Community account. You will be prompted to create a log-in password and start your
trial.
If you have already successfully activated your Tenable Community account, you can navigate to your
Nessus trial management page. You should see your license key, as well as a link to Download Nes-
sus to Start Trial.
There is a single Nessus package per operating system and processor. Download the appropriate pack-
age for your operating system.
Nessus-<version number>- Nessus <version number> for Windows Server 2008, Server 2008
x64.msi R2*, Server 2012, Server 2012 R2, 7, 8, and 10 - x86-64
Nessus-<version number>- Nessus <version number> for Debian 6 and 7 / Kali Linux - AMD64
debian6_amd64.deb
Nessus-<version num- Nessus <version number> for Mac OS X 10.8, 10.9, and 10.10 - x86-
ber>.dmg 64
Nessus-<version number>- Nessus <version number> for Red Hat ES 6 / CentOS 6 / Oracle
es6.i386.rpm Linux 6 (including Unbreakable Enterprise Kernel) - i386
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their -4-
respective owners.
Nessus Packages Package Descriptions
Nessus-<version number>- Nessus <version number> for SUSE 10.0 Enterprise - x86_64
suse10.x86_64.rpm
Nessus-<version number>- Nessus <version number> for Ubuntu 11.10, 12.04, 12.10, 13.04,
ubuntu1110_amd64.deb 13.10, and 14.04 - AMD64
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their -5-
respective owners.
Install and Configure Nessus
Install Nessus
For information on requirements to install Nessus, see the following topics in the Nessus User Guide:
l Hardware Requirements
l Software Requirements
For instructions, see the Appendix in this document or see the Installation topics in the Nessus User
Guide.
Configure Nessus
To configure Nessus:
2. Click Continue.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their -6-
respective owners.
3. Type your Activation Code.
4. Click Continue.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their -7-
respective owners.
5. Create a Nessus administrator user account that you use to log in to Nessus:
6. Click Submit.
Nessus finishes the configuration process, which may take several minutes.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their -8-
respective owners.
Navigate Nessus
The top navigation bar displays links to the two main pages: Scans and Settings. You can perform all
Nessus primary tasks using these two pages. Click a page name to open the corresponding page.
Item Description
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their -9-
respective owners.
Settings
The Settings page contains the information and settings related to your Nessus installation and
license.
For the purposes of your trial, you can leave most settings at their default value.
l View information such as the license expiration date and software version.
l (Optional) Configure proxy settings if you skipped it during initial configuration or need to
change the settings.
For more information on configuring settings, see Settings in the Nessus User Guide.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 10 -
respective owners.
Scans
On the Scans page, you can create, view, and manage scans and resources.
To access the Scans page, in the top navigation bar, click Scans. The left navigation bar displays the
Folders and Resources sections.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 11 -
respective owners.
Create a Scan
5. If you want to launch the scan later, click the Save button.
-or-
If you want to launch the scan immediately, click the button, and then click Launch.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 12 -
respective owners.
Scan Templates
The Nessus interface provides brief explanations of each template in the product. Some templates may
not be available during a trial and are available when you purchase a fully-licensed copy of Nessus Pro-
fessional. To see a full list of the types of templates that are available in Nessus, see Scan and Policy
Templates in the Nessus User Guide.
The template you choose determines what settings are configurable and how they can be set. For a
detailed explanation of scan settings, refer to Scan and Policy Settings in the Nessus User Guide.
A policy is a set of predefined configuration options related to performing a scan. After you create a
policy, you can select it as a template in the User Defined tab when you create a scan. For more inform-
ation, see Create a Policy in the Nessus User Guide.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 13 -
respective owners.
Example: Configure a Basic Network Scan
For your trial period, Tenable recommends using the Basic Network Scan template. This template
has several default settings preconfigured, which allows you to quickly perform your first scan and
view results without a lot of effort. This example walks you through configuring a basic network scan.
Setting Description
Name The name of the scan or policy. The name appears in the Nessus interface.
Folder The folder where the scan appears after you save it.
Targets Specifies one or more targets to be scanned. If you select a target group or
upload a targets file, you are not required to specify additional targets.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 14 -
respective owners.
Note: For your trial period, you can scan up to 32 targets total. A fully-
licensed installation of Nessus Professional allows you to scan an unlimited
number of targets.
Although you can leave the remaining settings at their preconfigured defaults, Tenable recom-
mends reviewing the Discovery, Assessment, Report, and Advanced settings to ensure that
they are appropriate for your environment.
For more information, see the Scan Settings documentation in the Nessus User Guide.
3. (Optional) Configure credentials.
This allows credentialed scans to run, which can result in much more complete results and a
more thorough evaluation of the vulnerabilities in your environment.
4. Launch scan.
After you have configured all your settings, save and launch the scan.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 15 -
respective owners.
The time it takes to complete a scan involves many factors such as network speed and con-
gestion, so the scan may take some time to run.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 16 -
respective owners.
Scan Results
You can view scan results to help you understand your organization’s security posture and vul-
nerabilities. Color-coded indicators and customizable viewing options allow you to customize how you
view your scan’s data.
Page Description
Remediations If the scan's results include Remediation information, this list displays sug-
gested remediations that address the highest number of vulnerabilities.
Notes Displays additional information about the scan and the scan’s results.
History Displays a listing of scans: Start Time, End Time, and the Scan Statuses.
Viewing scan results by vulnerabilities gives you a view into potential risks on your assets.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 17 -
respective owners.
View Vulnerabilities
You can view vulnerabilities found by a scan, or vulnerabilities found on a specific host by a scan.
When you drill down on a vulnerability, you can view information such as plugin details, description,
solution, output, risk information, vulnerability information, and reference information.
To view vulnerabilities:
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 18 -
respective owners.
l Click a specific host to view vulnerabilities found on that host.
4. (Optional) To sort the vulnerabilities, click an attribute in the table header row to sort by that
attribute.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 19 -
respective owners.
Create a Scan Report
You can create a scan report to help you analyze the vulnerabilities and suggested remediations on
affected hosts. You can create a scan report in PDF, HTML, or CSV format, and customize it to contain
only certain information.
When you create a scan report, it includes the results that are currently visible on your scan results
page. You can also select certain hosts or vulnerabilities to further narrow your report.
To export a scan in Nessus or Nessus DB format, which allows you to import the scan into another Nes-
sus instance or Tenable product, see Export a Scan in the Nessus User Guide.
2. Click a scan.
The scan's results page appears.
3. (Optional) To create a scan report that includes specific scan results, do the following:
l Search to narrow your scan results.
5. From the drop-down box, select the format in which you want to export the scan results.
CSV
a. Select the check boxes for the columns you want to appear in the CSV report.
Note: To select all columns, click Select All. To clear all columns, click Clear. To reset
columns to the system default, click System.
b. (Optional) To save your current configuration as the default for CSV reports, select the
Save as default check box.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 20 -
respective owners.
Nessus creates the scan report.
HTML or PDF
Do one of the following:
a. Select Custom.
c. (Optional) To save your current configuration as the default for HTML reports, select
the Save as default check box.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 21 -
respective owners.
Conclusion
By following these simple steps, you now have a foundation to begin your exploration into Nessus Pro-
fessional. Trusted by millions of security professionals worldwide, Nessus Professional is the
industry’s most widely deployed vulnerability assessment solution.
To continue scanning after your trial period ends and unlock additional features, purchase a Nessus
Professional license. You can buy from your Tenable Community account page, or through a Tenable
partner.
Purchasing directly from your Tenable Community page unlocks your current build to a 365-day, full
license subscription with no need to obtain another activation code.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 22 -
respective owners.
References
l Nessus Documentation
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 23 -
respective owners.
Appendix: Installation Procedures
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 24 -
respective owners.
Install Nessus on Linux
Debian version 6
# dpkg -i Nessus-<version number>-debian6_amd64.deb
FreeBSD version 10
# pkg add Nessus-<version number>-fbsd10-amd64.txz
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 25 -
respective owners.
Install Nessus on Mac OS X
Introduction
The Welcome to the Tenable, Inc. Nessus Server Installer window provides general information
about the Nessus installation.
License
1. On the Software License Agreement screen, read the terms of the Tenable, Inc. Nessus soft-
ware license and subscription agreement.
4. To continue installing Nessus, select the Agree button, otherwise, select the Disagree button to
quit and exit.
Installation Type
On the Standard Install on <DriveName> screen, choose one of the following options:
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 26 -
respective owners.
l Select the Change Install Location button.
l Select the Install button to continue using the default installation location.
Installation
When the Preparing for installation screen appears, you will be prompted for a username and pass-
word.
1. Enter the Name and Password of an administrator account or the root user account.
2. On the Ready to Install the Program screen, select the Install button.
Next, the Installing Tenable, Inc. Nessus screen will be displayed and a Status indication bar will
illustrate the remaining installation progress. The process may take several minutes.
Summary
When the installation is complete, the The installation was successful screen appears.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 27 -
respective owners.
Install Nessus on Windows
2. On the License Agreement screen, read the terms of the Tenable, Inc. Nessus software license
and subscription agreement.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 28 -
respective owners.
3. Select I accept the terms of the license agreement, then click Next.
4. On the Destination Folder screen, select the Next button to accept the default installation
folder. Otherwise, select the Change button to install Nessus to a different folder.
5. On the Ready to Install the Program screen, select the Install button.
The Installing Tenable, Inc. Nessus screen will be displayed and a Status indication bar will illus-
trate the installation progress. The process may take several minutes.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 29 -
respective owners.
1. On the Welcome to the WinPcap Setup Wizard screen, select the Next button.
2. On the WinPcap License Agreement screen, read the terms of the license agreement, and
then select the I Agree button to continue.
3. On the WinPcap Installation options screen, ensure that the Automatically start the WinP-
cap driver at boot time option is checked, and then select the Install button.
4. On the Completing the WinPcap Setup Wizard screen, select the Finish button.
TheTenable Nessus InstallShield Wizard Completed screen appears.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 30 -
respective owners.
After the InstallShield Wizard completes, the Welcome to Nessus page loads in your default
browser.
Copyright © 2019 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are
registered trademarks of Tenable, Inc.. Tenable.sc, Lumin, Assure, and the Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their - 31 -
respective owners.