Giter Site home page Giter Site logo

nessus-vulnerability-management's Introduction

Nessus Vulnerability Management

App logo

Overview

The Nessus Vulnerability Management project is designed to help identify and remediate security vulnerabilities in software and systems. This project uses the Nessus vulnerability scanner to scan for vulnerabilities, and provides tools and workflows for prioritizing and remediating those vulnerabilities.

What is Vulnerability Management?

Vulnerability management is a continuous, proactive, and often automated process that keeps your computer systems, networks, and enterprise applications safe from cyberattacks and data breaches.

Nessus Vulnerability Scanner

Nessus is a powerful vulnerability scanner that can identify security vulnerabilities in a variety of systems and software. Some of the key features of Nessus include:

  • High-speed asset discovery
  • Configuration auditing
  • Target profiling
  • Malware detection
  • Sensitive data discovery and more

Project Workflow

The project workflow for Nessus Vulnerability Management is as follows:

  1. Run Nessus scans to identify vulnerabilities in the target systems.
  2. Prioritize vulnerabilities based on severity and potential impact.
  3. Develop a remediation plan to address the most critical vulnerabilities first.
  4. Remediate vulnerabilities using appropriate tools and workflows.
  5. Re-scan to ensure that vulnerabilities have been remediated.

Using the Project

To use the Nessus Vulnerability Management project, follow these steps:

  1. Download and set up the Nessus tool.
  2. Configure the tool to scan the target systems.
  3. Run scans and review the results.
  4. Prioritize and remediate vulnerabilities using the tools and workflows provided in this project.

Steps of the Project

  1. Download and Install VMWare Player as a target system with Windows 10.
  2. Download and Install Nessus Essentials
  3. Ensure connectivity with VM. You can do that by pingcommand from your main machine. To find the VM's IP address, just use ipconfig command on the VM.
  4. Create a new scan in Nessus using VM's IP address.
  5. Inspect the first scan, w/o credentials

App logo

  1. Configure VM for Credentialed scans, by providing Nessus with our credentials.
  2. Inspect the second scan, with credentials. Now we can see, that scan with credentials can provide more information regarding the system's vulnerability.

App logo

  1. Install a deprecated Firefox on our VM. Every time software gets updated, hackers reverse engineer the patches and find what vulnerabilities have been eliminated with newer patches so that they can target computers with older software.
  2. Inspect scan results after installing deprecated Firefox.

App logo

  1. Remediate some vulnerabilities. Delete or update Firefox, and check for Windows updates.
  2. Once it's done, scan again and compare the results.

App logo

Conclusion

The Nessus Vulnerability Management project is an important tool for identifying and remediating security vulnerabilities in software and systems. By using this project, you can improve the security of your own systems and ensure that your organization is protected against potential security threats.

nessus-vulnerability-management's People

Contributors

stenone avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.