OpenVAS Best Practices for Vulnerability Assessment: Setup, Scanning and Reporting
OpenVAS is a robust and open-source tool for performing vulnerability assessments in networks and systems. With its extensive NVT database, customizable scanning options, and credentialed scanning features, OpenVAS is ideal for ethical hackers and cybersecurity professionals. By following best practices, such as regularly updating the NVT database, prioritizing vulnerabilities based on severity, and integrating OpenVAS with other security tools, professionals can ensure a thorough and effective vulnerability assessment process to protect against cyber threats.
Quick answer: OpenVAS is an open-source vulnerability scanner, now the scanner component of the Greenbone Vulnerability Management (GVM) framework. Best practice is to get written authorisation, define scope, update feeds, run credentialed scans on lab or approved targets, validate findings manually, prioritise by risk and re-scan after fixes.
Key takeaways
- OpenVAS began as a fork of the Nessus code base after Nessus became closed source. It is now maintained by Greenbone as part of GVM.
- The free Greenbone Community Edition uses a community feed. Greenbone also sells commercial products, so check what each includes.
- Credentialed scans give far better results than unauthenticated ones.
- Always validate: scanners create false positives and miss logic flaws.
- Scan only authorised targets, in agreed windows, with rate limits suitable for fragile systems.
What is OpenVAS?
OpenVAS (Open Vulnerability Assessment Scanner) is an open-source network vulnerability scanner. It started as a fork of the Nessus engine in 2005, after Nessus became proprietary software, and is now developed by Greenbone as part of the Greenbone Vulnerability Management (GVM) stack. GVM includes the scanner, a manager, a web interface (Greenbone Security Assistant) and a feed of vulnerability tests. Official documentation is at Greenbone docs.
The original version of this post said OpenVAS began as a fork of GNATS. That is incorrect.
Is OpenVAS free?
The open-source components and the Greenbone Community Edition are free to use. Greenbone also offers commercial products and a commercial feed. Check Greenbone's current documentation to see which feed and features apply to you.
How is OpenVAS different from Nessus?
| OpenVAS / GVM | Nessus | |
|---|---|---|
| Licence | Open-source components, free community edition | Commercial (Tenable), with limited free options |
| Interface | Greenbone Security Assistant (web) | Web interface |
| Support | Community and Greenbone | Vendor support |
| Strength | No licence cost, good for learning and many internal scans | Mature polish and vendor backing |
Both are valid tools, and the skill is in using them well. Compare with our Nessus overview.
How do you install OpenVAS on Kali Linux?
On Kali the packages are provided as gvm. Use a lab VM. The commands below follow the Kali documentation at the time of writing; check the Kali docs for current steps.
sudo apt update
sudo apt install gvm
sudo gvm-setup # downloads feeds, creates admin user (takes a while)
sudo gvm-check-setup # confirms the setup is complete
sudo gvm-start # starts the services
Open the web interface at https://127.0.0.1:9392 and sign in with the admin account created during setup. Keep the feed updated before each scan, because new tests are added regularly.
How do you run a scan step by step?
- Scope and authorisation. Write down targets, windows, exclusions and a contact. Scanning without permission is an offence under India's IT Act.
- Create a target. Enter an IP or range. For practice use a Metasploitable VM on a host-only network.
- Add credentials (SSH or SMB) for authenticated checks if the system is yours to log into.
- Choose a scan configuration. Start with a standard full and fast configuration. Use gentler settings for production or fragile devices.
- Create a task and start it. Monitor the progress and the load on the target.
- Review the report. Filter by severity and sort by quality of detection.
What are the best practices?
- Update feeds first, so results reflect current vulnerabilities.
- Prefer credentialed scans. They see installed packages and configuration, so there are fewer false positives and fewer misses.
- Tune the scan to the target. Rate limits and timing matter for old devices, embedded systems and busy production servers.
- Use overrides for confirmed false positives and record the reason, so they do not reappear each month.
- Validate before reporting. Reproduce critical findings with a second method.
- Prioritise using context. Combine severity (CVSS) with exposure, exploitability and business value.
- Schedule recurring scans and compare results over time to show fixes.
- Re-scan after remediation to prove closure.
- Protect the results. Reports list weaknesses, so treat them as sensitive.
How should you read and report results?
Each result shows a severity, a detection quality, affected host and port, a description and a solution. Group findings by remediation (for example "patch OpenSSH"), not as a raw list. A useful report has an executive summary, scope and method, top risks, grouped remediation and a note of what was not tested. CVE identifiers can be checked at the National Vulnerability Database.
What are the limits?
OpenVAS finds known vulnerabilities through tests. It does not find unknown flaws, most business logic problems, or issues in custom web applications. It can also disturb fragile systems if configured aggressively. For web applications use a proxy such as Burp Suite or OWASP ZAP in addition. See vulnerability scanning tool interview questions.
Next steps
Practise with a guided lab in WebAsha's VAPT course. For interview preparation, see VAPT tool proficiency interview questions.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0