OpenVAS Best Practices for Vulnerability Assessment: Setup, Scanning and Reporting

OpenVAS is a robust and open-source tool for performing vulnerability assessments in networks and systems. With its extensive NVT database, customizable scanning options, and credentialed scanning features, OpenVAS is ideal for ethical hackers and cybersecurity professionals. By following best practices, such as regularly updating the NVT database, prioritizing vulnerabilities based on severity, and integrating OpenVAS with other security tools, professionals can ensure a thorough and effective vulnerability assessment process to protect against cyber threats.

Dec 23, 2024 - 13:55
Updated: 8 days ago
108.4k
OpenVAS Best Practices for Vulnerability Assessment: Setup, Scanning and Reporting

Quick answer: OpenVAS is an open-source vulnerability scanner, now the scanner component of the Greenbone Vulnerability Management (GVM) framework. Best practice is to get written authorisation, define scope, update feeds, run credentialed scans on lab or approved targets, validate findings manually, prioritise by risk and re-scan after fixes.

Key takeaways

  • OpenVAS began as a fork of the Nessus code base after Nessus became closed source. It is now maintained by Greenbone as part of GVM.
  • The free Greenbone Community Edition uses a community feed. Greenbone also sells commercial products, so check what each includes.
  • Credentialed scans give far better results than unauthenticated ones.
  • Always validate: scanners create false positives and miss logic flaws.
  • Scan only authorised targets, in agreed windows, with rate limits suitable for fragile systems.

What is OpenVAS?

OpenVAS (Open Vulnerability Assessment Scanner) is an open-source network vulnerability scanner. It started as a fork of the Nessus engine in 2005, after Nessus became proprietary software, and is now developed by Greenbone as part of the Greenbone Vulnerability Management (GVM) stack. GVM includes the scanner, a manager, a web interface (Greenbone Security Assistant) and a feed of vulnerability tests. Official documentation is at Greenbone docs.

The original version of this post said OpenVAS began as a fork of GNATS. That is incorrect.

Is OpenVAS free?

The open-source components and the Greenbone Community Edition are free to use. Greenbone also offers commercial products and a commercial feed. Check Greenbone's current documentation to see which feed and features apply to you.

How is OpenVAS different from Nessus?

OpenVAS / GVMNessus
LicenceOpen-source components, free community editionCommercial (Tenable), with limited free options
InterfaceGreenbone Security Assistant (web)Web interface
SupportCommunity and GreenboneVendor support
StrengthNo licence cost, good for learning and many internal scansMature polish and vendor backing

Both are valid tools, and the skill is in using them well. Compare with our Nessus overview.

How do you install OpenVAS on Kali Linux?

On Kali the packages are provided as gvm. Use a lab VM. The commands below follow the Kali documentation at the time of writing; check the Kali docs for current steps.

sudo apt update
sudo apt install gvm
sudo gvm-setup # downloads feeds, creates admin user (takes a while)
sudo gvm-check-setup # confirms the setup is complete
sudo gvm-start # starts the services

Open the web interface at https://127.0.0.1:9392 and sign in with the admin account created during setup. Keep the feed updated before each scan, because new tests are added regularly.

How do you run a scan step by step?

  1. Scope and authorisation. Write down targets, windows, exclusions and a contact. Scanning without permission is an offence under India's IT Act.
  2. Create a target. Enter an IP or range. For practice use a Metasploitable VM on a host-only network.
  3. Add credentials (SSH or SMB) for authenticated checks if the system is yours to log into.
  4. Choose a scan configuration. Start with a standard full and fast configuration. Use gentler settings for production or fragile devices.
  5. Create a task and start it. Monitor the progress and the load on the target.
  6. Review the report. Filter by severity and sort by quality of detection.

What are the best practices?

  • Update feeds first, so results reflect current vulnerabilities.
  • Prefer credentialed scans. They see installed packages and configuration, so there are fewer false positives and fewer misses.
  • Tune the scan to the target. Rate limits and timing matter for old devices, embedded systems and busy production servers.
  • Use overrides for confirmed false positives and record the reason, so they do not reappear each month.
  • Validate before reporting. Reproduce critical findings with a second method.
  • Prioritise using context. Combine severity (CVSS) with exposure, exploitability and business value.
  • Schedule recurring scans and compare results over time to show fixes.
  • Re-scan after remediation to prove closure.
  • Protect the results. Reports list weaknesses, so treat them as sensitive.

How should you read and report results?

Each result shows a severity, a detection quality, affected host and port, a description and a solution. Group findings by remediation (for example "patch OpenSSH"), not as a raw list. A useful report has an executive summary, scope and method, top risks, grouped remediation and a note of what was not tested. CVE identifiers can be checked at the National Vulnerability Database.

What are the limits?

OpenVAS finds known vulnerabilities through tests. It does not find unknown flaws, most business logic problems, or issues in custom web applications. It can also disturb fragile systems if configured aggressively. For web applications use a proxy such as Burp Suite or OWASP ZAP in addition. See vulnerability scanning tool interview questions.

Next steps

Practise with a guided lab in WebAsha's VAPT course. For interview preparation, see VAPT tool proficiency interview questions.

Related reading

Frequently Asked Questions

OpenVAS is an open-source vulnerability scanner that began as a fork of the Nessus engine and is now developed by Greenbone as part of the Greenbone Vulnerability Management framework. It checks hosts and services for known vulnerabilities.

The open-source components and the Greenbone Community Edition are free. Greenbone also sells commercial products and feeds, so check their documentation for what each includes.

Get written authorisation, define scope, update feeds, use credentialed scans, tune scans for fragile targets, validate findings, prioritise by risk and re-scan after fixes. Protect reports as sensitive data.

OpenVAS has open-source components and a free community edition, while Nessus is commercial with vendor support and limited free options. Both scan for known vulnerabilities, and results still need validation.

Install the gvm package with apt, run gvm-setup to download feeds and create an admin user, check with gvm-check-setup, start services with gvm-start and open the web interface on port 9392. Check current Kali docs.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.