Nessus 6.8 User Guide
Total Page:16
File Type:pdf, Size:1020Kb
Nessus 6.8 User Guide Last Updated: 8/17/2016 Table of Contents Getting Started 11 About Nessus Products 12 About Nessus Plugins 15 Hardware Requirements 17 Supported Operating Systems 18 Nessus License & Activation Code 21 Setup Nessus 22 Product Download 23 Pre-install Nessus 25 Deployment 26 Host Based Firewalls 27 IPv6 Support 28 Virtual Machines 29 Anti-virus Software 30 Security Warnings 31 Install Nessus and Nessus Agents 32 Nessus Installation 33 Install Nessus on Mac OS X 34 Install Nessus on Linux 36 Install Nessus on Windows 37 Nessus Agent Install 39 Install a Nessus Agent on Mac OS X 40 Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Install a Nessus Agent on Linux 43 Install a Nessus Agent on Windows 47 Upgrade Nessus and Nessus Agents 51 Nessus Upgrade 52 Upgrade from Evaluation 53 Mac Upgrade 54 Linux Upgrade 55 Windows Upgrade 56 Nessus Agents: Upgrade 57 Installation - Web Browser Portion 58 Nessus (Home, Professional, or Manager) 60 Link to Nessus Manager 61 Link to Tenable Cloud 64 Managed by SecurityCenter 66 Install Nessus while Offline 67 Register Nessus Offline 71 Generate Challenge Code 73 Generate Your License 74 Download and Copy License File (nessus.license) 75 Register Your License with Nessus 76 Download and Copy Plugins 77 Install Plugins Manually 78 Remove Nessus and Nessus Agents 79 Nessus Removal 80 Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Uninstall Nessus on Mac OS X 81 Uninstall Nessus on Linux 82 Uninstall Nessus on Windows 84 Nessus Agent Removal 85 Uninstall a Nessus Agent on Mac OS X 86 Uninstall a Nessus Agent on Linux 87 Uninstall a Nessus Agent on Windows 89 Nessus Features 90 Navigating Nessus 91 Scans Page 92 Policies Page 96 User Profile 98 System Settings 100 Scanners / Local / Overview (Manager) 101 Scanners 102 Nessus Agents 109 Agent Groups 110 User and Group Accounts 111 Communication 112 Advanced Settings 114 Template Library 125 Scan Template Settings 128 Settings / Basic 131 Settings / Discovery 134 Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Settings / Assessment 140 Settings / Report 150 Scan Setting / Advanced 152 Scan Credentials Settings 155 Cloud Services 157 Amazon AWS 158 Microsoft Azure 159 Rackspace 160 Salesforce.com 161 Database 162 Database 163 MongoDB 165 Host 166 SSH 167 Public Key 169 Certificate 171 CyberArk Vault 172 Kerberos 174 Password Authentication 176 Thycotic Secret Server Authentication 177 SNMPv3 178 Windows 179 Password 183 CyberArk Vault 184 Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Kerberos 186 LM Hash 187 NTLM Hash 188 Thycotic Secret Server Authentication 189 Miscellaneous 190 ADSI 191 IBM iSeries 192 Palo Alto Networks PAN-OS 193 RHEV (Red Hat Enterprise Virtualization) 194 VMware ESX SOAP API 195 VMware vCenter SOAP API 196 X.509 197 Mobile Device Management 198 AirWatch 199 Apple Profile Manager 200 Good MDM 201 MaaS360 202 MobileIron 203 Patch Management 204 Dell KACE K1000 205 IBM Tivoli Endpoint Manager (TEM) 207 Microsoft System Center Configuration Manager (SCCM) 209 Windows Server Update Services (WSUS) 210 Red Hat Satellite 6 Server 211 Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Red Hat Satellite 5 Server 212 Symantec Altiris 213 Plaintext Authentication 215 HTTP 217 telnet/rsh/rexec 219 Scan Compliance Settings 220 Scan Plugins Settings 224 Special Use Templates 227 Manage Nessus 230 Manage Nessus License & Registration 231 Manage Activation Code 232 View your Activation Code 233 Reset Activation Code 234 Update Activation Code 235 Manage Your User Profile 237 Account Settings 238 API Keys 240 Change Password 241 Plugin Rules 242 System Settings 243 Manage Scanners 244 Nessus Professional 245 Scanners / Local / Overview (Professional) 246 Scanners / Local / Link 247 Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Scanners / Local / Software Update 249 Software Update Page 250 Update Nessus Version 252 Update Plugins 253 Update Activation Code 254 Updated Nessus Software using the Command Line 256 Nessus Manager 257 Scanners / Local / Overview (Manager) 258 Scanners / Local / Permissions 259 Scanners / Local / Software Update 260 Software Update Page 261 Update Nessus Version 263 Update Plugins 264 Update Activation Code 265 Updated Nessus Software using the Command Line 267 Scanners / Remote / Linked 268 Scanners / Agents / Linked 269 Manage Accounts 273 Manage Communications 276 LDAP Server 277 SMTP Server 279 Proxy Server 280 Cisco ISE 281 Manage Advanced Settings 282 Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Manage Scans 283 Create Scans 284 Create a Scan Folder 286 Manage Scans 287 Create an Unofficial PCI ASV Validation Scan 290 Scan Results 292 Dashboards 296 Scan Results Pages 300 Report Filters 301 Report Screenshots 305 Compare Report Results (Diff) 306 Knowledge Base 307 Exported Results 308 Manage Policies 309 Create a Policy 310 Create a Limited Plugin Policy 313 Manage Policies 317 Manage Nessus Agents 319 Manage Agent Groups 320 Create an Agent Scan 323 Custom SSL Certificates 327 Enable SSH Local Security Checks 334 Credentialed Checks on Windows 337 Additional Resources 341 Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Run Nessus as Non-Privileged User 342 Run Nessus on Linux with Systemd as Non-Privileged User 343 Run Nessus on Linux with init.d Script as Non-Privileged User 346 Run Nessus on MAC OSX as Non-Privileged User 348 Run Nessus on FreeBSD as non-privileged User 353 Scan Targets Explained 357 Command Line Operations 359 nessus-service 360 nessuscli 362 nessuscli agent 367 Start or Stop Nessus 369 Offline Update Page Details 371 More Nessus Resources 373 Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Getting Started This section provides information about your Nessus license, your system requirements, and how to down- load Nessus products. Additionally, this section includes information about Nessus features, including Nessus Agents, which are available for use with Nessus Manager and Tenable Cloud. Unless otherwise noted, features apply to Nessus Manager. l Hardware Requirements l Software Requirements l Licensing Requirements Copyright © 2016. Tenable Network Security, Inc. All rights reserved. Tenable Network Security and Nessus are registered trademarks of Tenable Network Security, Inc. SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. - 11 - About Nessus Products Nessus Manager Nessus ® Manager combines the powerful detection, scanning, and auditing features of Nessus, the world’s most