Nessus 8.3 User Guide
Total Page:16
File Type:pdf, Size:1020Kb
Nessus 8.3.x User Guide Last Updated: September 24, 2021 Table of Contents Welcome to Nessus 8.3.x 12 Get Started with Nessus 15 Navigate Nessus 16 System Requirements 17 Hardware Requirements 18 Software Requirements 22 Customize SELinux Enforcing Mode Policies 25 Licensing Requirements 26 Deployment Considerations 27 Host-Based Firewalls 28 IPv6 Support 29 Virtual Machines 30 Antivirus Software 31 Security Warnings 32 Certificates and Certificate Authorities 33 Custom SSL Server Certificates 35 Create a New Server Certificate and CA Certificate 37 Upload a Custom Server Certificate and CA Certificate 39 Trust a Custom CA 41 Create SSL Client Certificates for Login 43 Nessus Manager Certificates and Nessus Agent 46 Install Nessus 48 Copyright © 2021 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trade- marks of Tenable,Inc. Tenable.sc, Tenable.ot, Lumin, Indegy, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective Download Nessus 49 Install Nessus 51 Install Nessus on Linux 52 Install Nessus on Windows 54 Install Nessus on Mac OS X 56 Install Nessus Agents 58 Retrieve the Linking Key 59 Install a Nessus Agent on Linux 60 Install a Nessus Agent on Windows 64 Install a Nessus Agent on Mac OS X 70 Upgrade Nessus and Nessus Agents 74 Upgrade Nessus 75 Upgrade from Evaluation 76 Upgrade Nessus on Linux 77 Upgrade Nessus on Windows 78 Upgrade Nessus on Mac OS X 79 Upgrade a Nessus Agent 80 Configure Nessus 86 Install Nessus Home, Professional, or Manager 87 Link to Tenable.io 88 Link to Industrial Security 89 Link to Nessus Manager 90 Managed by Tenable.sc 92 Manage Activation Code 93 Copyright © 2021 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trade- marks of Tenable,Inc. Tenable.sc, Tenable.ot, Lumin, Indegy, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective View Activation Code 94 Reset Activation Code 95 Update Activation Code 96 Transfer Activation Code 98 Manage Nessus Offline 100 Install Nessus Offline 102 Generate Challenge Code 105 Generate Your License 106 Download and Copy License File (nessus.license) 107 Register Your License with Nessus 108 Download and Copy Plugins 109 Install Plugins Manually 110 Update Nessus Software Manually on an Offline system 112 Offline Update Page Details 114 Remove Nessus and Nessus Agents 115 Remove Nessus 116 Uninstall Nessus on Linux 117 Uninstall Nessus on Windows 119 Uninstall Nessus on Mac OS X 120 Remove Nessus Agent 121 Uninstall a Nessus Agent on Linux 122 Uninstall a Nessus Agent on Windows 124 Uninstall a Nessus Agent on Mac OS X 126 Scans 127 Copyright © 2021 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trade- marks of Tenable,Inc. Tenable.sc, Tenable.ot, Lumin, Indegy, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective Scan and Policy Templates 129 Agent Templates 132 Scan and Policy Settings 134 Basic Settings for Scans 136 Basic Settings for Policies 142 Discovery Scan Settings 144 Preconfigured Discovery Scan Settings 154 Assessment Scan Settings 173 Preconfigured Assessment Scan Settings 189 Report Scan Settings 198 Advanced Scan Settings 200 Preconfigured Advanced Scan Settings 205 Credentials 212 Cloud Services 214 Database Credentials 218 Database Credentials Authentication Types 224 Host 237 SNMPv3 238 SSH 240 Windows 254 Miscellaneous 268 Mobile 273 Patch Management 276 Plaintext Authentication 285 Copyright © 2021 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trade- marks of Tenable,Inc. Tenable.sc, Tenable.ot, Lumin, Indegy, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective Compliance 290 SCAP Settings 293 Plugins 295 Configure Dynamic Plugins 296 Special Use Templates 298 Unofficial PCI ASV Validation Scan 301 Create and Manage Scans 303 Example: Host Discovery 304 Create a Scan 306 Import a Scan 307 Create an Agent Scan 308 Modify Scan Settings 309 Configure an Audit Trail 310 Delete a Scan 311 Scan Results 312 Search and Filter Results 313 Dashboard 320 Vulnerabilities 322 View Vulnerabilities 323 Modify a Vulnerability 324 Group Vulnerabilities 325 Snooze a Vulnerability 327 Live Results 329 Enable or Disable Live Results 331 Copyright © 2021 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trade- marks of Tenable,Inc. Tenable.sc, Tenable.ot, Lumin, Indegy, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective Remove Live Results 332 Compare Scan Results 333 Export a Scan Report 334 Scan Exports and Reports 336 Scan Folders 337 Manage Scan Folders 339 Policies 341 Create a Policy 343 Import a Policy 344 Modify Policy Settings 345 Delete a Policy 346 About Nessus Plugins 347 Create a Limited Plugin Policy 349 Install Plugins Manually 353 Plugin Rules 355 Create a Plugin Rule 356 Modify a Plugin Rule 357 Delete a Plugin Rule 358 Customized Reports 359 Customize Report Title and Logo 360 Scanners 361 Link Nessus Scanner 362 Unlink Nessus Scanner 363 Enable or Disable a Scanner 364 Copyright © 2021 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trade- marks of Tenable,Inc. Tenable.sc, Tenable.ot, Lumin, Indegy, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective Remove a Scanner 365 Download Managed Scanner Logs 366 Agents 368 Modify Agent Settings 370 Filter Agents 371 Export Agents 373 Download Linked Agent Logs 374 Unlink an Agent 376 Agent Groups 378 Create a New Agent Group 379 Configure User Permissions for an Agent Group 380 Modify an Agent Group 382 Delete an Agent Group 384 Freeze Windows 385 Create a Blackout Window 386 Modify a Blackout Window 387 Delete a Blackout Window 388 Settings 389 About 391 Advanced Settings 393 LDAP Server 420 Configure an LDAP Server 421 Proxy Server 422 Configure a Proxy Server 423 Copyright © 2021 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trade- marks of Tenable,Inc. Tenable.sc, Tenable.ot, Lumin, Indegy, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective Remote Link 424 SMTP Server 427 Configure an SMTP Server 428 Custom CA 429 Upgrade Assistant 430 Password Management 431 Configure Password Management 433 Scanner Health 434 Monitor Scanner Health 437 My Account 438 Users 439 System-wide Agent Settings 440 Accounts 441 Modify Your User Account 442 Generate an API Key 443 Create a User Account 444 Modify a User Account 445 Delete a User Account 446 Set an Encryption Password 447 Update Nessus Software 448 Create a New Setting 450 Modify a Setting 451 Delete a Setting 452 Download Logs 453 Copyright © 2021 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trade- marks of Tenable,Inc. Tenable.sc, Tenable.ot, Lumin, Indegy, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective Additional Resources 454 Agent Software Footprint 455 Agent Host System Utilization 456 Amazon Web Services 457 Command Line Operations 458 Start or Stop Nessus 459 Start or Stop a Nessus Agent 461 Nessus-Service 463 Nessuscli 466 Nessuscli Agent 472 Update Nessus Software 479 Default Data Directories 480 Manage Logs 481 Nessus Credentialed Checks 489 Credentialed Checks on Windows 491 Prerequisites 495 Enable Windows Logins for Local and Remote Audits 496 Configure Nessus for Windows Logins 499 Credentialed Checks on Linux 500 Prerequisites 501 Enable SSH Local Security Checks 502 Configure Nessus for SSH Host-Based Checks 505 Run Nessus as Non-Privileged User 506 Run Nessus on Linux with Systemd as a Non-Privileged User 507 Copyright © 2021 Tenable, Inc. All rights reserved. Tenable, Tenable.io, Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trade- marks of Tenable,Inc. Tenable.sc, Tenable.ot, Lumin, Indegy, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective Run Nessus on Linux with init.d Script as a Non-Privileged User 510 Run Nessus on Mac OS X as a Non-Privileged User 513 Run Nessus on FreeBSD as a Non-Privileged User 518 Scan Targets 522 Upgrade Assistant 525 Copyright © 2021