Nessus 7.0 User Guide
Total Page:16
File Type:pdf, Size:1020Kb
Nessus 7.0 User Guide Last Updated: March 20, 2018 Table of Contents Welcome to Nessus 7.0 10 Nessus Workflow 13 Navigating Nessus 14 System Requirements 15 Hardware Requirements 16 Software Requirements 17 Licensing Requirements 20 Deployment Considerations 21 Host-Based Firewalls 22 IPv6 Support 23 Virtual Machines 24 Antivirus Software 25 Security Warnings 26 Install Nessus and Nessus Agents 27 Download Nessus 28 Install Nessus 30 Install Nessus on Linux 31 Install Nessus on Windows 32 Install Nessus on Mac OS X 34 Install Nessus Agents 36 Install a Nessus Agent on Linux 37 Install a Nessus Agent on Windows 40 Copyright © 2018. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Install a Nessus Agent on Mac OS X 44 Upgrade Nessus and Nessus Agents 47 Upgrade Nessus 48 Upgrade from Evaluation 49 Upgrade Nessus on Linux 50 Upgrade Nessus on Windows 51 Upgrade Nessus on Mac OS X 52 Upgrade a Nessus Agent 53 Configure Nessus 54 Install Nessus Home, Professional, or Manager 55 Link to Tenable.io 56 Link to Nessus Manager 57 Manage Activation Code 58 View Your Activation Code 59 Reset Activation Code 60 Update Activation Code 61 Transfer Activation Code 63 Manage Nessus Offline 65 Install Nessus Offline 67 Generate Challenge Code 70 Generate Your License 71 Download and Copy License File (nessus.license) 72 Register Your License with Nessus 73 Download and Copy Plugins 74 Copyright © 2018. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Install Plugins Manually 75 Update Nessus Software Manually 77 Remove Nessus and Nessus Agents 79 Nessus Removal 80 Uninstall Nessus on Linux 81 Uninstall Nessus on Windows 83 Uninstall Nessus on Mac OS X 84 Nessus Agent Removal 85 Uninstall a Nessus Agent on Linux 86 Uninstall a Nessus Agent on Windows 87 Uninstall a Nessus Agent on Mac OS X 88 Scans Page 89 Scan and Policy Templates 90 Settings 99 Basic Settings 100 Discovery Settings 104 Assessment Settings 113 Report Settings 126 Advanced Settings 128 Credentials 131 Cloud Services 133 Database 136 Host 139 SNMPv3 140 Copyright © 2018. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. SSH 141 Windows 149 Miscellaneous 157 Mobile 160 Patch Management 163 Plaintext Authentication 171 Compliance 174 Plugins 176 Special Use Templates 177 Scan Folders 180 Resources 182 Policies 183 Plugin Rules 185 Customized Reports 186 Scanners 187 Agents 188 Manage Scans 190 Create a Scan 191 Modify Scan Settings 192 Configure an Audit Trail 193 Delete a Scan 194 Manage Scan Folders 195 Resources 197 Create a Policy 198 Copyright © 2018. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Modify Policy Settings 199 Delete a Policy 200 Create a Plugin Rule 201 Modify a Plugin Rule 202 Delete a Plugin Rule 203 Customize Report Settings 204 Enable or Disable a Scanner 205 Remove a Scanner 206 Filter Agents 207 Unlink an Agent 209 Create a New Agent Group 210 Modify an Agent Group 211 Delete an Agent Group 212 Create a Blackout Window 213 Modify a Blackout Window 214 Delete a Blackout Window 215 Modify Agent Settings 216 Settings Page 217 About 218 Advanced Settings 220 LDAP Server 234 Proxy Server 235 Remote Link 236 SMTP Server 237 Copyright © 2018. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Custom CA 238 My Account 239 Users 240 Manage Settings 241 Update Nessus Software 242 Set a Master Password 245 Create a New Setting 246 Modify a Setting 247 Delete a Setting 248 Configure an LDAP Server 249 Configure a Proxy Server 250 Configure an SMTP Server 251 Add a Custom CA 252 Accounts 253 Modify Your User Account 254 Generate an API Key 255 Create a User Account 256 Modify a User Account 257 Delete a User Account 258 Additional Resources 259 About Nessus Plugins 260 About Scan Targets 262 Amazon Web Services 265 Command Line Operations 266 Copyright © 2018. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Start or Stop Nessus 267 Nessus-Service 269 Nessuscli 272 Nessuscli Agent 278 Update Nessus Software 281 Create a Limited Plugin Policy 282 Custom SSL Certificates 286 SSL Client Certificate Authentication 288 Create a New Custom CA and Server Certificate 289 Upload a Custom CA Certificate 291 Add a Root CA 292 Create Nessus SSL Certificates for Login 293 Enable Connections with Smart Card or CAC Card 296 Connect with Certificate or Card Enabled Browser 297 Default Data Directories 299 Manage Logs Using log.json 300 Nessus Credentialed Checks 305 Credentialed Checks on Windows 307 Prerequisites 310 Enable Windows Logins for Local and Remote Audits 311 Configure Nessus for Windows Logins 314 Credentialed Checks on Linux 315 Prerequisites 316 Enable SSH Local Security Checks 317 Copyright © 2018. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Configure Nessus for SSH Host-Based Checks 320 Offline Update Page Details 321 Unofficial PCI ASV Validation Scan 322 Run Nessus as Non-Privileged User 324 Run Nessus on Linux with Systemd as a Non-Privileged User 325 Run Nessus on Linux with init.d Script as a Non-Privileged User 328 Run Nessus on Mac OS X as a Non-Privileged User 331 Run Nessus on FreeBSD as a Non-Privileged User 336 Scan Targets 340 System Tray Application 343 Copyright © 2018. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners. Welcome to Nessus 7.0 If you are new to Nessus, see the Nessus Workflow. Nessus Solutions Tenable.io Tenable.io is a subscription based license and is available at the Tenable Store. Tenable.io enables security and audit teams to share multiple Nessus scanners, scan schedules, scan policies and most importantly scan results among an unlimited set of users or groups. By making different resources available for sharing among users and groups, Tenable.io allows for endless possibilities for creating highly customized work flows for your vulnerability management pro- gram, regardless of locations, complexity, or any of the numerous regulatory or compliance drivers that demand keeping your business secure. In addition, Tenable.io can control multiple Nessus scanners, schedule scans, push policies and view scan findings—all from the cloud, enabling the deployment of Nessus scanners throughout your net- work to multiple physical locations, or even public or private clouds. The Tenable.io subscription includes: l Unlimited scanning of your perimeter systems l Web application audits l Ability to prepare for security assessments against current PCI standards l Up to 2 quarterly report submissions for PCI ASV validation through Tenable, Inc.. l 24/7 access to the Tenable, Inc. Support Portal for Nessus knowledge base and support ticket creation Tenable.io Product Page Tenable.io User Manual Nessus Professional Nessus Professional, the industry’s most widely deployed vulnerability assessment solution helps you reduce your organization’s attack surface and ensure compliance. Nessus features high-speed asset discovery, configuration auditing, target profiling, malware detection, sensitive data discovery, and Copyright 2017 Tenable, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trademarks of - 10 - Tenable, Inc. Tenable, Tenable.io, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc. All other products or services are trademarks of their respective owners. more. Nessus supports more technologies than competitive solutions, scanning operating systems, network devices, hypervisors, databases, web servers, and critical infrastructure for vulnerabilities, threats, and compliance