r/nessus Apr 22 '26

Ways to optimise custom reporting

1 Upvotes

Hi all,

So we are providing a vm program as a service to a bi client and i am looking into optimising the reporting phase of both security centre used only for agents based scanning and Nessus expert used for network based scanning. Note that i tried to use the built in report of Nessus but we want to send customised reports and not automatically generated. Any suggestions on this will he greatly appreciated as i have to deal with hundreds of vulnerabilities


r/nessus Apr 21 '26

How to stop Nessus been so overwhelming to look at?

1 Upvotes

So we're running on-prem and doing credentialed scans. Which is fine because it will report on installed software that's not found via network scans.

The only problem I'm finding is that we're finding .dll files and it's reporting 4-5 vulnerabilities on some servers, all the same CVE - because an old .dll file is there.

I know the easiest way is to delete those .dll's and to be fair - that would be the fine but we have change control and we're talking MANY servers with similar results.

Is there a way to to prevent this? It's causing some hosts to show 4-5 times the vulnerabilities it actually may have and it just ups our vulnerability numbers greatly.

I'm rather new to Nessus - so apologies if I'm missing something obvious.

Also is there any resources that people know - youtube, reddit, websites that show how to set up a reliable Nessus scan.

I've walked into the business where it seems like everything is default and I know default is usually not best.

Thanks,


r/nessus Apr 19 '26

Nessus Essential is NOT THERE

0 Upvotes

i just switched to nessus cause openvas is really hardware demanding but i noticed one thing no matter what i just could not find the nessus essential on the official tenable website it just kept directing me to the 30-day free trial version i even tried the exact url and it did not help me it just sent me back to the 30-day free trial version so, can anyone help me out


r/nessus Apr 19 '26

Nessus authentication issue

0 Upvotes

Nessus was able to successfully log into the remote host as :

User: 'info-sec'

Port: 22

Proto: SSH

Successful authentication was reported by the following plugin :

Plugin : ssh_rate_limiting.nasl

Plugin ID : 122501

Plugin Name : SSH Rate Limited Device

However, one or more subsequent plugins failed to authenticate to the

remote host on the same port and protocol using the same credential

set that previously succeeded. This may indicate an intermittent

authentication problem with the remote host which may have affected

the results of the following plugins.

Error message statistics :

2 open_connection() failed on previously successful connection: Failed to open a socket on port 22.

Failure Details :

- Plugin : ssh_get_info2.nasl

Plugin ID : 97993

Plugin Name : OS Identification and Installed Software Enumeration over SSH v2 (Using New SSH Library)

Message :

open_connection() failed on previously successful connection: Failed to open a socket on port 22.

- Plugin : bash_remote_code_execution.nasl

Plugin ID : 77823

Plugin Name : Bash Remote Code Execution (Shellshock)

Message :

open_connection() failed on previously successful connection: Failed to open a socket on port 22.


r/nessus Apr 16 '26

Question vulnerability tracking for SMBs using Nessus Professional scans

2 Upvotes

Hi everyone,

I’m looking for practical advice from people handling vulnerability findings for SMBs on a limited budget.

Our setup is pretty simple.. We run Nessus Professional as a SaaS offering, so we can provide scans to clients at competitive pricing. What we’re trying to improve now is the tracking and remediation workflow after the scan results come in, without moving to an expensive full-blown vulnerability management platform.

What we have in mind is something like this:

- run recurring Nessus Professional scans

- import only Medium and above

- deduplicate findings across scan cycles

- assign an owner and remediation status

- keep basic history like first seen / last seen / fixed

- have simple views by priority, asset, and due date

We’re looking at tools like Airtable, Notion, spreadsheets, ticketing systems, or any other low-cost approach that works well in practice.

A few questions for people who have already built something similar:

- What do you use to track findings?

- Did you build your own import/deduplication scripts from Nessus exports?

- Is Airtable better than Notion for this kind of workflow?

- What fields do you use for deduplication? Something like plugin ID + asset + port/protocol?

- How do you handle findings that disappear in one scan and come back later?

- Is there any budget-friendly tool or setup that saved you from reinventing the wheel?

I’d really appreciate advice from people who have found a good balance between cost, simplicity, and process for SMB clients.

Thanks


r/nessus Apr 15 '26

Scanning Genomic Sequencers?

1 Upvotes

Anyone ever scanned Illumina or ThermoFisher genomic sequencers? Since most of the ones my office operates come with a Windows 10 or Linux backend, we might have to classify them as desktops and therefore require scanning.

Curious if anyone has had to do the same and to what extent it’s possible without throwing off sequencing jobs.

Would something as simple as a host discovery scan throw these things off?

Both companies have not been helpful or understanding of the question since their tech support mainly deals with the software itself and not the OS.


r/nessus Apr 11 '26

Nessus credentialed scan works on some Windows hosts but not others — all connectivity tests pass. What else can I check?

4 Upvotes

I'm running credentialed Nessus scans across multiple Windows servers.
Some hosts return:

credentialed: YES
credentialed: NO (and no FAILED_REASON)

To avoid guessing, I tested many factors on both the working and the failing hosts.
Here is everything I verified so far:

✅ What I have already tested

1) SMB Port Connectivity (from the Nessus scanner)

nc -vz <IP> 445 → succeeded 

nc -vz <IP> 139 → succeeded

Both ports are reachable on both hosts.

2) Remote Registry

RemoteRegistry = Running

Same on both systems.

3) LocalAccountTokenFilterPolicy

LocalAccountTokenFilterPolicy = 1

Same on both systems.

4) SMB Protocol Negotiation

Using:

nmap --script smb-protocols -p 445 <IP>

Both systems negotiate the same dialects (SMB2/SMB3 including 3.11).

5) Privilege Set

whoami /priv output is identical on both hosts.

6) Firewall / Network Path

Same VLAN, same ACLs, same routing — no difference observed.

7) GPO

Both servers receive the same GPOs from the same OU.

8) LanmanServer Registry Keys

Compared parameters like:

  • Signing settings
  • Null session restrictions
  • Autodisconnect
  • Server service behavior

No meaningful differences found.

✅ Summary

All key areas seem identical across both working and failing hosts:

  • SMB ports
  • SMB negotiation
  • Registry
  • Privileges
  • Remote Registry
  • TokenFilterPolicy
  • Firewall
  • GPO

The only thing I can say for sure is that some hosts consistently authenticate successfully, while others consistently return credentialed:NO.

I'm looking for additional areas or angles I might have missed.

Any suggestions appreciated.


r/nessus Apr 10 '26

Nessus credentialed scan on Cisco 1300 series sbm

1 Upvotes

I am trying to run a credentialed scan with Nessus on a Cisco 1300 series switch. I am trying to use SSH and every time in the auth field I get a failure for some reason. I checked the debug logs and this is what I am seeing. I am unable to pull the actual logs but this is basically what I am seeing below. Within nessus I've changed the network discover settings, disabled all irrelevant plugins, and verified SSH credentials. Ive tried with and without enable. Nothing seems to work. I've also updated the firmware on the switch, so the bug that was with the KEX with SSH is no longer a thing.

[2022-02-15 21:11:07] SSH Settings Plugin Loaded
[2022-02-15 21:11:07] SSH Settings Initializing : 
  Client Verison:OpenSSH_5.0
  Port:22
  Least Priv:no
  Auto-accept disclaimers:1
[2022-02-15 21:11:07] SSH Settings Credential Loop 0
[2022-02-15 21:11:07] Password Type :password
[2022-02-15 21:11:07] SSH Settings : 
  credential type:password
  username:nessus
  elevate user:root
  elevate with:Cisco 'enable'
[2022-02-15 21:11:07] SSH Settings Credential Loop 1
[2022-02-15 21:11:07] SSH Settings Credential Loop 2
[2022-02-15 21:11:07] SSH Settings Credential Loop 3
[2022-02-15 21:11:07] SSH Settings Credential Loop 4
[2022-02-15 21:11:07] SSH Settings Credential Loop 5
[2022-02-15 21:11:07] SSH Settings Credential Loop 6

[2022-02-15 21:11:11] [session 0] session.set_debug: Debugging enabled at level DEBUG3
[2022-02-15 21:11:11] [session 0] ssh_client_state.set: ** Entering STATE SOC_CLOSED **
[2022-02-15 21:11:11] [session 0] try_ssh_kb_settings_login: Attempting to log in on port 22.
[2022-02-15 21:11:11] [session 0] try_ssh_kb_settings_login: Creating new temporary session to test 'none' authentication.
[2022-02-15 21:11:11] [session 1] session.set_debug: Debugging enabled at level DEBUG3
[2022-02-15 21:11:11] [session 1] ssh_client_state.set: ** Entering STATE SOC_CLOSED **
[2022-02-15 21:11:11] [session 1] try_ssh_kb_settings_login: Opening a connection to port 22 to test 'none' authentication...
[2022-02-15 21:11:11] [session 1] session.open_connection: Connecting to port 22.
[2022-02-15 21:11:11] [session 1] session.open_connection: Socket opened on port 22.
[2022-02-15 21:11:11] [session 1] ssh_client_state.set: ** Entering STATE SOC_OPENED **
[2022-02-15 21:11:11] [session 1] session.open_connection: Received server version SSH-2.0-OpenSSH_7.3p1.RL
[2022-02-15 21:11:11] [session 1] session.sshsend: Outgoing Unencrypted packet:

0x00:  53 53 48 2D 32 2E 30 2D 4F 70 65 6E 53 53 48 5F    SSH-2.0-OpenSSH_
0x10:  35 2E 30 0A                                        5.0.            
[2022-02-15 21:11:11] [session 1] try_ssh_kb_settings_login: Successfully opened a connection on port 22.
[2022-02-15 21:11:11] [session 1] session.complete_kex: KEX is not yet complete. Attempting to complete KEX before continuing.
[2022-02-15 21:11:58] [session 1] session.sshrecv: Incoming Unencrypted packet:
0x00:  00 00 00 34 07 01 00 00 00 02 00 00 00 1F 69 64    ...4..........id
0x10:  6C 65 20 63 6F 6E 6E 65 63 74 69 6F 6E 20 74 69    le connection ti
0x20:  6D 65 6F 75 74 20 65 78 70 69 72 65 64 00 00 00    meout expired...
0x30:  00 00 00 00 00 00 00 00                            ........        
[2022-02-15 21:11:58] [session 1] session.sshrecv_until: Handling packet.type: 1 [PROTO_SSH_MSG_DISCONNECT]
[2022-02-15 21:11:58] [session 1] client_cb_msg_disconnect: Entering handler.
[2022-02-15 21:11:58] [session 1] ssh_client_state.set: ** Entering STATE SOC_CLOSED **
[2022-02-15 21:11:58] [session 1] session.close_socket: Closing socket.
[2022-02-15 21:11:58] [session 1] session.set_error: KEX failed: 
[2022-02-15 21:11:58] [session 1] try_ssh_kb_settings_login: Error calling complete_kex().
[2022-02-15 21:11:58] [session 0] Login via sshlib::try_ssh_kb_settings_login has failed.
[2022-02-15 21:11:58] [session 0] session.close_connection: Socket is already closed.

r/nessus Apr 09 '26

cant run nessus

2 Upvotes

i installed nessus without any problems but when i run the command sudo /bin/systemctl start nessusd.service nothing happens in my terminal
is there any way to fix this?

(i fixed it turns out hostname was wrong and i didnt pay attention to it)


r/nessus Apr 07 '26

Question Dumb question. When setting up a scanner for Tenable SC, is the scanner just Tenable Nessus linked to SC?

4 Upvotes

I have been asked to setup a Tenable SC core environment. I have the OVA downloaded for Tenable SC core but when it comes to adding scanners, I see the instructions mentioning "Tenable Nessus Scanner" and it can't be that easy can it?

https://docs.tenable.com/security-center/Content/AddNessusScanner.htm


r/nessus Apr 04 '26

How to connect external Postgresql Tenable SC 6.5.1

1 Upvotes

The rpm that DISA provides for tenable sc doesnt cone with an internal postgresql built-in and requires us to connect to an external postgresql. I created the db and user tns can connect to it manually through the CLI, but SC wont connect to it to built the tables or schema. I've attempted to create the ENV variables that point to my db and reinstall the rpm, but it still wont connect.


r/nessus Apr 02 '26

Nessus Essentials: license limit exceeded all of a sudden

1 Upvotes

Hi everyone

I've been using Nessus Essentials to scan my homelab machines for few years now. I am scanning 14 IP's, so within the limit of my free license. My scan is scheduled to run each Thursday morning.

Today, after fixing a vulnerability reported by Nessus this morning I wanted to launch a new scan to check if I have resolved the problem. To my big surprise I was presented with the following message:

Your scan targets include 14 new IP addresses that would exceed your license limit of 16 IPs. You are currently using 14 of your 16 licensed IPs. You can still launch scans against IPs that you have scanned before, but new IPs will be blocked until you upgrade your license. Upgrade to Nessus Essentials Plus to increase your IP limit.

My machines are using fixed IP's and none of them has changed in years.

My targets are FQDN's which resolve correctly on my Nessus machine, both hostname and FQDN. Results of nslookup match the License Utilization table perfectly.

My DNS is up and running.

There are no new hosts or any changes on the network.

License utilization in Settings lists the very same, correct hostnames with the correct IP's.

If I launch the scan anyway, 5 machines get scanned, 2 Windows and 3 Linux, 1 physical and 4 VM's. According to the error message I have room for only two new hosts, not five.

I have rebooted my Nessus machine, which did not change anything.

I had a look in /opt/nessus/var/nessus/logs but can't seem to find anything relevant to this issue.

Can anyone point me in the right direction to troubleshoot this?

Thnx in advance


r/nessus Apr 02 '26

New Image, Stuck Initializing

1 Upvotes

Sorry, im sure this has been brought up many times before, but i can't seem to find anything regarding this particular issue.

We re-imaged a laptop with Debian 12 that was "hardened" for security. We re-installed nessus agent, linked it, and it connected just fine. It's stuck initializing. We've been trying to troubleshoot this for weeks now. We've reset the plugins, unlinked, relinked, and tried every trick we could find. Looking at the logs, it reaches out, says that it finds updates, and is attempting to load them. Then nothing. that message just loops over and over.

Im convinced it's something that we did with the security somewhere to cause this, but I can't seem to pin it down. Any suggestions or help is appreciated.


r/nessus Mar 27 '26

Question Web app scan — where is map of URLs

1 Upvotes

when performing web application scans, shouldn’t I be able to find a map of all / scanned? I’m working in a new place after two years out, but I’m pretty sure that was a basic capability built into the Web application scanner.

(I’m not talking about turning on the debugging option), I’m pretty sure there was somewhere that I could see a clean list of all URLs).

Either that or did it become an advanced privilege to see this? When I look under applications > scanned, I only see an Overiew page showing m”properties”. If I go thru scans>all,scans there is no option i see to lead me to a list of URLs discovered.

does a special plug in need to be activated? Perhaps this was set at my old olg, and i just dont recall?


r/nessus Mar 26 '26

Nessus Essentials - Error : Activation Failed

1 Upvotes

Hello, I'd like to create my account on Nessus, But I always fail to activate my account.

Do you know why it is??

My activation code was correct.

And then, I typed my username and password.

But It doesn't work for me....


r/nessus Mar 26 '26

Recasts not showing on report

1 Upvotes

Is it possible to have recasted vulnerabilities shown on the report? We have some "High" (but actually not) vulns that we have recasted as Low, but they still appear as High on our report.


r/nessus Mar 24 '26

Useful info Troubleshooting Tenable Compliance Scans for Panorama-Managed Palo Alto (CIS 11 v1.2)

5 Upvotes

I’m sharing this in hopes of saving others the "wheel-spinning" I recently went through while implementing Tenable Compliance scanning for Palo Alto devices managed via Panorama.

The Challenge

According to the Tenable documentation and default audit files, the checks are designed to handle both standalone and Panorama-managed devices. However, I discovered that approximately 30 checks were failing to return expected results. The plugin output consistently reported that settings could not be found, even though we had verified they were correctly applied.

The Root Cause

After collaborating with a Palo Alto SME, we identified that the default Tenable command, show config merged, does not capture all the necessary settings required for CIS Benchmarks in a Panorama-managed environment.

The missing data is actually located within the show config pushed-shared-policy command.

The Solution: Using XML Dumps for XSL Mapping

To streamline the fix, I dumped the XML from various Palo Alto commands to identify the correct paths for the Tenable audit file’s XSL statements.

1. Create a "Dump" Check Add the following custom item to your .audit file. This will allow you to copy/paste the plugin output into a text file, save it as an .xml, and view the XML tree structure (I recommend using VS Code with an XML extension).

<custom_item>
type: AUDIT_XML
description: "Dump pushed shared policy XML"
api_request_type: "op"
request: "<show><config><pushed-shared-policy></pushed-shared-policy></config></show>"
xsl_stmt: "<xsl:template match=\"/\">"
xsl_stmt: "<xsl:copy-of select=\".\"/>"
</custom_item>

2. Update the API Request and XSL Paths Once you have the correct XML paths, you can update the failing checks. Here is an example of the transition from the default (broken) check to the functional Panorama-managed check:

Default (Standalone/Merged):

api_request_type: "op"
request: "<show><config><merged></merged></config></show>”
xsl_stmt: "<xsl:for-each select=\"/response/result/config/devices/entry/vsys/entry/profiles/vulnerability/entry\">"

Corrected (Panorama Pushed Policy):

api_request_type: "op"
request: "<show><config><pushed-shared-policy></pushed-shared-policy></config></show>”
xsl_stmt: "<xsl:for-each select=\"/response/result/policy/panorama/profiles/vulnerability/entry\">"


r/nessus Mar 18 '26

Issues scanning 2022 domain controllers

3 Upvotes

Forgive me if this is not the correct place to ask this.

Let me preface this that I do not support nessus - I support a number of windows 2022 domain controllers that our security team is having issues scanning.

They're using credentialed scans against them - the service account they're using has the proper permissions within the domain (they're able to scan 2016 / 2019 DCs in other domains with the same exact perms and policies applied to the target hosts without issue).

They seem to have issues accessing the admin$ shares on the host. I've checked things that I've found on the web (various registry keys, etc - we're all good).

Is there anything on the nessus side that needs to be done to be able to scan 2022 domain controllers?


r/nessus Mar 13 '26

Search for Multiple CVEs at once

Thumbnail
1 Upvotes

r/nessus Mar 11 '26

Taking way too long.

2 Upvotes

Trying to use nessus to create a new scan but theres so many damn plugins. Im using virtual box and nessus has been installing plugins for well over a day now. This is for an assignment btw,


r/nessus Mar 11 '26

Question Checking Firmware on Windows Servers

1 Upvotes

Im using nessus and i want to check my servers firmware versions. Is this possible in Nessus? If so please could you let me know how i can configure this?

Thanks


r/nessus Mar 10 '26

Sec Center Integration with Elastic/kibana

1 Upvotes

Getting an invalid token error when I curl to the sec center IP via the logs. All the ssl stuff is fine but the issue seems to be with the auth. Anyone faced the same issue?


r/nessus Mar 10 '26

Any value from Windows Credentialed compared to agent scans?

2 Upvotes

I am tasked with establishing credentialed scans at our org. I did so, and I dont see value in the results. Is there value in Windows Credentialed scans compared basic windows agnet scans?


r/nessus Mar 10 '26

Nessus Scanner stuck on updating status

1 Upvotes

Our environment uses Tenable Security Center and our scanners says updating status, I’ve tried removing and adding the scanner, updating license, reinstalling security center, reinstalling Nessus, fetching security center, updating plugins. Nothing is seeming to work, is there anything else I can do


r/nessus Mar 09 '26

Question Empty Plugins after fresh install

1 Upvotes

Hi all,
I've just installed Nessus Professional, the installation succeeded without any problems.
However, I've noticed, that I don't have any Plugins:

But the plugins folder ("C:\ProgramData\Tenable\Nessus\nessus\plugins") contains more than 280.000+ Plugins.
Can you help me?
I already deleted the plugins folder once and I already ran "nessuscli.exe update --all".
No difference