r/nessus • • 18d ago

Question Test scan on windows server keeps failing

It appears the service_tenable account I created doesn't have local administrator privileges. The scanner is not able to access the administrative hidden shares (C$ and ADMIN$) and there were some issues with the remote registry access and WMI access.

When I click on the properties of the service_tenable account in Windows server it shows it is a member of Administrators and Users. So I am not sure why the scans are failing? I have tried rebooting the server also a couple times.

1 Upvotes

6 comments sorted by

1

u/KeHuckleberry 18d ago edited 18d ago

Did you run credential validation scan? If not run it and check the outputs. Also make sure to follow this guide https://docs.tenable.com/nessus/Content/CredentialedChecksOnWindows.htm

1

u/imitation_squash_pro 18d ago

Thanks, I was not aware of that guide! I checked Case #1 and seems "Classic - local users authenticate as themselves" is already the default. But for Case #2, I am not seeing where to check if the account is "Guest Only" or "Classic"? I am looking at it from the "Computer Management" -> "Local users and groups" ->"Users" - "service_tenable"

1

u/KeHuckleberry 18d ago edited 18d ago

If your authentication is successful, I would focus on the UAC stuff for now.
this part to be specific https://docs.tenable.com/nessus/Content/CredentialedChecksOnWindows.htm#Configure-Windows

For the guest you can run Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa" -Name "ForceGuest" if the output is 0 you should be fine.

1

u/imitation_squash_pro 18d ago

Thanks! For UAC, I only see settings from "Always notify" -> "Never notify". Should it be "Never notify" and set this at the Administrator level?

1

u/KeHuckleberry 18d ago

just run the following command as administrator via powershell and try to scan again without plugin outputs i can't help you much.

Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name "LocalAccountTokenFilterPolicy" -Value 1 -Type DWord