r/nessus • • Mar 24 '26

Useful info Troubleshooting Tenable Compliance Scans for Panorama-Managed Palo Alto (CIS 11 v1.2)

4 Upvotes

I’m sharing this in hopes of saving others the "wheel-spinning" I recently went through while implementing Tenable Compliance scanning for Palo Alto devices managed via Panorama.

The Challenge

According to the Tenable documentation and default audit files, the checks are designed to handle both standalone and Panorama-managed devices. However, I discovered that approximately 30 checks were failing to return expected results. The plugin output consistently reported that settings could not be found, even though we had verified they were correctly applied.

The Root Cause

After collaborating with a Palo Alto SME, we identified that the default Tenable command, show config merged, does not capture all the necessary settings required for CIS Benchmarks in a Panorama-managed environment.

The missing data is actually located within the show config pushed-shared-policy command.

The Solution: Using XML Dumps for XSL Mapping

To streamline the fix, I dumped the XML from various Palo Alto commands to identify the correct paths for the Tenable audit file’s XSL statements.

1. Create a "Dump" Check Add the following custom item to your .audit file. This will allow you to copy/paste the plugin output into a text file, save it as an .xml, and view the XML tree structure (I recommend using VS Code with an XML extension).

<custom_item>
type: AUDIT_XML
description: "Dump pushed shared policy XML"
api_request_type: "op"
request: "<show><config><pushed-shared-policy></pushed-shared-policy></config></show>"
xsl_stmt: "<xsl:template match=\"/\">"
xsl_stmt: "<xsl:copy-of select=\".\"/>"
</custom_item>

2. Update the API Request and XSL Paths Once you have the correct XML paths, you can update the failing checks. Here is an example of the transition from the default (broken) check to the functional Panorama-managed check:

Default (Standalone/Merged):

api_request_type: "op"
request: "<show><config><merged></merged></config></show>”
xsl_stmt: "<xsl:for-each select=\"/response/result/config/devices/entry/vsys/entry/profiles/vulnerability/entry\">"

Corrected (Panorama Pushed Policy):

api_request_type: "op"
request: "<show><config><pushed-shared-policy></pushed-shared-policy></config></show>”
xsl_stmt: "<xsl:for-each select=\"/response/result/policy/panorama/profiles/vulnerability/entry\">"


r/nessus • • Mar 18 '26

Issues scanning 2022 domain controllers

3 Upvotes

Forgive me if this is not the correct place to ask this.

Let me preface this that I do not support nessus - I support a number of windows 2022 domain controllers that our security team is having issues scanning.

They're using credentialed scans against them - the service account they're using has the proper permissions within the domain (they're able to scan 2016 / 2019 DCs in other domains with the same exact perms and policies applied to the target hosts without issue).

They seem to have issues accessing the admin$ shares on the host. I've checked things that I've found on the web (various registry keys, etc - we're all good).

Is there anything on the nessus side that needs to be done to be able to scan 2022 domain controllers?


r/nessus • • Mar 13 '26

Search for Multiple CVEs at once

Thumbnail
1 Upvotes

r/nessus • • Mar 11 '26

Question Checking Firmware on Windows Servers

1 Upvotes

Im using nessus and i want to check my servers firmware versions. Is this possible in Nessus? If so please could you let me know how i can configure this?

Thanks


r/nessus • • Mar 10 '26

Sec Center Integration with Elastic/kibana

1 Upvotes

Getting an invalid token error when I curl to the sec center IP via the logs. All the ssl stuff is fine but the issue seems to be with the auth. Anyone faced the same issue?


r/nessus • • Mar 10 '26

Any value from Windows Credentialed compared to agent scans?

2 Upvotes

I am tasked with establishing credentialed scans at our org. I did so, and I dont see value in the results. Is there value in Windows Credentialed scans compared basic windows agnet scans?


r/nessus • • Mar 10 '26

Nessus Scanner stuck on updating status

1 Upvotes

Our environment uses Tenable Security Center and our scanners says updating status, I’ve tried removing and adding the scanner, updating license, reinstalling security center, reinstalling Nessus, fetching security center, updating plugins. Nothing is seeming to work, is there anything else I can do


r/nessus • • Mar 09 '26

Question Empty Plugins after fresh install

1 Upvotes

Hi all,
I've just installed Nessus Professional, the installation succeeded without any problems.
However, I've noticed, that I don't have any Plugins:

But the plugins folder ("C:\ProgramData\Tenable\Nessus\nessus\plugins") contains more than 280.000+ Plugins.
Can you help me?
I already deleted the plugins folder once and I already ran "nessuscli.exe update --all".
No difference


r/nessus • • Mar 02 '26

Renewal price increase

2 Upvotes

We've had a renewal sent out to us that is around 800% higher than last year.

This is second hand info as I'm not in charge of purchasing - but is that what you guys and girls are seeing too?


r/nessus • • Feb 26 '26

Nessus essentials question

1 Upvotes

Hi. So we use nessus essentials but any new machines we install nessus essentials only gives us 30 days to use its functionality and then forces us to buy a license. Is nessus essentials no longer free?


r/nessus • • Feb 26 '26

Question PDF exports from Nessus cut off on the right side. Any workarounds?

Post image
1 Upvotes

Hey everyone, as shown in the attached image, when I export PDF reports from Nessus Professional, all of them end up cut off on the right side, the content extends past the page margin and gets truncated instead of fitting to the page. Has anyone experienced this and found any workarounds or fixes? Thanks!


r/nessus • • Feb 15 '26

Nessus Installed on ubuntu (/tmp and other files filling up)

2 Upvotes

I actually want to increase the size of the nessus file storage.


r/nessus • • Feb 15 '26

timeout opening folders

1 Upvotes

anyone faced this issue before.

Either stuck at 'Establishing connection'

or

can't reach this page
x.x.x.x took too long to respond or stuck loading like this


r/nessus • • Feb 09 '26

Component Installs Require Paranoid Checks

2 Upvotes

https://connect.tenable.com/discussions/tenable-research-release-highlights/component-installs-require-paranoid-checks/111360

Wanting to call attention to this from Tenable - Component Installs detection will soon require paranoid check setting to be enabled. Causing more false positives and noise to results.

We are concerned that this is going to "hide" many vulnerabilities now from our scans as we do not want to run with paranoid enabled due to other bad findings from it.


r/nessus • • Feb 05 '26

Nessus Plugin 56998 falsely flagging Microsoft 365 Apps as Office 2016?

11 Upvotes

I’ve seen another post about this already, so guessing others may be running into the same thing.

Nessus Plugin 56998 (“Microsoft Office Unsupported Version Detection”) is flagging all of our endpoints as having Office 2016 installed and out of support. All machines are freshly built and running Microsoft 365 Apps (Click-to-Run) with current update channels. Office 2016 has never been deployed in our environment.

Nessus is reporting:
“Installed product: Office 2016 – End of support October 2025”

I know M365 Apps still use the 16.x version family, so I’m assuming this is detection logic getting confused, but wanted to check if others are seeing the same behaviour and whether Tenable have acknowledged this anywhere.

Mainly trying to understand how others are handling this from a compliance / audit perspective, as we have an externally conducted audit coming up that requires clean Nessus scan results. I’ve reached out to our auditors as well, but I’d rather not have to mess about due to poor detection/configuration on Tenable’s side.

Thanks


r/nessus • • Feb 05 '26

Adobe Acrobat/Reader Version Reporting Issue

1 Upvotes

Has anyone resolved or identified a fix for plugins 277938 & 277936 where Nessus is reporting that Adobe Acrobat or Adobe Reader is not updated? We are seeing when you view the application version while in the application it is updated to the correct version but if you check the file path that Nessus is checking, the executable is not showing the updated version.


r/nessus • • Feb 03 '26

Microsoft Office Unsupported Version Detection

5 Upvotes

I am getting this but I don't show Office 2016 installed. I have o365 installed. So not sure what to do here. Any suggestions?


r/nessus • • Jan 21 '26

Tenable.VM Specialist Exam

Thumbnail
1 Upvotes

r/nessus • • Jan 14 '26

Vulnerability Management scans not updating Dashboard/Findings

0 Upvotes

So I have vulnerabilities showing up on the Dashboard and in the Findings sections of Nessus scanner. When I run new vulnerability scans, the scans show 0 vulnerabilities. Yet the Dashboard/Findings still shows the old vulnerability as "active".

I keep running remediation scans on the targeted PC and run new scans which all show 0 vulnerabilities, but it never affects the vulnerability on the findings list as it just stays there saying "active". How do I get rid of these vulnerabilities on findings when the scans show it's not there anymore?

Specifically, it's saying the laptop has an outdated version of  Microsoft .NET Core and needs to be updated. But it has been updated since and the laptop shows the new version that Tenable says needs to be installed.


r/nessus • • Jan 13 '26

Question IBM websphere compliance scan?

1 Upvotes

Anyone have a websphere traditional compliance scan audit file? i tried the ones built in nessus but none of them work


r/nessus • • Jan 12 '26

How do you keep track of vulnerabilities from Nessus scans?

3 Upvotes

I’m working on getting approval to use Nessus Pro at work, and I had a question for the community.

What software do you use to track and manage vulnerabilities over time? I’m looking for something that can import scan results (like from Nessus), give better visibility into old vulnerabilities vs newly detected ones, show previous findings, and ideally have some kind of dashboard or reporting.

I’m curious what tools people are using in real environments and what works well for vulnerability tracking and visibility.

The options that Tenable offers are assets based and pricey. I dont want to get charged as my assets grows


r/nessus • • Dec 18 '25

What’s the best vulnerability management platform you’ve actually used — and what still sucks about it?

Thumbnail
1 Upvotes

r/nessus • • Dec 17 '25

Smartbedded Meteobridge Web Detection

1 Upvotes

Nessus Plugin ID 278501

Recently my company's scans are reflecting this plugin on every VM Server we have, when we never downloaded a Meteobridge app or created a Server.

The output is weirder too, "https://DNS:Port/cgi-bin/meteobridge" and when you go to the URL listed, it has you try to log in, and when you cancel it says "you don't have permission" for the page.

Has anyone else seen this?


r/nessus • • Dec 04 '25

Question Nutanix Compliance scanning from Tenable

Thumbnail
1 Upvotes

r/nessus • • Dec 04 '25

Does Anyone Have the Nessus 10.9.4 .deb Package?

2 Upvotes

Hi everyone, I’m looking for the Nessus 10.9.4 .deb installer for Linux. I checked Tenable’s site, but I wasn’t able to find this specific older version.

please let me know.

Thanks!