Vulnerability Scanning
Overview
This should be the first thing done before any kind of OSINT because of how long takes for scans to come back. The length can depend on the amount of IP's you have to scan and also how fast your internet speed is.
Vulnerability Scanning is for making sure there's nothing glaringly bad out there facing the internet. Most of it is going to be manual, looking for anything of value through the scan logs. Giving this extra information to the client provides more value to them.
Nessus is a great tool for automated vulnerability scanning.
Nessus Playbook
General
Advanced Scan
Add name and description
Add IP addresses in scope
Optionally schedule the scan
Discovery
Host Discovery - Default
Port Scanning
Scan all ports (1-65535)
Service Discovery - Default
Assessment
Web Applications
Turn on and enable generic web application tests
Advanced
Optionally change the amount of hosts scanned simultaneously
Last updated
Was this helpful?