Vulnerability Scanning

Overview

This should be the first thing done before any kind of OSINT because of how long takes for scans to come back. The length can depend on the amount of IP's you have to scan and also how fast your internet speed is.

Vulnerability Scanning is for making sure there's nothing glaringly bad out there facing the internet. Most of it is going to be manual, looking for anything of value through the scan logs. Giving this extra information to the client provides more value to them.

Nessus is a great tool for automated vulnerability scanning.

Nessus Playbook

  • General

    • Advanced Scan

    • Add name and description

    • Add IP addresses in scope

    • Optionally schedule the scan

  • Discovery

    • Host Discovery - Default

    • Port Scanning

      • Scan all ports (1-65535)

    • Service Discovery - Default

  • Assessment

    • Web Applications

      • Turn on and enable generic web application tests

  • Advanced

    • Optionally change the amount of hosts scanned simultaneously

Last updated

Was this helpful?