Elektrine lite

← Feed

@JohnsNotHere@infosec.exchange

2026-08-09 01:43 UTC

What exactly am I missing? I remember OpenVAS/Greenbone being this clunky, entry-level vulnerability scanner that took forever to setup. Nessus was the gold standard, and the masochists went with Qualys or Rapid7 for different reasons. I've used Nessus, Qualys, and Greenbone for the past few years, and now I have opinions. I actually moved to Kaseya's VulScanner last year, and I loved it for all the wrong reasons. It was easy to setup as a Docker image, meaning I could install it in a VM without much fuss. It worked well, but had a habit of eating disk space. I found out after about 3 months that it's just running Greenbone/OpenVAS under the covers, albeit with a nicer UI. I was happy. I recently did some subcontracting work with another firm, and they were also using Greenbone/OpenVAS, albeit the commercial version with a commercial feed. Lots of interesting findings. I decided to scan the same systems with VulScanner, but I didn't even come up with half the results. Odd. I reached out to Kaseya, and they confirmed that they are only using the community feeds, and the specific vulnerabilities I flagged as "missing" from their scan are just not in the free feed. I was paying like $350 / month for their software. Yes, I had support and an easier UI/setup than a generic OpenVAS/Greenbone install, but the number of missing findings was shocking. I then downloaded a trial of Nessus Expert, because Nessus Professional won't let you scan external targets. Oh, and Expert is a good $2,000 more expensive for the privilege. Guess what? Same type of results as what I saw from the free feed of Greenbone/OpenVAS. So yeah, I could spend around $10.5k CAD for Nessus Expert, or about $4.5k CAD for OpenVAS/Greenbone BASIC with their enterprise feed. For the sake of my clients, I'll spend the extra cash. Seriously, am I missing something? I'm not new to Nessus, and I'm trying a few different scans to find similar findings, but no luck. Is this just a case of Tenable being comfortable in their position that they just let things slide, or am I just missing something? Great example, the target I'm scanning has an outdated version of Grafana installed. Commercial version of Greenbone/OpenVAS catches it, but the free version does not. Likewise, Nessus ignores it completely as well. A manual scan would catch it for sure, but why am I paying for a commercial tool that doesn't actually find something so basic? It's literally running on port 443 under /grafana!

Replies (1)

  • To be fair, I'm looking at this stuff form a pentesters perspective, not a corporate security perspective, so my use case is different and I'm not installing agents on my client's machines. Also this is just one part of the process, I don't take any vulnerability scanners results as the final word, but it does help speed things up if it's accurate. When stuff is missed, I have to do a deeper dive with manual checks, which just takes time that I don't always have.

    Open ##4454964