Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Nice way to use .nessus files on linux command line?

Subject: Nice way to use .nessus files on linux command line?
Date: Wed, 21 Nov 2007 14:58:28 +1030
Hello,

 

I would like some assistance with a 'nice way' to setup automated scanning. I 
have RTFM and found it not overly useful (or i missed the pertinent bits), and 
browsed through the last 4 months of mail archives.

 

I have Nessus 3.0.6 setup on a (Vmware) SLES server, with some Windows Clients 
and also Linux Clients connecting to it and performing scans (manually) and it 
works great.

One of the windows clients has setup the plug-in policies (30 different 
groupings) and also all the network segments (100+) and has exported them to 
.nessus files.

 

How can I then make use of these files to automate the scanning from Linux? (I 
can just run them from the GUI Client and its fine, but I want it automated as 
well)

 

Is there anyway to have a target file exported from the Windows Client, _and_ a 
separate plug-in policy file? 

 

What I would like to do, is scan one network with some plug-ins at (x)Hours 
then another network with the same plug-ins at (y)Hours, and so on and so on.

 

But I would also then like to go to specific defined hosts and use different 
plug-ins with different plug-in credentials, again scheduled.

 

I understand I can do scans from the command line, but my use of them doesn?t 
show me a way to do what I want.

 

Then from the command line you can combine any combination of target and policy 
file?

If not, is there any other suggested methods of achieving the same thing?

 

Once I have that I will just put each command into cron have it output to a 
specific file and be read by our security admins and our SIEM.

 

 

Thanks.

 
Michael







_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>