Software Alternatives, Accelerators & Startups

OpenVAS

The Open Vulnerability Assessment System (OpenVAS) is a framework of several services and tools...

OpenVAS

OpenVAS Reviews and Details

This page is designed to help you find out whether OpenVAS is good and if it is the right choice for you.

Screenshots and images

  • OpenVAS Landing page
    Landing page //
    2023-03-22

Features & Specs

  1. Open Source

    OpenVAS is an open-source vulnerability scanning tool, which means it is free to use and the source code is available for customization.

  2. Comprehensive Scanning

    It offers comprehensive vulnerability scanning capabilities, including a wide range of tests for network vulnerabilities, web application security, and compliance checks.

  3. Regular Updates

    The tool receives regular updates, ensuring that it keeps up with the latest vulnerabilities and security threats.

  4. Community Support

    OpenVAS has a strong community of users and developers who contribute to its development and provide support through forums and other channels.

  5. Integration Capabilities

    OpenVAS can be integrated with other security tools and systems, enhancing its utility in a broader security infrastructure.

Badges

Promote OpenVAS. You can add any of these badges on your website.

SaaSHub badge
Show embed code

Videos

How to find Exploits with OpenVAS

Vulnerability Analysis with OpenVAS | Scanning and Reconnaissance

Vulnerability Identification and Remediation Cybrary Lab | Ep. 3 Kali Linux, OpenVAS, + more

Social recommendations and mentions

We have tracked the following product recommendations or mentions on various public social media platforms and blogs. They can help you see what people think about OpenVAS and what they use it for.
  • Link CVE to installed applications?
    Otherwise your on the right path checkout the open source Greenbones OpenVAS (this was Nessus before they closed source and became corporate) or Project Discovery Nuclei. Source: over 3 years ago
  • What should I be doing as the sole sysadmin for a company to keep up with security?
    Personally, I was lucky enough to get a license to Nessus for my own scanning, however you can use OpenVAS for some free to scan. Scanners aren't 100% correct no matter where you go but it'll give you some things to look at. OpenVAS. Source: about 4 years ago
  • Wanting to protect my own homelab
    Https://openvas.org/ OpenVAS is free and fairly capable. It might struggle cpu on a pi... Might need quite a bit of ram, but I'm hoping you've got some beefier kit in your stack. Source: over 4 years ago
  • Free nessus equivalent?
    Maybe OpenVAS would fill the bill. Itโ€™s been on my list of things to check out. Source: over 4 years ago
  • Internal Vulnerability Scanning
    OpenVAS - https://openvas.org Try it first, its free, just download a prebuilt VM and you're off and running. I found it valuable for my clients. Source: almost 5 years ago
  • Unable to finish my eng degree and trying to get into cyber security full time.. Is it doable?
    Look into setting up some vulnerability scanning tools in your home network like https://openvas.org/ or https://www.tenable.com/products/nessus/nessus-essentials. Source: over 5 years ago

Summary of the public mentions of OpenVAS

Overview of OpenVAS in the Industry

OpenVAS (Open Vulnerability Assessment System) continues to hold a respectable position in the cybersecurity landscape as a robust, open-source vulnerability scanning and management tool. As an established competitor among notable names such as Nessus, Burp Suite, and Acunetix, OpenVAS delivers comprehensive security testing capabilities, particularly within networks and web applications. Its primary deployment involves conducting extensive security assessments of IP addresses by performing port scans and testing identified services for vulnerabilities using a large database of Network Vulnerability Tests (NVTs).

Features and Capabilities

OpenVAS is renowned for its expansive vulnerability scanning capabilities, which are facilitated through a well-documented protocol that aims to support developers and users alike. The tool's ability to perform in-depth assessments of system vulnerabilitiesโ€”ranging across a vast array of known issuesโ€”paints it as a reliable option for organizations seeking a free and powerful alternative to commercial security solutions. Regular updates to its data feeds ensure that OpenVAS remains current in its vulnerability detection, allowing users to execute large-scale scans efficiently and accurately. Moreover, it provides comprehensive reports that include risk assessments and recommended countermeasures.

Public Perception and Community Feedback

OpenVAS enjoys largely positive feedback within various cybersecurity communities. It is often highlighted as a capable and cost-effective option for individuals and organizations not wanting to invest in proprietary software like Nessus or Burp Suite. Users appreciate its open-source nature, which offers flexibility and transparency that are sometimes absent in more commercialized products. Since most components are licensed under the GNU General Public License (GNU GPL), OpenVAS aligns well with those who advocate for open-source and freely accessible security tools.

Several practical encounters shared by users emphasize the tool's effectiveness for performing vulnerability scanning in various environmentsโ€”from personal homelabs to enterprise networks. While its resource demands may pose challenges on lower-powered hardware setups, such as Raspberry Pis, it is generally well-regarded for its ability to run effectively on more robust systems.

Comparisons with Competitors

In the context of competitors, OpenVAS is regularly benchmarked against tools like Nessus and Burp Suite. While Nessus offers a comprehensive feature set, its transition to a corporate, closed-source model has directed open-source enthusiasts toward OpenVAS as a comparable alternative. Users frequently mention OpenVAS in discussions about free Nessus equivalents or alternatives, underscoring its reputation as a go-to choice for budget-conscious security practitioners. Notably, its reliance on NASL (Nessus Attack Scripting Language) for plugin writing underscores its historical connection to Nessus's earlier development stages before the latter transitioned to a proprietary solution.

In summary, OpenVAS emerges as a mature, capable, and credible option in the landscape of vulnerability assessment tools. Its ongoing updates, extensive feature set, and open-source model ensure it remains a preferred choice across a spectrum of users seeking effective security solutions without the financial overhead of commercial offerings.

Do you know an article comparing OpenVAS to other products?
Suggest a link to a post with product alternatives.

Suggest an article

OpenVAS discussion

Log in or Post with

Is OpenVAS good? This is an informative page that will help you find out. Moreover, you can review and discuss OpenVAS here. The primary details have not been verified within the last quarter, and they might be outdated. If you think we are missing something, please use the means on this page to comment or suggest changes. All reviews and comments are highly encouranged and appreciated as they help everyone in the community to make an informed choice. Please always be kind and objective when evaluating a product and sharing your opinion.