Open Source
OpenVAS is an open-source vulnerability scanning tool, which means it is free to use and the source code is available for customization.
Comprehensive Scanning
It offers comprehensive vulnerability scanning capabilities, including a wide range of tests for network vulnerabilities, web application security, and compliance checks.
Regular Updates
The tool receives regular updates, ensuring that it keeps up with the latest vulnerabilities and security threats.
Community Support
OpenVAS has a strong community of users and developers who contribute to its development and provide support through forums and other channels.
Integration Capabilities
OpenVAS can be integrated with other security tools and systems, enhancing its utility in a broader security infrastructure.
OpenVAS is a good choice for those seeking a reliable and free vulnerability management solution. However, users should be prepared for a potentially steep learning curve and the need for manual configuration to tailor the scanner to their specific environment.
We have collected here some useful links to help you find out if OpenVAS is good.
Check the traffic stats of OpenVAS on SimilarWeb. The key metrics to look for are: monthly visits, average visit duration, pages per visit, and traffic by country. Moreoever, check the traffic sources. For example "Direct" traffic is a good sign.
Check the "Domain Rating" of OpenVAS on Ahrefs. The domain rating is a measure of the strength of a website's backlink profile on a scale from 0 to 100. It shows the strength of OpenVAS's backlink profile compared to the other websites. In most cases a domain rating of 60+ is considered good and 70+ is considered very good.
Check the "Domain Authority" of OpenVAS on MOZ. A website's domain authority (DA) is a search engine ranking score that predicts how well a website will rank on search engine result pages (SERPs). It is based on a 100-point logarithmic scale, with higher scores corresponding to a greater likelihood of ranking. This is another useful metric to check if a website is good.
The latest comments about OpenVAS on Reddit. This can help you find out how popualr the product is and what people think about it.
Otherwise your on the right path checkout the open source Greenbones OpenVAS (this was Nessus before they closed source and became corporate) or Project Discovery Nuclei. Source: over 3 years ago
Personally, I was lucky enough to get a license to Nessus for my own scanning, however you can use OpenVAS for some free to scan. Scanners aren't 100% correct no matter where you go but it'll give you some things to look at. OpenVAS. Source: about 4 years ago
Https://openvas.org/ OpenVAS is free and fairly capable. It might struggle cpu on a pi... Might need quite a bit of ram, but I'm hoping you've got some beefier kit in your stack. Source: over 4 years ago
Maybe OpenVAS would fill the bill. Itโs been on my list of things to check out. Source: over 4 years ago
OpenVAS - https://openvas.org Try it first, its free, just download a prebuilt VM and you're off and running. I found it valuable for my clients. Source: almost 5 years ago
Look into setting up some vulnerability scanning tools in your home network like https://openvas.org/ or https://www.tenable.com/products/nessus/nessus-essentials. Source: over 5 years ago
OpenVAS (Open Vulnerability Assessment System) continues to hold a respectable position in the cybersecurity landscape as a robust, open-source vulnerability scanning and management tool. As an established competitor among notable names such as Nessus, Burp Suite, and Acunetix, OpenVAS delivers comprehensive security testing capabilities, particularly within networks and web applications. Its primary deployment involves conducting extensive security assessments of IP addresses by performing port scans and testing identified services for vulnerabilities using a large database of Network Vulnerability Tests (NVTs).
OpenVAS is renowned for its expansive vulnerability scanning capabilities, which are facilitated through a well-documented protocol that aims to support developers and users alike. The tool's ability to perform in-depth assessments of system vulnerabilitiesโranging across a vast array of known issuesโpaints it as a reliable option for organizations seeking a free and powerful alternative to commercial security solutions. Regular updates to its data feeds ensure that OpenVAS remains current in its vulnerability detection, allowing users to execute large-scale scans efficiently and accurately. Moreover, it provides comprehensive reports that include risk assessments and recommended countermeasures.
OpenVAS enjoys largely positive feedback within various cybersecurity communities. It is often highlighted as a capable and cost-effective option for individuals and organizations not wanting to invest in proprietary software like Nessus or Burp Suite. Users appreciate its open-source nature, which offers flexibility and transparency that are sometimes absent in more commercialized products. Since most components are licensed under the GNU General Public License (GNU GPL), OpenVAS aligns well with those who advocate for open-source and freely accessible security tools.
Several practical encounters shared by users emphasize the tool's effectiveness for performing vulnerability scanning in various environmentsโfrom personal homelabs to enterprise networks. While its resource demands may pose challenges on lower-powered hardware setups, such as Raspberry Pis, it is generally well-regarded for its ability to run effectively on more robust systems.
In the context of competitors, OpenVAS is regularly benchmarked against tools like Nessus and Burp Suite. While Nessus offers a comprehensive feature set, its transition to a corporate, closed-source model has directed open-source enthusiasts toward OpenVAS as a comparable alternative. Users frequently mention OpenVAS in discussions about free Nessus equivalents or alternatives, underscoring its reputation as a go-to choice for budget-conscious security practitioners. Notably, its reliance on NASL (Nessus Attack Scripting Language) for plugin writing underscores its historical connection to Nessus's earlier development stages before the latter transitioned to a proprietary solution.
In summary, OpenVAS emerges as a mature, capable, and credible option in the landscape of vulnerability assessment tools. Its ongoing updates, extensive feature set, and open-source model ensure it remains a preferred choice across a spectrum of users seeking effective security solutions without the financial overhead of commercial offerings.
Do you know an article comparing OpenVAS to other products?
Suggest a link to a post with product alternatives.
Is OpenVAS good? This is an informative page that will help you find out. Moreover, you can review and discuss OpenVAS here. The primary details have not been verified within the last quarter, and they might be outdated. If you think we are missing something, please use the means on this page to comment or suggest changes. All reviews and comments are highly encouranged and appreciated as they help everyone in the community to make an informed choice. Please always be kind and objective when evaluating a product and sharing your opinion.