Basic Vulnerability Management

Using Tenable Nessus Server

After downloading the installer file from the Nessus website, I checked the file hashes against the hashes provided by the vendor.

1

2

I then double-clicked on the installer and followed the instructions as prompted.

3 4
5 6
7 9

The installer prompted the web application where I configured & registered for Nessus Essential.

10 11
12 13
14 15

Then I waited about 10 mins for the plugin to be compiled after which I manually updated the plugins.

16

17

To get started, I was prompted to launch a host discovery scan to identify my laptop.

18

Then I started basic network scan that I named the “Maccy Mac Scan” with the target being my laptop. Under the “Assessment” tab, I changed the Scan Type to “Scan for all web vulnerabilities (quick)” before saving and starting the vulnerability scan.

19 20
21 22
23 24

25

The scan was ready after 16 mins.

26

Vulnerability Scan Result

27 28

Remediation 1

29 30

Remediation 2 Changed the Nessus configuration of the SSL Cipher List to only allow “NIAP Approved Ciphers”

31 32

33

Then I started another basic network scan that I named the “Maccy Mac Validation Scan” with the target being my laptop. Under the “Assessment” tab, I changed the Scan Type to “Scan for all web vulnerabilities (quick)” before saving and starting the vulnerability scan.

34 35
36 37

38

The scan was ready after 7 mins and the vulnerabilities were remediated.

39 40