Overview
Nessus authenticates to hosts where possible, enumerates installed software, and maps it against CVE data to report exploitable findings with severity scores.\nAuthenticated scans are dramatically more accurate than unauthenticated ones, because so much is invisible without login.\nIt is widely used for compliance evidence as well as pure vulnerability management.
Indicators of Compromise
Signals that suggest this is present on a system.
- Plugin output and version banners collected from many hosts
- Scheduled unauthenticated scans hitting production
- Scanner IP ranges appearing in host logs