
Learn to use OpenVAS as a vulnerability manager, scanning targets, analyzing reports, and prioritizing fixes. Explore asset management, business process mapping, user roles, and chart-driven risk to strengthen your network.
Discover the updated OpenVAS interface, including the left-side menu, and note that some options were removed in the new version. Ensure the training stays up to date through 2026.
Illustrates the GVM architecture for Greenborne Vulnerability Manager versions 20.08 and 21.04, detailing browser access via the Greenborne Security Assistant and command-line access via Greenborne Management Protocol clients.
Discover the updated Greenbone Community Edition architecture (version 22.4) with a no scanner, note scanner, and Json-based scans that focus on affected patches for faster performance.
Explore the vulnerability management life cycle: plan scans, identify operating systems and services, classify findings by severity, assign remediation tasks, verify fixes, and continuously improve security.
Download the latest virtual machines and tools from the provided links, including VirtualBox, Kali Linux, and Metasploitable 2, and set up the Greenburn security manager as the environment.
Learn how to download VirtualBox from the updated site and install the extension pack, and discover the OpenVAS Free download process via email with VMware or VirtualBox links.
Install virtualbox, import kali linux and gsm virtual machines, adjust memory configurations, and create a metasploitable virtual machine from an existing disk image to complete the setup.
Launch Kali Linux and Metasploitable, update and upgrade packages, configure a bridged network to obtain an IP, then log in and access Metasploit.
install and set up GVM (OpenVAS) on Kali Linux, create the admin user, verify the setup, fix configuration issues, and access the web interface at 127.0.0.1:9392.
Change your password in settings by entering the old password and a new one. Reset a forgotten password via a terminal command, then log in with the new password.
Access in-app help and the user manual to learn about reports, dashboards, and resilience. Open the help icon, view per-tab manuals, and use the task wizard to create tasks.
Provide updates on gsa/openvas version 22.4, including the login page, the updated user manual, and changes to the help tab and architecture.
Compare commercial and community versions of Green Born Solutions; commercial offerings include physical and virtual appliances with professional support and cloud options, while community versions run on Kali Linux.
Explore the open vars.org community forum to sign up, view FAQs, and find solutions for vulnerability tests by filtering categories and versions like CVM 20.08 or 21.04.
Learn how to find solved issues efficiently by filtering with category and tags in the Greenborne Professional edition, then use the tag solver to search keywords like 'connection refused'.
Explore the updated OpenVAS community portal and forum design, with install, troubleshooting, and upgrade guidance, plus build-from-source options and admin password changes.
Explore the CVSS calculator, its two versions, and how the common vulnerability scoring system classifies severity using access vector, access complexity, authentication, and confidentiality, integrity, and availability.
CVSS calculators determine vulnerability severity across three options, including legacy version two, the second option used by most scanners, and version four for future proofing, with risk tolerance shaping outcomes.
Manage Nvidia, Scapy, and CPU feeds from the administration feed status page and perform updates via terminal commands to keep all feeds current.
Understand the legal prerequisites for using Openvas: obtain written permission, document scope, and anticipate logs, IDS alerts, latency, and potential impacts on devices and services.
Learn how SCAP enables security content automation with the national vulnerability database, CVSS scoring, CPE, and OVAL, guiding vulnerability management and risk management framework preparation, implementation, and monitoring.
Openvas uses NVT scripts to detect vulnerabilities during scans, classifying findings by severity, family, and creation time, and presenting solution types to mitigate issues.
Identify a target's hardware, operating system, and applications via common platform enumeration (CPEs) in a Kali Linux OpenVAS scan, with vendor, product, version, language, and severity levels.
Learn to identify zero-day vulnerabilities by Siva numbers, searchable by the unique identifier, and assess risk using the description, publication date, CVSS base vector, and severity.
Learn how to request a CVE ID for a new vulnerability by locating the CNA, contacting them, and submitting a web form with details and optional encrypted responses.
Explore the four main classes of oval definitions—vulnerability, compliance, inventory, and patch definition tests—and how they assess software presence, configurations, and required patches.
Understand why the updated oval definitions in 5.1 SecInfo show missing overall definitions, because legacy features are removed, and learn where to find the source code release and learning resources.
Cert-bund and dfn-cert advisories present vulnerability information, associated CVEs, severity, and remediation guidance, with links and charts to explore advisory details.
Master basic Linux commands like pwd, ls, cd, mkdir, touch, cp, rm, nano, and locate in Kali Linux, noting case sensitivity and file navigation for efficient system exploration.
Learn to create and manage scan tasks with the task wizard in Greenborne Security Assistant, generate reports, view vulnerabilities, and explore results, hosts, ports, and trends.
Learn to create and configure advanced task wizard scans in OpenVas with Kali Linux, selecting full and fast scan to reveal vulnerabilities, and schedule targets by time zone.
Master the advanced task wizard's log4shell scan config to detect this high-severity vulnerability using deep, authenticated checks and focused web server scans.
Learn how authenticated scans use credentials in OpenVAS to assess targets like Windows Server, using ssh, smb, and esxi credentials, and how to configure email reports and tasks.
Learn to modify tasks with the Modify Task Wizard, selecting a task to adjust options like schedule, time zone, and email, and set the start date and time for scans.
Create a new task and target, add hosts by IP or IP range, set scan targets, and learn to scan networks with Nmap for host discovery.
Learn to specify targets in OpenVas by using IP addresses, host names, or IPv6 in long and short formats, and to scan an entire network.
Explore IANA port lists and understand how IANA assigns official TCP and UDP ports, with references to Nmap top 100 UDP ports and how to view port details.
Run a live test to determine if the host is online or offline by default. Use icmp ping, tcp service ping, tcp syn ping, and arp ping to assess status.
Create and manage credentials for SMB and other services, test connections, and choose reverse lookup options to control how DNS resolves targets during scans.
Create a new alert, name it, and set conditions such as task run status change to done or ticket received, choose delivery methods and options like severity and delta report.
Configure SMB alert delivery by creating credentials for a shared Windows folder, specifying the target path, selecting PDF report format, and activating alerts for scan results.
Test the alert to SMB by starting a scan from Kali, monitor progress to completion, and verify the scan report and alert delivery in GBM reports on Windows.
Create and configure a scan schedule by naming it, setting the time zone, choosing first run details, and selecting recurrence options such as hourly, daily, weekly, or custom.
Configure openvas default to detect vulnerabilities with and without cvar numbers, set host discovery with a network interface, and apply overrides, alterable task, and newest five report retention before saving.
Explore how alterable tasks in OpenVas let you modify targets, alerts, and schedules after creation. Learn when these changes are blocked once a scan starts.
Create and manage a container task in OpenVAS to group reports from multiple scans, import XML reports across offices, and organize them under a single container.
Review the task overview: interpret charts by severity, monitor task status and last reports, and learn to clone, edit, export, or delete tasks, plus definitions of task statuses.
Explore using nmap as a network scanner to discover live hosts, detect open ports, operating systems, and services, then scan networks, filter IPs with grep, and save targets for openvas.
Explore how Nmap and Wireshark reveal the three-way handshake and host availability, comparing scan methods and firewall effects, with hands-on captures and TCP stream analysis.
Create a new target under configuration targets, name it target one, enter an IP address, select the last alive port list, save, then use it when creating a task.
Create and customize port lists by adding new port lists, naming them, and importing from files. Configure TCP and UDP ranges, save changes, and reuse or clone existing lists.
Create credentials by opening configuration credentials, adding a new credential with user plus password, and saving. Edit or clone as needed; deletion is blocked when the credential is in use.
Create and customize scan configurations in openvas, name scans, select network modes like fast or full, and manage trends and vulnerability tests.
Install postfix on Kali Linux, configure the SMTP relay, and test email alerts to verify sending from the mail server.
Test postfix alerts with the Greenborne security assistant by configuring an email alert, attaching a PDF report, and sending it when the scan status changes to done, with customizable subject.
Troubleshoot alert delivery in OpenVas on Kali Linux by ensuring postfix is running, inspecting the mail log for errors, and using postfix resources to resolve issues.
Create and manage schedules for OpenVas scans by naming each schedule, setting the time zone, and choosing recurrence options from hourly to custom weekly or monthly with exact day selections.
Review report formats in the Greenborne Security assistant, including names, extensions, and content types; import, digitally sign, and activate formats after Greenborne Networks approval.
Learn how OpenVAS scanners work in Kali Linux, noting community version limits on certificates and edits, while you verify and export scanners using host, port, and credentials.
Create and apply filters in OpenVas to tailor displayed results by type and syntax. Configure per-page results, sorting, and default filters to control what you see.
Explore the filter syntax in openvas, using keywords and time specifications to refine results. Set object, rows per page, and sort by severity, using equals or contains to target hosts.
Learn to filter vulnerabilities in OpenVas by creation date, including 2024, adjust page size, and sort by severity to view results such as Invictus efficiently.
Create and associate tags with targets, such as hosts, to link information to objects. Use the tag syntax tag equal and apply filters to display resources associated with a tag.
Configure openvas for external access on the local network by binding to 0.0.0.0, restarting the server, and connecting to the greenborne security assistant via the LAN IP on port 9392.
Create and manage users in the OpenVAS security assistant by assigning roles, host access, and authentication types; clone users and configure permissions.
Create and manage groups by adding users, assigning roles, and granting full read/write access across group members. Configure host access by IPs and interfaces and review group membership.
Create and customize roles by cloning or editing predefined rules, assign users and permissions, manage create alert and schedule permissions, and grant group super permissions.
Create custom permissions in OpenVas by defining the permission name, description, resource type, subject type, and actions, then save to assign to a user, rule, or group.
Explore the performance tab to view charts of system load, CPU usage, and hard disk activity during scans, adjust the time window, and review the captured performance.
Navigate to administration and Reg scan to view deleted credentials, targets, and tasks, and restore them as needed. Only done status tasks can be restored; empty trash permanently deletes items.
Learn to open and review Metasploitable scan reports, inspect task details, and navigate the results to view detected vulnerabilities. Understand end-of-life detections and the recommended upgrade solution to mitigate risks.
OpenVas basic to advanced with Kali Linux covers vulnerability solution types including vendor patches, workarounds, and configuration mitigations, and how to interpret detection codes and results.
Explore OpenVAS reports by mapping hosts, IPs, ports, and detected applications to vulnerabilities, severities, CVEs, and TLS certificates for actionable remediation insights.
Explore how to generate and manage OpenVAS scan reports, view vulnerabilities and certificates, apply filters, and download PDFs, while setting alerts for future scans and sharing results with supervisors.
Manage assets in OpenVas by reviewing hosts, operating systems, and TLS certificates; view host details, export data, and analyze severity across hosts and OS.
Open the results and vulnerabilities sections to view all scans, compare with a single-scan report, and filter by severity to inspect vulnerabilities by name and host.
Create notes to annotate vulnerabilities for specific users or groups in OpenVAS, either from the scans notes tab using an ID, or from results and reports.
Master how to create and apply overrides in openvas, change vulnerability severities, and attach notes to results. Enable overwrites to include overrides in final reports.
Learn to filter OpenVAS reports by severity or keywords, such as passwords or Ubuntu, download filtered reports, and view vulnerabilities limited to your keywords.
Learn to create and interpret delta reports to compare two scans of the same task in OpenVAS, using filters for gone, new, same, and change, and download the delta results.
With the growing number of cyber attacks, system invasions, data theft, malware attacks such as Ransomware among others, vulnerability management to prevent invasions and ensure information security has become an indispensable task for IT professionals and organizations in general. In addition to implementing security mechanisms to protect oneself, it is necessary to know the vulnerabilities and deal with them. The issue of vulnerability management is so serious that even in the phase of a penetration test or cyber attack, the phase that precedes the invasion, is the discovery of vulnerabilities, i.e. when an attacker wants to attack a system, he will need to know the vulnerabilities and after knowing them, exploit them. Therefore, in this course you will have the opportunity to learn how to find the vulnerabilities in systems, find solutions, and elaborate a mitigation plan for them and implement countermeasures with the best practices guide according to the Center for Internet Security (CIS Control Set), an entity that works to support organizations to implement best practices for asset management and data backup. It is important to know how vulnerability scanners work for better positioning when it comes to decision making after analysis. After completing this course, you will be able to implement and manage OpenVas as well as assign tickets to the different people responsible for each department where vulnerabilities are detected as well as to IT professionals.