
Explore the fundamentals of vulnerability management for security analysts, learning types, impacts, and practical use of scanners like Nessus and Qualys to identify, assess, and remediate vulnerabilities.
Explore how CVSS base, temporal and environmental scores prioritize vulnerabilities, and run a formal vulnerability management program with continuous scans and remediation to reduce attack surface and meet regulations.
Learn five core components of vulnerability management: asset inventory, scanning and assessment, prioritization with risk assessment, remediation and mitigation, and reporting and monitoring, plus the lifecycle from discovery to monitoring.
Explore core components of the vulnerability management program, including threat modeling methodologies like STRIDE and PASTA, exploit development, vulnerability intelligence, automation, and cloud vulnerability management.
Establish secure baselines with CIS benchmarks, continuously monitor configurations, coordinate vulnerability disclosure, and enable proactive vulnerability response using SIEM, EDR, and SOAR integrations.
Master vulnerability management by using Nessus, OpenVAS, and ManageEngine Vulnerability Manager Plus to automatically scan, prioritize risk, and automate remediation across Windows, Linux, and macOS.
Set up a Metasploitable 2 lab in VMware by downloading, extracting, and configuring bridged and NAT adapters, then boot and scan with Nessus.
Register for the Nessus expert trial, download Nessus 10.9.1, and set up a lab in VMware using the Tenable Core Nessus virtual appliance (OVA/ISO/QCOW).
Set up a Nessus expert lab on VMware by importing the VM, configuring 8 GB RAM, 4 cores, and extra network adapter.
Explore the Nessus Expert dashboard by navigating scans and settings, reviewing plugins and licenses, and noting the upcoming deep dive into advanced proxy server settings.
Explore Nessus host discovery scans by creating folders and launching a Linux device scan to identify live hosts and open ports. Schedule scans and export reports in pdf or csv.
Execute a basic Nessus network scan against the Metasploitable Ubuntu host, using SSH credentials to enable full vulnerability checks and plugin validations, including unpatched and web vulnerabilities.
Analyze a basic Nessus network scan, including summary metrics, host details, vulnerabilities by severity, remediation options, and generate pdf or csv reports for prioritization.
Manage Nessus plugin tools by adjusting plugin severity, expiration, and host scope (all or specific), and build custom reports with templates, client logos such as Amazon, and remediation chapters.
Learn how Nessus policies serve as reusable templates to define scan configurations, discovery settings, credentials, plugins, and scheduling for Windows and firewall assessments.
Explore Nessus settings overview, including advanced options, proxy, remote link, smtp server, custom certificates, upgrade and password management, scanner health, logs, notifications, and update plans for vulnerability management.
Explore OpenVAS, a free, open source vulnerability scanning and management system maintained by Greenbaum. Learn how to access the free download and choose installation options for VMware or Oracle VirtualBox.
Install and configure OpenVAS in a VMware environment, create a web user, skip licensing, and access the Greenbone dashboard at 192.168.1.11 for vulnerability scanning.
Learn to scan with OpenVAS, configure host discovery scans, create targets and tasks, define custom port lists and ping types, and use credentials for deeper checks.
Learn how OpenVAS performs a full and fast end-to-end vulnerability scan, using diverse NVTs, targets, and credentials, and generates actionable reports with vendor fixes, workarounds, or mitigations.
Explore OpenVAS assets and host inventory, including IP, hostname, operating system, and TLS certificates. Explore information, including NVT feeds, CVSS details, and vendor fixes, and learn how exports support reporting.
Manage openvas administration by creating users, groups, and roles; assign permissions and enforce least privilege, then monitor performance, thresholds, and feed status for secure vulnerability management.
Explore OpenVAS resilience: create and apply compliance policies, run targeted audits on windows devices, review audit reports for compliance against benchmarks, and note remediation limitations in the free version.
Explore the OpenVAS help section and learn how CVSS versions 2, 3, and 4 assess vulnerabilities using vector components, access, and impact metrics for effective risk prioritization.
Learn to configure OpenVisor general settings, including time zone, time and date formats, language, rows per page, defaults, and filters, for tailored vulnerability scans.
Explore ManageEngine's vulnerability manager plus (VMP): perform vulnerability assessment, risk-based prioritization, patch management, and compliance reporting with an agent-based architecture.
download, install, and configure the VMP server in the lab, then deploy the agent on a system to enable vulnerability scanning via agent-based or network-based methods.
Review the VMP dashboard overview, tracking vulnerabilities, fixable patches, misconfigurations, and threats with CVEs. See how the local agent and admin panel enable patch deployment and reporting.
Manage patches across Windows and third-party apps with vulnerability management using VMP. Learn to scan, deploy, and re-scan patches for software like VLC and Sublime Text, validating installations.
Deploy security misconfigurations on local and remote systems, configure settings, and validate web server misconfigurations with scans, resolutions, and notification emails.
Explore the reporting session in VMP, delivering executive asset and threat summaries, patch status, and high priority vulnerabilities for stakeholders. Discover how to export, schedule, and customize reports.
Automate patch deployment and automated reporting in vmp, covering microsoft updates and installed applications, with scheduled reports delivered by email.
Resolve VMP issues using the built-in AI chat, the official VMP guide and product pages, and select YouTube videos. Share unresolved problems in the course comments for expert help.
Create compliance policies in VMP by forming Windows systems target group and policy group with audit. Configure quarantine policies to isolate compromised devices, block network access, and send alerts.
This course is designed to provide a practical and structured approach to Vulnerability Management for Security Analysts, covering both foundational concepts and real-world tool-based implementation.
You will begin by understanding core principles such as vulnerability lifecycle, risk assessment, CVSS scoring, and prioritization strategies. The course then moves into hands-on training with industry-relevant tools including Nessus, OpenVAS, and ManageEngine Vulnerability Manager Plus (VMP), giving you practical exposure to how vulnerabilities are identified, analyzed, and remediated in real environments.
You will learn how to perform vulnerability scanning across endpoints and networks, interpret scan results, and eliminate false positives. The course also focuses heavily on patch management, security misconfiguration detection, and compliance enforcement, which are critical skills for modern security analysts.
Additionally, you will explore automation techniques to streamline vulnerability workflows, generate professional reports, and track remediation progress effectively. Integration concepts with SIEM, ITSM, and security operations workflows are also covered to align with real-world SOC environments.
By the end of this course, you will be able to confidently manage vulnerabilities across systems, prioritize risks based on impact, and implement effective remediation strategies to improve an organization’s security posture.
This course is ideal for aspiring security analysts, SOC analysts, and IT professionals looking to build strong, job-ready vulnerability management skills.