
Learn to set up a lab, install Nessus, perform vulnerability scanning and discovery, review results, and explore an exploitation example using Metasploit.
Explore vulnerability scanning with Nessus within a comprehensive penetration testing roadmap. Build skills in ethical hacking, reconnaissance, enumeration, exploitation, and report writing across interconnected courses.
Join the vulnerability scanning with Nessus for penetration testing course, presented by Central InfoSec, and begin your learning journey.
Connect with us on LinkedIn and X to follow central InfoSec for training updates and CTF events, and to engage with professionals in the vulnerability scanning community.
Learn how proper authorization, in writing, governs legal versus illegal vulnerability testing, guided by the Computer Fraud and Abuse Act (18 U.S.C. 1030), the Morris worm case, and state laws.
Set up Metasploitable 2, a vulnerable Ubuntu VM, in VMware or VirtualBox with host-only networking; download and unzip the file, log in as MSF admin, and find IP with ifconfig.
Explore how Tenable Nessus, a comprehensive vulnerability scanning tool, identifies vulnerabilities and misconfigurations across networks, systems, and applications using agentless and agent-based scanning.
Use Nessus for asset discovery and inventory of network devices, identify rogue devices, assess security posture, prioritize vulnerabilities, and support IT asset management and compliance with PCI-DSS, HIPAA, and GDPR.
Download Nessus from the Noble.com website and choose Linux Debian amd64. Navigate to the downloads folder and install Nessus.
Start the nest service with systemctl start nest, then open Nessus in your browser at https://127.0.0.1:8834 and register to view the Nessus login screen.
Log into Nessus and create a new scan from the My Scans dashboard. Explore templates by category—discovery, vulnerability, and compliance—covering host discovery, basic network scans, and PCI audits.
Configure a host discovery scan in the Nessus scan setup page, name it Discovery Scan, add a description, choose a folder, and specify targets.
View Nessus scan results, including the scan summary with vulnerabilities count, template, start and end times, and the vulnerabilities and host tabs for per-host severities and remediations plus history.
The Nessus 19 506 plugin displays information about the scan and shows critical details for every tested host, including scan type, policy name, port scanners, and port ranges.
Nessus scan results show critical findings: a bind shell backdoor, NFS information disclosure, Unix OS, and vnc with a default password; tomcat ajp injection and ssl weaknesses; tls 1.2/1.3 recommended.
Create branded Nessus reports for internal teams or clients in HTML, CSS, CSV, or PDF formats, and select templates and columns to list vulnerabilities by host.
Welcome to your Vulnerability Scanning with Tenable Nessus & Penetration Testing course! Throughout this course, you will learn techniques that hackers use to attack and penetrate computers and networks. You will learn Cyber Security, Ethical Hacking, Penetration Testing, and Nessus. You will learn about ethical hacking and penetration testing. You will also discover just how easy a cyber criminal could break into your own network. Furthermore, you will gain a comprehensive understanding of cyber attacks. After understanding how a hacker thinks and performs an attack, you will instantly be able to better defend your own computer and network from hackers. You will learn the importance of security along with highly desired skills that could boost your career. How would you like to land a job that pays you to ethically hack and perform penetration tests from your very own house?
Do you value the privacy of your own home network? Imagine the comforting feeling that your computer and network is more secure from attacks because you know how to test the strength of your own computer and network using the amazing skills that you learned in this course. Act now to protect your wealth before it is too late and you become victim to another cyber attack.
This course covers a broad range of cybersecurity, ethical hacking and penetration testing topics.