Categorie:
Software de segurança de rede /
Software de gerenciamento de vulnerabilidades /
Nessus Reveja
Excelente | |
Boa | |
Média | |
Mau | |
Horrível |
Built for security practitioners, by security professionals, Nessus Professional is the de-facto industry standard for vulnerability assessment. Nessus performs point-in-time assessments to help security professionals quickly identify and fix vulnerabilities, including software flaws, missing patches, malware, and misconfigurations. With features such as pre-built policies and templates, group snooze functionality, and real-time updates, it makes vulnerability assessment easy and intuitive.
Slightly expensive, tough to view reports all in one place unless using tenable.io software
Lacked reporting module that helped show more of the picture for non technical people and pretty graphs. To get those you needed to move to Tenable.io or SecurityCenter.
Very easy to use. Very easy to configure a scan. Very easy to export a report and data about a scan. Very easy to customize scan templates. You can also create your own audit templates, so you can customize this tool for the specific policies of the organization. If you get to know the ins and outs of the scanner, you can get the most value from it.
Most of the time the documentation is incomplete if you get picky with the use cases. Support via Tenable Support Portal has been very slow lately, it seems like if they had a single person to handle all the support cases they have everyday. It used to be slow, but that's been improved a lot in the latest version I've used (7.0.2).
Ease of use and simplicity. Rarely have had to reference online documentation. They make it very easy to figure out and use right away. For more specific sets of scans or devices, the documentation is helpful. There is also a very active community on their forums. Reporting is very informative, and scheduling makes it so you don't have to interact much after everything is all set.
Sometimes there are some false positives that take time to realize. Also seems to think many of the things they mark as medium risk are low risk. This depends on your situation and network, but for me most of the medium risks can be disregarded.
We use Nessus because is very good tool to manage you vulnerabilities. Fast scan and easy to make reports and to monitor vulnerabilities. Easy to adjust the profile scan, easy to add scan targets. Good price and a lot of features.
We did not find any problems with the Nessus vulnerability management.
Easy to set up, use and report on. We started using this application after our first major client security audit a few years ago. It's a been great tool.
Not much to dislike with Nessus. Maybe some better reports, and the cost could always be better, although it's not bad.
This is really helpful me to scan and fix the compliance and patch audit of our servers.
The ultimate result sheet is pretty good.But need more diagrams to display the final results.
Some things on the website are rather slow, and there could be better flexibility to manage older data, like from hosts that are no longer in service.
It supports from simple host discovery scans to detailed vulnerability scans like malware scan, credential path audit. This tool can also perform scan to test the latest vulnerabilities like Meltdown and Spectre and WannaCry ransomware etc.
The professional version of this tool is very costly.
is a great product to scan systems for vulnerabilities, nice GUI and easy to manage. customer support has also been great to us
I would have like that it had more documentation and books about this tool to take out the most of it.
- Ease of use for non-authenticated scans
- Needs improvement in case of web application scan and authenticated scan.
Without more than basic setup the scans can be picked up by virus scanners.
Nessus is a vulnerability Scanning tool helps to identify Known Vulnerabilities, Malware, Patches and etc. There is a free trial version every use can use. Nessus can work under any OS version. It is very helpful to protect our PC and Servers from any fraud or threat. Simply it’s very effective and compliance with user preference.
In the paid version includes more features than trial one but license cost is higher. It takes too much time to scan security devices.
That I can analyze networks, web applications, elements in the cloud and customize the type of output or analysis that will be executed, either manually or I can program it.
So far the tool has covered my expectations. So far the tool has covered my expectations. I usually use it to perform advanced scans where I can select which elements I want to enable.
Sometimes can take a few scans to recognise that all the vulnerabilities have been addressed on an assest
That it was really easy to implement and use
The reports are very basic and need to improve.
Very handy, powerful and easy to use software for vulnerability scanning. This can be also utilize for web application scanning and system configuration review. One can schedule the scanning and get the report. It gives standard and custom reports which are helpful for presentation purpose. Nessus scanning reports suggest the required patch for their respective vulnerabilities. To get the best possible result plugins should be up to date with latest release.
Report doesn't show in graphical format. It doesn't scan system with 2FA enabled.
It is easy to use very intuitive, completely modular, mature and highly scalable from small networks to operational networks critical for security
The License schema need be modular according to the user's need.
Really comprehensive and tons of scan and reporting options, easy to start a basic scan or get into the weeds with customizing a more complex scan
The cost, the more advanced options are harder to set up and not always clear exactly what you are doing
The soft is very useful to identify and manage vulnerabilities. The implementation was fast. Easy to scan and easy to generate reports. Predefined report for the management. Also you can generate compliance reports.
We did not find problems. Nessus is working very well.
A very low false positive rate and a very intuitive interface
It would be desirable to make comparisons possible between different audits over time
Nessus is very easy to use and it houses a lot of known vulnerabilities. Reporting from a scan couldn't be easier. Timely updates are also necessary for any vulnerability scanner worth its salt, and Nessus updates regularly to cover any emerging threats in a timely manner.
For the paid version its pricey but you can't put a price tag on keeping things secure. My experience lies in the free version that is available for home use. It requires you to request a key, which is fine but it took close to 3 days for the email to be sent with the key. I'm hoping this was a fluke but it was unfortunate.
Easy to use and configure no matter if you are not an expert on the vulnerabilities topics. The dashboard gives you a real time data about the risks on your network . You can integrate this solution with for example ServiceNow to improve your Sercurity Response Times.
You must know that as any sotware that goes through the network you must have valid credentials is order to obtain good results.
Easy to use. Quick and qualitative scan. Ideal vulnerability manager.
Require too much hardware resources. But the scanner is very fast.
I am still new to Nessus and have not experienced any negative results while using the tool through my training and testing.
Easy to use . Smart user interface. Perfect for beginners.
Can not use Nessus to detect Web application vulnerabilities
We are currently trying out Tenable.io and using the Nessus scanner to run local vulnerability scans and remediation at our company. I like the ease of setup and use of the Nessus scanner and the detailed reporting that is available with Tenable.io (cloud version).
The Nessus scanner does utilize a lot of system resources and the scan (less than 50 nodes) can take up to 2 days to complete. It would be nice if the scan was faster.
Simple interface, even end-user can use it. Easy to install.
Everything is good, but since they stop nessus manager, I can not find the way to do automation.
Nessus is great about releasing new plugins for vulns. It's lightweight and has an agent option or a hardware scanner option. The cost is pretty standard.
The reports that tenable can generate are lack luster at best. We use the API to pull the info we want, but that takes more work and development time than we like
It is relatively straightforward to scan an entire enterprise network due to the ease-of-use with the policies that are available. Customized creation enhances the overall process.
Configuration expertise is required when it comes to specifically tailored assessments in separate domains. This can be slightly tedious with expected results; but once you get it right, the scans are highly effective.
You have to have a powerful rig to get the most out of this software since it's a bit CPU hungry. It'll get days to run a scan for 100 hosts if you have low end system.
Without the local client or group policy that shuts off wifi when your on wired you may get hit with 2 licenses per device because it sees both the wireless and wired instance. Something to know going into it if you are buying.
Tenable products dictates market standard for securty assesment. Nessus Profesional is part of that family. It has simillar capabilities like Tenable.io but can be run inside your datacenter as a stand alone solution. It's easy to configure, reliable and what's most importand it will give you a hint how to solve every voulnerability detected inside your infrastructure.
It misses some interesting predefined reports and usefull configuration options comparing to Tenable.io.
I use this scanner often to scan web application and also to run other scans. It provides the best results and it is really helpful as this also saves some time. There's are variety of scanning types available in this scanner and after scanning it gives a full report including the url when scanning a web application.
It takes a really long time when doing a scan but
This product is one of the best network scanners on the market. After properly installing the server with the scanner in the network and placing the credentials of the administrator, the system works perfectly. Vulnerability scanning and compliance scanning are executed properly, all the standards included in Nessus are very useful.
The vulnerability scanner is not totally accurate in some situations and some results must be checked to verify the vulnerability. Therefore, it is possible that there are false positives. Many times the supplements are not updated in a timely manner and this hurts even more with the false positives generated.
- Web interface might sometimes be tricky when sharing scans between multiple users
Nessus and its graphical interface is attractive, I would say that minimalist but punctual and charming, it is very clean, it should be applauded that in each version they improve it and include some types of scans that can bring you more complete results when you carry out an analysis. It is very remarkable that the plugins in your database are up to date and that your community generates an adequate response on time.
For now all the experience I have with Nessus has been nice, with the constancy that you have in your team working every day to improve it I know it will be a good tool for vulnerability detection.
Took some tuning to get reporting correct.
Very frequent vulnerability database updates
Some false positives
Some of the templates can be abit basic, but these can be edited to suit.
It's Simplicity of use to the user, great tool for vulnerability scanning for any enterprise. the reports are detailed and easy to understand
So far there is not much but if it has the function to record the previous records it will be better
It has up to date plugins to scan latest vulnerabilities or malwares are in the market. Plugins are updated every week to cover latest vulnerabilities.
Nessus doesn’t detect any active protection on scope system which can block the credential scan.
In some cases, Nessus assumes that a service is vulnerable to a vulnerability just because it is listening for incoming connections, so you always have to go through the results and carefully double check each finding.
I've been using Nessus since it's very beginning. Frankly speaking, I like the older implementations more. But the recent developments are more mainstream and corporate ready
Some plugins are buggy and can crash the testing system. Also licensing is a bit of a turn off, even though it's really worth it for professionals
Trust on leader on VM market and movement
Nessus in the Pro version is limited to one user
It can be troublesome to setup the very first time but when it is set up it is a breeze to use
The software can be difficult to use sometimes and it doesn't always scan with the credentials needed to have compliant scans.
What I like most about Nessus is that they have many plugins available for the various vulnerabilities that are out there. The ability to scan static and dynamic asset lists is great. The ability to schedule recurring scan jobs is helpful and aids in the scanning of systems. Integration with ticketing systems such as ServiceNow is also great.
It would be nice if their website had the published or revised date of their plugins. Resolving issues related to their Nessus Agents would also be nice. The UI could be improved so that queries didn't take so long. It would be nice if there was an easy way to purge old data associated with particular IPs.
FÁCIL DE USAR
Lacking in application security