Tenable Nessus Expert onboarding portal

Nessus Expert basics and getting started

Leverage these key resources and events to hit the ground running and stay informed of the latest product updates and releases.

Tenable Nessus getting started guide

Nessus Expert interactive onboarding product tour

Monthly customer update webinars

Tenable Nessus 10.8.x user guide

Major onboarding
steps

To get started with Nessus Expert, follow the steps below.

Onboarding steps

Prepare

Prepare

Ensure that your setup meets the minimum system requirements and obtain your activation code for Nessus Expert.

Resources:

Docs: Get started with Tenable Nessus

Install and configure Nessus Expert

Install and configure Nessus Expert

Tenable Nessus can be installed on Windows, Linux, macOS, or Raspberry Pi. It can also be deployed as a Docker image. Follow the installation steps depending on your Tenable Nessus software and operating system and perform the initial configuration steps.

Resources:

Docs: Install and configure Tenable Nessus

Demo: Installing Nessus on Windows

Demo: Installing Nessus on Linux

Create and configure scans

Create and configure scans

Run a host discovery scan to identify assets on your network. Then, create a vulnerability scan by selecting a scan template and configuring the scan to meet your needs. Finally, launch the scan.

Resources:

Docs: Create and configure scans

Demo: Create and Launch a Host Discovery Scan

Demo: Create and Launch a Basic Network Scan

View and analyze scan results

View and analyze scan results

View and analyze scan results, manage vulnerabilities and scan folders, and create a scan report or export.

Resources:

Docs: View and analyze scan results

Demo: Review Basic Network Scan Results

Video: Comparing scan results

Create a report and export findings

Create a report and export findings

Create a scan report to help you analyze the vulnerabilities and remediations on affected hosts. You can create a scan report in PDF, HTML, or CSV format, and customize it to contain only certain information.

Resources:

Docs: Scan Exports and Reports

Demo: Create a Report and Export Findings

Refine Nessus settings

Refine Nessus settings

Adjust scan settings to address warning messages and monitor scan health.

Resources:

Docs: Refine Tenable Nessus settings

Video: Measuring scan success

Set up web app scanning

Set up web app scanning

While Tenable Nessus itself is installed directly on the host operating system, the web scanner portion of Tenable Nessus Expert is installed as a Docker image on the same host. The web application scanner cannot run if the host does not have Docker installed.

Resources:

Docs: Get started with web application scanning in Nessus Expert

Demo: Create and launch a web application scan

Create an external attack surface discovery scan

Create an external attack surface discovery scan

You can use Tenable Nessus's integration with Bit Discovery to create an attack surface discovery scan. This scan type allows you to scan top-level domains and generate DNS records based on the scan findings. Tenable Nessus Expert allows you to scan up to five different licensed domains.

Resources:

Docs: Create an Attack Surface Discovery Scan

Demo: Create and launch an external attack surface discovery scan

Best practices

Use these best practices to get the most from your investment and set the foundation for becoming a power user:

  • Utilize the Tenable vulnerability priority rating (VPR) to prioritize the remediation of the highest risk vulnerabilities first.
  • The scan or policy's Credentials page allows you to configure the Tenable Nessus scanner to use authentication credentials during scanning. Configuring credentials allows Tenable Nessus to perform a wider variety of checks that result in more accurate scan results.
  • You can compare two scan results to see differences between them. This comparison is not a true differential of the two results; it shows the new vulnerabilities that Tenable Nessus detected between the older baseline scan and the newer scan. Comparing scan results helps you see how a given system or network has changed over time. This information is useful for compliance analysis by showing how vulnerabilities are being remediated, if systems are patched as Tenable Nessus finds new vulnerabilities, or how two scans may not be targeting the same hosts.
  • Use the Live Results feature to view scan results for new plugins based on a scan's most recently collected data, without running a new scan. Live Results allow you to see potential new threats and determine if you need to launch a scan manually to confirm the findings.