Security Basics mailing list archives

Re: Nessus Reporting frontend options - scan management


From: Nikhil Wagholikar <visitnikhil () gmail com>
Date: Wed, 6 May 2009 07:35:58 +0530

Hi Daniel,

Though not exactly as what you require, an open source software named
'Nessusconnect' can help you in this regard.

One of the key features of Nessusconnect' is:

Reports are generated in XML, and XSLT style sheets can be used to
easily produce customized reports, including charts/graphs.
Nessconnect also supports vulnerability trending, allowing you track
hosts vulnerabilities across multiple scans over a certain period.

More Info: http://linux.softpedia.com/get/System/System-Administration/Nessconnect-34728.shtml

Best of Luck!!
---
Nikhil Wagholikar
Practice Lead | Security Assessment & Digital Forensics
Network Intelligence (India) Pvt. Ltd. [NII Consulting]
Web: http://www.niiconsulting.com/
Comprehensive solution for firewall rulebase analysis
http://www.niiconsulting.com/products/Firesec.html

2009/5/5 Daniel I. Didier <ddidier () netsecureia com>

Hello,
I am looking for input on available Nessus scan management solutions.  I
have used inprotect in the past and have been generally pleased with its
capabilities but it seems to lack development.  I am also aware of
autonessus which has similar functions.  I am curious what other options
exist.

The primary requirements are the ability to schedule scans and compare
results; new, mitigated, and existing vulnerabilities and produce useful
reports.  Also, the ability to mark a finding as a false positive or
acceptable risk is needed.  Any input and experience is appreciated

Dan

------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Learn all of the latest penetration testing techniques in InfoSec Institute's Ethical Hacking class.
Totally hands-on course with evening Capture The Flag (CTF) exercises, Certified Ethical Hacker and Certified 
Penetration Tester exams, taught by an expert with years of real pen testing experience.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Learn all of the latest penetration testing techniques in InfoSec Institute's Ethical Hacking class.
Totally hands-on course with evening Capture The Flag (CTF) exercises, Certified Ethical Hacker and Certified 
Penetration Tester exams, taught by an expert with years of real pen testing experience.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------


Current thread: