OpenVAS (''Open Vulnerability Assessment System'', originally known as ''GNessUs'') is the scanner component of Greenbone Vulnerability Manager (GVM), a
software framework
In computer programming, a software framework is an abstraction in which software, providing generic functionality, can be selectively changed by additional user-written code, thus providing application-specific software. It provides a standard ...
of several services and tools offering
vulnerability
Vulnerability refers to "the quality or state of being exposed to the possibility of being attacked or harmed, either physically or emotionally."
A window of vulnerability (WOV) is a time frame within which defensive measures are diminished, com ...
scanning and
vulnerability management.
All Greenbone Vulnerability Manager products are
free software
Free software or libre software is computer software distributed under terms that allow users to run the software for any purpose as well as to study, change, and distribute it and any adapted versions. Free software is a matter of liberty, ...
, and most components are licensed under the
GNU General Public License
The GNU General Public License (GNU GPL or simply GPL) is a series of widely used free software licenses that guarantee end user
In product development, an end user (sometimes end-user) is a person who ultimately uses or is intended to ulti ...
(GPL). Plugins for Greenbone Vulnerability Manager are written in the
Nessus Attack Scripting Language, NASL.
History
Greenbone Vulnerability Manager began under the name of OpenVAS, and before that the name GNessUs, as a
fork of the previously
open source
Open source is source code that is made freely available for possible modification and redistribution. Products include permission to use the source code, design documents, or content of the product. The open-source model is a decentralized sof ...
Nessus scanning tool, after its developers
Tenable Network Security changed it to a proprietary (
closed source
Proprietary software is software that is deemed within the free and open-source software to be non-free because its creator, publisher, or other rightsholder or rightsholder partner exercises a legal monopoly afforded by modern copyright and in ...
) license in October 2005.
OpenVAS was originally proposed by
pentesters at SecuritySpace, discussed with
pentesters at Portcullis Computer Security and then announced by Tim Brown on
Slashdot
''Slashdot'' (sometimes abbreviated as ''/.'') is a social news website that originally advertised itself as "News for Nerds. Stuff that Matters". It features news stories concerning science, technology, and politics that are submitted and evalu ...
.
Greenbone Vulnerability Manager is a member project of
Software in the Public Interest.
Structure

There is a daily updated feed of Network Vulnerability Tests (NVTs) - over 50,000 in total (as of July 2020).
Documentation
The OpenVAS protocol structure aims to be well-documented to assist developers. The OpenVAS Compendium is a publication of the OpenVAS Project that delivers documentation on OpenVAS.
See also
*
Aircrack-ng
*
BackBox
BackBox is a penetration test and security assessment oriented Ubuntu-based Linux distribution providing a network and informatic systems analysis toolkit. It includes a complete set of tools required for ethical hacking and security testing.
C ...
*
BackTrack
*
Kali Linux
*
Kismet (software)
*
List of free and open-source software packages
*
Metasploit Project
*
Nmap
*
ZMap (software)
References
External links
OpenVAS web siteOpenVAS, Nikto Nmap, OWASP Zed Attack Proxy (ZAP) all in oneOpenVAS, Nessus and NexPose TestedOpenVAS Compendium - A Publication of The OpenVAS Project
{{DEFAULTSORT:Openvas
Free security software
Network analyzers
2005 software
Pentesting software toolkits