Network Vulnerability Scanner

OPENVAS (Enterprise)

OPENVAS SCAN is an enterprise version of a well-known network vulnerability scanner.

Greenbone, the vendor of OPENVAS, combines 18 years of experience to serve 1000+ customers from different industries, including government entities, international private companies, critical infrastructure sector and MSSP providers.

Logo - OPENVAS - Product Page (1)

Request a free trial



    18 years

    of experience in the field

    1000+

    customers

    100000+

    installations

    Enterprise version capabilities

    Greenbone iso certified (1)
    OPENVAS enterprise version capabilities
    Asset discoveryNetwork vulnerability scanningReliable vulnerability coverageFlexible scan configurationReporting and complianceTransparency and data control

    Asset discovery

    OPENVAS SCAN helps create visibility into assets available across the network before vulnerability assessment begins.

    It includes detection of:
    • Live hosts
    • Open ports
    • Services and protocols
    • Operating systems
    • Running software and its versions

    Teams can perform deeper discovery using authentication.

    Asset Discovery OPENVAS

    Network vulnerability scanning

    OPENVAS SCAN analyzes network assets for vulnerabilities like an attacker would.

    During scanning, the solution selects relevant security checks, sends payloads and analyzes their responses.

    Authentication can be used for deeper vulnerability detection, as it provides additional information that may not be uncovered through external network testing alone.

    For quick checks, CVE scan is available. It allows teams to compare product identifiers detected in the previous full scan with an up-to-date vulnerability database.

    Network vulnerability scanning OPENVAS

    Reliable vulnerability coverage

    The Enterprise feed includes a lot more security checks the Community edition, and provides coverage for more than 4,500 systems, including Cisco, Oracle and VMware.

    Security checks are updated per SLA and the sources includ:
    • NVD
    • CERT-Bund
    • DFN-CERT
    • Vendor security advisories
    • Greenbone security research

    For some of CVEs, Greenbone develops security checks before an official CVE publication, thanks to extensive vendor research, including Darknet forums.

    Reliable vulnerability coverage OPENVAS (1)

    Flexible scan configuration

    Scanning can be adapted to different use cases, configurations include:
    • Scan scope
    • Authentication
    • Scan depth
    • Custom selection of vulnerability checks
    • Limit for concurrent host scanning and checks per host
    • Minimum vulnerability confidence level (Quality-of-Detection)
    • Built-in scan scheduling
    • Built-in alerts based on rules

    This allows organizations to balance scan depth, performance and accuracy according to the requirements of each environment.

    Flexible scan configuration OPENVAS

    Reporting and compliance

    To fit reporting requiremens of organizations of different sizes, OPENVAS SCAN provides the following capabilities:
    • CVSS, EPSS, and vulnerability confidence level (Quality-of-Detection) for deeper risk context of the issue.
    • Issue details, possible impact and recommended solution are provided.
    • The tool allows teams to assign issues, create technical exports and PDF reports, helping with the process of vulnerability management.
    • The Enterprise version also supports compliance scans, including policies based on CIS Benchmarks.
    • A variety of connections to third-party systems are supported, and API can be used for additional integrations.
    • Organizations can use built-in and custom roles and group for granular user access.

    Reporting and compliance OPENVAS

    Transparency and data control

    OPENVAS SCAN is designed for organizations that require full control over their data.

    • The solution operates entirely on-premises, providing the following setup options: standard instance, master/sensor, and air-gapped deployment for isolated environments.
    • The source code of the underlying engine is fully visible and suitable for deep audit.
    • OPENVAS is developed in Germany, making it fully GDPR compliant.
    • The solution is trusted by Germany’s Federal Office for Information Security (BSI).

    This makes OPENVAS SCAN particularly suitable for public-sector organizations and critical infrastructure where transparency, data control and on-premise deployment are important requirements.

    Transperency and data control OPENVAS

    Enterprise vs Community versions of OPENVAS

    The key differences between the Enterprise and Community versions of OPENVAS include but are not limited to:

    Reliable vulnerability coverage:

    Daily updates with SLA (some of CVEs are added before the official publication) and approximately x2 more security checks in the Enterprise version compared to the Community edition.

    Coverage of a wide range of enterprise systems:

    4500+ systems are supported (including Cisco, Oracle, VMware) in the Enterprise version, contrary to the Community edition.

    Streamlined master/sensor and air-gapped deployment:

    Aside from the turnkey applicance for a standatd on-premise instance, the solution provides an option for master/sensor setup and air-gapped deployment for isolated environments.

    Official technical support from the vendor:

    No more advice-seeking on forums, you can receive professional support for free, if you use the Enterprise version.

    FAQ

    How does network vulnerability scanning work?

    The scanner sends payloads to scan targets and analyzes their responses, detecting vulnerabilities based on response patterns.

    Is authenticated scanning available?

    Yes, the solution supports authenticated scanning, including SSH (username and password/SSH key), SMB (Kerberos, NTLM), ESXi, SNMP.

    What are the main differences between the Enterprise and Community versions of OPENVAS?

    The key advantages of the Enterprise version include:

    • A lot more checks (some of CVEs are added before an official publication)
    • Coverage of 4500+ systems
    • Official technical support

    To learn about more benefits for your unique use case, please reach out to us in a way convenient for you.

    Is official technical support included in the subscription?

    Yes, official technical support from the vendor is included in the OPENVAS SCAN subscription.

    What deployment options are available?

    On-premise deployment with the following setup options: standard instance, master/sensor for distributed networks, air-gapped deployment.

    Can the enterprise version be tested for free?

    Yes, a free temporary license for testing can be provided. To receive it, please contact us in a way convenient for you.