From 68465b7298d46e5fe567c2f065a73f6abf4064bb Mon Sep 17 00:00:00 2001 From: xer0dayz <1N3@hushmail.com> Date: Sat, 15 Aug 2020 12:44:44 -0700 Subject: [PATCH] Created Nessus Integration (markdown) --- Nessus-Integration.md | 44 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 44 insertions(+) create mode 100644 Nessus-Integration.md diff --git a/Nessus-Integration.md b/Nessus-Integration.md new file mode 100644 index 0000000..daf2fc2 --- /dev/null +++ b/Nessus-Integration.md @@ -0,0 +1,44 @@ +### Requirements +This add-on requires a [Sn1per Professional v8.0](https://xerosecurity.com) license along with the following add-ons and components: +- Command Execution Add-on +- Nessus Add-on +- Nessus v8.11.x + +This assumes that you already have a working Nessus installation running the latest version (8.11.x). If not, you can obtain a free Nessus license from https://www.tenable.com/downloads/nessus?loginAttempted=true + +### Installation +After Nessus is installed, follow the steps below to install the Nessus add-on: + +1. Run ```/etc/init.d/nessusd start``` to start the Nessus service +2. Open a new browser window and go to: https://127.0.0.1:8834/#/ and login to confirm your Nessus installation +3. Extract contents of nessus-add-on.tar.gz to /tmp/ +``` +cd tmp +tar -zxvf nessus-add-on.tar.gz +``` +4. Run install-nessus-add-on.sh script as 'root': +``` +sudo bash install-nessus-add-on.sh +``` + +### Configuration +5. Add your Nessus host/IP, username and password to your /root/.sniper.conf file and set NESSUS="1" value to enable Nessus scanning in Sn1per +``` +# NESSUS CONFIG +NESSUS="1" +NESSUS_HOST="127.0.0.1:8834" +NESSUS_USERNAME="admin" +NESSUS_PASSWORD="" +NESSUS_POLICY_ID="c3cbcd46-329f-a9ed-1077-554f8c2af33d0d44f09d736969bf" #DEFAULT POLICY +``` + +### Running scans +6. Run a test vuln scan to confirm your installation: +``` +sniper -t 127.0.0.1 -m vulnscan -w 127.0.0.1 +``` +For multi-host scans, you can also use ```sniper -f targets.txt -m massvulnscan -w targets``` command. + +### Reporting +After the scan(s) complete, results will be shown in the workspace report view under the "Vulnerabilities" section and from the host report. +