Plugins
Some Tenable Nessus templates include Plugin options.
Plugins options enable you to select security checks by Plugin Family or individual plugins checks.
For more information on specific plugins, see the Tenable plugins site. For more information on plugin families, see About Plugin Families on the Tenable plugins site.
Plugin Families
Clicking on the Plugin Family allows you to enable (green) or disable (gray) the entire family. Selecting a family shows the list of its plugins. You can enable or disable individual plugins to create specific scans.
A family with some plugins disabled is purple and shows Mixed to indicate only some plugins are enabled. Clicking on the plugin family loads the complete list of plugins, and allow for granular selection based on your scanning preferences.
Mixed plugin families have a padlock icon that is locked or unlocked.
-
Locked — New plugins added to the plugin family via plugin feed updates are disabled in the policy automatically.
-
Unlocked — New plugins added to the plugin family via plugin feed updates are enabled in the policy automatically.
Click the padlock to lock or unlock the plugin family.
Caution: The Denial of Service family contains some plugins that could cause outages on a network if you do not enable the Safe Checks option, in addition to some useful checks that do not cause any harm. You can use the Denial of Service family with Safe Checks to ensure that Tenable Nessus does not run any potentially dangerous plugins. However, Tenable recommends that you do not use the Denial of Service family on a production network unless scheduled during a maintenance window and with staff ready to respond to any issues.
View Plugin Output Details
Selecting a specific Plugin Name shows the plugin output that you would see in a report.
The plugin details include the information described in the following table. Some plugins do not provide all the listed information.
Section | Description |
---|---|
Synopsis | View an overview of the plugin. |
Description | View a detailed description of the plugin and its related vulnerability. |
Solution | View the plugin vulnerability's solution. |
See Also | View security advisories related to the plugin. |
Plugin Information |
View the following plugin information:
|
Risk Information |
View the plugin's following vulnerability risk information:
|
Vulnerability Information |
View the plugin's following vulnerability information:
|
Reference Information | View the plugin's related reference material (CVE, CWE, CERT, IAVA, BID, SECUNIA, or other related information). |
To view more detailed information about the plugin, search for the plugin on the Tenable Plugins website.
Note: When viewing plugins on the Tenable Plugins website, some plugins are documented with the following note: "Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number." This note means that Tenable does not have a complete resolution for the plugin's vulnerability and must manually validate whether the vulnerability is resolved.