Settings Configuration
Once you select the scan template to use for your scan, there are several settings that you can use to tune the scan configuration's performance. The following topics describe each of the scan configuration sections—Settings, Credentials, Compliance, and Plugins—and how you can configure each section to maximize your scan's performance.
A scan configuration's settings greatly affect the scan's capabilities, performance, and scan time. Use the settings to configure when and how often Tenable Nessus launches the scan, discovery options, debugging capabilities, assessment methods, performance options, and other scan behavior. Tenable Nessus has into five Settings categories: Basic, Discovery, Assessment, Report, and Advanced.
Some of the scan configuration settings are informational or do not affect scan performance (for example, Name, Description, and Notification settings). This section describes all the settings that do affect scan performance and how to tune them for better scan performance.
Click the following setting categories to learn more about them and how to tune them:
Use the Basic settings to choose which scanner or agents perform the scan, what targets or assets the sensors scan, and the schedule on which Tenable Nessus launches the scan. All three of these aspects greatly impact the scope and performance of the scan.
| Setting | Description | Tuning Tips |
|---|---|---|
| General | ||
| Scanner |
Specifies the scanner that performs the scan. Select a scanner based on the location of the targets you want to scan. You can select a linked scanner to scan non-routable IP addresses, or you can select Local Scanner. |
|
| Targets and Upload Targets |
(Scanner templates only) The Targets and Upload Targets options are different methods you can use to specify which hosts the scan runs against. |
Targeting specific assets provides faster scan results than scans that target IP ranges or CIDR notation. |
| Schedule | ||
| Frequency |
Specifies how often Nessus launches the scan.
|
Tenable recommends running full vulnerability scans against most types of assets at least twice a week. |
| Starts |
Specifies the exact date and time when a scan launches. The starting date defaults to the date when you are creating the scan. The starting time is the nearest half-hour interval. For example, if you create your scan on 09/31/2018 at 9:12 AM, Tenable Nessus sets the default starting date and time to 09/31/2018 and 09:30. |
|
| Time Zone | Specifies the timezone of the value set for Starts. | |
For more information, see Basic Settings for Scans.
The Discovery settings determine the scan configuration's discovery-related capabilities: host discovery, port scanning, and service discovery.
Discovery settings are limited for Nessus Agent scan templates because agents cannot perform remote checks or scan the network. You can only set the WMI and SSH settings for agent scans.
| Setting | Description | Tuning Tips |
|---|---|---|
| Host Discovery (Scanner templates only) | ||
| Ping the remote host | (missing or bad snippet) | |
| Use fast network discovery |
(Available if Ping the remote host is enabled) (missing or bad snippet) |
This setting can increase scan speeds, but it may not be appropriate in all environments due to target configurations. |
| Ping Methods |
(Available if Ping the remote host is enabled) Specifies the scanner's pinging method. |
In most environments, Tenable recommends using the default ping methods. Enabling UDP can greatly increase scan times. For more information, see the Ping Type Order/Hierarchy community article. |
| Fragile Devices | Determines which fragile devices the scanner or scanners detect. You can enable scanning for network printers, Novell NetWare hosts, and Operational Technology (OT) devices. | Tenable does not recommend scanning fragile devices in a production environment because it may cause an operational impact. If you need to assess OT devices, consider using Tenable One OT Exposure to perform in-depth assessments. |
| Wake-on-LAN | The Wake-on-LAN (WOL) menu controls which hosts to send WOL magic packets to before performing a scan. You can provide a list of hosts that you want to start before scanning by uploading a text file that lists one MAC address per line. | |
| Port Scanning | ||
| Consider unscanned ports as closed |
(Scanner templates only) (missing or bad snippet) |
|
| Port scan range |
(Scanner templates only) (missing or bad snippet) |
If you have insight into local cross-traffic in your network, you can customize this setting to only include the active listening services on your network, but this may cause the scan to unused services. |
| SSH (netstat) | (missing or bad snippet) If any port enumerator (netstat or SNMP) is successful, the port range becomes all. |
|
| WMI (netstat) | (missing or bad snippet) | |
| SNMP |
(Scanner templates only) (missing or bad snippet)If any port enumerator (netstat or SNMP) is successful, the port range becomes all. |
|
| Only run network port scanners if local port enumeration failed |
(Scanner templates only) (missing or bad snippet) |
|
| Verify open TCP ports found by local port enumerators |
(Scanner templates only) (missing or bad snippet) |
|
| TCP |
(Scanner templates only) (missing or bad snippet) |
|
| SYN |
(Scanner templates only) (missing or bad snippet) |
|
| Override automatic firewall detection |
(Scanner templates only) (missing or bad snippet) |
|
| UDP |
(Scanner templates only) This option engages the built-in Tenable Nessus UDP scanner to identify open UDP ports on the targets. Due to the nature of the protocol, a port scanner usually cannot tell the difference between open and filtered UDP ports. |
Enabling the UDP port scanner may dramatically increase the scan time and produce unreliable results. Consider using the netstat or SNMP port enumeration options instead if possible. |
| Service Discovery (Scanner templates only) | ||
| Probe all ports to find services | (missing or bad snippet) | |
| Search for SSL/TLS/DTLS services | (missing or bad snippet) | Enabling CRL checking increases scan times. |
For more information, see Discovery Scan Settings. To learn more about the preconfigured Discovery scan template settings, see Preconfigured Discovery Scan Settings.
The Assessment section allows you to configure how the scan identifies vulnerabilities and which vulnerabilities the sensors identify. This includes identifying malware, assessing the vulnerability of a system to brute force attacks, and the susceptibility of web applications.
| Setting or Settings Group | Description | Tuning Tips |
|---|---|---|
| General | ||
| Override normal accuracy | (missing or bad snippet) | |
| Perform thorough tests (may disrupt your network or impact scan speed) | Causes various plugins to work harder. For example, when looking through SMB file shares, a plugin analyzes 3 directory levels deep instead of 1. This could cause much more network traffic and analysis in some cases. By being more thorough, the scan is more intrusive and is more likely to disrupt the network, while potentially providing better audit results. | Enabling this setting increases scan times. |
| Antivirus definition grace period (in days) | Configure the delay of the Antivirus software check for a set number of days (0-7). The Antivirus Software Check menu allows you to direct Tenable Nessus to allow for a specific grace time in reporting when antivirus signatures are out of date. By default, Tenable Nessus considers signatures out of date regardless of how long ago an update became available (for example, a few hours ago). You can configure this option to allow for up to 7 days before reporting them out of date. | |
| SMTP |
(Scanner templates only) Allows you to enable SMTP testing on the scan configuration. |
|
| Brute Force (Scanner templates only) | ||
| Only use credentials provided by the user | In some cases, Tenable Nessus can test default accounts and known default passwords. This can cause the account to lock if too many consecutive invalid attempts trigger security protocols on the operating system or application. By default, this setting is enabled to prevent Tenable Nessus from performing these tests. | |
| Test default accounts (slow) | Test for known default accounts in Oracle software. | |
|
SCADA (Scanner templates only) This is a legacy configuration and should not be altered in most environments. You can use Tenable One OT Exposure to assess SCADA systems. |
||
| Modbus/TCP Coil Access | The Modbus/TCP Coil Access settings are available for commercial users. This drop-down menu item is generated by the SCADA plugins available with the commercial version of Tenable Nessus. Modbus uses a function code of 1 to read coils in a Modbus child. Coils represent binary output settings and are mapped to actuators typically. The ability to read coils may help an attacker profile a system and identify ranges of registers to alter via a write coil message. | |
| ICCP/COTP TSAP Addressing Weakness | The ICCP/COTP TSAP Addressing menu determines a Connection-Oriented Transport Protocol (COTP) Transport Service Access Points (TSAP) value on an ICCP server by trying possible values. | |
| Web Applications (Scanner templates only) | ||
| Scan web applications | If enabled, Nessus enables web application-level checks. | This setting can be useful for scanning network services running web applications. To scan for more generic web application vulnerabilities like Cross Site Scripting or SQL Injection, Tenable recommends using the Tenable One Web App Scanning module. For more information, see Tenable One Web App Scanning Scanning Overview. |
| Windows | ||
| Request information about the SMB Domain | If enabled, domain users are queried instead of local users. | |
| User Enumeration Methods | You can enable as many of the user enumeration methods as appropriate for user discovery. | |
| Malware | ||
| Scan for malware | Configures the scan to scan for malware on the target hosts. Enable this setting to view the remaining Malware options. | |
| Disable DNS resolution | Checking this option prevents Tenable Nessus from using the cloud to compare scan findings against known malware. | |
| Custom Netstat IP Threat List | (missing or bad snippet) | |
| Provide your own list of known bad MD5 hashes |
A text file with one MD5 hash per line that specifies more known bad MD5 hashes. Optionally, you can include a description for a hash by adding a comma after the hash, followed by the description. If the sensor finds any matches when scanning a target, the description appears in the scan results. You can also use hash-delimited comments (for example, fop) in addition to comma-separated comments. |
|
| Provide your own list of known good MD5 hashes |
A text file with one MD5 hash per line that specifies more known good MD5 hashes. Optionally, you can include a description for each hash by adding a comma after the hash, followed by the description. If the sensor finds any matches when scanning a target, and you provide a description for the hash, the description appears in the scan results. You can also use hash-delimited comments (for example, #) in addition to comma-separated comments. |
|
| Hosts file allow list |
Tenable Nessus checks system hosts files for signs of a compromise (for example, Plugin ID 23910 titled Compromised Windows System (hosts File Check)). This option allows you to upload a file containing a list of IPs and hostnames you want Tenable Nessus to ignore during a scan. Include one IP and one hostname (formatted identically to your hosts file on the target) per line in a regular text file. |
|
| Yara Rules |
A .yar file containing the YARA rules to be applied in the scan. You can only upload one file per scan, so include all rules in a single file. For more information, see yara.readthedocs.io. |
Tenable supports all the YARA 3.4 built-in keywords including those defined in the PE and ELF sub-modules, excluding hash functionality. Tenable products do not support Yara imphash checks. |
| Scan file system |
If enabled, Tenable Nessus can scan system directories and files on host computers. Caution: Enabling this setting in scans targeting 10 or more hosts could result in performance degradation. |
Enabling this setting increases scan times. |
| Windows Directories |
(Available with Scan file system enabled) Enables file system scanning for certain Windows directories and user profiles. |
|
| Linux Directories |
(Available with Scan file system enabled) Enables file system scanning for certain Linux directories. |
|
| MacOS Directories |
(Available with Scan file system enabled) Enables file system scanning for certain macOS directories. |
|
| Custom Directories |
(Available with Scan file system enabled) A custom file that lists directories to scan with malware file scanning. List each directory on one line. You cannot list root directories (for example, C://) and you cannot use variables (for example, %Systemroot%). |
|
| Databases (Scanner templates only) | ||
| Use detected SIDs |
When enabled, if at least one host credential and one Oracle database credential are configured, the scanner authenticates to scan targets using the host credentials, and then attempts to detect Oracle System IDs (SIDs) locally. The scanner then attempts to authenticate using the specified Oracle database credentials and the detected SIDs. If the scanner cannot authenticate to scan targets using host credentials or does not detect any SIDs locally, the scanner authenticates to the Oracle database using the manually specified SIDs in the Oracle database credentials. |
|
For more information, see Assessment Scan Settings. To learn more about the preconfigured Assessment scan template settings, see Preconfigured Assessment Scan Settings.
The Report settings affect the verbosity and formatting of scan reports you can create for the scan configuration. Report settings do not affect scan performance. However, Tenable recommends reviewing and configuring them per your organization's needs. For more information, see Report Scan Settings.
The Advanced section allows you to configure more general settings, performance options, and debugging capabilities.
| Setting | Description | Tuning Tips |
|---|---|---|
| General Settings (Scanner templates only) | ||
| Enable safe checks | When enabled, disables all plugins that may have an adverse effect on the remote host. | Tenable does not recommend disabling this setting in production environments; the plugins could crash services or targets. However, disabling the setting may provide more insight for systems likely to be under attack (for example, internet-facing systems). |
| Stop scanning hosts that become unresponsive during the scan | When enabled, Nessus stops scanning if it detects that the host has become unresponsive. This may occur if users turn off their PCs during a scan, a host has stopped responding after a denial of service plugin, or a security mechanism (for example, an IDS) has started to block traffic to a server. Normally, continuing scans on these machines sends unnecessary traffic across the network and delay the scan. | |
| Scan IP addresses in a random order | By default, Nessus scans a list of IP addresses in sequential order. When you enable this option, Nessus scans the list of hosts in a random order within an IP address range. This approach is typically useful in helping to distribute the network traffic during large scans. | |
| Automatically accept detected SSH disclaimer prompts |
When enabled, if a credentialed scan tries to connect via SSH to a FortiOS host that presents a disclaimer prompt, the scanner provides the necessary text input to accept the disclaimer prompt and continue the scan. |
|
| Scan targets with multiple domain names in parallel |
When enabled, Nessus can simultaneously scan multiple targets that resolve to a single IP address within a single scan task or across multiple scan tasks. Scans complete more quickly, but hosts could potentially become overwhelmed, causing timeouts and incomplete results. |
|
| Create unique identifier on hosts scanned using credentials | When enabled, the scanner creates a unique identifier for credentialed scans. | |
| Trusted CAs | Specifies CA certificates that the scan considers as trusted. This allows you to use self-signed certificates for SSL authentication without triggering plugin 51192 as a vulnerability in Tenable Nessus. | |
| Performance Options (Scanner templates only) | ||
| Slow down the scan when network congestion is detected | (missing or bad snippet) | |
| Network timeout (in seconds) | (missing or bad snippet) | Be cautious when increasing this setting as it impacts every check that relies on a timeout. It can increase scan times by an order of magnitude. |
| Max simultaneous checks per host | (missing or bad snippet) | Tenable recommends that you monitor scan target performance when adjusting this setting. |
| Max simultaneous hosts per scan |
Specifies the maximum number of hosts that each Nessus scanner scans per scan chunk. The number of scan chunks is determined by the available resources on each Nessus scanner. |
Increasing this setting's value can decrease scan times, but doing so increases the load on your Nessus scanners. After a certain point, dependent on the available resources on the Nessus scanner and the number of systems being scanned, increasing this setting can make scans slower by making the scanners do more than they are capable of. |
| Max number of concurrent TCP sessions per host | (missing or bad snippet) | |
| Max number of concurrent TCP sessions per scan |
(missing or bad snippet)For scanners installed on any Windows host, you must set this value to 19 or less to get accurate results. |
|
| Unix find command Options | ||
| Exclude filepath |
A plain text file containing a list of filepaths to exclude from all plugins that search using the find command on Unix systems. In the file, enter one filepath per line, formatted per patterns allowed by the Unix find command -path argument. For more information, see the find command man page. |
|
| Exclude filesystem |
A plain text file containing a list of filesystems to exclude from all plugins that search using the find command on Unix systems. In the file, enter one filesystem per line, using filesystem types supported by the Unix find command -fstype argument. For more information, see the find command man page. |
|
| Include filepath | (missing or bad snippet) | |
|
Debug Settings Note: Tenable does not recommend enabling debug settings in production environments. Debug settings generate a substantial amount of data, and can alter the overall scan time and performance. Tenable only recommends the settings for specific debugging instances, and not for constant use. |
||
| Always report SSH commands |
When enabled, Tenable Nessus generates a report of all the commands run over SSH on the host in a machine-readable format. You can view the reported commands under plugin 168017. Note: The setting does not function correctly if you disable plugin 168017. |
|
| Enable plugin debugging | Attaches available debug logs from plugins to the vulnerability output of this scan. | |
| Debug Log Level | Controls the verbosity and content of debug log statements. | Unless Tenable Support instructs your organization otherwise, set Debug Log Level to Level 3:. |
| Enumerate launched plugins |
Shows a list of plugins that Tenable Nessus launched during the scan. You can view the list in scan results under plugin 112154. Note: The setting does not function correctly if you disable plugin 112154. |
|
| Audit Trail Verbosity |
Controls verbosity of the plugin audit trail. Options include:
|
|
| Packet Capture Settings (Scanner templates only) | ||
| Packet Capture |
When enabled, Tenable Nessus logs the TCP and UDP communications between a scanner and a target host. For more information, see Advanced Debugging - Packet Capture. Note: This setting is only available in Tenable Nessus Expert and Tenable Nessus Professional. |
|
| Stagger scan start (Agent templates only) | ||
| Maximum delay (minutes) | (missing or bad snippet) | This setting is useful for preventing resource overuse in shared infrastructure (for example, virtual hosts). |
| Compliance Output Settings | ||
| Maximum compliance output length in KB |
Controls the maximum output length for each individual compliance check value that the target returns. If a compliance check value that is greater than this setting's value, Tenable Nessus truncates the result. Note: If you notice that your compliance scan processing is slow, Tenable recommends reducing this setting to increase the processing speed. |
|
For more information, see Advanced Scan Settings. To learn more about the preconfigured Advanced scan template settings, see Preconfigured Advanced Scan Settings.
For more information about Nessus scan settings, see Scan and Policy Settings.