Nessus Reporting Karma

Null Meet Pune May 2011

21 May 2011

This talk focused on the latest Nessus reporting format, and how to use it in your own  project. Consuming XML and making sense of the data. WE also discussed about ways to eliminate false positives and multiple entries pointing to same issue.

Abstract

Slides

AI Generated Summary

AI Generated Content Disclaimer

Note: This summary is AI-generated and may contain inaccuracies, errors, or omissions. If you spot any issues, please contact the site owner for corrections. Errors or omissions are unintended.

This interactive session covers Nessus vulnerability scanner reporting formats, custom report parsing, and building an integrated vulnerability management system with PHP and Oracle database backend.

Key Topics Covered

Nessus Reporting Formats:

Format Evolution:

Custom Parsing Approaches:

Integrated Vulnerability Management System:

Plugin Detail Extraction:

Planned Enhancements:

Actionable Takeaways

  1. Understanding Nessus XML formats enables powerful custom reporting
  2. Integrating vulnerability data with asset inventory provides organizational context
  3. Automated false positive identification by plugin ID reduces analysis burden
  4. Grouping vulnerabilities by common remediation streamlines patching efforts
  5. Historical tracking reveals vulnerability trends and persistent issues