Difference between revisions of "Vulnerability Scanning"
Jump to navigation
Jump to search
(→Tools) |
|||
Line 10: | Line 10: | ||
==Tools== | ==Tools== | ||
− | *[[Nessus]] - is one of the most famous but is not free. | + | * [[Nessus]] - is one of the most famous but is not free. |
+ | * [[Wireshark]] | ||
+ | * [[nmap]] | ||
+ | * [[OpenVAS]] | ||
+ | * [[Qualys]] | ||
+ | * [[Burp Suite]] | ||
+ | * [[OpenSCAP]] | ||
− | + | == Services == | |
− | + | * [[Detectify]] web service: https://detectify.com/ | |
− | *[[ | + | * [[Tenable.io]] service: https://www.tenable.com/products/tenable-io |
− | |||
− | |||
− | |||
− | |||
− | |||
− | *[[ | ||
==See also== | ==See also== |
Revision as of 06:15, 28 April 2020
The vulnerability scanner uses a database to compare details about the target attack surface. The database references known flaws, coding bugs, packet construction anomalies, default configurations, and potential paths to sensitive data that can be exploited by attackers.
Types of vulnerability scanners
- Port Scanner: Probes a server or host for open ports
- Network Enumerator: A computer program used to retrieve information about users and groups on networked computers
- Network Vulnerability Scanner: A system that proactively scans for network vulnerabilities
- Web Application Security Scanner: A program that communicates with a Web application to find potential vulnerabilities within the application or its architecture
- Computer Worm: A type of self-replicated computer malware, which can be used to find out vulnerabilities
Tools
- Nessus - is one of the most famous but is not free.
- Wireshark
- nmap
- OpenVAS
- Qualys
- Burp Suite
- OpenSCAP
Services
- Detectify web service: https://detectify.com/
- Tenable.io service: https://www.tenable.com/products/tenable-io
See also
- Security tools: Password cracking, Vulnerability Scanning, Chainguard
- Security: Security portfolio, Security standards, Hardening, CVE, CWE, Wireless Network Hacking, vulnerability scanner, Security risk assessment, SCA, Application Security Testing, OWASP, Data leak, NIST, SANS, MITRE, Security policy, Access Control attacks, password policy, password cracking, Password manager, MFA, OTP, UTF, Firewall, DoS, Software bugs, MITM, Certified Ethical Hacker (CEH) Contents, Security+ Malware, FIPS, DLP, Network Access Control (NAC), VAPT, SIEM, EDR, SOC, pentest, PTaaS, Clickjacking, MobSF, Janus vulnerability, Back Orifice, Backdoor, CSO, CSPM, PoLP, forensic, encryption, Keylogger, Pwn2Own, CISO, Prototype pollution
- Certified Ethical Hacker (CEH) Contents
Advertising: