{"id":792,"date":"2018-12-11T21:56:14","date_gmt":"2018-12-11T18:56:14","guid":{"rendered":"http:\/\/kifarunix.com\/?p=792"},"modified":"2018-12-11T21:56:14","modified_gmt":"2018-12-11T18:56:14","slug":"creating-custom-nessus-scan-policy-templates","status":"publish","type":"post","link":"https:\/\/kifarunix.com\/creating-custom-nessus-scan-policy-templates\/","title":{"rendered":"Creating Custom Nessus Scan Policy Templates"},"content":{"rendered":"<p>Nessus Scan policy template is a set of predefined configuration options related to performing a scan. They define specific actions that are performed during a scan. To create custom Nessus scan policy templates, you need to select the existing templates and modify them to suit your scan requirements. After that, they can be selected from the list of scan templates when new scan is created under the user defined tab. Note that it is more useful to create scan policy templates because they can be reused over and over <span class=\"test-id__field-value slds-form-element__static slds-grow slds-form-element_separator is-read-only\" data-aura-rendered-by=\"106:183;a\">for creating scans<\/span><\/p>\n<p>In our previous article, we learnt <a href=\"https:\/\/kifarunix.com\/security\/vulnerability-scanners\/nessus\/how-to-run-nessus-scan-against-a-system-or-host\/\" target=\"_blank\" rel=\"noopener\">how to create a new Nessus scan<\/a>. In the same tutorial, we selected a template specific to that scan only. Well, in this guide, we are going to learn how to create simple scan policy templates and use them to create scans.<\/p>\n<h4>Create Policy Template<\/h4>\n<p>To create a policy template, login to Nessus and under <strong>Scans<\/strong> tab, <strong>Resources<\/strong> on the left pane, click <strong>Policies.<\/strong><\/p>\n<p>When a new page opens up, click &#8220;<strong>New Policy<\/strong>&#8221; button to create a new policy template.<\/p>\n<p><a href=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/10\/new-policy.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-793 size-full\" src=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/10\/new-policy.png\" alt=\"Nessus new scan policy\" width=\"1898\" height=\"458\" title=\"\" srcset=\"https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/10\/new-policy.png 1898w, https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/10\/new-policy-768x185.png 768w\" sizes=\"(max-width: 1898px) 100vw, 1898px\" \/><\/a><\/p>\n<p>When you click on <strong>New Policy<\/strong>, scanner policy templates page will open up.<\/p>\n<p><a href=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/10\/scanner-templates.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-794 size-full\" src=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/10\/scanner-templates.png\" alt=\"Nessus scan policy templates\" width=\"1909\" height=\"891\" title=\"\" srcset=\"https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/10\/scanner-templates.png 1909w, https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/10\/scanner-templates-768x358.png 768w\" sizes=\"(max-width: 1909px) 100vw, 1909px\" \/><\/a><\/p>\n<p>Select a template to modify from the list as shown above. The templates with upgrade banner are only available with the commercially licensed version of Nessus.<\/p>\n<p>As an example, let us assume that you want to create a Nessus scan policy template to do basic host enumeration to discover live hosts and open ports in your local environment. Therefore click on <strong>Host Discovery<\/strong> template.<\/p>\n<p><a href=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-host-discovery.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1701\" src=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-host-discovery.png\" alt=\"nessus host discovery policy template\" width=\"1380\" height=\"525\" title=\"\" srcset=\"https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-host-discovery.png 1380w, https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-host-discovery-768x292.png 768w\" sizes=\"(max-width: 1380px) 100vw, 1380px\" \/><\/a><\/p>\n<p>Under the <strong>Basic Settings <\/strong>tab, define the name and the description of the custom template.<\/p>\n<p><a href=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-basic-settings.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1702\" src=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-basic-settings.png\" alt=\"nessus scan policy basic settings\" width=\"964\" height=\"509\" title=\"\" srcset=\"https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-basic-settings.png 964w, https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-basic-settings-768x406.png 768w\" sizes=\"(max-width: 964px) 100vw, 964px\" \/><\/a><\/p>\n<p>Under <strong>DISCOVERY <\/strong>settings, you can select the type of scan you want to perform. There are multiple scan types; host enumeration, OS Identification, Port Scan (all ports and custom ports), or custom scan where you can customize the default options for Host Discovery and Port Scanning.<\/p>\n<p><a href=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-scan-type.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1703\" src=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-scan-type.png\" alt=\"Nesus policy scan type\" width=\"1028\" height=\"656\" title=\"\" srcset=\"https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-scan-type.png 1028w, https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-scan-type-768x490.png 768w\" sizes=\"(max-width: 1028px) 100vw, 1028px\" \/><\/a><\/p>\n<p>On the <strong>REPORT<\/strong> settings, you can choose to allow or disallow a user to delete items from the report, designate hosts by their DNS names, display hosts that respond to ping or display unreachable hosts.<\/p>\n<p><a href=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-report-settings.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1704\" src=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-report-settings.png\" alt=\"Nessus scan report settings\" width=\"903\" height=\"542\" title=\"\" srcset=\"https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-report-settings.png 903w, https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-report-settings-768x461.png 768w\" sizes=\"(max-width: 903px) 100vw, 903px\" \/><\/a><\/p>\n<p>On the <strong>ADVANCED<\/strong> settings, you can opt to;<\/p>\n<ul>\n<li>enable or disable Nessus to slow down the scan when network congestion is detected<\/li>\n<li>specify the time that Nessus waits for a response from a host<\/li>\n<li>specify the maximum number of checks a Nessus scanner will perform against a single host at one time<\/li>\n<li>specify the maximum number of hosts that a Nessus scanner will scan at the same time<\/li>\n<li>specify the maximum number of established TCP sessions for a single host<\/li>\n<li>specify the maximum number of established TCP sessions for the entire scan, regardless of the number of hosts being scanned<\/li>\n<\/ul>\n<p><a href=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-advanced-settings.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1705\" src=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-advanced-settings.png\" alt=\"Nessus advanced scan setttings\" width=\"971\" height=\"681\" title=\"\" srcset=\"https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-advanced-settings.png 971w, https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/nessus-policy-advanced-settings-768x539.png 768w\" sizes=\"(max-width: 971px) 100vw, 971px\" \/><\/a><\/p>\n<p>Once you are done configuring the Nessus scan policy template, click <strong>save<\/strong>. The customized scan policy templates should now be available under the <strong>User Defined<\/strong> tab.<\/p>\n<p>Whenever you need to run host enumeration scan on your local environment and want to use the customized, just click <strong>New Scan<\/strong> from the scans page and select your template from the <strong>User Defined<\/strong> tab.<\/p>\n<p><a href=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/custom-policy-new-scan.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1706\" src=\"http:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/custom-policy-new-scan.png\" alt=\"Nessus custom policy new scan\" width=\"1427\" height=\"761\" title=\"\" srcset=\"https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/custom-policy-new-scan.png 1427w, https:\/\/kifarunix.com\/wp-content\/uploads\/2018\/12\/custom-policy-new-scan-768x410.png 768w\" sizes=\"(max-width: 1427px) 100vw, 1427px\" \/><\/a><\/p>\n<p>You can then enter the basic details of the scan; the name, description, the network to scan, folder to save the results, whether to schedule or run the scan once, email the results after scanning.<\/p>\n<p>Basically, that is what it takes to create a custom Nessus scan policy template. Feel free to explore and customize other templates to suit your scan requirements.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nessus Scan policy template is a set of predefined configuration options related to performing a scan. They define specific actions that are performed during a<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rank_math_lock_modified_date":false,"footnotes":""},"categories":[151,34,150],"tags":[139,141],"class_list":["post-792","post","type-post","status-publish","format-standard","hentry","category-nessus","category-security","category-vulnerability-scanners","tag-nessus","tag-nessus-vulnerability-scan","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50"],"_links":{"self":[{"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/posts\/792"}],"collection":[{"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/comments?post=792"}],"version-history":[{"count":4,"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/posts\/792\/revisions"}],"predecessor-version":[{"id":1707,"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/posts\/792\/revisions\/1707"}],"wp:attachment":[{"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/media?parent=792"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/categories?post=792"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kifarunix.com\/wp-json\/wp\/v2\/tags?post=792"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}