Overview of Nexpose Community
Nexpose is another vulnerability scanner that is very similar to OpenVAS.
Nexpose Community is supported by Rapid7 and you can download it here: https://www.rapid7.com/info/nexpose-community/.
We have to highlight the fact that the functionality has been limited; however, in case you want the full version, they also offer the full version of Nexpose for a 30-day trial.
The installation steps are well documented at the following link: https://docs.rapid7.com/nexpose/download.
To run a scan, you just need to follow this simple flow, as highlighted in Figure 13.16:
- INFO & SECURITY: Here, you just need to add a name and description of the testing.
- ASSETS: Select the assets or system to be scanned.
- AUTHENTICATION: Here, you can add the credentials for authenticated tests.
- TEMPLATES: Here, you can choose the type of scan to be performed—for example, a Sarbanes-Oxley (SOX) scan or PCI DSS.
- ENGINES: Here, you select...