Let's say we're working in an organization and we are provided with the credentials to access Nessus via the Metasploit terminal ONLY. In situations like these, it's always better to run some basic commands to understand what we can and cannot do. Let's have a look at these commands over the course of the following steps:
- The first command we can execute is nessus_server_properties in msfconsole. This command will give us the details regarding the scanner (Type, Version, UUID, and so on). Based on the type of scanner, we can set our scanning preferences, as shown here:
- The nessus_server_status command is used to confirm the status of the scanner so that we can determine whether it is ready. This is helpful in situations where the organization is using a cloud-based Nessus with distributed scanner agents. The output of the command is shown...