Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

this version can perform the CIS compliance scan? #47

Open
wongcc2012 opened this issue Sep 20, 2023 · 14 comments
Open

this version can perform the CIS compliance scan? #47

wongcc2012 opened this issue Sep 20, 2023 · 14 comments

Comments

@wongcc2012
Copy link

just a question.
this version can perform the CIS compliance scan?

@dhruvvyas25
Copy link

No, you can't perform the CIS compliance scan because it does not have compliance plugins installed.

@elliot-bia
Copy link
Owner

I had no working experience of CIS compliance scan , is that means Center for Internet Security ?
More information will be helpful to solved this, thanks

@dhruvvyas25
Copy link

Yes, The Center for Internet Security (CIS) developed a series of best practice benchmarks for a variety of applications, operating systems, servers, and databases used within organizations today.

@elliot-bia
Copy link
Owner

Are there any photos can show more details?
For example:
image

@dhruvvyas25
Copy link

Yes, that's the CIS scan, but in that Compliance Tab missing in the UI and that's because the nessus doesn't have compliance plugins in /opt/nessus/lib/nessus/plugins/compliance_check.

@wongcc2012
Copy link
Author

Yes you are correct there is the compliance auditing in the official version.
image
image

@dhruvvyas25
Copy link

Can you add the compliance plugins in the cracked nessus ?

@wongcc2012
Copy link
Author

agree please add the compliance!

@elliot-bia
Copy link
Owner

Yes, that's the CIS scan, but in that Compliance Tab missing in the UI and that's because the nessus doesn't have compliance plugins in /opt/nessus/lib/nessus/plugins/compliance_check.

Sorry, I still don't get it.
Is this help?
image

@elliot-bia
Copy link
Owner

Ah, maybe I get what you say.
Unfortunately, this nessus version base on Nessus-10.x, and I think your nessus version base on something else.
I'm not sure the method I used would be also works the same way

@wongcc2012
Copy link
Author

this is NOT the complete CIS scan, can you get the nessus EXPERT trial and see what's inside?

@elliot-bia
Copy link
Owner

My daily job doesn't involve this...Nessus-10.x is what I need🤣
I can try from nessus website, but I am not guarantee it will be work

@wongcc2012
Copy link
Author

image
image
image

I am also using Nessus 10.x EXPERT trial, it has the compliance tab in scanning. then I can choose different compliance / audit to check the target systems.

MY cases: most using the CIS compliance for MS windows systems.

@jerrycheny
Copy link

Can CIS check be added to this version?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants