skip to content

OpenVAS

Greenbone's open-source scanner: the Community versus Enterprise feed of NVTs, the gvmd/ospd-openvas architecture, and GMP. It is the free alternative to Nessus, so expect a feed-freshness comparison.

on this pageshow

explore

questions

6

How does the Greenbone Community Feed differ from the Greenbone Enterprise Feed, and is the free feed really delayed behind the paid one?

level: middleimportance: must knowfreq 24%

answer

  1. coverage, not calendar
  2. 2017 change to the release scheme
  3. enterprise-product tests left out
  4. no warranty versus an SLA

basics

~20 s

Both Greenbone feeds publish daily. The free Community Feed carries the most important VTs plus basic configs, without VTs for enterprise products and with no warranty; the commercial Enterprise Feed adds those VTs, compliance checks, more report formats and an SLA.

solid answer

~30 s

The **Greenbone Community Feed** is free and open-source licensed: the most important vulnerability tests, basic scan configurations, report formats and port lists, updated daily with no warranty or promise of fixes or completeness. The **Greenbone Enterprise Feed** is commercial and adds VTs for enterprise products, policy and compliance checks, extensive report formats, special scan configurations and a service-level agreement. The "two weeks behind" idea is stale: in 2017 Greenbone moved the public feed from a 14-day delay to daily publication without delay, but it now excludes the enterprise-product VTs. So the gap is coverage and assurance, not freshness.

go deeper

for a junior

Recall the two feed names, that both are updated daily, and that the Community Feed is free and the Enterprise Feed commercial.

for a middle

Explain what each feed contains, and why the old fourteen-day delay no longer describes the Community Feed since 2017.

for a senior

Judge what a clean Community Feed report proves for products whose tests sit only in the Enterprise Feed, and say so to the asset owners.

for a principal

Weigh self-supported best-effort coverage against paying for enterprise-product tests, compliance content and an SLA, given what your estate actually runs.

## What a Greenbone feed is A **feed** is the data a Greenbone scanner needs in order to find anything. The glossary defines it as a set of files delivered continuously via `rsync` and updated on a daily basis. It carries several kinds of content: - **VT data**: the Vulnerability Tests, as `.nasl` scripts processed by the OpenVAS Scanner and `.notus` files used for local security checks; - **SCAP data**: CPE and CVE information; - **CERT data**: advisories from the German DFN-CERT and CERT-Bund; - **GVMD data** (also called data objects): scan configurations, compliance policies, port lists and report formats. The feed exists in two editions: the free **Greenbone Community Feed** and the commercial **Greenbone Enterprise Feed**. ## The two feeds side by side | | Greenbone Community Feed | Greenbone Enterprise Feed | |---|---|---| | Price and licence | Freely available, licensed as open source | Commercial | | VT coverage | The most important vulnerability tests | Adds VTs for enterprise products | | Data objects | Basic scan configurations, report formats and port lists | Adds policy and compliance checks, extensive report formats and special scan configurations | | Update cadence | Daily | Daily | | Guarantees | No warranty or promises for fixes or completeness | A service-level agreement covering support, quality assurance and availability | | Where it comes from | `greenbone-feed-sync`, or the Community Containers' data images | Shipped with the Greenbone Enterprise line | The Community Edition is developed as part of the Greenbone Enterprise line, and the Enterprise appliances also run the GVM framework; much of what the commercial line adds sits in the feed, the appliance operating system and the support around them. ## The delay that no longer exists Many people still describe the free feed as the commercial feed published two weeks late. That was once true. Greenbone's own history records that in 2017 the public feed was renamed the Greenbone Community Feed, feed development was brought in-house, and the release scheme changed **from a 14-day delay to a daily publication without delay, now excluding vulnerability tests for enterprise products**. So the honest comparison today is: 1. **Freshness**: both feeds publish daily; there is no built-in lag on the Community Feed for the content it carries. 2. **Coverage**: the Community Feed leaves out the VTs for enterprise products, so checks for those products are missing rather than late. 3. **Content beyond VTs**: the glossary lists policy and compliance checks, extensive report formats and special scan configurations as Enterprise Feed additions; the Community Feed's data objects are the basic set. 4. **Assurance**: the Community Feed carries no warranty or promise of fixes or completeness; the Enterprise Feed comes with an SLA. Why a gap in checks matters to a finding is a general scanner question; for Greenbone the specific answer is that the gap is about which products are covered, not how many days behind the free feed runs. ## What this means when you stand up the Community Edition - **Know your estate.** If the hosts you care about run enterprise products whose VTs sit only in the Enterprise Feed, a clean Community Feed report for those products is an absence of tests, not evidence of safety. - **Validate what you download.** The source-build guide creates a GnuPG keyring with the Greenbone Community Feed integrity key so the scanner can verify feed content. - **Download is not the end.** A sync has two steps: the download, then the daemons loading the data into memory and the database; until loading finishes, scans are incomplete. - **Do not overclaim.** The free feed has no promise of completeness, so present it to stakeholders as best-effort coverage. ## How the Community Feed reaches a self-hosted scanner - **Source build**: `greenbone-feed-sync`, a Python script released independently of the Community Edition, downloads the data with `rsync`. With no arguments it fetches every data type; `--type` limits it to one, for example `nasl`, `notus`, `scap`, `cert` or `gvmd-data`. - **Community Containers**: the feed ships as data container images (`vulnerability-tests`, `notus-data`, `scap-data`, `dfn-cert-data`, `cert-bund-data`, `report-formats`, `data-objects`); `docker compose pull` followed by `up -d` copies the new data into the volumes the daemons read. - **Older scripts**: `greenbone-nvt-sync`, `greenbone-scapdata-sync` and `greenbone-certdata-sync` are deprecated or no longer installed; the new `greenbone-feed-sync` replaces them all. ## How to answer in an interview Lead with the two-row summary: same daily cadence, different coverage and guarantees. Then correct the stale "two weeks behind" claim with its date, 2017, and name what the Enterprise Feed adds: enterprise-product VTs, policy and compliance checks, report formats, scan configurations and an SLA.

  • A Community Edition scan reports nothing for an enterprise product your team runs. What does that tell you?
    Possibly nothing. The Community Feed excludes VTs for enterprise products, so a quiet report may mean no test ran rather than no weakness exists. Check whether VTs for that product exist on the SecInfo pages of your install before you treat the result as clean.
  • Which kinds of data does a Greenbone Community Feed sync download besides the VTs?
    SCAP data with CPE and CVE information, CERT data from DFN-CERT and CERT-Bund, and GVMD data, also called data objects: scan configurations, compliance policies, port lists and report formats. `greenbone-feed-sync` fetches them all by default, and each type can be fetched alone with `--type`.

saying these in an interview costs you the question

  • The Community Feed is the Enterprise Feed released two weeks later.
  • The Community Feed is refreshed weekly, so new checks arrive days late.
  • The free feed comes with Greenbone's promise of fixes and completeness.
  • The Community Feed contains no CVE or CPE data, only test scripts.
  • Switching to the Enterprise Feed requires a different scanner engine.
open as a page

In Greenbone Community Edition, what do gvmd, ospd-openvas, openvas-scanner and gsad each do, and which protocols connect them?

level: middleimportance: must knowfreq 18%

basics

~20 s

gvmd is the manager: it offers GMP, stores everything in PostgreSQL and drives the scanner over OSP. ospd-openvas launches openvas-scanner, which runs the VTs using Redis; gsad serves the web interface and speaks GMP to gvmd.

open as a page

When a colleague says they run OpenVAS, what might they mean, and how do OpenVAS, GVM and Greenbone Community Edition relate?

level: juniorimportance: should knowfreq 20%

basics

~20 s

OpenVAS can mean just the scan engine or the whole framework. The framework was renamed GVM after OpenVAS 9, and since 2022 Greenbone calls its open-source releases Greenbone Community Edition, with the OpenVAS Scanner as one component.

open as a page

After a fresh Greenbone Community Edition source build and a greenbone-feed-sync run, GSA lists no scan configs and a test scan finds nothing: what is happening, and how do you confirm it?

level: seniorimportance: should knowfreq 9%

basics

~20 s

Downloading the feed is only half a sync: ospd-openvas and gvmd must then load it, which can take hours, and scan configs also need a Feed Import Owner set in gvmd. Confirm with both daemons' load messages.

open as a page

How do you drive a Greenbone scan from a script over GMP with gvm-tools, and when would you pick gvm-cli over gvm-script?

level: middleimportance: nice to knowfreq 12%

basics

~20 s

gvm-tools clients speak GMP, gvmd's XML protocol: create a target, create a task with a scan config and scanner, start it, poll get_tasks, then fetch the report. gvm-cli sends raw XML for simple shell jobs; gvm-script runs Python for anything with logic.

open as a page

In Greenbone's OpenVAS, how does a NASL NVT differ from a Notus local security check, and why did Greenbone introduce Notus?

level: middleimportance: nice to knowfreq 6%

basics

~20 s

An NVT is a NASL script, identified by an OID, that openvas runs against a host. Notus replaces script-per-check local security checks with one comparison of the installed packages against a list of vulnerable versions for that OS.

open as a page