openvas

Bot User-Agent: openvas

⚠️ Overview

OpenVAS (Open Vulnerability Assessment System) is an open-source vulnerability scanning framework originally forked from the Nessus project in 2005 and now maintained by Greenbone Networks as part of the Greenbone Security Manager. It is primarily used by security professionals for authorized penetration testing and compliance audits, but its availability and power make it a frequent tool for unauthorized reconnaissance and exploitation attempts against web applications.

🔧 Technical Capabilities

OpenVAS operates through a modular architecture consisting of the openvas-scanner engine, which executes Network Vulnerability Tests (NVTs) written in a custom scripting language. The scanner currently supports over 100,000 NVTs covering a wide range of vulnerabilities including critical CVEs, misconfigurations in web servers (e.g., Apache, Nginx), SQL injection flaws, cross-site scripting (XSS), insecure SSL/TLS ciphers, and default credential checks. It can perform authenticated and unauthenticated scans, leveraging plugins to test for everything from outdated software versions to weak password policies. The scanner communicates via the OpenVAS Transfer Protocol (OTP) and is typically managed through the Greenbone Security Assistant (GSA) web interface. Scanning is highly configurable with customizable scan configurations and scheduling, and the tool can generate detailed XML or HTML reports that attackers often use to prioritize exploitation.

📜 History & Notable Incidents

OpenVAS originated from the Tenable Nessus project’s transition to a closed-source model; the open-source community created and continued to develop the fork, which eventually became the OpenVAS project under Greenbone. Notable CVEs that OpenVAS frequently detects include CVE-2017-5638 (Apache Struts2), CVE-2020-1472 (Zerologon), and CVE-2021-44228 (Log4Shell). In 2021, researchers demonstrated that misconfigured OpenVAS instances could be leveraged by external attackers to perform scans on internal networks, highlighting the tool’s dual-use nature. Malicious actors have been observed using publicly exposed Greenbone Security Assistant dashboards to conduct reconnaissance, as documented in threat intelligence reports from SANS and various CERTs.

🔍 Detection Indicators

Scanning from OpenVAS can be identified by its default User-Agent string, often appearing as Mozilla/5.0 (compatible; OpenVAS) or Greenbone in HTTP request headers. The scanner produces rapid sequential requests across multiple paths, HTTP methods, and parameter variations, often with unusually high request rates and frequent 404 errors. Network defenders can also detect OpenVAS by the signature of its NVT probes, which include specific payload strings like openvas in URL path fragments or POST data. Behavioral fingerprints include systematic port scanning followed by application-layer vulnerability checks, distinct from generic bot traffic.

☠️ Risk & Impact

When used maliciously, OpenVAS enables an attacker to map a target’s attack surface, discover unpatched software and misconfigurations, and identify exploitable vulnerabilities within minutes. Successful exploitation following an OpenVAS scan can lead to data breaches, server compromise, credential theft, and lateral movement within a network. The tool’s comprehensive reporting provides attackers with a ready-made exploitation roadmap, significantly reducing the time from reconnaissance to compromise.

🛡️ Mitigation

OpenVAS is blocked immediately on detection because its systematic scanning activity is a clear precursor to targeted attacks, and any unauthorized scanning violates security policies and may be illegal under computer fraud laws. Immediate blocking through WAF rules, IP blacklisting, and rate limiting prevents the attacker from completing vulnerability discovery, thereby protecting the application from subsequent exploitation.

53% of Web Traffic Is Bots in 2026

— Imperva Bad Bot Report 2026

How much of your traffic is automated? Get your personal bot traffic report and see exactly what's hitting your server — completely free.

📊 Get My Bot Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.