Retrieving exploit information from Nessus / Tenable scans #9736
-
Hi, I'm using Nessus with DefectDojo and I'd like for DefectDojo to provide a CSV that'd include columns like Exploit Available This information is provided by the Nessus scan in its XML export file (.nessus extension) but I can't get DefectDojo to parse the information. Whenever DefectDojo parses the Nessus scan it seems to ignore everything regarding exploits. Even if Nessus says that an exploit is present in metasploit, it ignores all information regarding the exploitability. For example, I tried this Nessus XML sample: Which includes one exploit present in metasploit, and this one, which includes more than 10: but when I ask DefectDojo to import any of these XML scans and then export the results to CSV, it has no information regarding exploitability (in fact EPSS is N.A. for all findings). Exploit information also doesn't appear in the DefectDojo's dashboard. A CSV with these columns regarding exploits can be found here: But I am unable to produce anything similar. Am I doing something wrong? Is there a setting I should be configuring differently? Or is this just a limitation of DefectDojo? It would help me greatly to know the answer, |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Hi @SeaofThought, I guess you are talking about multiple problems here.
Best, Manuel |
Beta Was this translation helpful? Give feedback.
Hi @SeaofThought,
I guess you are talking about multiple problems here.