Skip to content

About

Deploying Greenbone/OpenVAS via Docker for vulnerability assessment on ARM64, feed management, scanning, OS fingerprinting, and real-world troubleshooting.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

🔍 Vulnerability Assessment Lab

Greenbone / OpenVAS on ARM64

typing summary

type nvts full report

greenbone docker ubuntu nmap

A home SOC lab deploying Greenbone Community Edition (OpenVAS) via Docker to perform vulnerability assessments against local network targets, with full documentation of setup challenges, ARM64 compatibility issues, and scan results.

Overview

This lab installs and configures Greenbone Community Edition in a Docker environment on Ubuntu 26.04 ARM64, syncs the full Greenbone vulnerability feed (156,018 NVTs), and runs scans against two local network targets. The lab documents a real-world troubleshooting scenario involving Python 3.14 incompatibility with ospd-openvas and ARM64 Docker scanner limitations.

Scanner: Greenbone Community Edition 26.18.0 (Docker)
Targets: Ubuntu-SIEM (192.168.1.58), Mac Mini (192.168.1.68)
Host: Apple Mac Mini M4, 32GB RAM, macOS (UTM virtualization)


Lab Environment

Host IP OS Role
Ubuntu-SIEM 192.168.1.58 Ubuntu 26.04 ARM64 SIEM host / scan target
Mac Mini 192.168.1.68 macOS (FreeBSD base) Host machine / scan target

Stack:

  • Greenbone Community Edition 26.18.0
  • gvmd 26.24.0
  • ospd-openvas 22.10.1
  • 156,018 NVTs loaded from Greenbone Community Feed
  • SCAP data: CVEs and CPEs current as of April 2026

Feed Status

Greenbone Community Feed fully synced — 156,018 NVTs with current SCAP (CVE/CPE) data.


Setup Challenges

Python 3.14 Incompatibility

Initial installation via apt install openvas failed at runtime. Ubuntu 26.04 ships with Python 3.14 which introduced breaking changes to the multiprocessing module that ospd-openvas 22.10.1 depends on. The scanner crashed with FileNotFoundError on every scan attempt. No updated package was available in the Ubuntu repositories or PyPI.

Resolution: Switched to Docker-based Greenbone Community Edition which bundles its own Python environment.

Disk Space

The Docker images combined with the existing ELK stack exceeded the original 20GB VM disk. The VM disk was expanded to 120GB using qemu-img from the Mac host, then the Ubuntu LVM partition was grown using growpart and lvextend.

Web Interface Binding

The default Docker configuration bound the nginx container to 127.0.0.1:9392, making it unreachable from the Mac browser. Fixed by editing the port bindings in compose.yaml to use 0.0.0.0.

Greenbone Dashboard

The Greenbone Security Assistant console, reachable after rebinding the web interface to 0.0.0.0.


Scans Performed

Task Target Duration Results
Ubuntu-SIEM Scan v3 192.168.1.58 ~1 minute 4 log findings
Mac-Mini Scan 192.168.1.68 ~1 minute 4 log findings, OS detected
Vulnerability Scan 192.168.1.58 ~1 minute 4 log findings

Scan Tasks

All three scan tasks completed in the Greenbone task view.


Findings

All scans returned four informational (log-level) host discovery findings:

  • OS Detection Consolidation and Reporting — Severity: 0.0 (Log), QoD: 80%
  • Traceroute — Severity: 0.0 (Log), QoD: 80%
  • CPE Inventory — Severity: 0.0 (Log), QoD: 80%
  • Hostname Determination Reporting — Severity: 0.0 (Log), QoD: 80%

Scan Results

Scan report showing the four host-discovery (log-level) findings.

OS Fingerprinting

The Mac Mini scan correctly identified the host OS via ICMP fingerprinting:

  • Primary match: FreeBSD (cpe:/o:freebsd:freebsd) — macOS is built on a FreeBSD-derived kernel
  • Secondary match: Apple Mac OS X (cpe:/o:apple:mac_os_x)

OS Detection

OS detection tab identifying the Mac Mini host as FreeBSD-based.

OS Detection Detail

Detailed OS-detection result with the matched CPE data.

No CVEs or vulnerability findings were produced due to the ARM64 scanner limitation described below.


ARM64 Docker Scanner Limitation

All scans completed in under two minutes with zero open ports detected, despite nmap confirming ports 22, 80, 443, 5601, and 9392 were open and reachable on the target.

Root cause: The boreas alive detection module and internal port scanner in ospd-openvas use raw sockets and Linux kernel capabilities that do not function correctly inside a QEMU-emulated ARM64 Docker container on Apple Silicon. This is a known platform limitation, not a configuration error.

nmap executed from inside the ospd-openvas container successfully reached port 80 on the target, confirming network connectivity was not the issue — the scanner itself does not use standard TCP connections for port enumeration.

Workaround for future labs: Run the scanner natively on an x86_64 VM, or use an external scanner appliance on a different host.


Tools Used

Tool Purpose
Greenbone Community Edition 26.18.0 Vulnerability scanner and management platform
gvmd 26.24.0 Greenbone Vulnerability Manager daemon
ospd-openvas 22.10.1 OpenVAS scanner daemon
Docker Container runtime for the Greenbone stack
nmap Port verification and host discovery
qemu-img VM disk expansion from macOS host

Using Claude as a Tool

I used Claude (Anthropic) as a tool throughout this lab, the same way I use it across the series. It helped me walk through each stage, deepen my understanding of the techniques as I ran them, and document what I did along the way. I directed the work, made the operational decisions, and built and validated every detection myself, verifying each command and result independently.


Other Labs in This Series

Lab Topic Repo
Lab 1 SOC/SIEM Detection soc-siem-lab
Lab 2 Incident Response Simulation incident-response-lab
Lab 3 Web Application Attack web-app-attack-lab
Lab 4 Vulnerability Assessment This repo
Lab 5 Malware Analysis malware-analysis-lab
Lab 6 Phishing Analysis phishing-analysis-lab
Lab 7 Active Directory Attack active-directory-lab

About

Deploying Greenbone/OpenVAS via Docker for vulnerability assessment on ARM64, feed management, scanning, OS fingerprinting, and real-world troubleshooting.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors