A home SOC lab deploying Greenbone Community Edition (OpenVAS) via Docker to perform vulnerability assessments against local network targets, with full documentation of setup challenges, ARM64 compatibility issues, and scan results.
This lab installs and configures Greenbone Community Edition in a Docker environment on Ubuntu 26.04 ARM64, syncs the full Greenbone vulnerability feed (156,018 NVTs), and runs scans against two local network targets. The lab documents a real-world troubleshooting scenario involving Python 3.14 incompatibility with ospd-openvas and ARM64 Docker scanner limitations.
Scanner: Greenbone Community Edition 26.18.0 (Docker)
Targets: Ubuntu-SIEM (192.168.1.58), Mac Mini (192.168.1.68)
Host: Apple Mac Mini M4, 32GB RAM, macOS (UTM virtualization)
| Host | IP | OS | Role |
|---|---|---|---|
| Ubuntu-SIEM | 192.168.1.58 | Ubuntu 26.04 ARM64 | SIEM host / scan target |
| Mac Mini | 192.168.1.68 | macOS (FreeBSD base) | Host machine / scan target |
Stack:
- Greenbone Community Edition 26.18.0
- gvmd 26.24.0
- ospd-openvas 22.10.1
- 156,018 NVTs loaded from Greenbone Community Feed
- SCAP data: CVEs and CPEs current as of April 2026
Greenbone Community Feed fully synced — 156,018 NVTs with current SCAP (CVE/CPE) data.
Initial installation via apt install openvas failed at runtime. Ubuntu 26.04 ships with Python 3.14 which introduced breaking changes to the multiprocessing module that ospd-openvas 22.10.1 depends on. The scanner crashed with FileNotFoundError on every scan attempt. No updated package was available in the Ubuntu repositories or PyPI.
Resolution: Switched to Docker-based Greenbone Community Edition which bundles its own Python environment.
The Docker images combined with the existing ELK stack exceeded the original 20GB VM disk. The VM disk was expanded to 120GB using qemu-img from the Mac host, then the Ubuntu LVM partition was grown using growpart and lvextend.
The default Docker configuration bound the nginx container to 127.0.0.1:9392, making it unreachable from the Mac browser. Fixed by editing the port bindings in compose.yaml to use 0.0.0.0.
The Greenbone Security Assistant console, reachable after rebinding the web interface to 0.0.0.0.
| Task | Target | Duration | Results |
|---|---|---|---|
| Ubuntu-SIEM Scan v3 | 192.168.1.58 | ~1 minute | 4 log findings |
| Mac-Mini Scan | 192.168.1.68 | ~1 minute | 4 log findings, OS detected |
| Vulnerability Scan | 192.168.1.58 | ~1 minute | 4 log findings |
All three scan tasks completed in the Greenbone task view.
All scans returned four informational (log-level) host discovery findings:
- OS Detection Consolidation and Reporting — Severity: 0.0 (Log), QoD: 80%
- Traceroute — Severity: 0.0 (Log), QoD: 80%
- CPE Inventory — Severity: 0.0 (Log), QoD: 80%
- Hostname Determination Reporting — Severity: 0.0 (Log), QoD: 80%
Scan report showing the four host-discovery (log-level) findings.
The Mac Mini scan correctly identified the host OS via ICMP fingerprinting:
- Primary match: FreeBSD (cpe:/o:freebsd:freebsd) — macOS is built on a FreeBSD-derived kernel
- Secondary match: Apple Mac OS X (cpe:/o:apple:mac_os_x)
OS detection tab identifying the Mac Mini host as FreeBSD-based.
Detailed OS-detection result with the matched CPE data.
No CVEs or vulnerability findings were produced due to the ARM64 scanner limitation described below.
All scans completed in under two minutes with zero open ports detected, despite nmap confirming ports 22, 80, 443, 5601, and 9392 were open and reachable on the target.
Root cause: The boreas alive detection module and internal port scanner in ospd-openvas use raw sockets and Linux kernel capabilities that do not function correctly inside a QEMU-emulated ARM64 Docker container on Apple Silicon. This is a known platform limitation, not a configuration error.
nmap executed from inside the ospd-openvas container successfully reached port 80 on the target, confirming network connectivity was not the issue — the scanner itself does not use standard TCP connections for port enumeration.
Workaround for future labs: Run the scanner natively on an x86_64 VM, or use an external scanner appliance on a different host.
| Tool | Purpose |
|---|---|
| Greenbone Community Edition 26.18.0 | Vulnerability scanner and management platform |
| gvmd 26.24.0 | Greenbone Vulnerability Manager daemon |
| ospd-openvas 22.10.1 | OpenVAS scanner daemon |
| Docker | Container runtime for the Greenbone stack |
| nmap | Port verification and host discovery |
| qemu-img | VM disk expansion from macOS host |
I used Claude (Anthropic) as a tool throughout this lab, the same way I use it across the series. It helped me walk through each stage, deepen my understanding of the techniques as I ran them, and document what I did along the way. I directed the work, made the operational decisions, and built and validated every detection myself, verifying each command and result independently.
| Lab | Topic | Repo |
|---|---|---|
| Lab 1 | SOC/SIEM Detection | soc-siem-lab |
| Lab 2 | Incident Response Simulation | incident-response-lab |
| Lab 3 | Web Application Attack | web-app-attack-lab |
| Lab 4 | Vulnerability Assessment | This repo |
| Lab 5 | Malware Analysis | malware-analysis-lab |
| Lab 6 | Phishing Analysis | phishing-analysis-lab |
| Lab 7 | Active Directory Attack | active-directory-lab |





