OpenVAS is the scanning engine of Greenbone Community Edition, an open source vulnerability management suite that tests hosts against tens of thousands of known vulnerabilities and misconfigurations. The Greenbone project's recommended way to run it is as a set of Docker containers, which avoids building a dozen components from source. In this tutorial you will deploy Greenbone Community Edition on Ubuntu 24.04 with Docker Compose, wait for the vulnerability feeds to load, scan a host and read the report.
Prerequisites
To follow this tutorial you need:
- A server running Ubuntu 24.04 LTS with at least 4 CPU cores, 8 GB of RAM and 60 GB of free disk space, for example a CubePath VPS. Greenbone's documented minimum is 2 cores, 4 GB of RAM and 20 GB of disk, but feed loading and scans are slow on that size.
- A non-root user with
sudoprivileges. - SSH access from your workstation, which you will also use to reach the web interface.
- Written permission to scan every target you add.
WarningVulnerability scans send large numbers of probes and exploit checks. Only scan systems you own or are explicitly authorised to test. Scanning third-party hosts can be illegal and may get your IP address blocked.
Step 1 - Installing Docker Engine and Docker Compose
Greenbone's containers need Docker Engine with the Compose plugin. Install them from Docker's official repository. First add Docker's signing key:
sudo apt update
sudo apt install ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc
Add the repository:
echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | sudo tee /etc/apt/sources.list.d/docker.list
Install the packages:
sudo apt update
sudo apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
Verify that Docker and Compose work:
sudo docker compose version
Docker Compose version v2.39.4
Step 2 - Downloading the Greenbone Compose file
Greenbone publishes a ready-made docker-compose.yml that defines all services: the scanner (ospd-openvas), the manager (gvmd), the web interface (gsa), PostgreSQL, Redis and a set of containers that carry the vulnerability feed data.
Create a directory for it:
mkdir -p ~/greenbone-community-container
Download the file:
curl -f -L https://greenbone.github.io/docs/latest/_static/docker-compose.yml -o ~/greenbone-community-container/docker-compose.yml
Open it and read it before running anything. Note in particular the port mapping of the web interface: it publishes port 9392 on 127.0.0.1 only, so it is not exposed to the internet.
less ~/greenbone-community-container/docker-compose.yml
Step 3 - Starting Greenbone Community Edition
Pull the images. This downloads several gigabytes, including the feed data:
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml pull
Start the stack in the background:
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml up -d
Check the state of the containers:
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml ps
The long-running services (gvmd, gsa, ospd-openvas, pg-gvm, redis-server and the others) show Up. The feed data containers such as vulnerability-tests and scap-data copy their files into shared volumes and then exit, which is expected.
Step 4 - Setting the administrator password
The Compose setup creates a user called admin with the password admin. Change it immediately, replacing your_strong_password with a long unique password:
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml exec -u gvmd gvmd gvmd --user=admin --new-password='your_strong_password'
The command prints nothing when it succeeds.
Step 5 - Opening the web interface through an SSH tunnel
Because the web interface only listens on the server's loopback address, reach it through an SSH tunnel. On your local workstation, run:
ssh -L 9392:127.0.0.1:9392 your_user@your_server_ip
Keep this session open and browse to http://127.0.0.1:9392 on your workstation. Log in as admin with the password you just set.
This approach keeps the scanner's management interface off the public internet without having to configure TLS or a reverse proxy.
Step 6 - Waiting for the feeds to load
After the first start, gvmd imports the vulnerability tests (NVTs), SCAP data (CVEs and CPEs) and CERT advisories into its database. Scans started before this finishes find nothing or fail, so wait for it.
In the web interface, go to Administration > Feed Status. Every feed must show Current in the status column. While loading, they show Update in progress.
You can also follow the progress from the server:
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml logs -f gvmd
On the first start, the import typically takes 30 minutes to a few hours depending on CPU and disk speed. Press Ctrl+C to stop following the logs; the containers keep running.
Step 7 - Creating a scan target
A target defines which hosts to scan and which ports to test. Go to Configuration > Targets and click the new target icon (the star in the top left). Fill in:
- Name: a descriptive name, for example
web01. - Hosts: an IP address, a list, a range such as
192.168.1.10-20or a CIDR such as192.168.1.0/24. - Port List:
All IANA assigned TCPis a good default.All TCP and Nmap top 100 UDPis more thorough but slower. - Alive Test: leave
Scan Config Default. If the target blocks ICMP, chooseConsider Aliveso the host is scanned anyway.
Optionally add Credentials for SSH (Linux) or SMB (Windows). An authenticated scan logs in and checks installed package versions, which finds far more issues and produces fewer false positives than an unauthenticated one. Create the credentials first under Configuration > Credentials, preferably for a dedicated low-privilege account.
Click Save. The target appears in the list.
Step 8 - Running a scan
A task combines a target with a scan configuration. Go to Scans > Tasks, click the new task icon and choose New Task. Set:
- Name: for example
web01 weekly. - Scan Targets: the target you created.
- Scanner:
OpenVAS Default. - Scan Config:
Full and fast, the recommended configuration. It uses information from earlier checks to skip tests that cannot apply.
Click Save, then click the play button in the task's row. The status changes to Requested, then Queued, then shows a progress percentage. A full and fast scan of one host usually takes 10 to 60 minutes.
To confirm the scanner is working, follow its log on the server:
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml logs -f ospd-openvas
You should see lines reporting that the scan of your target has started and, later, finished.
Step 9 - Reading the report
When the task shows Done, click the date in its Last Report column. The report has several tabs:
- Results: every finding, with a severity score (CVSS, from 0 to 10) and a QoD (Quality of Detection) percentage that indicates how reliable the detection is.
- Hosts, Ports, Applications and Operating Systems: what the scanner discovered.
- CVEs: the CVE identifiers behind the findings.
Start with results rated High and Critical. Each result explains what was detected, its impact and the recommended solution, usually a package update or a configuration change. After fixing an issue, run the task again to confirm the result disappears.
To share a report, click the download icon and pick a format such as PDF, CSV or XML.
If a finding is a confirmed false positive, open it and create an Override that sets its severity to False Positive, so it no longer appears in future reports of that task.
Step 10 - Scheduling scans and updating the feeds
Regular scans catch new vulnerabilities as they are published. Create a schedule under Configuration > Schedules (for example weekly on Sunday at 03:00), then edit the task and select it in the Schedule field.
The feed data is delivered as container images, so updating the feeds and the software is the same operation. Run it weekly:
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml pull
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml up -d
After each update, gvmd loads the new data in the background; check Administration > Feed Status before starting important scans.
Troubleshooting
The Scan Config or Port List drop-downs are empty. The feeds have not finished loading. Wait until every feed shows Current in Feed Status.
A task stays at Requested or ends as Interrupted at 0%. Check the ospd-openvas and gvmd logs. The scanner usually needs its NVTs loaded into Redis first, which happens after the feed import; restarting only the scanner can help:
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml restart ospd-openvas
The host is reported as dead. The target drops ICMP. Change the target's Alive Test to Consider Alive.
The web interface does not load. Make sure the SSH tunnel session is still open and that the web interface container is Up in docker compose ps.
Conclusion
You deployed Greenbone Community Edition with the OpenVAS scanner on Ubuntu 24.04, secured the admin account, kept the web interface behind an SSH tunnel, and ran and interpreted your first vulnerability scan. Next, add SSH credentials to your targets for authenticated scans, schedule weekly scans of all your servers, and feed the findings into your patching process so that each report is shorter than the last.
