OpenVAS is the scanning engine of Greenbone Community Edition, an open source vulnerability management suite that tests hosts against tens of thousands of known vulnerabilities and misconfigurations. The Greenbone project's recommended way to run it is as a set of Docker containers, which avoids building a dozen components from source. In this tutorial you will deploy Greenbone Community Edition on Ubuntu 24.04 with Docker Compose, wait for the vulnerability feeds to load, scan a host and read the report.

Prerequisites

To follow this tutorial you need:

  • A server running Ubuntu 24.04 LTS with at least 4 CPU cores, 8 GB of RAM and 60 GB of free disk space, for example a CubePath VPS. Greenbone's documented minimum is 2 cores, 4 GB of RAM and 20 GB of disk, but feed loading and scans are slow on that size.
  • A non-root user with sudo privileges.
  • SSH access from your workstation, which you will also use to reach the web interface.
  • Written permission to scan every target you add.

Step 1 - Installing Docker Engine and Docker Compose

Greenbone's containers need Docker Engine with the Compose plugin. Install them from Docker's official repository. First add Docker's signing key:

sudo apt update
sudo apt install ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc

Add the repository:

echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | sudo tee /etc/apt/sources.list.d/docker.list

Install the packages:

sudo apt update
sudo apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin

Verify that Docker and Compose work:

sudo docker compose version
Docker Compose version v2.39.4

Step 2 - Downloading the Greenbone Compose file

Greenbone publishes a ready-made docker-compose.yml that defines all services: the scanner (ospd-openvas), the manager (gvmd), the web interface (gsa), PostgreSQL, Redis and a set of containers that carry the vulnerability feed data.

Create a directory for it:

mkdir -p ~/greenbone-community-container

Download the file:

curl -f -L https://greenbone.github.io/docs/latest/_static/docker-compose.yml -o ~/greenbone-community-container/docker-compose.yml

Open it and read it before running anything. Note in particular the port mapping of the web interface: it publishes port 9392 on 127.0.0.1 only, so it is not exposed to the internet.

less ~/greenbone-community-container/docker-compose.yml

Step 3 - Starting Greenbone Community Edition

Pull the images. This downloads several gigabytes, including the feed data:

sudo docker compose -f ~/greenbone-community-container/docker-compose.yml pull

Start the stack in the background:

sudo docker compose -f ~/greenbone-community-container/docker-compose.yml up -d

Check the state of the containers:

sudo docker compose -f ~/greenbone-community-container/docker-compose.yml ps

The long-running services (gvmd, gsa, ospd-openvas, pg-gvm, redis-server and the others) show Up. The feed data containers such as vulnerability-tests and scap-data copy their files into shared volumes and then exit, which is expected.

Step 4 - Setting the administrator password

The Compose setup creates a user called admin with the password admin. Change it immediately, replacing your_strong_password with a long unique password:

sudo docker compose -f ~/greenbone-community-container/docker-compose.yml exec -u gvmd gvmd gvmd --user=admin --new-password='your_strong_password'

The command prints nothing when it succeeds.

Step 5 - Opening the web interface through an SSH tunnel

Because the web interface only listens on the server's loopback address, reach it through an SSH tunnel. On your local workstation, run:

ssh -L 9392:127.0.0.1:9392 your_user@your_server_ip

Keep this session open and browse to http://127.0.0.1:9392 on your workstation. Log in as admin with the password you just set.

This approach keeps the scanner's management interface off the public internet without having to configure TLS or a reverse proxy.

Step 6 - Waiting for the feeds to load

After the first start, gvmd imports the vulnerability tests (NVTs), SCAP data (CVEs and CPEs) and CERT advisories into its database. Scans started before this finishes find nothing or fail, so wait for it.

In the web interface, go to Administration > Feed Status. Every feed must show Current in the status column. While loading, they show Update in progress.

You can also follow the progress from the server:

sudo docker compose -f ~/greenbone-community-container/docker-compose.yml logs -f gvmd

On the first start, the import typically takes 30 minutes to a few hours depending on CPU and disk speed. Press Ctrl+C to stop following the logs; the containers keep running.

Step 7 - Creating a scan target

A target defines which hosts to scan and which ports to test. Go to Configuration > Targets and click the new target icon (the star in the top left). Fill in:

  • Name: a descriptive name, for example web01.
  • Hosts: an IP address, a list, a range such as 192.168.1.10-20 or a CIDR such as 192.168.1.0/24.
  • Port List: All IANA assigned TCP is a good default. All TCP and Nmap top 100 UDP is more thorough but slower.
  • Alive Test: leave Scan Config Default. If the target blocks ICMP, choose Consider Alive so the host is scanned anyway.

Optionally add Credentials for SSH (Linux) or SMB (Windows). An authenticated scan logs in and checks installed package versions, which finds far more issues and produces fewer false positives than an unauthenticated one. Create the credentials first under Configuration > Credentials, preferably for a dedicated low-privilege account.

Click Save. The target appears in the list.

Step 8 - Running a scan

A task combines a target with a scan configuration. Go to Scans > Tasks, click the new task icon and choose New Task. Set:

  • Name: for example web01 weekly.
  • Scan Targets: the target you created.
  • Scanner: OpenVAS Default.
  • Scan Config: Full and fast, the recommended configuration. It uses information from earlier checks to skip tests that cannot apply.

Click Save, then click the play button in the task's row. The status changes to Requested, then Queued, then shows a progress percentage. A full and fast scan of one host usually takes 10 to 60 minutes.

To confirm the scanner is working, follow its log on the server:

sudo docker compose -f ~/greenbone-community-container/docker-compose.yml logs -f ospd-openvas

You should see lines reporting that the scan of your target has started and, later, finished.

Step 9 - Reading the report

When the task shows Done, click the date in its Last Report column. The report has several tabs:

  • Results: every finding, with a severity score (CVSS, from 0 to 10) and a QoD (Quality of Detection) percentage that indicates how reliable the detection is.
  • Hosts, Ports, Applications and Operating Systems: what the scanner discovered.
  • CVEs: the CVE identifiers behind the findings.

Start with results rated High and Critical. Each result explains what was detected, its impact and the recommended solution, usually a package update or a configuration change. After fixing an issue, run the task again to confirm the result disappears.

To share a report, click the download icon and pick a format such as PDF, CSV or XML.

If a finding is a confirmed false positive, open it and create an Override that sets its severity to False Positive, so it no longer appears in future reports of that task.

Step 10 - Scheduling scans and updating the feeds

Regular scans catch new vulnerabilities as they are published. Create a schedule under Configuration > Schedules (for example weekly on Sunday at 03:00), then edit the task and select it in the Schedule field.

The feed data is delivered as container images, so updating the feeds and the software is the same operation. Run it weekly:

sudo docker compose -f ~/greenbone-community-container/docker-compose.yml pull
sudo docker compose -f ~/greenbone-community-container/docker-compose.yml up -d

After each update, gvmd loads the new data in the background; check Administration > Feed Status before starting important scans.

Troubleshooting

The Scan Config or Port List drop-downs are empty. The feeds have not finished loading. Wait until every feed shows Current in Feed Status.

A task stays at Requested or ends as Interrupted at 0%. Check the ospd-openvas and gvmd logs. The scanner usually needs its NVTs loaded into Redis first, which happens after the feed import; restarting only the scanner can help:

sudo docker compose -f ~/greenbone-community-container/docker-compose.yml restart ospd-openvas

The host is reported as dead. The target drops ICMP. Change the target's Alive Test to Consider Alive.

The web interface does not load. Make sure the SSH tunnel session is still open and that the web interface container is Up in docker compose ps.

Conclusion

You deployed Greenbone Community Edition with the OpenVAS scanner on Ubuntu 24.04, secured the admin account, kept the web interface behind an SSH tunnel, and ran and interpreted your first vulnerability scan. Next, add SSH credentials to your targets for authenticated scans, schedule weekly scans of all your servers, and feed the findings into your patching process so that each report is shorter than the last.