Greenbone / OpenVAS
Scanner-centric / self-hosted open source
The OpenVAS Scanner engine, available as free open-source Community Edition or as a commercial Greenbone appliance/feed.
- Not itemizedGov / FedRAMP
- No / integrationBuilt-in patch
- YesOpen source
- On-premises, Self-hosted / air-gappedDeployment
- Classification
- Open-source/self-hosted vulnerability scanning and vulnerability management.
- Discovery / scanning
- Official/Verified: The OpenVAS Scanner executes vulnerability tests against target systems, drawing on the Greenbone Community Feed or the commercial Greenbone Enterprise Feed (200,000+ vulnerability tests per current vendor claims).
- Agent model
- Official/Verified: Primarily a network-scanner architecture, not an agent/CNAPP-style agentless-cloud model.
- Asset inventory
- Not itemized in source research.
- Risk prioritization
- Official/Verified: Severity/prioritization is driven by the vulnerability tests themselves rather than a proprietary composite risk score like TruRisk or VPR.
- Remediation
- EVULNABLE Assessment: No integrated enterprise patch-deployment capability comparable to Qualys/Tenable/ManageEngine — remediation is handled outside the product.
- ITSM / ticketing integration
- EVULNABLE Assessment: External/integration-dependent — not natively itemized in source research.
- Cloud / container / OT coverage
- Not itemized in source research.
- Data residency
- Official/Verified: Self-hosted/on-premises by design, which is attractive where cloud SaaS is prohibited, data must remain local, or full control of scanner infrastructure is desired. Greenbone states its products are used in more than 150 countries.
- Pricing
- Published Price: OPENVAS BASIC (entry-level enterprise product) — €2,524/year. The underlying Greenbone Community Edition / OpenVAS stack is open source and free to run, though operating it still incurs infrastructure and labor costs.Verified against Greenbone's own product page as part of this tab's fact-check pass — matched; the OPENVAS BASIC price is a flat annual fee, not per-asset.
- Time to initial data
- Estimated: Hours to days.
- Typical production rollout
- Estimated: Days to 3 weeks — simple scanner setup can be quick, but tuning/scaling/credentials require expertise.
- Best-fit company size
- EVULNABLE Assessment: Small and mid-size organizations, labs, security researchers, privacy-conscious environments, organizations with Linux/security-engineering expertise, and teams needing a lower-cost self-hosted scanner.
- Potential limitations / evaluation considerations
- EVULNABLE Assessment: No modern CNAPP-style agentless cloud graph, no integrated enterprise patch deployment, and a scanner-only feature set relative to full-suite competitors; running it (even the free Community Edition) still has infrastructure and labor costs.
Last verified: August 27, 2026
