As part of ongoing/managed vulnerability assessments, 7 Minute Security may ask you to designate an internal network system as a Nessus sensor. This system will essentially serve as a conduit for vulnerability scanning by conducting scans and then uploading them to the Tenable.io portal. Installing the Nessus sensor on a system does not give 7 Minute Security the ability to remote control, screen share, or access files on it.
To install the Nessus sensor:
Review the hardware requirements for Nessus: https://docs.tenable.com/general-requirements/Content/NessusScannerHardwareRequirements.htm. Note: 7 Minute Security has found that scans with ~500 endpoints or less seem to run fine on a slightly lower spec'd machine, such as a dual-processor system with 4 GB of RAM.
Visit the Nessus download page. Download the installer for the operating system you are using:
Run the installer. Agree to the terms of service and click Next:
Pick an install location and click Next:
Review the installation configuration and click Install when ready:
Note: if you are not already running as a local or domain administrator, Tenable will prompt you for elevated credentials:
When the install is complete, visit https://localhost:8834 in your browser:
Note: click Advanced > Proceed to localhost to continue.
At the next screen, click Continue:
At the next screen, choose Link Nessus to another Tenable product:
At the next screen, make sure under Managed by that Tenable.io is selected, and then under Linking Key, paste in the code provided by 7 Minute Security, then click Continue:
At the next screen, enter the username and password provided to you by 7 Minute Security, and click Submit:
The Nessus install and plugin download/compiling will now begin. This process can take 10-15 minutes:
Eventually your screen will refresh to the Tenable portal:
At this point, the sensor installation and configuration should complete within the next hour automatically. You can simply click the "head" icon in the upper right and click Sign Out:
Note: if 7 Minute Security does not see the sensor check in to the Tenable.io portal, we may ask you for a copy of the nessusd.messages file, which is located at C:\ProgramData\Tenable\Nessus\nessus\logs: