Open Source Nessus AlternativesTop Vulnerability Scanners and other similar apps like Nessus

The best open source alternative to Nessus is SiteOne Crawler. If that doesn't suit you, our users have ranked more than 25 alternatives to Nessus and 13 is open source so hopefully you can find a suitable replacement. Other interesting open source alternatives to Nessus are Metasploit, OpenVAS, PhoneSploit Pro and OpenSCAP.

Copy a direct link to this comment to your clipboard
Nessus alternatives page was last updated

Alternatives list

  1. SiteOne Crawler icon
     21 likes

    A free in-depth website analyzer providing audits of security, performance, SEO, accessibility and other technical aspects. Available as a desktop application for Windows/macOS/Linux and as a CLI tool for advanced users and CI/CD processes. It also includes an offline web page exporter.

    30 SiteOne Crawler alternatives

    Cost / License

    • Free
    • Open Source (MIT)

    Application types

    Platforms

    • Mac
    • Windows
    • Linux
     
  2. Metasploit icon
     46 likes

    Metasploit Community Edition simplifies network discovery and vulnerability verification for specific exploits, increasing the effectiveness of vulnerability scanners such as Nexpose - for free. This helps prioritize remediation and eliminate false positives, providing true...

    22 Metasploit alternatives

    Cost / License

    • Free Personal
    • Open Source

    Platforms

    • Windows
    • Linux
    • BSD
     
  3. OpenVAS icon
     24 likes

    The Open Vulnerability Assessment System (OpenVAS) is a framework of several services and tools offering a comprehensive and powerful vulnerability scanning and vulnerability management solution.

    31 OpenVAS alternatives

    Cost / License

    • Freemium
    • Open Source

    Application type

    Platforms

    • Linux
     
  4. OpenSCAP icon
     4 likes

    SCAP is a line of standards managed by NIST. It was created to provide a standardized approach to maintaining the security of enterprise systems, such as automatically verifying the presence of patches, checking system security configuration settings, and examining systems for...

    15 OpenSCAP alternatives

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Linux
     
  5. nuclei icon
     2 likes

    Nuclei is used to send requests across targets based on a template, leading to zero false positives and providing fast scanning on a large number of hosts. Nuclei offers scanning for a variety of protocols, including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless etc.

    24 nuclei alternatives

    Cost / License

    • Free
    • Open Source (MIT)

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
     
  6. skipfish icon
     13 likes

    A fully automated, active web application security reconnaissance tool. Key features: High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint - easily achieving 2000 requests per second with responsive targets.

    Cost / License

    • Free
    • Open Source

    Application type

    Alerts

    • Discontinued

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
     
  7. BabySploit icon
     1 like

    BabySploit is a penetration testing toolkit aimed at making it easy to learn how to use bigger, more complicated frameworks like Metasploit. With a very easy to use UI and toolkit, anybody from any experience level will find...

    Cost / License

    Application type

    Platforms

    • Self-Hosted
    • Python
     
  8. Strobes icon
     1 like

    Strobes is an integrated cybersecurity platform that combines Attack Surface Management, Penetration Testing-as-a-service, and Risk-Based Vulnerability Management to continuously manage your threat exposure.

    Cost / License

    • Freemium
    • Open Source

    Application type

    Platforms

    • Software as a Service (SaaS)
     
  9. Tsunami icon
     2 likes

    A general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.

    Cost / License

    Application type

    Platforms

    • Self-Hosted
     
  10. RedEye icon
     Like

    RedEye is an open-source analytic tool developed by CISA and DOE’s Pacific Northwest National Laboratory to assist Red Teams with visualizing and reporting command and control activities. This tool, released in October 2022 on GitHub, allows an operator to assess and display...

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
     
  11. kube-hunter hunts for security weaknesses in Kubernetes clusters. The tool was developed to increase awareness and visibility for security issues in Kubernetes environments. You should NOT run kube-hunter on a Kubernetes cluster that you don't own!

    Cost / License

    Platforms

    • Linux
     
12 of 13 Nessus alternatives