About OpenVAS
OpenVAS Scanner is the scanning engine of the Greenbone Community Edition and is also used in Greenbone Enterprise appliances. It performs vulnerability scans by running a set of Vulnerability Tests (VTs) that is updated and extended continuously through a feed.
The module is configured, built and installed with CMake and make, and the INSTALL.md file explains how to set up openvas and expose the scanner to other GVM modules. Release files are signed with the Greenbone Community Feed integrity key. Docker images are published to the Greenbone registry, and a fully containerized setup for the Community Edition is also provided.
The repository also contains a Rust project that aims to replace the existing scanner stack made up of openvas-scanner, ospd-openvas and notus-scanner, simplifying scanning by centralizing everything in one place; for now it uses openvas-scanner as the scan engine. The code is licensed under GPL-2.0. Anyone not comfortable building from source is pointed to the Greenbone Enterprise TRIAL virtual machine.
Key features
- Vulnerability scan engine
- Continuously updated vulnerability test feed
- Signed release files
- Docker images and containerized setup
- Rust-based replacement scanner stack in progress
- Integration with other GVM modules
Good fit for
- →Vulnerability assessment of servers and networks
- →Building a self-hosted Greenbone Community Edition setup
- Built with
- Rust
- Tags
- vulnerability-scanner
- openvas
- greenbone
- security
- vulnerability-management
- gvm
- rust
- docker
OpenVAS: questions and answers
- What is OpenVAS used for?
- OpenVAS is the scanner component of Greenbone Community Edition, a vulnerability scan engine that runs a continuously updated feed of vulnerability tests. It is a good fit for vulnerability assessment of servers and networks, and building a self-hosted Greenbone Community Edition setup.
- Is OpenVAS open source?
- Yes. OpenVAS is open source under the GPL-2.0 licence. Its source code is on GitHub at greenbone/openvas-scanner and is written mainly in Rust.
- Is OpenVAS free?
- Yes. OpenVAS is open source, so the software itself is free to use.
- Can I self-host OpenVAS?
- Yes. OpenVAS can be self-hosted on your own server or infrastructure.
- What is OpenVAS an alternative to?
- OpenVAS is an open-source alternative to Tenable, Qualys, Rapid7 and Intruder. Other open-source alternatives to Tenable include DefectDojo and Wazuh.
- Is OpenVAS actively maintained?
- Yes. The most recent commit to OpenVAS was on 2 October 2026, and the latest release is v23.50.26, published on 1 October 2026. The project has 4.8k stars on GitHub.
Open-source alternatives to OpenVAS
See all
DefectDojo
Security
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
BSD-3-Clausevs Tenable★ 5k
Wazuh
Security
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints a
OSSvs Splunk★ 17k
Security Onion
Security
Security Onion is a free and open platform for threat hunting, enterprise security monitor
OSSvs Splunk★ 4.9k
Graylog
Monitoring & Observability
Free and open log management
OSSvs Splunk★ 8.2k
Fleet
Security
Open device management
OSSvs Jamf★ 6.9k
ClamAV
Security
ClamAV - Documentation is here: https://docs.clamav.net
GPL-2.0vs Avast★ 7.3k
SaaS alternatives to OpenVAS
See all
Tenable
Security
Vulnerability management and exposure assessment, maker of the Nessus scanner
SaaS
Qualys
Security
Cloud platform for vulnerability management, compliance and asset inventory
SaaSRapid7
Security
Vulnerability management, SIEM and managed detection tools for security teams
SaaS
Intruder
Security
Cloud-based vulnerability scanner for external attack surface
SaaS
Pentera
Security
Automated penetration testing and security validation platform
SaaS
Censys
Security
Internet scanning data and attack surface management platform
SaaS

