
Authenticated Vulnerability Scan
FreeRun deep vulnerability scans with valid credentials.
Free · Opens the source repo
What Authenticated Vulnerability Scan does
The Authenticated Vulnerability Scan skill enables users to perform in-depth vulnerability assessments by leveraging valid system credentials to access target hosts. This approach allows for a comprehensive inspection of installed software, configurations, and security settings, leading to a significant increase in vulnerability detection rates—up to 60% more than unauthenticated scans. By directly querying the target operating systems, this skill minimizes false positives and provides a clearer picture of the security posture.
This skill is particularly useful for security professionals conducting assessments, incident response, or compliance audits. It supports various vulnerability scanners such as Nessus, Qualys, OpenVAS, and Rapid7 InsightVM, and can utilize multiple credential types across different platforms, including SSH for Linux, SMB for Windows, and SNMP for network devices. The ability to configure and manage these credentials effectively is crucial for accurate scanning and risk assessment.
To get started, users must set up dedicated service accounts with the necessary privileges on target systems, ensuring secure storage of credentials. The skill provides detailed workflows for creating these accounts and configuring scanners, making it accessible for both seasoned security experts and those newer to vulnerability management. It also emphasizes the importance of written authorization from system owners before conducting scans, aligning with best practices in cybersecurity.
Overall, this skill is designed for those who need to ensure their systems are secure against vulnerabilities that unauthenticated scans might overlook, making it an essential tool in any security assessment toolkit.
When to use it
Use this skill when performing security assessments, incident response, or scheduled audits that require authenticated scanning.
When not to use it
This skill is not suitable for environments where credentialed access is not feasible or where unauthorized scanning is prohibited.
What you can build with it
Conducting Security Assessments
Utilize the skill to perform thorough security assessments that require credentialed access, ensuring a comprehensive evaluation of system vulnerabilities.
Incident Response Procedures
Employ the skill during incident response to validate and assess vulnerabilities that may have been exploited, providing critical insights for remediation.
Scheduled Security Audits
Integrate this skill into regular security audits to ensure ongoing compliance and security posture improvements across systems.
How to install Authenticated Vulnerability Scan
View source1. Install with the skills CLI
npx skills add mukul975/anthropic-cybersecurity-skills/performing-authenticated-vulnerability-scan --agent claude-code2. Or install it manually
Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.
Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs
Inside SKILL.md
Written by mukul975Performing Authenticated Vulnerability Scan
Overview
Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and perform deep inspection of installed software, patches, configurations, and security settings. Compared to unauthenticated scanning, credentialed scans detect 45-60% more vulnerabilities with significantly fewer false positives because they can directly query installed packages, registry keys, and file system contents.
When to Use
- When conducting security assessments that involve performing authenticated vulnerability scan
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Prerequisites
- Vulnerability scanner (Nessus, Qualys, OpenVAS, Rapid7 InsightVM)
- Service accounts with appropriate privileges on target systems
- Secure credential storage (vault integration preferred)
- Network access from scanner to target management ports
- Written authorization from system owners
Core Concepts
Why Authenticated Scanning
Unauthenticated scanning can only assess externally visible services and banners, often leading to:
- Missed vulnerabilities in locally installed software
- Inaccurate version detection from banner changes
- Inability to check patch levels, configurations, or local policies
- Higher false positive rates due to inference-based detection
Authenticated scanning resolves these by directly querying the target OS.
Credential Types by Platform
Linux/Unix Systems
- SSH Key Authentication: RSA/Ed25519 key pairs (recommended)
- SSH Username/Password: Fallback for systems without key-based auth
- Sudo/Su Elevation: Non-root user with sudo privileges
- Certificate-based SSH: X.509 certificates for enterprise environments
Windows Systems
- SMB (Windows): Domain or local admin credentials
- WMI: Windows Management Instrumentation queries
- WinRM: Windows Remote Management (HTTPS preferred)
- Kerberos: Domain authentication with service tickets
Network Devices
- SNMP v3: USM with authentication and privacy (AES-256)
- SSH: For Cisco IOS, Juniper JunOS, Palo Alto PAN-OS
- API Tokens: REST API for modern network platforms
Databases
- Oracle: SYS/SYSDBA credentials or TNS connection
- Microsoft SQL Server: Windows auth or SQL auth
- PostgreSQL: Role-based authentication
- MySQL: User/password with SELECT privileges
Workflow
Step 1: Create Dedicated Service Accounts
# Linux: Create scan service account
sudo useradd -m -s /bin/bash -c "Vulnerability Scanner Service Account" nessus_svc
sudo usermod -aG sudo nessus_svc
# Configure sudo for passwordless specific commands
echo 'nessus_svc ALL=(ALL) NOPASSWD: /usr/bin/dpkg -l, /usr/bin/rpm -qa, \
/bin/cat /etc/shadow, /usr/sbin/dmidecode, /usr/bin/find' | sudo tee /etc/sudoers.d/nessus_svc
# Generate SSH key pair
sudo -u nessus_svc ssh-keygen -t ed25519 -f /home/nessus_svc/.ssh/id_ed25519 -N ""
# Distribute public key to targets
for host in $(cat target_hosts.txt); do
ssh-copy-id -i /home/nessus_svc/.ssh/id_ed25519.pub nessus_svc@$host
done
# Windows: Create scan service account via PowerShell
New-ADUser -Name "SVC_VulnScan" `
-SamAccountName "SVC_VulnScan" `
-UserPrincipalName "SVC_VulnScan@domain.local" `
-Description "Vulnerability Scanner Service Account" `
-PasswordNeverExpires $true `
-CannotChangePassword $true `
-Enabled $true `
-AccountPassword (Read-Host -AsSecureString "Enter Password")
# Add to local Administrators group on targets via GPO or:
Add-ADGroupMember -Identity "Domain Admins" -Members "SVC_VulnScan"
# For least privilege, use a dedicated GPO for local admin rights instead
# Enable WinRM on targets
Enable-PSRemoting -Force
Set-Item WSMan:\localhost\Service\AllowRemote -Value $true
winrm set winrm/config/service '@{AllowUnencrypted="false"}'
Step 2: Configure Scanner Credentials
Nessus Configuration
{
"credentials": {
"add": {
"Host": {
"SSH": [{
"auth_method": "public key",
"username": "nessus_svc",
"private_key": "/path/to/id_ed25519",
"elevate_privileges_with": "sudo",
"escalation_account": "root"
}],
"Windows": [{
"auth_method": "Password",
"username": "DOMAIN\\SVC_VulnScan",
"password": "stored_in_vault",
"domain": "domain.local"
}],
"SNMPv3": [{
"username": "nessus_snmpv3",
"security_level": "authPriv",
"auth_algorithm": "SHA-256",
"auth_password": "stored_in_vault",
"priv_algorithm": "AES-256",
"priv_password": "stored_in_vault"
}]
}
}
}
}
Step 3: Validate Credential Access
# Test SSH connectivity
ssh -i /path/to/key -o ConnectTimeout=10 nessus_svc@target_host "uname -a && sudo dpkg -l | head -5"
# Test WinRM connectivity
python3 -c "
import winrm
s = winrm.Session('target_host', auth=('DOMAIN\\\\SVC_VulnScan', 'password'), transport='ntlm')
r = s.run_cmd('systeminfo')
print(r.std_out.decode())
"
# Test SNMP v3 connectivity
snmpwalk -v3 -u nessus_snmpv3 -l authPriv -a SHA-256 -A authpass -x AES-256 -X privpass target_host sysDescr.0
Step 4: Run Authenticated Scan
Configure and launch the scan using the Nessus API:
# Create scan with credentials
curl -k -X POST https://nessus:8834/scans \
-H "X-Cookie: token=$TOKEN" \
-H "Content-Type: application/json" \
-d '{
"uuid": "'$TEMPLATE_UUID'",
"settings": {
"name": "Authenticated Scan - Production",
"text_targets": "192.168.1.0/24",
"launch": "ON_DEMAND"
},
"credentials": {
"add": {
"Host": {
"SSH": [{"auth_method": "public key", "username": "nessus_svc", "private_key": "/keys/id_ed25519"}],
"Windows": [{"auth_method": "Password", "username": "DOMAIN\\SVC_VulnScan", "password": "vault_ref"}]
}
}
}
}'
Step 5: Verify Credential Success
After scan completion, check credential verification results:
- Plugin 19506 (Nessus Scan Information): Shows credential status
- Plugin 21745 (OS Security Patch Assessment): Confirms local checks
- Plugin 117887 (Local Security Checks): Credential verification
- Plugin 110385 (Nessus Credentialed Check): Target-level auth status
Credential Security Best Practices
- Use a secrets vault (HashiCorp Vault, CyberArk, AWS Secrets Manager) for credential storage
- Rotate credentials every 90 days or after personnel changes
- Principle of least privilege - only grant minimum required access
- Audit credential usage - monitor service account login events
- Encrypt in transit - use SSH keys over passwords, WinRM over HTTPS
- Separate accounts per scanner - never share credentials across tools
- Disable interactive login for scan service accounts where possible
- Log all authentication events for scan accounts in SIEM
Common Pitfalls
- Using domain admin accounts instead of least-privilege service accounts
- Storing credentials in plaintext scan configurations
- Not testing credentials before scan launch (leads to wasted scan windows)
- Forgetting to configure sudo/elevation for Linux targets
- Windows UAC blocking remote credentialed checks
- Firewall rules blocking WMI/WinRM/SSH between scanner and targets
- Credential lockout from multiple failed authentication attempts
Related Skills
- scanning-infrastructure-with-nessus
- performing-network-vulnerability-assessment
- implementing-continuous-vulnerability-monitoring
Frequently asked questions about Authenticated Vulnerability Scan
Similar skills
Resemble Detect
Detect and analyze AI-generated media for authenticity.
Licenca para Auditar
Comprehensive security audits and threat modeling for projects.
Agentless Vulnerability Scanning
Assess systems for vulnerabilities without agents.
Implementing Rapid7 InsightVM for Scanning
Streamline vulnerability management with InsightVM setup.
Next-Generation Firewall Deployment
Streamline Palo Alto firewall configuration and management.
Implementing Network Policies for Kubernetes
Enforce security with Kubernetes NetworkPolicies.
