无法使用Python Nessrest客户端自动化Nessus 7 Professional扫描求助
Hey Ranjan, let’s work through why your Nessrest client is throwing errors when automating Nessus 7 scans—since manual scans work, we can narrow this down to a few common API/client compatibility or payload issues. Here’s what to check first:
1. Verify Nessrest Version Compatibility
Nessus 7 uses the Nessus API v2, and older versions of the Nessrest client might not support this newer API standard. If you’re using an outdated Nessrest package, it’ll fail to communicate properly with Nessus 7.
- Check your current Nessrest version with:
pip list | grep nessrest - If it’s not the latest compatible build, install the updated version (the official Tenable-maintained fork supports Nessus 7):
pip install git+https://github.com/tenable/nessrest.git
2. Fix Truncated/Invalid JSON Payload
From the partial error you shared, your JSON payload cuts off at "folder..."—this is a red flag. Nessus expects a fully valid, closed JSON object when creating a scan. Common issues here include:
- Unfinished parameters: The
folderfield needs a valid value (either a folder ID number or folder name string). For example:"folder_id": 3, // Use numeric ID for existing folders // OR "folder": "Automated Scans" // Use name if you've created this folder - Invalid target format: Ensure
text_targetsuses Nessus-accepted formats (single IP, comma-separated IPs, CIDR ranges, or hostnames). For example:"text_targets": "192.168.1.10,192.168.1.11/24" - Missing required fields: Double-check that you’re including all mandatory scan settings (like
name,policy_id, ortemplate_id—Nessus won’t create a scan without these).
3. Validate API Permissions & Authentication
Even if your user can run manual scans, the API keys you’re using might lack the necessary permissions, or you’re not authenticating correctly:
- Confirm your API keys (Access Key + Secret Key) belong to a user with Scan Creator or Admin privileges in Nessus.
- Ensure you’re initializing the Nessrest scanner with the correct keys and API version:
from nessrest import ness6rest # Initialize scanner with v2 API (required for Nessus 7) scanner = ness6rest.Scanner( url="https://your-nessus-server:8834", api_keys=("YOUR_ACCESS_KEY", "YOUR_SECRET_KEY"), ssl_verify=False, # Disable for self-signed certs (test environments only) api_version=2 )
4. Check SSL Certificate Handling
Nessus uses self-signed certificates by default. If you don’t disable SSL verification (or import the cert into your Python trust store), Nessrest will throw SSL errors. For production environments, replace ssl_verify=False with the path to your Nessus certificate file.
5. Match Manual Scan Settings
Your manual scan works, so replicate those settings in your automation code:
- Note the policy/template you use for manual scans, then specify its
policy_idin your scan creation call:# Example: Create a scan using policy ID 12 (replace with your policy's ID) scanner.scan_create( name="Automated Vulnerability Scan", targets="192.168.1.0/24", policy_id=12 )
Next Steps for Debugging
If you’re still stuck, share:
- The full error message (not just the truncated JSON—Nessus usually returns an
errorfield with a descriptive message) - The exact Python code snippet you’re using to initialize the scanner and create the scan
That’ll help pinpoint the exact issue!
内容的提问来源于stack exchange,提问作者Ranjan

