You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法使用Python Nessrest客户端自动化Nessus 7 Professional扫描求助

Troubleshooting Nessrest Automation Issues with Nessus 7

Hey Ranjan, let’s work through why your Nessrest client is throwing errors when automating Nessus 7 scans—since manual scans work, we can narrow this down to a few common API/client compatibility or payload issues. Here’s what to check first:

1. Verify Nessrest Version Compatibility

Nessus 7 uses the Nessus API v2, and older versions of the Nessrest client might not support this newer API standard. If you’re using an outdated Nessrest package, it’ll fail to communicate properly with Nessus 7.

  • Check your current Nessrest version with:
    pip list | grep nessrest
    
  • If it’s not the latest compatible build, install the updated version (the official Tenable-maintained fork supports Nessus 7):
    pip install git+https://github.com/tenable/nessrest.git
    

2. Fix Truncated/Invalid JSON Payload

From the partial error you shared, your JSON payload cuts off at "folder..."—this is a red flag. Nessus expects a fully valid, closed JSON object when creating a scan. Common issues here include:

  • Unfinished parameters: The folder field needs a valid value (either a folder ID number or folder name string). For example:
    "folder_id": 3, // Use numeric ID for existing folders
    // OR
    "folder": "Automated Scans" // Use name if you've created this folder
    
  • Invalid target format: Ensure text_targets uses Nessus-accepted formats (single IP, comma-separated IPs, CIDR ranges, or hostnames). For example:
    "text_targets": "192.168.1.10,192.168.1.11/24"
    
  • Missing required fields: Double-check that you’re including all mandatory scan settings (like name, policy_id, or template_id—Nessus won’t create a scan without these).

3. Validate API Permissions & Authentication

Even if your user can run manual scans, the API keys you’re using might lack the necessary permissions, or you’re not authenticating correctly:

  • Confirm your API keys (Access Key + Secret Key) belong to a user with Scan Creator or Admin privileges in Nessus.
  • Ensure you’re initializing the Nessrest scanner with the correct keys and API version:
    from nessrest import ness6rest
    
    # Initialize scanner with v2 API (required for Nessus 7)
    scanner = ness6rest.Scanner(
        url="https://your-nessus-server:8834",
        api_keys=("YOUR_ACCESS_KEY", "YOUR_SECRET_KEY"),
        ssl_verify=False,  # Disable for self-signed certs (test environments only)
        api_version=2
    )
    

4. Check SSL Certificate Handling

Nessus uses self-signed certificates by default. If you don’t disable SSL verification (or import the cert into your Python trust store), Nessrest will throw SSL errors. For production environments, replace ssl_verify=False with the path to your Nessus certificate file.

5. Match Manual Scan Settings

Your manual scan works, so replicate those settings in your automation code:

  • Note the policy/template you use for manual scans, then specify its policy_id in your scan creation call:
    # Example: Create a scan using policy ID 12 (replace with your policy's ID)
    scanner.scan_create(
        name="Automated Vulnerability Scan",
        targets="192.168.1.0/24",
        policy_id=12
    )
    

Next Steps for Debugging

If you’re still stuck, share:

  • The full error message (not just the truncated JSON—Nessus usually returns an error field with a descriptive message)
  • The exact Python code snippet you’re using to initialize the scanner and create the scan

That’ll help pinpoint the exact issue!

内容的提问来源于stack exchange,提问作者Ranjan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:08:08