Exposure discovery EU-developed
OPENVAS SCAN
Vulnerability scanner for networks, endpoints, and containers with authenticated checks, risk prioritization, remediation guidance, and virtual-appliance deployment.
By Greenbone · Germany
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Exposure discovery
- Developer or maintainer
- Greenbone
- Recorded country
- Germany
- Product model
- Commercial
- Deployment
- Self-hosted
- Software license
- Mixed: open-source software packages and tests; subscription-controlled OPENVAS ENTERPRISE FEED database and access key
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteGreenbone explicitly says OPENVAS SCAN was developed in Germany and remains its German product stewardship; upstream open-source components and paid feed differ in license.
Reported capabilities
- Scans network services, endpoints, and container images.
- Runs as customer-hosted virtual or hardware appliance.
- Enterprise Feed is subscription controlled despite open-licensed individual tests.
Scope and limits
The previous Greenbone Enterprise Appliance name now maps to OPENVAS SCAN. The Enterprise Feed as a whole has subscription restrictions; no blanket proprietary or fully open-source label is accurate.
Inspect the research evidence 3 source observations
identity / origin / country / capabilities / deployment
Greenbone says OPENVAS SCAN was developed in Germany, describes scanning features and shows hardware and virtual deployment.
Read sourcelicense
Greenbone's license page distinguishes open-licensed component packages and individual vulnerability tests from subscription restrictions on the Enterprise Feed database and access key.
Read sourceidentity / maintenance
The official lifecycle page maps the former Greenbone Enterprise Appliance to OPENVAS SCAN as its current product name.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.
From vulnerability finding to verified remediation