Phase 03 · From Surface to Weakness

Vulnerability Analysis

You now have an inventory of services and versions. This phase turns that inventory into a ranked list of weaknesses — running automated scanners, separating real findings from false positives by hand, and scoring what is left so the highest-impact issues drive the rest of the engagement.

00

About this phase

Automated scanners like OpenVAS and Nessus compare your service inventory against huge vulnerability databases and produce a flood of findings. The skill is not running the scan — it is triage: validating which findings are real, discarding false positives, and ranking what remains with CVSS so the report leads with what actually matters. Benchmarks like the CIS controls give you a configuration yardstick to measure hardening against.

Scoring and prioritization here reuse the CVE & CVSS fundamentals. The methodology aligns with NIST SP 800-115, the standard for technical security testing.
Lessons
5 live
Phase
03 of 08
Status
Complete
01

Lessons in this phase