What you are evaluating
Community versus Enterprise feed coverage, authenticated scan quality, distributed management, and support responsibilities sit with the operator. Open-source licensing reduces a license line while leaving hosting, feed maintenance, and triage work. The scanner inventories weaknesses; it is not CTEM or EASM by itself.
A useful evaluation context
A plausible evaluation context is a team comparing an open-ecosystem scanner plus its own FIRST and CISA overlays with a commercial platform, including feed coverage and support load.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Network vulnerability scanning on hardware or virtual appliances under the OPENVAS brand.
- Enterprise Feed and Community Feed or Community Edition content paths with different coverage and support expectations.
- Authenticated scanning options whose quality depends on credentials, reachability, and operator-maintained infrastructure.
Where it fits in the work
- Stand up scanning infrastructure you operate, choose Community or Enterprise feed content deliberately, and store credentials in a controlled way.
- Run authenticated assessments on owned systems, export results with CVE identifiers, and keep CVSS, EPSS, and KEV as separate overlays if you add them.
- Assign owners outside the scanner if needed, patch or mitigate, and re-scan; retain feed and engine versions with the evidence pack.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
On lab hosts you own, run OPENVAS with the feed you actually operate. Plant an outdated package on a credentialed host and leave a second host without credentials. Overlay KEV and EPSS in the export if you use those signals.
Evidence to look for
The credentialed planted issue is found, the unauthenticated host is visibly weaker coverage, feed edition is recorded, and a re-scan after patch shows the finding closed without scanning unowned addresses.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- What is the coverage difference between Community and Enterprise feeds on the organization's actual software?
- How is authenticated scan quality measured, including failures when credentials cannot reach a host?
- Who operates distributed scanners, upgrades feeds, and supports triage when there is no vendor evidence pack?
Names you may encounter: OPENVAS · OpenVAS · Greenbone Community Edition. Historical names do not establish current availability or feature equivalence.