Abusing Tenable Nessus / Security Center with Audit Files and Powershell. #Nessus #Infosec #ExploitDelivery #RBACBypass #InsiderThreat
Title: Abuse of Tenable Nessus/Security Center with Audit Files and Powershell. Class: Exploit Delivery System/RBAC Bypass/Insider Abuse/Pivot Vector. Signed PDF with Keybase PGP key Wylie's PGPKey Date Published: 2017-07-27 Last Update: 2017-06-22 Vendors contacted: Tenable Network Security - https://www.tenable.com 2016-12-05 - First notification sent by Wylie Bayes to Tenable Consultant Jack Daniel. 2016-12-07 - Acknowledgement of first notification received from Tenable team. 2017-01-04 - Sent follow up email for progress update to Tenable…