Skip to content

1. About NESSviewer

NESSviewer is a Windows desktop application for reviewing Nessus and ACAS vulnerability scans. You load the .nessus files your scanner produced, and NESSviewer turns them into something you can actually work with: a dashboard of where you stand, a searchable list of every finding, an inventory of the software and open ports it discovered, checks that prove whether a required agent is installed everywhere, and finished reports you can hand to leadership or attach to a package.

Everything happens on your own machine. NESSviewer does not connect to a scanner, and your scan data never leaves your computer. It reads the files you give it and writes the files you ask for.

The one network connection it makes is the license check, to licensing.stigsolution.com over HTTPS (port 443). The check sends your license key, a hashed computer ID and the application version, never your data. NESSviewer revalidates every 7 days and keeps working for up to 14 days if it cannot reach the service. On a disconnected, classified or air-gapped network, coordinate with us at mail@stigsolution.com and we will set up licensing for your environment.

A raw .nessus export is XML. Opened in a spreadsheet it is thousands of rows with no context, and the questions you actually need to answer are not in any single column:

  • Which hosts did not scan properly, so their “clean” result means nothing?

  • Which findings are old enough that they belong on the POA&M, and which are already on it?

  • Which patch would fix the most machines if I did it first?

  • Is our endpoint agent actually installed on every server, or just most of them?

  • What software and what open ports did the scan find that are not on our approved lists?

  • Can I produce a report for the ISSM this afternoon instead of next week?

NESSviewer is built around those questions. It joins your scan data to the reference material you already maintain — the hardware baseline, the eMASS POA&M export, the remediation plan — and keeps everything in one place so the answers come from one screen instead of five spreadsheets.

The only file NESSviewer truly requires is a scan export. Everything else is optional and adds detail.

File Extension Required? What it adds
Nessus / ACAS scan export .nessus Yes Every finding, every host, every plugin write-up. This is the core data.
A zip of scan exports .zip Alternative A bundle of .nessus files. NESSviewer opens it and loads every scan inside, including scans in nested zips.
Hardware baseline / test plan .tpln No The authoritative list of hosts and what each must be tested with. Adds the In Testplan? answer, and can fill in hostnames and descriptions your scans could not resolve.
eMASS POA&M export .xlsx or .xlsm No Your open POA&M items. Adds POA&M status, item ID and a direct link to each item in eMASS, matched to findings by plugin ID.
Remediation plan .xml No Planned actions, owners and estimated completion dates, matched to findings by plugin ID. You can also edit the plan from inside NESSviewer.

The left-hand navigation has seven destinations. They are listed here in the order they appear, which is also roughly the order you will use them.

Area What you do there Chapter
Files Load scans and reference files; see what is loaded; unload what you do not want. 3 and 4
Dashboard Where you stand: totals, aging, scan quality, per-host and per-patch summaries, IAVM advisories. 5
Analyze Every finding in a searchable, filterable, groupable grid, with a details panel and POA&M / remediation / exception editing. 6 and 7
Software The software the scans enumerated, and your own tracked software list to compare it against. 8
Ports The open ports the scans found, and your own tracked ports list. 9
Reports Build a report from selected sections and export it to Excel, PDF or both; plus the Hardware, DVL and Host Info exports. 10
Options How severities are calculated, which policy rules flag a scan, hostname handling, reference data updates. 11

Chapters follow the order of a real session: get the app running, load your data, look at where you stand, dig into findings, reconcile your inventories, produce a report. Each chapter can be read on its own if you already know the rest.

Text that appears on screen is shown like this — button labels, field names, column headers, menu items and the exact wording of messages. Where this guide says a button is labelled Load Files, that is character for character what you will see.

Four kinds of callout appear throughout:

Screenshot placeholders appear as dashed blue boxes with a caption describing exactly what to capture. Appendix E collects every one of them into a single checklist so they can be captured in one pass.

The appendices are reference material rather than instruction: every Analyze column and what it means (Appendix A), every message the application can display and what causes it (Appendix B), the exact values you will see in severity, status and coverage fields (Appendix C), and a glossary of the security terms used throughout (Appendix D).