Skip to content

7. Coverage Checks — Proving Something Is (or Is Not) Installed

A scan tells you what it found. A coverage check tells you what it did not find, and where — which is the harder and usually more important question.

Coverage checks exist for questions of the form “is this on every machine that should have it?” and its opposite, “is this on any machine that should not have it?”

  • Is the endpoint agent installed on all 340 servers, or on 337?

  • Is the log forwarder running everywhere, or did four builds miss it?

  • Is there any prohibited remote-access software anywhere in the enclave?

  • Which Windows servers are missing the required antivirus, ignoring the network appliances that were never meant to have it?

The trap in all of these is that a machine which failed to authenticate produces almost no findings — so it looks like every check passed. Coverage checks handle that explicitly by separating “we looked and it is not there” from “we could not look”.

Open a coverage tab from the Analyze page with the + Coverage button. The controls run across the top of the pane.

  1. Set Match by to Plugin IDs or Software names.

  2. Enter what you are looking for in the terms box, or click Find… to pick from what is actually in your scans.

  3. Set Expectation to Should be installed or Should NOT be installed.

  4. Narrow the comparison down to comparable machines using the scope controls (section 7.3).

  5. Click Run.

Option When to use it What you type
Plugin IDs When a Nessus plugin detects the thing you care about. This is the more reliable of the two — a plugin either fired or it did not. Plugin numbers, separated by commas, semicolons, spaces or new lines. Placeholder: e.g. 12107, 16193
Software names When you are checking enumerated software by name. Matching is “contains”, so Splunk finds Splunk Universal Forwarder. Names separated by commas, semicolons or new lines — not spaces, since names contain spaces. Placeholder: e.g. Splunk Universal Forwarder, McAfee

Rather than guessing plugin numbers or exact product names, click Find… (tooltip Search the loaded scans (plugins or enumerated software) and add the checked items). A dialog opens titled Find Plugins or Find Software, with the subtitle:

Everything unique in the loaded scans. Search, check the ones you want, then Add — they append to the check’s items.

In plugin mode the list shows Plugin ID, Plugin Name and DOD Severity. In software mode it shows Software, Version and Hosts. Search, tick what you want, and click Add Selected; Cancel closes without adding.

Option What gets flagged
Should be installed Every host where the thing is missing. Use for required agents, antivirus, log forwarders.
Should NOT be installed Every host where the thing is present. Use for prohibited or unapproved software.

Without scoping, a check compares every scanned host to every other. “Antivirus missing” will then flag your switches and printers along with your servers, and the result is useless. Three controls narrow the comparison.

Control What it does
OS contains (any; blank = all) Only include hosts whose operating system text contains one of these terms. Placeholder: e.g. Windows. Leave blank to include everything.
OS excludes Drop hosts whose operating system contains one of these terms. Placeholder: e.g. Palo Alto, F5.
Anchor plugins (scope = hosts where these fired) The strongest option. Only include hosts where at least one of these plugins fired — proof the scan could actually see this kind of thing on that host. Placeholder: e.g. 22869 (nix) / 20811 (Windows).
Credentialed hosts only Drop hosts that were not scanned with credentials, instead of listing them as unverifiable.

Five chips sit above the grid. Three of them filter it when clicked; click again to clear.

Chip Meaning Clickable
in scope How many hosts survived your scope filters and were compared. No
present Rows where the plugin fired or the software was found. Yes
missing Rows where it was not found on a host that should have had it looked for. Yes
unverifiable Rows where the host was scanned without credentials, so absence proves nothing. Yes
flagged Rows that violate your expectation — the ones that need action. No
Column What it shows
Status Present, Missing or Unverifiable. Shown in green normally, amber for unverifiable, and red when the row violates your expectation.
Hostname The host being checked.
Host IP Its IP address.
OS Its operating system — useful for spotting scope that is still too wide.
Check Item What was looked for: the plugin ID, or the software term.
Identified By Plugin In software mode only: which plugin reported the match. Host CPE means it came from the scanner’s per-host software inventory rather than a plugin.
Credentialed Yes, No, or blank when unknown.
DOD Severity The severity of the check plugin.
Plugin Name The plugin’s title.
Plugin Output The evidence on that host. In software mode, a list of Name — Version lines.

Flagged rows are listed first, then by hostname. Clicking a row opens a details panel with the same information laid out for reading, including the full plugin output.

Before you run anything, the grid shows:

No results — enter plugin id(s) above and Run. Hosts come from the loaded scans; scope with OS terms or anchor plugins to compare like hosts.

A check you have tuned is worth keeping. The library controls sit along the top row.

Control What it does
Saved checks: A dropdown of your saved checks. Choosing one loads all its settings and runs it immediately.
Name: The name to save under. Placeholder: e.g. Splunk forwarder installed.
Save Saves or updates the check under that name. Tooltip: Save/update this check in the library.
Delete Removes the named check. Tooltip: Remove this check from the library.
Run Re-evaluates against the currently loaded scans.
Export… Writes the whole library to a .json file you can back up or send to a colleague. Tooltip: Save the check library to a .json file (backup / share).
Import… Merges checks from a .json file into your library. Checks with the same name are updated. Tooltip: Merge checks from a .json file into the library (same names update).

Saved checks and any open coverage tabs come back the next time you start NESSviewer, and a check re-runs itself automatically whenever you load or unload scans — so once a check is set up, checking again next month is a matter of loading the new scans and reading the numbers.

The grey text at the end of the top row reports what just happened.

Message What it means
Enter plugin id(s) and Run. / Enter software name(s) and Run. The terms box is empty.
No scans loaded. There is nothing to check against. Load scans on the Files page.
{n} host(s) in scope · {m} flagged row(s). The check ran. This is the summary of the result.
Name the check before saving it to the library. Type something in the Name: box first.
Saved “{name}” to the check library. Saved.
Deleted “{name}” from the check library. Deleted.
No saved checks to export — Save one to the library first. The library is empty.
Exported {n} check(s) to {filename}. The export succeeded.
No named checks found in that file. The file you imported does not contain any usable checks.
Imported {n} check(s) from {filename}. The import succeeded.
Import failed: {message} The file could not be read. The message gives the reason.
No enumerated software — load credentialed scans first. Software names can only come from credentialed scans. Without credentials the scanner cannot enumerate installed software.
No scans loaded — the plugin list comes from the loaded scan data. Find… has nothing to offer because no scans are loaded.
Check the item(s) to add first. You clicked Add Selected without ticking anything.
Added {n} item(s) — Run to evaluate. Items were added to the check. Click Run.
The selected items were already in the check. Everything you ticked was already in the terms box.