7. Coverage Checks — Proving Something Is (or Is Not) Installed
A scan tells you what it found. A coverage check tells you what it did not find, and where — which is the harder and usually more important question.
7.1 What a coverage check answers
Section titled “7.1 What a coverage check answers”Coverage checks exist for questions of the form “is this on every machine that should have it?” and its opposite, “is this on any machine that should not have it?”
-
Is the endpoint agent installed on all 340 servers, or on 337?
-
Is the log forwarder running everywhere, or did four builds miss it?
-
Is there any prohibited remote-access software anywhere in the enclave?
-
Which Windows servers are missing the required antivirus, ignoring the network appliances that were never meant to have it?
The trap in all of these is that a machine which failed to authenticate produces almost no findings — so it looks like every check passed. Coverage checks handle that explicitly by separating “we looked and it is not there” from “we could not look”.
7.2 Building a check
Section titled “7.2 Building a check”Open a coverage tab from the Analyze page with the + Coverage button. The controls run across the top of the pane.
-
Set Match by to Plugin IDs or Software names.
-
Enter what you are looking for in the terms box, or click Find… to pick from what is actually in your scans.
-
Set Expectation to Should be installed or Should NOT be installed.
-
Narrow the comparison down to comparable machines using the scope controls (section 7.3).
-
Click Run.
Match by
Section titled “Match by”| Option | When to use it | What you type |
|---|---|---|
| Plugin IDs | When a Nessus plugin detects the thing you care about. This is the more reliable of the two — a plugin either fired or it did not. | Plugin numbers, separated by commas, semicolons, spaces or new lines. Placeholder: e.g. 12107, 16193 |
| Software names | When you are checking enumerated software by name. Matching is “contains”, so Splunk finds Splunk Universal Forwarder. | Names separated by commas, semicolons or new lines — not spaces, since names contain spaces. Placeholder: e.g. Splunk Universal Forwarder, McAfee |
The Find… picker
Section titled “The Find… picker”Rather than guessing plugin numbers or exact product names, click Find… (tooltip Search the loaded scans (plugins or enumerated software) and add the checked items). A dialog opens titled Find Plugins or Find Software, with the subtitle:
Everything unique in the loaded scans. Search, check the ones you want, then Add — they append to the check’s items.
In plugin mode the list shows Plugin ID, Plugin Name and DOD Severity. In software mode it shows Software, Version and Hosts. Search, tick what you want, and click Add Selected; Cancel closes without adding.
Expectation
Section titled “Expectation”| Option | What gets flagged |
|---|---|
| Should be installed | Every host where the thing is missing. Use for required agents, antivirus, log forwarders. |
| Should NOT be installed | Every host where the thing is present. Use for prohibited or unapproved software. |
7.3 Scoping — comparing like with like
Section titled “7.3 Scoping — comparing like with like”Without scoping, a check compares every scanned host to every other. “Antivirus missing” will then flag your switches and printers along with your servers, and the result is useless. Three controls narrow the comparison.
| Control | What it does |
|---|---|
| OS contains (any; blank = all) | Only include hosts whose operating system text contains one of these terms. Placeholder: e.g. Windows. Leave blank to include everything. |
| OS excludes | Drop hosts whose operating system contains one of these terms. Placeholder: e.g. Palo Alto, F5. |
| Anchor plugins (scope = hosts where these fired) | The strongest option. Only include hosts where at least one of these plugins fired — proof the scan could actually see this kind of thing on that host. Placeholder: e.g. 22869 (nix) / 20811 (Windows). |
| Credentialed hosts only | Drop hosts that were not scanned with credentials, instead of listing them as unverifiable. |
7.4 Reading the results
Section titled “7.4 Reading the results”The chips
Section titled “The chips”Five chips sit above the grid. Three of them filter it when clicked; click again to clear.
| Chip | Meaning | Clickable |
|---|---|---|
| in scope | How many hosts survived your scope filters and were compared. | No |
| present | Rows where the plugin fired or the software was found. | Yes |
| missing | Rows where it was not found on a host that should have had it looked for. | Yes |
| unverifiable | Rows where the host was scanned without credentials, so absence proves nothing. | Yes |
| flagged | Rows that violate your expectation — the ones that need action. | No |
The grid
Section titled “The grid”| Column | What it shows |
|---|---|
| Status | Present, Missing or Unverifiable. Shown in green normally, amber for unverifiable, and red when the row violates your expectation. |
| Hostname | The host being checked. |
| Host IP | Its IP address. |
| OS | Its operating system — useful for spotting scope that is still too wide. |
| Check Item | What was looked for: the plugin ID, or the software term. |
| Identified By Plugin | In software mode only: which plugin reported the match. Host CPE means it came from the scanner’s per-host software inventory rather than a plugin. |
| Credentialed | Yes, No, or blank when unknown. |
| DOD Severity | The severity of the check plugin. |
| Plugin Name | The plugin’s title. |
| Plugin Output | The evidence on that host. In software mode, a list of Name — Version lines. |
Flagged rows are listed first, then by hostname. Clicking a row opens a details panel with the same information laid out for reading, including the full plugin output.
Before you run anything, the grid shows:
No results — enter plugin id(s) above and Run. Hosts come from the loaded scans; scope with OS terms or anchor plugins to compare like hosts.
7.5 Saving, sharing and reusing checks
Section titled “7.5 Saving, sharing and reusing checks”A check you have tuned is worth keeping. The library controls sit along the top row.
| Control | What it does |
|---|---|
| Saved checks: | A dropdown of your saved checks. Choosing one loads all its settings and runs it immediately. |
| Name: | The name to save under. Placeholder: e.g. Splunk forwarder installed. |
| Save | Saves or updates the check under that name. Tooltip: Save/update this check in the library. |
| Delete | Removes the named check. Tooltip: Remove this check from the library. |
| Run | Re-evaluates against the currently loaded scans. |
| Export… | Writes the whole library to a .json file you can back up or send to a colleague. Tooltip: Save the check library to a .json file (backup / share). |
| Import… | Merges checks from a .json file into your library. Checks with the same name are updated. Tooltip: Merge checks from a .json file into the library (same names update). |
Saved checks and any open coverage tabs come back the next time you start NESSviewer, and a check re-runs itself automatically whenever you load or unload scans — so once a check is set up, checking again next month is a matter of loading the new scans and reading the numbers.
7.6 Coverage messages
Section titled “7.6 Coverage messages”The grey text at the end of the top row reports what just happened.
| Message | What it means |
|---|---|
| Enter plugin id(s) and Run. / Enter software name(s) and Run. | The terms box is empty. |
| No scans loaded. | There is nothing to check against. Load scans on the Files page. |
| {n} host(s) in scope · {m} flagged row(s). | The check ran. This is the summary of the result. |
| Name the check before saving it to the library. | Type something in the Name: box first. |
| Saved “{name}” to the check library. | Saved. |
| Deleted “{name}” from the check library. | Deleted. |
| No saved checks to export — Save one to the library first. | The library is empty. |
| Exported {n} check(s) to {filename}. | The export succeeded. |
| No named checks found in that file. | The file you imported does not contain any usable checks. |
| Imported {n} check(s) from {filename}. | The import succeeded. |
| Import failed: {message} | The file could not be read. The message gives the reason. |
| No enumerated software — load credentialed scans first. | Software names can only come from credentialed scans. Without credentials the scanner cannot enumerate installed software. |
| No scans loaded — the plugin list comes from the loaded scan data. | Find… has nothing to offer because no scans are loaded. |
| Check the item(s) to add first. | You clicked Add Selected without ticking anything. |
| Added {n} item(s) — Run to evaluate. | Items were added to the check. Click Run. |
| The selected items were already in the check. | Everything you ticked was already in the terms box. |