Tenable Nessus Professional
Vulnerability scanner for point-in-time and recurring assessment of IT assets.
For: Network pentesters, Cybersecurity consultants and other profiles
Learn more about the productNessus Expert starts from the same vulnerability assessment foundation as Nessus Professional and extends its scope into two territories that traditional network scanning doesn't cover well: web applications and the assets the organization exposes on the internet — including the ones nobody remembers still exist. The choice between the two, then, is a choice about scope.
A scan restricted to internal ranges describes servers and workstations well, and almost nothing else well. Published web applications, subdomains created for a campaign and forgotten, staging environments left accessible — none of that shows up in an inventory built from the internal network, and that's exactly where an attacker starts looking.
Information as stated by the vendor. See sources at the end of the page.
Web application assessment alongside infrastructure assessment, within the same tool.
Visibility into internet-facing assets. The official material states a limit of 5 domains per quarter.
Identifying assets within scope and assessing vulnerabilities on them.
More than 70,000 detectable CVEs, with real-time vulnerability updates.
More than 450 scan templates and adjustable reports, as in Nessus Professional.
Engagements that need to cover application and infrastructure without switching between separate tools.
Identifying public domains and hosts associated with the organization, including assets created outside the formal IT process.
Development teams without a dedicated AppSec function that need a recurring technical scan.
Defining what will be assessed: network ranges, web applications, and external domains.
Surveying network assets within scope and internet-facing assets associated with the domains provided.
Scanning for vulnerabilities across infrastructure and the identified web applications.
Consolidating findings from different sources into a single report, ranked by severity.
The official material presents Expert as the version "built for the modern attack surface," with the same vulnerability assessment foundation plus web application scanning and external attack surface scanning. To confirm the item-by-item breakdown for your edition, check the vendor's official comparison.
It depends on the size of the organization's digital footprint. For a company with few institutional domains, it tends to be adequate. For environments with many domains, campaign subdomains, or multiple brands, the limit can be restrictive — at that point the discussion shifts to attack surface management at scale.
They serve different purposes. Expert's scanning works well for point-in-time assessments within a broader scope. AppSec programs with many applications, pipeline integration, and continuous testing usually call for a dedicated DAST solution.
The official material mentions that Nessus Professional users can try Expert for a limited period. Trial and purchasing terms change over time, so check current availability and terms.
Commercial terms, availability and licensing models are defined by the vendor and may change. Check the official purchase page or talk to a specialist to assess your organization’s scenario.