# bro not alert nessus attack

**URL:** <https://community.zeek.org/t/bro-not-alert-nessus-attack/5323>\
**Category:** Zeek\
**Created:** [May 24, 2018, 7:52pm UTC](https://community.zeek.org/t/bro-not-alert-nessus-attack/5323 "2018-05-24T19:52:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![fatema\_bannatwala](https://avatars.discourse-cdn.com/v4/letter/f/5f9b8f/32.png) [@fatema\_bannatwala](https://community.zeek.org/u/fatema_bannatwala)\
**Post date:** [May 24, 2018, 7:52pm UTC](https://community.zeek.org/t/bro-not-alert-nessus-attack/5323/1 "2018-05-24T19:52:00Z")

</div>

Hi Bz Oz,

It depends on what you are testing with nessus and how are you testing it.  
Bro should be able to detect scanning, ssh-bruteforce, sql injection, htp-bruteforce etc. by default.  
Hence, if you are scanning the systems from your nessus machine, and if Bro is able to sniff that traffic, then scanning get reported in notice.log file.  
It might not able to detect all the attacks that you launch from nessus, unless you have custom scripts/plugins installed in Bro.

Fatema.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/bro-not-alert-nessus-attack/5323/2 "2022-05-06T15:45:49Z")

</div>


