Greenbone
Osnabrück's open-source OpenVAS vulnerability scanner, with enterprise appliances on top
Quick Overview
| Company | Greenbone AG |
|---|---|
| Category | Web Security |
| Headquarters | Osnabrück, Germany |
| Founded | 2008 |
| EU Presence | EU (Germany) |
| Data Location | Germany |
| Open Source | Yes |
| Compliance | ISO 9001, ISO 27001 |
| Pricing | Free OpenVAS / Community Edition; Greenbone Enterprise appliances from OPENVAS BASIC at €2,524 per year |
| Free Option | Free Community Edition (OpenVAS) |
| Replaces | Tenable Nessus, Qualys VMDR, Rapid7 InsightVM |
Detailed Review
Greenbone builds on OpenVAS, the vulnerability scanning engine it has maintained as open source since the company's founding in 2008, and that lineage is the whole pitch: the scanning engine and its vulnerability tests can be inspected, self-hosted and run at no licence cost, rather than trusted on the vendor's word. OpenVAS Free and the Community Edition let anyone try the same core engine that the paid appliances run.
The commercial layer sits on top rather than replacing the open core: Greenbone Enterprise appliances add a maintained vulnerability feed, support and management tooling, starting with OPENVAS BASIC at €2,524 a year as the entry point into that feed. For a public body or university with a procurement rule against unauditable security software, that combination of an open engine and a paid, supported feed is a specific answer few competitors offer.
Greenbone AG is based in Osnabrück, Germany, and holds ISO 9001 and ISO 27001 certification of its own management systems; it converted into a stock company (AG) in 2023. The honest limit: OpenVAS finds and reports vulnerabilities, it does not block an attack in progress, and running the open-source edition well still requires someone with real vulnerability-management expertise to interpret and prioritise the output.
What Greenbone does well
- Open-source scanning engine (OpenVAS/GVM), inspectable by anyone
- Free Community Edition with no licence cost
- Enterprise appliances with maintained feed from €2,524/year
- ISO 9001 and ISO 27001 certified
- German company, EU jurisdiction
Where Greenbone falls short
- Finds vulnerabilities; does not block attacks itself
- Self-hosted use requires real in-house expertise
- Enterprise appliance pricing is on top of the free core
- Less polished interface than SaaS-first competitors
Standout feature. An open-source scanning engine you can audit yourself, with a paid feed on top rather than instead of it.
Pros and Cons
Pros
- Open-source scanning engine (OpenVAS/GVM), inspectable by anyone
- Free Community Edition with no licence cost
- Enterprise appliances with maintained feed from €2,524/year
- ISO 9001 and ISO 27001 certified
- German company, EU jurisdiction
Cons
- Finds vulnerabilities; does not block attacks itself
- Self-hosted use requires real in-house expertise
- Enterprise appliance pricing is on top of the free core
- Less polished interface than SaaS-first competitors
Alternatives to Greenbone
Frequently Asked Questions
What is Greenbone?
Greenbone builds on OpenVAS, the vulnerability scanning engine it has maintained as open source since the company's founding in 2008, and that lineage is the whole pitch: the scanning engine and its vulnerability tests can be inspected, self-hosted and run at no licence cost, rather than trusted on the vendor's word. OpenVAS Free and the Community Edition let anyone try the same core engine that the paid appliances run.
Where is Greenbone based?
Greenbone operates from Osnabrück, Germany, which places it under EU (Germany). Compliance: ISO 9001, ISO 27001.
What does Greenbone cost?
Free OpenVAS / Community Edition; Greenbone Enterprise appliances from OPENVAS BASIC at €2,524 per year. Free Community Edition (OpenVAS).
Who is Greenbone best for?
Organisations that want an open-source vulnerability scanner they can run themselves. An open-source scanning engine you can audit yourself, with a paid feed on top rather than instead of it.
What are the drawbacks of Greenbone?
Finds vulnerabilities; does not block attacks itself. Self-hosted use requires real in-house expertise. Enterprise appliance pricing is on top of the free core. Less polished interface than SaaS-first competitors.