
What is Quality of Detection (QoD) in OpenVAS scans?
For OpenVAS, Quality of Detection (QoD) describes the reliability of a vulnerability detection on a scale from 100% (most confident) to 0% (least confident).
Why is QoD Useful?
QoD is useful for filtering false positive vulnerabilities. A lower QoD test is more likely to create false positives. Generally, results with a QoD of 70% or higher are reliable, and those below are more likely to be false positives.
What QoD filtering should I use?
There is no setting that is best for everyone. The right minimum QoD threshold will depend on the systems being scanned and your tolerance for false positives vs complete results. A common cause of false positives is open source software backporting security fixes to older package version numbers. If you are running Linux distributions with many backported fixes, you may see a higher rate of false positives from low QoD tests.
The default QoD is 70%. However, it can be helpful to run a scan at 0%, which will show you all possible findings. You can then review those finding to determine what level is best for your use case. Note: after you lower your OpenVAS QoD setting in HostedScan, you will need to rescan with OpenVAS to discover all of the lower QoD findings.
How can I improve my detections?
Many vulnerability detections, like WordPress and WordPress plugin vulnerabilities are detected at a lower threshold of QoD. Lowering QoD will create more detection results but at the cost of more false positives. In the case of a WordPress site, a lower QoD, for example, 30%, may be appropriate.
What are the available QoD levels?
Here are the QoD levels and their corresponding types:
100% — exploit. Detection came from an actual exploit, so the finding is fully verified.
99% — remote_vul. Remote active checks (code execution, traversal, SQL injection, etc.) where the response clearly shows the vulnerability is present.
98% — remote_app. Remote active checks where the response clearly shows the vulnerable application is present.
97% — package. Authenticated package-based checks on Linux(oid) systems.
97% — registry. Authenticated registry-based checks on Microsoft Windows systems.
95% — remote_active. Remote active checks where the response indicates the vulnerable application or the vulnerability is likely present. "Likely" here means only rare circumstances could make the detection wrong.
80% — remote_banner. Remote banner checks against applications whose version string includes the patch level, as many proprietary products do.
80% — executable_version. Authenticated executable version checks on Linux(oid) or Windows systems where the application exposes its patch level in the version.
75% — (no type). Assigned to results that arrive without any QoD information, for example when migrating data from a legacy system into a supported one.
70% — remote_analysis. Remote checks that perform some analysis but aren't consistently reliable.
50% — remote_probe. Remote checks where an intermediate system such as a firewall can mimic a correct response, leaving it unclear whether the application itself answered. Non-TLS connections are a common case.
30% — remote_banner_unreliable. Remote banner checks against applications that don't expose the patch level in their version string — common in open source products because of backported patches.
30% — executable_version_unreliable. Authenticated executable version checks on Linux(oid) systems where the application doesn't expose its patch level in the version.
1% — general_note. A general note about a potential vulnerability, with no affected application actually found.
Where can I change the QoD for my HostedScan account?
If you already have an account, you can change the QoD on your account settings page.
If you would like to try out OpenVAS, with different QoD settings, you can start a free trial below. By default, we run the OpenVAS scanner with a 70% QoD.
Where can I learn more on OpenVAS QoD?
For detailed information about the different QoD levels, Greenbone documentation provides additional breakdowns of the levels and the type of detection they map to. See their OpenVAS/GVM documentation.
Speed and power,
without the complexity
The world's leading vulnerability scanners, all in one platform.