Turn off testing default login/brufe force attacks

A general advice is to not weaken the scan coverage of a vulnerability scanner just to keep the amount of logging low.

The simple rationale behind this recommendation is that such default accounts are a high level security risk and if you exclude these checks you are simply missing checks for known default credentials (some of them you even might not know).

Instead of weaken the scan coverage i would suggest to correctly configure your logging so that e.g. the scanner IP is excluded from the logging.

1 Like