OPENVAS SCAN from Greenbone, Tenable Security Center and Cyberwatch are vulnerability managers that can run with no internet connection, and all three go further into the host than Ibex. They find the missing patch on a server because they log into it. Ibex does not.
Ibex starts from a different question: what is on this isolated network, including the source code, the databases and the AI nobody registered, and how the findings in one connect to the others. It is one sealed appliance that answers that from the network, and hands the auditor the record. Many organisations will want both, and the table says where each one is the stronger choice.
Reviewed on 26 September 2026. Every statement about another product cites the vendor's own page, read that day; the sources are at the end. "Not described on the pages we read" means exactly that, and not that the product cannot do it.
| Question | Ibex | OPENVAS SCAN (Greenbone) | Tenable Security Center | Cyberwatch |
|---|---|---|---|---|
| What it is | One sealed appliance, on your hardware, that assesses the network, source code, AI and databases and keeps one inventory behind all four. | A vulnerability scanner sold as a hardware or virtual appliance, built on the OpenVAS open-source scanner.[1] | Tenable's on-premises vulnerability management, built on Nessus, with scanners, agents and passive monitoring.[7] | Vulnerability and compliance management deployed on infrastructure you control, local or cloud.[14] |
| Without an internet connection | Updates arrive as signed bundles imported by hand. The appliance never opens a connection of its own. | Air-gapped deployment on hardware; a master appliance fetches the feed and passes it on, over USB or a second appliance. The USB route needs Greenbone's own drive and an Enterprise 400 or larger.[2][3] | Offline plugin and feed updates, with Security Center and scanners inside each isolated network; Tenable advises updating at least monthly, and a few plugins need internet access and do not run air-gapped.[8][9] | The server installs offline, the signed vulnerability database is downloaded elsewhere and imported, and an air-gap mode runs scan scripts on the host with no network flow.[16][17] |
| Vulnerability knowledge | Product and version from discovery, matched against a vulnerability database held on the appliance. | More than 200,000 vulnerability tests, updated daily.[1][2] | 446,458 plugins covering 155,608 CVE IDs, by Tenable's own counter.[10] | Vulnerabilities identified in more than 70,000 technologies.[15] |
| Checks from inside the host | None. Ibex works from the network: what a service announces, not what is installed behind it. | Authenticated scans that log into the target to find missing patches and insecure configurations.[2] | Agents, including for assets that are offline or need standing host credentials.[7] | Scan scripts that run on the host, including in air-gap mode.[16] |
| Source code | Four offline scanners (Trivy, Opengrep, gitleaks, osv-scanner) over your Git repositories, with findings in SARIF. | Not described on the pages we read. | Not described on the pages we read. On-premises web application scanning (DAST) is.[7] | Static analysis of web applications through its compliance rules engine.[19] |
| Databases | Configuration posture for PostgreSQL, MySQL and MariaDB, SQL Server, Oracle and MongoDB across eight families (authentication, privilege, encryption, audit logging, exposure, patch level, backup), and where sensitive data sits. | Not described on the pages we read. | CIS benchmark audits for SQL Server, DB2, MongoDB and MySQL, among others.[11] | Vulnerability detection by version for Oracle, MySQL, MariaDB, PostgreSQL, MongoDB and Redis.[18] |
| AI on the network | Finds AI services such as Ollama and LM Studio from their ports, keeps an inventory with model cards, and exports it as a CycloneDX ML-BOM. | An AI product is announced as upcoming, for remediation.[1] | AI Aware, inside Security Center, detects AI software, libraries and browser plugins.[7][12] | Not described on the pages we read. |
| Compliance | Findings mapped to ISO 27001 Annex A, NIST CSF, NIS2 and QNRCS, the Portuguese national framework; AI packs for ISO 42001 and the EU AI Act. | BSI IT-Grundschutz and TR-03116 policies; CIS benchmarks in the Enterprise feed.[4][5] | ISO 27001/27002, PCI, NIST CSF, NIST SP 800-171 and CIS Controls; 1,773 audit files covering 653 benchmarks.[7][11] | SCAP benchmarks with CIS preinstalled, and ANSSI's MIRE classification method.[19] |
| Across the pillars | One inventory, so a code or database finding names the host it runs on and the segments that reach it. | Not described on the pages we read. | Not described on the pages we read. | Not described on the pages we read. |
| Track record | From DeltaCoders, which has built security software for regulated organisations since 2011. | Founded in Germany in 2008; more than 1,000 customers and 100,000 installations; ISO 9001 and ISO 27001 for the company since 2021.[6] | Founded in 2002; more than 40,000 customers.[13] | A French company, subsidiary of Framatome; labels include Used by French Army and Cybersecurity Made in Europe.[14][20] |
When to pick them instead
If the question is which servers are missing which patches, any of the three answers it better than Ibex, because they check from inside the host and carry far larger vulnerability content. Pick Greenbone if you want an open-source core, German compliance policies such as IT-Grundschutz and a vendor in the market since 2008. Pick Tenable Security Center if you need the largest plugin and audit libraries, agents for hosts that are rarely on the network, web application scanning on premises, and a vendor with tens of thousands of customers. Pick Cyberwatch if you want to deploy the patches as well as find them, or a French vendor with public-sector labels.
When Ibex is the better fit
When the isolated network holds more than servers: source code in a Git server that never leaves the building, databases whose configuration nobody has reviewed, and AI services that someone started on a workstation. Ibex covers the four from one appliance, keeps them in one inventory so a finding in the code names the host it runs on, and produces the evidence an auditor asks for (SARIF, PDF and an audit record on the appliance) with the findings mapped to NIS2 and the Portuguese QNRCS. And when nothing on that network may open a connection, not even to fetch an update.
Ibex also sits beside a scanner you already run, rather than in place of it: the host checks stay where they are, and Ibex adds the code, the databases, the AI and the view across them. See how Ibex works.
Sources
- Greenbone, Products, https://www.greenbone.net/en/products/, read on 26 September 2026.
- Greenbone, OPENVAS SCAN, https://www.greenbone.net/en/openvas-scan/, read on 26 September 2026.
- Greenbone OS 22.04 manual, Managing the Greenbone Operating System, https://docs.greenbone.net/GSM-Manual/gos-22.04/en/managing-gos.html, read on 26 September 2026.
- Greenbone OS 22.04 manual, Compliance and special scans, https://docs.greenbone.net/GSM-Manual/gos-22.04/en/compliance-and-special-scans.html, read on 26 September 2026.
- Greenbone, Feed comparison, https://www.greenbone.net/en/feed-comparison/, read on 26 September 2026.
- Greenbone, About Greenbone, https://www.greenbone.net/en/about-greenbone/, read on 26 September 2026.
- Tenable, Tenable Security Center, https://www.tenable.com/products/security-center, read on 26 September 2026.
- Tenable Security Center documentation, Air-gapped environments, https://docs.tenable.com/security-center/Content/AirGappedEnvironments.htm, read on 26 September 2026.
- Tenable Security Center documentation, Offline plugin and feed updates, https://docs.tenable.com/security-center/Content/OfflinePluginFeedUpdates.htm, read on 26 September 2026.
- Tenable, Plugins (live counter), https://www.tenable.com/plugins, read on 26 September 2026.
- Tenable, Audits, https://www.tenable.com/audits, read on 26 September 2026.
- Tenable, AI Aware, https://www.tenable.com/products/vulnerability-management/ai-aware, read on 26 September 2026.
- Tenable, About us, https://www.tenable.com/about-tenable/about-us, read on 26 September 2026.
- Cyberwatch, home page, https://cyberwatch.fr/en/, read on 26 September 2026.
- Cyberwatch, Vulnerability Manager features, https://cyberwatch.fr/en/vulnerability-manager-features/, read on 26 September 2026.
- Cyberwatch documentation, scan modes (French), https://docs.cyberwatch.fr/help/fr/use_assets/scan_modes_presentation/, read on 26 September 2026.
- Cyberwatch documentation, importing the security database offline (French), https://docs.cyberwatch.fr/help/fr/general_administration_software/offline_administration/swarm/import_securitydb/, read on 26 September 2026.
- Cyberwatch documentation, supported software (French), https://docs.cyberwatch.fr/help/fr/use_vulnerability_scanner/supported_software/, read on 26 September 2026.
- Cyberwatch, Compliance Manager, https://cyberwatch.fr/en/our-platform/compliance-manager/, read on 26 September 2026.
- Cyberwatch, About, https://cyberwatch.fr/en/about/, read on 26 September 2026.
OPENVAS, Greenbone, Tenable, Tenable Security Center, Nessus and Cyberwatch are trademarks of their owners, named here only to compare. Something here out of date or wrong about your product? Tell us and we will correct it.

