Skip to content
This repository was archived by the owner on Aug 11, 2026. It is now read-only.

About

End-to-end vulnerability management program on Azure — credentialed Tenable scanning, CAB remediation cycle, 80% vulnerability reduction

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Latest commit

 

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

Vulnerability Management Lab Walkthrough

This repo documents my hands-on walkthrough of Josh Madakor's vulnerability management lab, part of his public cybersecurity course material. I completed it as structured learning.

The program design is his. So are the meeting videos, policy documents, scan exports, and remediation data linked below. The scripts in scripts/ are his scripts, vendored here for study with attribution in each file header. What I did myself: stood up the lab environment and worked through each phase on my own test VM, following the course.

What the lab covers

The lab simulates building a vulnerability management program from scratch in an enterprise environment, using Azure VMs and Tenable (Nessus) as the scanner. It runs the full lifecycle: policy drafting, stakeholder negotiation, credentialed scanning, change board approval, remediation rounds, and ongoing maintenance.


image

Technologies Used

  • Tenable (enterprise vulnerability management platform)
  • Azure Virtual Machines (for the Nessus scan engine and target systems)
  • PowerShell & Bash (remediation automation)

Lab Overview

Starting Point: No vulnerability management policy, no processes in place.

End State: An approved policy, stakeholder buy-in, and a complete remediation cycle across the environment.


Table of Contents


Vulnerability Management Policy Draft

The lab opens with drafting a practical Vulnerability Management Policy covering scope, roles and responsibilities, remediation timelines, and scanning cadence. The draft linked here is the course's document.

→ View the course's draft policy


Stakeholder Policy Review Meeting

The draft goes to the server team for review. The recorded session shows their concerns being worked through. One example: the critical remediation timeline moves from 48 hours to one week based on operational feedback.

image

→ Watch the course meeting


Policy Finalization & Leadership Sign-Off

The policy is revised with the team's feedback and sent to leadership for sign-off. The finalized document linked here is the course's version.

image

→ Finalized policy (course document)


Initial Scan Permission Meeting

Before any scanning, the lab covers getting the server team's approval for credentialed scans. The approach: start with one server, monitor the impact, and use just-in-time AD credentials.

image

→ Watch the course meeting


Initial Scan of Server Assets

Following the course, I provisioned a deliberately vulnerable Windows Server, introduced common issues, and ran a full authenticated scan. The scan screenshot and export below are from the source project.

image

→ Scan 1 results (source project)


Vulnerability Assessment & Prioritization

The scan results get prioritized by risk, ease of remediation, and business impact. The course's top priorities:

  1. Remove outdated third-party software (Wireshark)
  2. Disable insecure protocols & cipher suites
  3. Remove Guest account from Administrators group
  4. Apply Windows OS updates

Distributing Remediations

This phase covers sending the server team clear remediation guidance, scripts, and scan reports.

image

→ Example remediation email (from the source repo)


Post-Scan Review Meeting

The findings are reviewed with the team, and remediation packages are prepared for Change Advisory Board (CAB) approval.

→ Watch the course meeting


CAB Meeting for Remediation Approval

The remediation plan goes to the CAB. The changes are approved with rollback scripts and a phased rollout.

→ Watch the course CAB meeting


Remediation Rounds

The scripts below are the course's scripts, vendored here for study (attribution in each file header). The scan screenshots and exports are from the source project.

Round 1: Outdated Wireshark Removal

A PowerShell script uninstalls the vulnerable version. A follow-up scan verifies the fix.

→ Wireshark Removal Script

image

→ Scan 2 results (source project)


Round 2: Insecure Protocols & Ciphers

Weak protocols and cipher suites are disabled via PowerShell.

→ Protocols Script
→ Ciphers Script

image

→ Scan 3 results (source project)


Round 3: Guest Account Group Membership

The Guest account is removed from the local Administrators group.

→ Guest Account Script

image

→ Scan 4 results (source project)


Round 4: Windows OS Updates

Updates are re-enabled and applied until the system is current.

image

→ Scan 5 results (source project)


First Cycle Results

The source project reports an 80% reduction in total vulnerabilities (from 30 to 6) after the first cycle:

  • Criticals: 100% resolved
  • Highs: 90% resolved
  • Mediums: 76% resolved

These are Josh Madakor's reported results for his course environment, not measurements from my own lab. The spreadsheet below is his. In a real environment, the next step is to keep driving the count down using asset criticality scoring.

image

→ Full remediation data (source project)


Maintenance Mode

The lab closes with the program shifting into steady-state operations: regular scans, patch management, continuous monitoring, policy reviews, and stakeholder coordination, all defined in the course's finalized policy.

Key activities:

  • Scheduled scans: weekly or monthly cadence to catch new vulnerabilities as systems evolve
  • Patch management: continuous application of security updates
  • Remediation follow-ups: prioritized by risk and business impact
  • Policy reviews: kept current with evolving best practices and organizational needs
  • Audit & compliance: internal audits to verify adherence to policy and external requirements
  • Stakeholder communication: ongoing coordination with remediation teams

The goal is to stay ahead of new vulnerabilities instead of playing constant catch-up.


Credit

  • Program design, videos, policy documents, scan exports, and remediation data: Josh Madakor, from lognpacific-public. The scripts in scripts/ are vendored from that repo's automation/ folder.
  • My part: running the lab hands-on and keeping these notes.

If you want to run the same exercise, start from the source repo. The recorded meetings are worth watching in full.

About

End-to-end vulnerability management program on Azure — credentialed Tenable scanning, CAB remediation cycle, 80% vulnerability reduction

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages