I wanted to see if anyone had any knowledge or experience performing authenticated scans regarding Citrix NS, VPX, and SDCs. How are you performing your authenticated scan via least privledge? I would assume running as Sudo or Su wouldnt be best. On the NS in the web gui are you creating local accounts or using a sec group with a domain user account to share the group between them? I would assume in the site created in R7 Insight we would just create an SSH account and scan the targets to get OS, Software versioning etc but would like to know what privledges would be needed on the NS for this said account to be able to get all the versioning details. Any experience or thoughts would be appreciated.
[(Critical Zero-Day Vulnerability in Citrix NetScaler ADC and NetScaler Gateway | Rapid7 Blog)