Renaud Deraison: The Teenager Who Built Nessus
On April 4, 1998, a teenager in Paris posted an announcement to the Bugtraq mailing list: a free Linux program with a graphical interface that'd check a network for about 50 known vulnerabilities.
Renaud Deraison expected to incorporate a little feedback and move on to something else. Instead, Nessus became the vulnerability scanner the world standardized on, and its author became the co-founder and chief technology officer of a company that listed on Nasdaq.
Along the way he dropped out of college, moved to Maryland, took the scanner closed-source over the objections of the open-source community, and watched the thing he built as a teenager turn into an industry. Then, after a quarter century, he started again.
Renaud Deraison at a Glance
- Deraison released the first public version of Nessus on April 4, 1998, as a teenager living in Paris, after about a year of work.
- The feedback was so strong he dropped out of college to keep developing it. The scanner ran on Linux and shipped with 50 plugins written in C.
- Tenable Network Security was incorporated in 2002, and in 2003 Deraison moved from Paris to Columbia, Maryland, to build it with Ron Gula and Jack Huffard.
- In 2005, with Nessus 3, the project left the GNU General Public License for a proprietary one, prompting a fork called OpenVAS.
- By 2008 Nessus had more than 20,000 plugins and 5 million downloads; by 2013, more than 54,000 plugins and 10 million downloads.
- Tenable went public on Nasdaq in July 2018 under the ticker TENB, with Deraison as co-founder and CTO.
- Tenable's leadership page no longer lists him, and the company named a new CTO in December 2025. By 2026 he was building Bromure, an open-source macOS tool that runs browser sessions and AI coding agents inside disposable virtual machines.
The Life of Renaud Deraison
Deraison's Early Years
Renaud Deraison grew up in France and was a student in Paris in the late 1990s, when the commercial internet was young and most of the machines on it were wide open.
The problem that caught his attention was configuration: servers running old software with known holes, services that should never have been exposed, defaults nobody had changed. A tool called SATAN had shown in 1995 that you could scan for such things automatically, but it was aging and awkward.
Deraison spent about a year, in his own telling, building something better. He called it Nessus, and he gave it away.
April 4, 1998
The announcement went to Bugtraq, the security mailing list where the field's news broke in the 1990s. Nessus was a free remote security scanner for Linux, with a graphical client, a scanning daemon and 50 checks written in C.
"I'd release the software, incorporate the little feedback I'd get and move on to something else," Deraison wrote 20 years later of his expectations at the time. The feedback didn't stay little.
Users wanted more checks, and checks written in C were painful to add. Deraison answered with NASL, the Nessus Attack Scripting Language, so that anyone could write a plugin, and the plugin count started climbing toward the thousands.
He also made a decision his parents didn't like. "I ended up dropping out of college," he wrote on Nessus's 20th birthday, "(my parents were NOT happy, but that's a story for another day)."
Nessus Takes Over
By 2001 the free scanner was beating commercial products: it won Network Computing magazine's vulnerability-scanner comparison that year, and in 2002 passed 1,000 plugins. Deraison presented the project at Black Hat USA in 2001, and the professionals who'd been paying for commercial scanners took note.
Nessus's architecture was part of the appeal. The scanner could be pointed at an entire network and would run its checks in parallel, which, Deraison has said, he first made work on a machine with 56 MB of RAM.
The other part was price. Nessus was free, under the GPL, and the plugins arrived daily. For a security team in 2002 it was the obvious choice.
Tenable
The obvious business was to support it. Tenable Network Security was incorporated in Delaware in 2002, and in 2003 Deraison moved from Paris to Columbia, Maryland, to build the company with Ron Gula, who became chief executive, and Jack Huffard.
Tenable's first product beyond the scanner was SecurityCenter, released in 2003 to manage fleets of Nessus instances across a large organization. Deraison's job was the engine underneath.
In 2005 came the decision that still gets argued about. With the release of Nessus 3, the project left the GNU General Public License for a proprietary one, to the anger of open-source advocates. The last GPL version was forked as OpenVAS, which lives on today.
The numbers suggest the market sided with Tenable. By Nessus's tenth birthday in 2008 it had more than 20,000 plugins and 5 million downloads; by its fifteenth, 54,396 plugins, more than 55,000 configuration checks and over 10 million downloads.
Growing Up
Tenable grew with the scanner, and in January 2017 Amit Yoran, the former RSA president, took over as chief executive.
Deraison stayed in the CTO's chair through all of it, holding three patents on network scanning and collecting the Ernst & Young Entrepreneur of the Year award for defense and security in 2013. In January 2019, Tenable sent its co-founder and CTO to Davos to sit on a World Economic Forum panel.
On July 26, 2018, the company listed on Nasdaq as TENB, a public company built on a program a Paris teenager had posted to a mailing list two decades earlier.
The Next Thing
Deraison's byline on Tenable's blog stops in December 2021, with a post on the Log4j vulnerability that he called a "Fukushima moment" for the industry. The company's current leadership page doesn't list him, and in December 2025 Tenable appointed a Microsoft cloud-security veteran, Vlad Korsunsky, as its chief technology officer.
What Deraison did next looks a lot like what he did in 1998. In 2026 he released Bromure, an open-source project for Apple Silicon Macs that runs each browser session, and each AI coding agent, inside its own disposable Linux virtual machine so that real credentials never enter the sandbox. The repository's credits list Deraison for direction and an AI model for implementation.
He's spent 2026 talking about it: on security podcasts in April, in the closing keynote at SSTIC, the French security symposium in Rennes, in June, and in a French podcast episode titled "From Nessus to Bromure."
Renaud Deraison: Still Scanning
Nessus did for vulnerability assessment what Nmap did for port scanning: it made a specialist tool free, then made the free tool the standard. Deraison's second act, taking it proprietary and building a public company on top, is the part open-source purists still hold against him, and the part that kept the plugins coming for 28 years.
He's in his mid-forties now, the scanner is still here 28 years on, and he's back to shipping small, free, slightly provocative security tools from scratch.
The feedback, presumably, won't stay little this time either.
QUOTE:
"Amateurs hack systems, professionals hack people."