Let's add a new profile for scanning web servers:
- Launch Zenmap.
- Click on Profile on the main toolbar.
- Click on New Profile or Command (Ctrl + P). The Profile Editor will be launched.
- Enter a profile name and a description on the Profile tab.
- Enable Version detection and select TCP connect scan (-sT) in the Scan tab.
- Enable Don't ping before scanning (-Pn) in the Ping tab.
- Enable the following scripts on the Scripting tab:
- hostmap-ip2hosts
- http-apache-negotiation
- http-apache-server
- http-auth-finder
- http-backup-finder
- http-config-backup
- http-cors
- http-cross-domain-policy
- http-csrf
- http-default-accounts
- http-devframework
- http-dombased-xss
- http-enum
- http-exif-spider
- http-favicon
- http-git
- http-headers
- http-iis-short-name-brute ...