A scanner that reports 400 findings has not found 400 problems. It has found 400 things to check, and a good share of them are not real. The false positive is the tax you pay for automation.
Handing that raw list to a client is how you lose their trust. Triage is the job, not an afterthought.
Why scanners over-report
Version-based detection is the usual culprit: a distribution backports a security fix without bumping the version number, so the software looks vulnerable while it is patched. Add unauthenticated guessing from banners and generic signatures, and the noise adds up.
Scanners err toward reporting on purpose. For the tool, a missed finding is worse than a false one, so it hands the judgement to you.
Authenticated scans cut the guessing
Running with credentials lets the scanner read actual package versions and configuration instead of inferring from what a service advertises. It is the single biggest reduction in false positives available to you.
Unauthenticated external scans are inherently noisier. That is fine for mapping exposure, but expect to triage more of what comes back.
Deduplicate across tools
Run Nmap, Nessus and Nuclei and you get the same real issue three times, plus three tools worth of false positives. Correlating findings so one issue is one entry, with several pieces of evidence, cuts the noise and surfaces the disagreements worth investigating.
Where two tools agree, confidence goes up. Where they disagree, you have found the thing that actually needs a human to look.
The report proves you triaged
A client can tell the difference between a raw scanner dump and a report where someone removed the noise, kept the evidence, and explained why each remaining finding matters. That difference is the value of the engagement.
Clean, deduplicated, honestly scored: that is the deliverable people pay for, not the 400-line export.
- Nessus vs OpenVAS: which scanner for whatThe honest trade-offs between the commercial standard and the open-source workhorse.
- Prioritising vulnerabilities: why CVSS is not enoughCVSS ranks severity. It does not rank your risk.
- The structure of a good pentest reportWhat a client really wants. And what they don't know.