This document provides an overview of using the Nessus vulnerability scanner to test web applications. It begins with introductions to Nessus, its licensing models, terminology, and customization options. It then demonstrates how to create a basic web application scan policy and template to scan unknown sites. The document also shows how to create an advanced policy and template tailored for a specific known web application, using the Damn Vulnerable Web Application as an example. The steps include configuring login authentication, start pages, and exclusion patterns. The document concludes by reviewing scan reports and download options.