Skip to main content
Vulnerability Management (VM)

Tenable VM

Connect Tenable Vulnerability Management to import assets and open vulnerabilities into Guard, rated by CVSS.

The Tenable VM integration imports assets and vulnerabilities from Tenable Vulnerability Management (Tenable.io) into the Praetorian Guard Platform (PGP).

What the Integration Does

On each sync, PGP uses the Tenable export APIs to:

  • Import assets -- Exports assets that Tenable assessed in the last 30 days. Each asset is named by its first FQDN, or its first IPv4 address when it has no FQDN. Private, internal, and cloud-provider addresses are skipped.
  • Import vulnerabilities -- Exports Low, Medium, High, and Critical findings in the Open or Reopened state that Tenable found in the last 30 days. Each finding becomes a risk in triage, attached to its port when the finding has one and to the asset otherwise.
  • Set severity -- Uses the finding's CVSSv3 temporal score, or its CVSSv3 base score when there is no temporal score: 9.0 and above is Critical, 7.0 High, 4.0 Medium, 0.1 Low, and anything lower Info.
  • Attach details -- Adds the plugin description, solution, and references as the risk definition, and the plugin output, service, CVEs, and CVSS scores and vector as proof.

Prerequisites

Before setting up the Tenable VM integration, you'll need:

  1. An active Tenable.io account with access to create users and generate API keys
  2. API access keys from Tenable.io (Access Key and Secret Key)
  3. Access to your PGP instance

Setup Instructions

Set or Confirm Service Account Permissions

First, make sure Tenable VM has a permission that grants Can View access to All Assets. PGP needs to assign this permission to the service account you'll create in the next step.

Log in to your Tenable console and navigate to Settings > Access Control.

Click the Permissions tab.

Verify that a permission exists granting Can View access to All Assets.

If no such permission exists, create one. Click Create Permission.

Configure the permission to allow Can View for All Assets, assign it to the appropriate users or groups, and click Save.

Create a Service Account in Tenable VM

Next, create a dedicated service account for PGP to use when connecting to Tenable VM.

From Settings > Access Control, open the Users tab.

Click Create User.

Enter a Name, Username, Email, and password, and set the Role to Standard User.

Enable API Key Authentication, then click Next.

Optionally, add the user to a user group.

Assign the Can View All Assets permission, then click Save.

Generate API Keys

Next, generate API keys for the new service account.

In Settings > Access Control > Users, click the service account you just created. Scroll to the API Keys section and click More to expand the options.

Click Generate API Keys.

Click Replace & Generate to create the new keys.

Copy and securely store both the Access Key and Secret Key — you'll need them in the next step, and Tenable will not display them again.

Configure the Integration in PGP

In PGP, open Integrations from the left navigation (under Administration, near the bottom).

Click Add Integration.

Under Vulnerability Management, find the Tenable VM card and click Integrate.

Enter your connection details:

  • Tenable VM URL
  • Access Key
  • Secret Key

Then choose what data PGP should import:

  • Import Assets — imports external assets from Tenable VM
  • Import Vulnerabilities — imports external vulnerabilities and their associated assets

Click Connect. PGP checks the keys by requesting an asset export and a vulnerability export. If either request fails, check that the service account has the Can View permission on All Assets.

If you need help with this integration, contact support@praetorian.com.

Still need help? Ask the team