Nessus Professional
Import Nessus Professional hosts as assets and their findings as risks, by API sync or scan file upload.
The Nessus integration imports vulnerability data from Nessus Professional into the Praetorian Guard Platform (PGP). There are two methods:
- API integration -- PGP connects to your Nessus instance and syncs scan results on a schedule.
- File import -- You export a
.nessusfile from Nessus and upload it to PGP. Use this when PGP cannot reach your Nessus instance over the network.
What the Integration Does
The Nessus integration performs the following operations during each API sync cycle:
- Retrieves scan list — Queries the Nessus API for all available scans in the instance.
- Enumerates hosts — For each scan, retrieves the list of scanned hosts and their host IDs.
- Imports host data as assets — For each host, extracts the IP address and FQDN (if available) and creates an asset record in PGP. When a host has a fully qualified domain name, PGP uses the FQDN as the primary identifier; otherwise, the IP address is used.
- Imports vulnerabilities as risks — For each host, retrieves all vulnerability findings with a severity greater than zero (informational findings are excluded). Each vulnerability is imported as a risk associated with the corresponding asset, with an Info triage status for you to review.
- Retrieves plugin details — For each vulnerability, fetches the full plugin output including the description and detailed findings, which are attached as proof to the risk record.
All operations are strictly read-only. PGP does not create, modify, or delete any scans, policies, or configurations in Nessus.
Prerequisites
Before configuring the Nessus integration, ensure you have:
- Nessus Professional installed and running with accessible network connectivity from PGP
- API access keys generated from your Nessus instance (for API integration)
- At least one completed scan with results available
Continuous integration using the API
To enable the continuous integration between PGP and Nessus, you'll need to generate API credentials from your Nessus Professional instance.
Generating Nessus API Keys
Make sure you have administrator access to the Nessus Professional portal. To generate an API key:
- In Tenable Nessus, in the top navigation bar, click Settings. The About page appears.
- In the left navigation bar, click My Account. The My Account page appears.
- Click the API Keys tab.
- Click Generate. A dialog box appears, confirming your selection to generate a new API key._Note: After clicking the Generate button, a warning window notifies you that any previously generated keys will no longer be valid after generating new API keys._Notice: API Keys are only presented upon initial generation. Please store them in a safe location as they can not be retrieved later and will need to be regenerated if lost. Your new API key appears.
Configuring the Integration in PGP
- In PGP, go to Integrations and open Vulnerability Management → Nessus Professional.
- Click Connect and enter:
- API URL - The API URL for your Nessus Professional instance. The expected format is
https://ip:portorhttps://domain.tld:port. The default port used by Nessus Professional is8834. - Access Key - Your 64-character Tenable access key.
- Secret Key - Your 64-character Tenable secret key.
- API URL - The API URL for your Nessus Professional instance. The expected format is
- Leave Import Assets and Import Vulnerabilities selected to import both, or clear one to skip it.
- Click Connect. PGP checks the keys by listing your scans before saving the integration.
Importing Nessus Scan Results
- In your Nessus console, open My Scans, select the scan, and click Export.
- Choose the Nessus format. PGP accepts only
.nessus(XML) files; CSV and other formats are rejected. - In PGP, go to Vulnerabilities and click Import.
- Select Nessus and upload the
.nessusfile.
PGP creates an asset for each host, using the FQDN when the file has one and the IP address otherwise. Each finding with a severity above zero becomes a risk. Informational findings are skipped. For file imports:
- The risk's triage severity comes from the finding's Nessus risk factor (Critical, High, Medium, or Low).
- The risk comment is the finding's synopsis.
- The full finding record from the file is attached as proof.
If the file is not valid Nessus XML, PGP shows Nessus file was invalid. Did you upload a .nessus file?
What Data Is Synced
Assets
PGP creates asset records for each host discovered in Nessus scans.
Risks
PGP creates risk records for each vulnerability finding with a severity level above zero. The table below describes the API integration; file imports differ as described in the previous section.
Severity Mapping
Nessus findings are imported with the following severity filtering:
API Endpoints Used
The integration uses the following Nessus REST API endpoints. All requests are authenticated using the X-ApiKeys header with the configured access key and secret key.
Troubleshooting
Security and Data Handling
- Read-only access — The integration only reads scan results and host data from Nessus. It does not create, modify, or delete scans, policies, plugins, or any other Nessus configuration.
- Credential storage — API access keys and secret keys are stored encrypted within PGP and are never exposed in logs or the user interface after initial configuration.
- TLS support — The integration accepts self-signed TLS certificates on the Nessus instance.
- Data transfer — All communication between PGP and your Nessus instance occurs over HTTPS.
If you need help with this integration, contact support@praetorian.com.
Still need help? Ask the team