Skip to main content
Vulnerability Management (VM)

Nessus Professional

Import Nessus Professional hosts as assets and their findings as risks, by API sync or scan file upload.

The Nessus integration imports vulnerability data from Nessus Professional into the Praetorian Guard Platform (PGP). There are two methods:

  • API integration -- PGP connects to your Nessus instance and syncs scan results on a schedule.
  • File import -- You export a .nessus file from Nessus and upload it to PGP. Use this when PGP cannot reach your Nessus instance over the network.

What the Integration Does

The Nessus integration performs the following operations during each API sync cycle:

  • Retrieves scan list — Queries the Nessus API for all available scans in the instance.
  • Enumerates hosts — For each scan, retrieves the list of scanned hosts and their host IDs.
  • Imports host data as assets — For each host, extracts the IP address and FQDN (if available) and creates an asset record in PGP. When a host has a fully qualified domain name, PGP uses the FQDN as the primary identifier; otherwise, the IP address is used.
  • Imports vulnerabilities as risks — For each host, retrieves all vulnerability findings with a severity greater than zero (informational findings are excluded). Each vulnerability is imported as a risk associated with the corresponding asset, with an Info triage status for you to review.
  • Retrieves plugin details — For each vulnerability, fetches the full plugin output including the description and detailed findings, which are attached as proof to the risk record.

All operations are strictly read-only. PGP does not create, modify, or delete any scans, policies, or configurations in Nessus.

Prerequisites

Before configuring the Nessus integration, ensure you have:

  • Nessus Professional installed and running with accessible network connectivity from PGP
  • API access keys generated from your Nessus instance (for API integration)
  • At least one completed scan with results available

Continuous integration using the API

To enable the continuous integration between PGP and Nessus, you'll need to generate API credentials from your Nessus Professional instance.

Generating Nessus API Keys

Make sure you have administrator access to the Nessus Professional portal. To generate an API key:

  1. In Tenable Nessus, in the top navigation bar, click Settings. The About page appears.
  2. In the left navigation bar, click My Account. The My Account page appears.
  3. Click the API Keys tab.
  4. Click Generate. A dialog box appears, confirming your selection to generate a new API key._Note: After clicking the Generate button, a warning window notifies you that any previously generated keys will no longer be valid after generating new API keys._Notice: API Keys are only presented upon initial generation. Please store them in a safe location as they can not be retrieved later and will need to be regenerated if lost. Your new API key appears.

Configuring the Integration in PGP

  1. In PGP, go to Integrations and open Vulnerability Management → Nessus Professional.
  2. Click Connect and enter:
    • API URL - The API URL for your Nessus Professional instance. The expected format is https://ip:port or https://domain.tld:port. The default port used by Nessus Professional is 8834.
    • Access Key - Your 64-character Tenable access key.
    • Secret Key - Your 64-character Tenable secret key.
  3. Leave Import Assets and Import Vulnerabilities selected to import both, or clear one to skip it.
  4. Click Connect. PGP checks the keys by listing your scans before saving the integration.

Importing Nessus Scan Results

  1. In your Nessus console, open My Scans, select the scan, and click Export.
  2. Choose the Nessus format. PGP accepts only .nessus (XML) files; CSV and other formats are rejected.
  3. In PGP, go to Vulnerabilities and click Import.
  4. Select Nessus and upload the .nessus file.

PGP creates an asset for each host, using the FQDN when the file has one and the IP address otherwise. Each finding with a severity above zero becomes a risk. Informational findings are skipped. For file imports:

  • The risk's triage severity comes from the finding's Nessus risk factor (Critical, High, Medium, or Low).
  • The risk comment is the finding's synopsis.
  • The full finding record from the file is attached as proof.

If the file is not valid Nessus XML, PGP shows Nessus file was invalid. Did you upload a .nessus file?

What Data Is Synced

Assets

PGP creates asset records for each host discovered in Nessus scans.

Nessus Field

PGP Field

Description

host-fqdn

Asset name

Fully qualified domain name of the scanned host (preferred)

host-ip

Asset IP

IP address of the scanned host (used as name if no FQDN)

Risks

PGP creates risk records for each vulnerability finding with a severity level above zero. The table below describes the API integration; file imports differ as described in the previous section.

Nessus Field

PGP Field

Description

plugin_name

Risk name

The name of the Nessus plugin that detected the vulnerability

description

Risk comment

Detailed description of the vulnerability from the plugin attributes

plugin_output

Risk proof

Raw plugin output providing evidence and technical details of the finding

severity

Import filter

Findings with severity 0 are excluded. Imported risks start at Info triage status regardless of Nessus severity.

Severity Mapping

Nessus findings are imported with the following severity filtering:

Nessus Severity

Description

Imported

0

Informational

No

1

Low

Yes

2

Medium

Yes

3

High

Yes

4

Critical

Yes

API Endpoints Used

The integration uses the following Nessus REST API endpoints. All requests are authenticated using the X-ApiKeys header with the configured access key and secret key.

Method

Endpoint

Purpose

GET

/scans

Retrieves the list of all scans

GET

/scans/{scan_id}

Retrieves scan details including host list

GET

/scans/{scan_id}/hosts/{host_id}

Retrieves host details and vulnerability list

GET

/scans/{scan_id}/hosts/{host_id}/plugins/{plugin_id}

Retrieves plugin details and output for a specific finding

Troubleshooting

Issue

Cause

Fix

Connection refused or timeout

Nessus instance is not reachable from PGP

Verify the URL is correct and that network/firewall rules allow connectivity on the configured port (default 8834)

401 Unauthorized

Invalid or expired API keys

Regenerate API keys in Nessus and update the integration configuration in PGP

SSL/TLS certificate error

Self-signed or untrusted certificate on Nessus instance

The integration supports self-signed certificates. Verify the URL uses the correct protocol (https)

No assets or risks imported

No completed scans with results in Nessus

Run at least one scan in Nessus and wait for it to complete before syncing

Missing vulnerabilities

Only informational-severity findings exist

The integration excludes severity-0 (informational) findings. Verify that scans have detected vulnerabilities with severity 1 or higher

Partial data imported

Network interruption during sync

Re-run the integration; each run fetches data from all scans again

Security and Data Handling

  • Read-only access — The integration only reads scan results and host data from Nessus. It does not create, modify, or delete scans, policies, plugins, or any other Nessus configuration.
  • Credential storage — API access keys and secret keys are stored encrypted within PGP and are never exposed in logs or the user interface after initial configuration.
  • TLS support — The integration accepts self-signed TLS certificates on the Nessus instance.
  • Data transfer — All communication between PGP and your Nessus instance occurs over HTTPS.

If you need help with this integration, contact support@praetorian.com.

Still need help? Ask the team