Tenable Security Center
runZero imports data from Tenable Security Center (previously Tenable.sc) through the Tenable Security Center API.
Getting started with Tenable Security Center
To set up the Tenable Security Center integration:
- Create an API key for a user who can view and query vulnerabilities in Tenable Security Center.
- Add the Tenable Security Center credential to runZero.
- Choose whether to run the integration as a scan probe or a connector task.
- Activate the integration to pull your data into runZero.
Requirements
- Administrator access to the Tenable Security Center portal.
Step 1: Create an API key
- Sign in to Tenable Security Center with an Administrator account.
- Make sure API key authentication is enabled.
- Go to Users > Users.
- Check the box for the user you want to create an API key for. The key gets the same access as that user, so pick one who can view and query vulnerabilities in the organization you want.
- At the top of the table, click API Keys > Generate API Key.
- Click Generate, then download or copy the API token.
Step 2: Add the Tenable Security Center credential to runZero
- Go to the Credentials page in runZero and name the credential, for example
Tenable Security Center. - Choose Tenable Security Center Access & Secret from the list of credential types.
- Generate your Tenable Security Center API key as described in Step 1, then fill in the fields:
- Enter your 64-character Tenable Security Center access key in Access key.
- Enter your 64-character Tenable Security Center secret key in Secret key.
- To share this credential with other organizations, select Make this a global credential. Otherwise, you can grant access per organization.
- Save the credential.
Step 3: Choose how to configure the Tenable Security Center integration
You can run the Tenable Security Center integration as a scan probe or a connector task. A scan probe gathers integration data during a scan task. A connector task runs on its own, from the cloud or from one of your Explorers, and performs only the integration sync. For an internal Tenable Security Center instance, we recommend a connector that runs from one of your Explorers. For an external-facing instance, the connector can run from the cloud. If you self-host runZero, run the connector from an Explorer or from your runZero host, whichever can reach your Tenable Security Center install.
Step 4: Set up and activate the integration to sync data
Step 4a: Configure the Tenable Security Center integration as a connector task
A connection needs a schedule, which sets when the sync runs.
- Activate a connection to Tenable Security Center. You can also reach every third-party connection from the integrations page, your inventory, or the tasks page.
- Choose the credentials you added earlier. If they aren’t listed, check that they have access to your current organization.
- Set the Tenable Security Center query mode (optional):
- Select Define filters to filter by vulnerability severity and risk level. Much of the host information from Tenable comes from Info-level plugins, so if you import only higher severities, assets may show little information.
- Select Use existing query ID to specify the Tenable Security Center query to use. The query must be the Vulnerability type and use the Vulnerability Detail List tool.
- Set the Fingerprint only toggle to Yes to use vulnerability records for fingerprint analysis without storing them in your runZero vulnerability inventory (optional).
- Enter a name for the task, like
Tenable Security Center sync(optional). - Choose the Explorer that runs this connector task (optional).
- Choose the site for the connector.
- Enter a description for the task (optional).
- Schedule the sync to run once or on a recurring schedule, starting on the date and time you set.
- Activate the connection. The sync runs on your schedule, and the Scheduled tasks page shows when the next one will run.
Step 4b: Configure the Tenable Security Center integration as a scan probe
Run the Tenable Security Center integration as a scan probe to have the runZero Explorer pull your vulnerability data into the runZero Console.
In a new or existing scan configuration:
- Set the TENABLESECURITYCENTER option to Yes in the Probes and SNMP tab and change any default options you need.
- Optionally, set the severity and risk levels for ingested vulnerability scan results or provide a query ID.
- Set the correct
TenableSecurityCentercredential to Yes in the Credentials tab.
Step 5: View Tenable Security Center assets and vulnerabilities
After a successful sync, your Tenable Security Center assets appear in your inventory with a Tenable icon in the Source column.
The integration also gathers the vulnerabilities Tenable Security Center detected. Go to Inventory > Vulnerabilities to view the vulnerability data from Tenable Security Center.
To filter by Tenable Security Center assets or vulnerabilities, run these queries:
-
View all Tenable Security Center assets:
source:tenablesecuritycenter -
View all Tenable Security Center vulnerabilities:
source:tenablesecuritycenter
Open an asset or vulnerability to see the attributes runZero gathered from the Tenable Security Center API.