0% found this document useful (0 votes)
5 views8 pages

Tenable Feature Overview

The document provides an overview of Tenable.io's Vulnerability Management features, including Active Scan, Agent Scan, Policy management, Dashboard functionalities, and other settings. Active Scans assess network vulnerabilities using credentialed and non-credentialed methods, while Agent Scans utilize lightweight agents for offline assets. The Dashboard offers real-time visibility and risk prioritization, and the platform supports various integrations and user management features.

Uploaded by

gikene9710
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views8 pages

Tenable Feature Overview

The document provides an overview of Tenable.io's Vulnerability Management features, including Active Scan, Agent Scan, Policy management, Dashboard functionalities, and other settings. Active Scans assess network vulnerabilities using credentialed and non-credentialed methods, while Agent Scans utilize lightweight agents for offline assets. The Dashboard offers real-time visibility and risk prioritization, and the platform supports various integrations and user management features.

Uploaded by

gikene9710
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

T E N A B L E .

I O

Vulnerability Management
Feature Overview
Active Scan Agent Scan Policy Dashboard Settings

Network Security | Vulnerability Assessment


A G E N D A

What We Will Cover

Active Scan Dashboard


01 04
Network-based credential & non-credential scanning Real-time visibility, widgets & risk prioritization

Agent Scan Other Settings


02 05
Lightweight agents for offline & distributed assets Users, notifications, integrations & system config

Policy
03
Scan templates, credentials & compliance profiles
01 | ACTIVE SCAN

Network-Based Vulnerability Scanning


Credentialed Scanning Non-Credentialed
What is Active Scan?
Uses SSH / WMI credentials for deep OS External perimeter scanning without
& application-level visibility credentials – maps attack surface
Active Scans actively probe network devices and hosts by sending
packets and analyzing responses. They can be credentialed (using
SSH/WMI) for deep OS-level visibility or non-credentialed for Targets & Ranges Scheduling
external exposure assessment.
Define IP ranges, CIDR blocks, FQDNs, Run on-demand or schedule recurring
or import asset lists scans with timezone awareness

Key Considerations

• Scanner placement matters — deploy scanners close to target segments to avoid firewall interference.
• Credentialed scans produce significantly more findings (CVEs, misconfigurations) vs non-credentialed.
• Rate-limit settings prevent scan traffic from saturating bandwidth-sensitive environments.
• Linked scanners (cloud or on-prem) require network connectivity and appropriate firewall rules.
02 | AGENT SCAN

Lightweight Agents for Distributed Assets


Active Scan Limitations Agent Scan Advantages

Requires network reachability to target Runs locally on each host – no network scan traffic

Firewall / NAT can block scanner traffic Works for off-network, VPN-off, and cloud workloads

Offline or intermittently connected assets missed Captures changes between traditional scan windows

Credential management overhead on scanner side Supports Windows, Linux, macOS endpoints

Temporary bandwidth impact during scan window Lightweight daemon (~10 MB, minimal CPU impact)

Agent Groups & Scan Profiles


Agents are organized into Groups (e.g. Windows Servers, Linux Workstations). Scan profiles are assigned per group, allowing different scan policies and scheduling per
asset category — all managed from [Link] cloud.
03 | POLICY

Scan Templates, Credentials & Compliance Profiles

Scan Templates Credentials Compliance / Audit

Basic Network Scan SSH (Linux/Unix) CIS Benchmarks

Advanced Scan Windows (SMB/WMI) DISA STIG

Web Application Tests SNMP PCI-DSS

Malware Scan Database credentials HIPAA

PCI ASV / Internal HTTP/API auth tokens ISO 27001 checks

💡 Policies are reusable — create once, attach to multiple scans. Custom audit files (.audit) can be imported for organization-specific compliance checks beyond
default templates.
04 | DASHB OAR D

Real-Time Visibility & Risk Prioritization

Assets Vulnerabilities Scan Coverage Cyber Exposure


Track & Manage By Severity % of Known Assets Risk Score

Dashboard Widgets Customization & Sharing

Vulnerability by Severity (Bar/Pie charts) Drag-and-drop widget arrangement

Asset Inventory heatmap Role-based dashboard sharing (per user/group)

Top Vulnerabilities by VPR score Filters: Tags, Networks, Asset groups

Remediation Summary & SLA tracking Export as PDF or schedule email reports

Scan Status & Coverage map VPR (Vulnerability Priority Rating) integration

Tenable Lumin (add-on) extends dashboards with business context scoring, SLA benchmarking, and peer industry comparison to communicate cyber risk to
executive leadership.
05 | OTHER SETTIN G S

Administration, Integrations & System Configuration

User & Access Management Notifications & Alerts Integrations

Role-Based Access Control (RBAC) Email alerts on new critical CVEs Jira / ServiceNow ticketing

SSO via SAML 2.0 / LDAP Slack / Teams webhook integration Splunk / QRadar SIEM export

API key generation per user Scan completion notifications AWS / Azure / GCP connectors

Audit logs for user actions SLA breach warnings REST API for custom automation

Sensors & Scanner Mgmt License & Compliance Security Settings

Link/unlink scanners Asset-based licensing (ALU) Two-Factor Authentication (2FA)

Scanner group assignment License utilization reporting Session timeout policies

Nessus agent health monitoring Plugin update schedules IP allowlisting for UI/API

Update & plugin management Sensor activation codes Data retention configuration
Summary
[Link] Capabilities at a Glance

Active Scan Agent Scan Policy

Network-based scanning with credential & non- Host-based agents for distributed, offline, or Reusable templates, credentials & compliance
credential modes cloud-only assets audit profiles

Dashboard Other Settings

Real-time widgets, VPR scoring & exportable risk RBAC, integrations, alerting & sensor lifecycle
reporting management

[Link] | Vulnerability Management Platform

You might also like