Tenable Vulnerability Management (formerly Tenable.io) is a vulnerability assessment solution that automatically discovers and evaluates an organization’s environment for vulnerabilities, misconfigurations, and other cybersecurity issues. The Balbix integration with Tenable Vulnerability Management ingests on-premises and cloud infrastructure assets, associated vulnerabilities, software entities, controls data, and configured operational or business data.
Balbix uses AI to aggregate, normalize, and deduplicate the ingested data from Tenable, along with information from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their operational and business context.
Balbix’s AI models analyze this data to deliver insights such as:
Deployment gap analysis: Identify areas lacking security coverage.
Risk-based vulnerability prioritization: Provide detailed ranking and scoring of vulnerabilities based on risk.
Risk quantification: Assess risk at the asset, group, or enterprise level.
This comprehensive approach enables more informed and effective security decisions, allowing you to proactively manage risk across your organization.
Integration summary
This table provides a summary of the Balbix integration for the Tenable Vulnerability Management connector.
Integration Type | Fetch: An inbound API integration used to fetch assets, vulnerabilities and related metadata such as tags. |
Types of Assets Fetched | Infrastructure devices such as servers, virtual machines, desktops, laptops, networking, and IoT. |
Types of Data Fetched | Asset names (e.g., NetBIOS), DNS, hardware information, CPU information, open port information, location information, interface information (MAC address, IP address), OS information, BIOS information, tags (flat and hierarchical), software information, system status (e.g., reboot pending), vulnerabilities, compliance findings, controls data, and timestamps. |
Note: Availability of specific Tenable fields, such as operating system details, may depend on the implementation and whether a Tenable host-based agent is deployed.
Prerequisites
To configure the Balbix connector, you must first create Tenable Vulnerability Management API credentials with the appropriate permissions. These credentials are required for completing the configuration process. Here are the steps you need to complete:
Use required role name(s): Log in to Tenable to get the API endpoint URL.
Set up access to the Tenable Cloud Security API: Create a service account in Tenable to get the Client ID and Client Secret.
Create an API key: Generate an API key to authenticate any application with Tenable Cloud Security.
Required role name(s)
The Tenable API access provided during connector configuration requires a “basic” permission level. The following privileges are required to successfully fetch the asset and vulnerability information.
Basic role with view access to Assets.
Basic role with view, export access to Vulnerabilities.
Important: In addition to assigning the Basic role, you must ensure the API user has Can View permissions on the asset scope. Without Can View (for example, if the user only has Can Use or Can Edit on tags or access groups), Tenable will return successful exports with zero assets and zero vulnerabilities.
The user must be in an Access Group or Tag scope that actually covers your estate, with at least:
– View Assets
– View Vulnerabilities
– (Optional) Use/Read Exports for better performance and troubleshooting.
Access to the Tenable Cloud Security API
To set up access to the Tenable Cloud Security API:
Verify that you have a valid user account with appropriate permissions by logging into Tenable Cloud Security.
Generate the API keys for the account. You can perform these steps to generate an API token for the Cloud Security account.
Create an API key
You can generate API keys to authenticate any application with Tenable Cloud Security.
Log in to the Tenable Cloud Security portal.
Click Settings from the Vulnerability Management pane.
Click the My Account tile where you can view and update your account details.
Click your user profile icon.
Click the API Keys tab to view the API Keys section.
Click Generate.
In the API Keys window, review the warning and click Generate.
The system generates new access, secret keys, and displays the new keys in the Custom API Keys section.
Copy the access and secret keys and and securely save them for later use when setting up the Tenable Vulnerability Management connector in Balbix.
Caution: Be sure to copy and save the access and secret keys—it will no longer be visible after you leave the page.
Set up your Tenable VM connector
After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Tenable Vulnerability Management.
API reference documentation
To learn more about the Tenable Vulnerability Management API, see the references listed below: