Enriching Data with Tenable Vulnerability Management

The Tenable Vulnerability Management enrichment is a cloud-based risk and vulnerability management solution provided by Tenable. The enrichment enables you to access vulnerability data within your cloud and IT environments, providing insights into affected assets of your organization. The details of the affected assets can be viewed in ThreatStream and exported in CSV format for further analysis.

Activating the Tenable Vulnerability Enrichment

The activation process involves specifying your Tenable Access Key and Secret Key.

To activate the Tenable Vulnerability Management enrichment:

  1. Navigate to ThreatStream > APP STORE > APP Store.

  2. Click Get Access on the Tenable Vulnerability Management tile.

  3. On the wizard page that opens, click I have credentials.
  4. Click Credentials and enter your Tenable Access Key and Secret Key.

  5. Click Activate.

The Tenable Vulnerability management enrichment is now active. Allow ThreatStream up to 15 minutes to sync up with your Tenable account.

Using the Tenable Vulnerability Enrichment in ThreatStream

After activating the Tenable Vulnerability Management enrichment, assets and vulnerabilities data for the last 30 days will be imported from your Tenable account to ThreatStream. After the initial import, ThreatStream will sync up with your Tenable account every hour. Cached data older than 30 days will be removed.

Imported assets and vulnerability data appears under the Tenable tab of Vulnerability details pages. It includes the CVE Summary table displaying CVEs, severity of vulnerabilities (medium, high, or critical), CVSS V3 base score, plugin name, plugin publish date, and plugin last updated date. The Vulnerabilities Distribution charts display the criticality and frequency of vulnerabilities in your IT environment. Below the charts, the Vulnerable Assets table is displayed. The table includes the following information about vulnerable assets: asset IP, DNS name, operating system, discovered vulnerabilities, first seen, last seen, and repository.

Tip: Tenable plugins contain vulnerability information, a simplified set of remediation actions and the algorithm to test for the presence of the security issue.

Below is an example of the Tenable Vulnerability Management tab on the Vulnerability details page.
(Click the image to enlarge it.)

Exporting Tenable Vulnerability Management Data in CSV Format

Imported data displayed in the table can be exported in CSV format.

To export Tenable.sc information in CSV format:

  1. Navigate to the details page of the vulnerability of interest.

    To search for a vulnerability:

    1. Navigate to ThreatStreamAnalyze > Threat Model.
    2. Select Vulnerabilities in the filter on the right side of the screen. Vulnerabilities are not included in search results unless this filter is selected.
    3. Enter your search query.
    4. Click the name of the vulnerability of interest in the search results to visit its details page.

    See Accessing Threat Models for more information on searching for Threat Model entities.

  2. On the vulnerability details page, open the Enrichments tab and click Tenable Vulnerability Management. If available, details on vulnerable assets in your network are displayed.
  3. To export these results in CSV format, click > Export to CSV.

Your download starts automatically.