Tenable Vulnerability Management (beta)
Connect Nebulock Helix to Tenable Vulnerability Management for just-in-time vulnerability enrichment.
The Tenable integration enables Nebulock Helix to query vulnerability and asset data from Tenable Vulnerability Management on demand, during hunts and investigations.
Create a dedicated Tenable service account
Log in to Tenable Vulnerability Management at cloud.tenable.com as an administrator, click the settings gear (top right), and go to Access Control.
Create a service user account with an email not tied to an employee (recommended for production), and assign it the minimal role of Basic User.
Log out, then log back in with the newly created service account.
API keys inherit the permissions of the user they belong to. Use a dedicated service account with only the minimum permissions required, rather than a personal admin account.
Generate the API keys
Click the profile avatar (top right) and go to My Profile.
In the left navigation, select API Keys. In the bottom right, click Generate. A warning will note that this overwrites any previously generated keys — click Continue.
Copy the Access Key and Secret Key and store them in a secure vault.
Generating new keys overwrites any existing keys for this account, and Tenable only displays them once. If they're lost, you'll need to generate a new pair.
Enable the integration in Nebulock
In Nebulock, go to Settings > Integrations.
In the search bar, type "Tenable" and click Add New Connection.
Enter the connection details:
- Name: a description of your choice, e.g. "Nebulock Tenable"
- Access Key: the Access Key value generated above
- Secret Key: the Secret Key value generated above
Click Test, then Create Configuration.
Test the integration
Within Nebulock, navigate to Investigate. A simple "List the assets from Tenable" will pull data from your Tenable Vulnerability Management instance.
Updated 27 days ago