Skip to content

Tenable

Tenable is a cybersecurity company that specializes in exposure management and vulnerability assessment. You can integrate Tenable Vulnerability Management with Sophos XDR so that it sends vulnerability findings to Sophos.

This page gives you an overview of the integration.

Tenable product overview

Tenable Vulnerability Management is a cloud-based vulnerability management service. It identifies vulnerabilities on assets, highlights the CVEs, and provides details on remediating vulnerabilities. This integration enriches detection data in the Sophos Fusion platform with the vulnerability data ingested by leveraging Tenable's Vulnerability Management export API.

What we ingest

The integration ingests vulnerability findings from Tenable Vulnerability Management for assets in the configured Tenable account.

By default, it ingests findings in the following states:

  • OPEN
  • REOPENED
  • FIXED

It ingests low, medium, high, and critical severity vulnerabilities. Findings with an accepted severity are excluded by default. Recast findings are included.

Data provided by this integration

Data provided by Tenable can include the following:

  • Affected asset information, such as hostname, FQDN, IP address, operating system, and asset ID.
  • Tenable plugin information, including plugin ID, name, family, type, and description.
  • CVEs and CVSS scores when provided.
  • Finding state, severity, and timestamps, such as first found, last found, and indexed.
  • Port and protocol information when present.

Vendor documentation