Skip to content

Integrate Tenable

Tenable is a cybersecurity company that specializes in exposure management and vulnerability assessment. You can integrate Tenable Vulnerability Management with Sophos XDR so that it sends vulnerability findings to Sophos.

Key steps

The key steps in a Tenable integration are as follows:

  • Generate a Vulnerability Management API Key in Tenable.
  • Gather API credentials from Tenable.
  • Configure the integration in Sophos XDR.

Requirements

The following is required for Tenable configuration:

  • An active Tenable Vulnerability Management subscription.
  • Access to the Tenable Vulnerability Management portal.

Add a Tenable integration

To integrate Tenable, you must first gather certain details from Tenable, then provide them in Sophos XDR.

Get API details from the Vulnerability Management API

To get the Tenable API details you need for integration, do as follows:

  1. Log in to Tenable.
  2. Take note of the base URL for your Tenable application, as this is required in Sophos XDR later (for example, https://cloud.tenable.com/).
  3. Go to Settings > Access Control, and select the user you'd like to create API keys for.
  4. Under API Keys, select Generate API Keys.
  5. Copy the Access Key and Secret Key immediately to use later in Sophos XDR.

    The keys are only displayed once.

Next, you configure an integration in Sophos XDR.

Configure the integration in Sophos XDR

To integrate Tenable with Sophos XDR, do as follows:

  1. In Sophos Central, go to Security Operations > Integrations > Marketplace.
  2. Click Tenable.

    The Tenable page opens. You can configure integrations here and see a list of any you've already configured.

  3. In Configured integrations, click Add new.

  4. In Add an integration, do as follows:

    1. Enter a name for the integration.
    2. Enter the Base URL, Access Key, and Secret Key you got from Tenable.
  5. Click Done.

When you save the configuration, Sophos XDR validates the values by making an authenticated request to Tenable. The integration must pass this validation before scheduled ingestion can begin.

The new integration appears under Configured integrations. If its status icon shows a green tick, the ingested data will begin to enrich your detections.

Configuration notes

Keep the following in mind during Tenable configuration:

  • Once a Tenable integration is configured, a new Vulnerabilities tab appears in detections. The Vulnerablities tab shows details of the vulnerabilities impacting any of the hosts associated with the detection. See Vulnerabilities tab.

Additional resources

For more information on configuring Tenable, see the following documents: