Back to skills
SKILL.md
Tenable
ASecurityExpert agent for Tenable Nessus, Tenable.io, and Tenable One. Covers scanner deployment, credentialed scan policies, plugin management, compliance auditing, VPR/EPSS prioritization, Nessus Agent configuration, and Tenable One exposure management. WHEN: \"Tenable\", \"Nessus\", \"Tenable.io\", \"Tenable One\", \"VPR\", \"Nessus agent\", \"plugin families\", \"credentialed scan\", \"Tenable SC\", \"exposure management\".
- 4 stars
- 0 votes
- 0 copies
- 0 views
- Added September 24, 2026
Works with
Security analysis
92/100- Installs packages at runtime which could introduce malicious dependencies
Pro scans all 3 files and shows the line behind each finding
npx -y skills add chrishuffman5/domain-expert --skill tenable --agent claude-codeAre you the author of Tenable?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/chrishuffman5-tenable)---
name: tenable
description: "Expert agent for Tenable Nessus, Tenable.io, and Tenable One. Covers scanner deployment, credentialed scan policies, plugin management, compliance auditing, VPR/EPSS prioritization, Nessus Agent configuration, and Tenable One exposure management. WHEN: \"Tenable\", \"Nessus\", \"Tenable.io\", \"Tenable One\", \"VPR\", \"Nessus agent\", \"plugin families\", \"credentialed scan\", \"Tenable SC\", \"exposure management\"."
license: MIT
---
# Tenable
This skill covers the Tenable product family: Nessus (Professional and Expert), Tenable Security Center (on-premises), Tenable.io (cloud platform), and Tenable One (unified exposure management). It has deep expertise in scanner architecture, scan policy design, plugin management, compliance auditing, and exposure management workflows.
## How to Approach Tasks
When you receive a request:
1. **Classify** the request:
- **Scanner deployment / architecture** -- Load `references/architecture.md`
- **Scan policy / best practices** -- Load `references/best-practices.md`
- **Compliance auditing** -- Load `references/best-practices.md`
- **Prioritization / VPR** -- Apply scoring guidance below
- **Tenable One / exposure management** -- Apply exposure management guidance below
- **Troubleshooting** -- Apply diagnostics guidance below
2. **Identify product context** -- Nessus Professional/Expert, Tenable Security Center (on-prem), Tenable.io (cloud), or Tenable One? Each has different capabilities and configuration surfaces.
3. **Load context** -- Read the relevant reference file for deep knowledge.
4. **Analyze** -- Apply Tenable-specific reasoning. Scanner configuration, plugin selection, and credential management are the top sources of poor scan quality.
5. **Recommend** -- Provide specific, actionable guidance with Tenable UI paths or API endpoints where applicable.
## Product Family Overview
| Product | Deployment | License Model | Primary Use |
|---|---|---|---|
| **Nessus Professional** | Self-hosted (VM/bare metal) | $4,790/yr, up to 512 IPs per scan | SMB/teams, on-prem VM |
| **Nessus Expert** | Self-hosted | $6,790/yr | Adds IaC scanning, external attack surface, supply chain |
| **Tenable Security Center** | On-premises enterprise | Asset-based | Large on-prem environments, air-gapped |
| **Tenable.io** | SaaS/cloud | Asset-based | Cloud-managed VM, distributed orgs |
| **Tenable One** | SaaS + connectors | Asset-based | Unified exposure management: VM + CNAPP + ASM + identity |
**Asset-based licensing:** Tenable charges per "asset" -- a unique device detected in any scan. Assets count against your license regardless of how many times scanned or how many IPs they have.
## Core Concepts
### Plugin Architecture
Nessus detects vulnerabilities through plugins -- small programs that test for specific conditions.
**Key facts:**
- 200,000+ plugins in the Tenable plugin library
- 60,000+ CVEs covered
- Plugins are organized into plugin families (see architecture.md)
- Plugins are updated automatically (Tenable releases updates daily)
- Plugins can be individually enabled/disabled in scan policies
**Plugin families (key ones):**
- Windows / Windows: Microsoft Bulletins -- OS patch detection
- Web Servers -- web server vulns
- Databases -- MSSQL, Oracle, MySQL, PostgreSQL, etc.
- Firewalls -- network device detection
- General -- miscellaneous, banner grabs, fingerprinting
- Policy Compliance -- CIS, DISA STIG, PCI DSS audits
- Port Scanners -- TCP/UDP port discovery plugins
**Plugin severity mapping:**
- Critical (10): CVSS 9.0-10.0
- High (8-9): CVSS 7.0-8.9
- Medium (4-7): CVSS 4.0-6.9
- Low (1-3): CVSS 0.1-3.9
- Informational (0): No severity, discovery/fingerprinting
### Vulnerability Priority Rating (VPR)
VPR is Tenable's proprietary risk score that enriches CVSS with threat intelligence.
**VPR components:**
- CVSS base metrics
- Age of vulnerability
- Exploit code maturity (PoC available? Weaponized?)
- Threat intensity (active campaigns using this CVE)
- Product coverage (number of products affected)
**VPR scoring:**
- Critical: 9.0-10.0
- High: 7.0-8.9
- Medium: 4.0-6.9
- Low: 0.1-3.9
**VPR vs. CVSS:** VPR dynamically updates as threat intelligence changes. A CVE with CVSS 7.5 may have VPR 9.2 if a new exploit kit is actively using it. Use VPR for prioritization when available; CVSS for compliance reporting baselines.
**ACR (Asset Criticality Rating):** Tenable.io assigns a 1-10 rating to assets based on business context (internet-facing? sensitive data? privilege level?). Combined with VPR: ACR × VPR exposure feeds the Asset Exposure Score (AES).
### Credentialed vs. Uncredentialed Scanning
| Aspect | Credentialed | Uncredentialed |
|---|---|---|
| **Detection rate** | 95%+ | ~40-60% |
| **Windows auth** | WMI/DCOM (port 135, 139, 445) or WinRM | None |
| **Linux auth** | SSH (port 22) | None |
| **Detects** | Patches, software inventory, config, registry | Network services, open ports, banner vulns |
| **Required ports** | Windows: 135, 139, 445; Linux: 22 | Target service ports |
**Credential types in Tenable:**
- **Windows:** Username/password, Kerberos, LM Hash, NTLM Hash
- **SSH:** Username/password, public key (preferred), certificate
- **Database:** Specific DB credentials for Oracle, MSSQL, MySQL, PostgreSQL
- **API/service:** SNMP community strings, VMware vSphere credentials, AWS/Azure/GCP API keys
**Privilege requirements:**
- Windows: Local Administrator or Domain Administrator (for registry/WMI access)
- Linux: Root or sudo with NOPASSWD for elevated plugin execution
- Best practice: Create dedicated Tenable scan accounts, never use sysadmin/root accounts
## Scan Policy Design
### Policy Templates
Tenable provides built-in scan templates as starting points:
| Template | Use Case |
|---|---|
| **Basic Network Scan** | General-purpose, recommended starting point |
| **Advanced Scan** | Full control over all settings |
| **Advanced Dynamic Scan** | Uses dynamic plugin filters instead of static families |
| **Web Application Tests** | HTTP crawling + web app vulnerability tests |
| **Credentialed Patch Audit** | Focused on patch detection with credentials |
| **Policy Compliance Auditing** | CIS/DISA STIG/PCI compliance checks |
| **Malware Scan** | Detects malware indicators |
| **MDM Config Compliance** | Mobile device management |
### Critical Policy Settings
**Discovery settings:**
- **Host discovery:** Ping sweep before scanning (reduces missed hosts, improves performance)
- **Port scanning:** SYN scan recommended (faster, less disruptive than full TCP)
- **Port range:** Default is 1-65535 for all ports; limit to common ports for faster scans
- **Service detection:** Identify services even on non-standard ports
**Assessment settings:**
- **Accuracy:** Avoid false alarms when possible (safer plugin execution)
- **Perform thorough tests:** More complete but slower; can be disruptive on fragile systems
- **Enable safe checks:** Default ON -- avoids potentially disruptive plugins (crash testing)
**Advanced settings:**
- **Max simultaneous hosts per scanner:** Default 100; reduce for slow networks or fragile systems
- **Max simultaneous checks per host:** Default 5; balance between speed and host load
- **Network timeout:** Default 5 seconds; increase for high-latency environments
- **Scan delay:** Add inter-packet delay for rate-limited devices (IDS/IPS, network equipment)
### Live Results
Available in Tenable.io -- automatically calculates scan results based on software inventory detected in previous credentialed scans, applying new plugins without re-scanning. Updated daily as plugins update. Reduces the time between plugin release and detection.
### Scan Scheduling Best Practices
- **Frequency:** Production servers weekly (credentialed), desktops daily via agent
- **Timing:** Off-hours for server scans; fragile systems (OT, legacy) during maintenance windows
- **Stagger scans:** Don't scan all assets simultaneously -- stagger by subnet to reduce network load
- **Agent vs. network for remote workers:** Nessus Agent for laptops that rarely connect to corporate network
## Tenable Nessus Agent
Lightweight agent (< 40MB) installed on endpoints that performs local vulnerability assessment.
**Agent configuration:**
- Agents link to Tenable.io or Tenable Security Center via agent keys
- Agent polling: every 24 hours by default
- Scan execution: triggered by agent group policies (scan windows, plugin sets)
- Results sync back to management platform on completion
**Agent groups:**
- Logical groupings for policy assignment and reporting
- Assign agents to groups by OS, business unit, environment, criticality
**Agent deployment methods:**
- Manual installation (MSI/RPM/DEB)
- Tenable.io bulk deployment via API
- GPO/MECM for Windows environments
- Ansible/Chef/Puppet for Linux
- Cloud-init for cloud VMs
## Tenable One Exposure Management
Tenable One unifies:
- **Tenable VM** (Nessus/Tenable.io vulnerability data)
- **Tenable Web App Scanning** (DAST for web apps)
- **Tenable Identity Exposure** (Active Directory attack path analysis)
- **Tenable Attack Surface Management** (external ASM, internet-facing asset discovery)
- **Tenable OT Security** (operational technology)
- **Tenable Cloud Security** (CNAPP: CSPM, CWPP, CIEM)
**Exposure View:** Executive dashboard showing Asset Exposure Score (AES) trends, coverage gaps, remediation effort required.
**Attack Path Analysis:** Graph-based visualization of how an attacker could move from an entry point to a target. Shows chained exploits across systems. Powered by Tenable Lumin.
**Benchmark:** Compare your exposure score against industry peers and similar organizations.
## Compliance Auditing
Tenable compliance plugins perform configuration audits against security benchmarks.
**Supported audit frameworks:**
- **CIS Benchmarks** -- Full coverage (Level 1 and 2) for Windows, Linux, cloud, network devices, databases
- **DISA STIGs** -- DoD compliance standards for US government systems
- **PCI DSS** -- Payment card industry requirements
- **HIPAA** -- Healthcare security configuration checks
- **NIST 800-53** -- Federal security controls
- **Custom .audit files** -- Write your own compliance checks in Tenable audit file format
**Audit file format (.audit):**
```
# Example: Check that password minimum length is at least 14
<custom_item>
type: REGISTRY_SETTING
description: "CIS 1.1.1 - Minimum Password Length"
value_type: POLICY_DWORD
value_data: 14
reg_key: "HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters"
reg_item: "MinimumPasswordLength"
check_type: CHECK_GREATER_THAN_OR_EQUAL
</custom_item>
```
## Tenable API
Tenable.io and Tenable Security Center expose REST APIs for automation.
**Key Tenable.io API endpoints:**
- `GET /scans` -- List scans
- `POST /scans` -- Create scan
- `POST /scans/{id}/launch` -- Launch scan
- `GET /scans/{id}/export` -- Export scan results (CSV, PDF, Nessus XML)
- `GET /workbenches/assets` -- Asset inventory
- `GET /workbenches/vulnerabilities` -- Vulnerability findings with filters
- `GET /workbenches/assets/{asset_id}/vulnerabilities` -- Vulns for specific asset
**Authentication:** API key pairs (Access Key + Secret Key) in headers:
```
X-ApiKeys: accessKey=ACCESS_KEY; secretKey=SECRET_KEY
```
**Python SDK:** `pytenable` library (pip install pytenable) provides Pythonic wrappers.
**Common automation tasks:**
- Schedule and launch scans programmatically
- Export findings to SIEM or ITSM
- Sync asset inventory with CMDB
- Generate compliance reports on schedule
## Troubleshooting Common Issues
**Issue: Low plugin count / missing vulns**
- Check credential validity (test with Nessus credential verification scan)
- Verify firewall allows scan traffic (Windows: 135, 139, 445; Linux: 22)
- Check Windows Firewall on target: File and Printer Sharing + WMI exceptions needed
- Review plugin family selections in scan policy -- ensure relevant families are enabled
**Issue: Scan performance / timeouts**
- Reduce max simultaneous hosts per scanner (try 50 instead of 100)
- Reduce max simultaneous checks per host (try 3)
- Increase network timeout for high-latency links
- Enable scan delay for rate-sensitive devices
**Issue: False positives**
- Check if plugin has been superseded by a newer version
- Verify using the specific plugin output -- does the evidence match?
- Use "Accept Risk" in Tenable.io to suppress known FPs with documentation
- Report to Tenable support for plugin quality issues
**Issue: Agents not checking in**
- Verify agent service is running (nessusagent service)
- Check agent linked status in Tenable.io (Sensors > Agents)
- Confirm outbound connectivity to cloud.tenable.com on port 443
- Review agent logs: `/opt/nessus_agent/var/nessus/logs/agent.log`
## Reference Files
Load these when you need deep knowledge for a specific area:
- `references/architecture.md` -- Scanner architecture, scanner types, cloud agent internals, plugin families, Tenable SC architecture. Read for "how does X work" questions.
- `references/best-practices.md` -- Scan policies, credentialed scanning setup, compliance auditing workflows, Tenable One exposure management, operational best practices.
Files in this skill
- SKILL.md
- references/architecture.md
- references/best-practices.md
Attribution
Comments
Loading comments…