Expert agent for Tenable Nessus, Tenable.io, and Tenable One. Covers scanner deployment, credentialed scan policies, plugin management, compliance auditing, VPR/EPSS prioritization, Nessus Agent configuration, and Tenable One exposure management. WHEN: \"Tenable\", \"Nessus\", \"Tenable.io\", \"Tenable One\", \"VPR\", \"Nessus agent\", \"plugin families\", \"credentialed scan\", \"Tenable SC\", \"exposure management\".
Pro scans all 3 files and shows the line behind each finding
Scanned 9/24/2026
npx -y skills add chrishuffman5/domain-expert --skill tenable --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Tenable?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/chrishuffman5-tenable)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: tenable
description: "Expert agent for Tenable Nessus, Tenable.io, and Tenable One. Covers scanner deployment, credentialed scan policies, plugin management, compliance auditing, VPR/EPSS prioritization, Nessus Agent configuration, and Tenable One exposure management. WHEN: \"Tenable\", \"Nessus\", \"Tenable.io\", \"Tenable One\", \"VPR\", \"Nessus agent\", \"plugin families\", \"credentialed scan\", \"Tenable SC\", \"exposure management\"."
license: MIT
---
# Tenable
This skill covers the Tenable product family: Nessus (Professional and Expert), Tenable Security Center (on-premises), Tenable.io (cloud platform), and Tenable One (unified exposure management). It has deep expertise in scanner architecture, scan policy design, plugin management, compliance auditing, and exposure management workflows.
## How to Approach Tasks
When you receive a request:
1. **Classify** the request:
- **Scanner deployment / architecture** -- Load `references/architecture.md`
- **Scan policy / best practices** -- Load `references/best-practices.md`
- **Compliance auditing** -- Load `references/best-practices.md`
- **Prioritization / VPR** -- Apply scoring guidance below
- **Tenable One / exposure management** -- Apply exposure management guidance below
- **Troubleshooting** -- Apply diagnostics guidance below
2. **Identify product context** -- Nessus Professional/Expert, Tenable Security Center (on-prem), Tenable.io (cloud), or Tenable One? Each has different capabilities and configuration surfaces.
3. **Load context** -- Read the relevant reference file for deep knowledge.
4. **Analyze** -- Apply Tenable-specific reasoning. Scanner configuration, plugin selection, and credential management are the top sources of poor scan quality.
5. **Recommend** -- Provide specific, actionable guidance with Tenable UI paths or API endpoints where applicable.
## Product Family Overview
| Product | Deployment | License Model | Primary Use |
|---|---|---|---|
| **Nessus Professional** | Self-hosted (VM/bare metal) | $4,790/yr, up to 512 IPs per scan | SMB/teams, on-prem VM |
| **Nessus Expert** | Self-hosted | $6,790/yr | Adds IaC scanning, external attack surface, supply chain |
| **Tenable Security Center** | On-premises enterprise | Asset-based | Large on-prem environments, air-gapped |
| **Tenable.io** | SaaS/cloud | Asset-based | Cloud-managed VM, distributed orgs |
| **Tenable One** | SaaS + connectors | Asset-based | Unified exposure management: VM + CNAPP + ASM + identity |
**Asset-based licensing:** Tenable charges per "asset" -- a unique device detected in any scan. Assets count against your license regardless of how many times scanned or how many IPs they have.
## Core Concepts
### Plugin Architecture
Nessus detects vulnerabilities through plugins -- small programs that test for specific conditions.
**Key facts:**
- 200,000+ plugins in the Tenable plugin library
- 60,000+ CVEs covered
- Plugins are organized into plugin families (see architecture.md)
- Plugins are updated automatically (Tenable releases updates daily)
- Plugins can be individually enabled/disabled in scan policies
**Plugin families (key ones):**
- Windows / Windows: Microsoft Bulletins -- OS patch detection
- Web Servers -- web server vulns
- Databases -- MSSQL, Oracle, MySQL, PostgreSQL, etc.
- Firewalls -- network device detection
- General -- miscellaneous, banner grabs, fingerprinting
- Policy Compliance -- CIS, DISA STIG, PCI DSS audits
- Port Scanners -- TCP/UDP port discovery plugins
**Plugin severity mapping:**
- Critical (10): CVSS 9.0-10.0
- High (8-9): CVSS 7.0-8.9
- Medium (4-7): CVSS 4.0-6.9
- Low (1-3): CVSS 0.1-3.9
- Informational (0): No severity, discovery/fingerprinting
### Vulnerability Priority Rating (VPR)
VPR is Tenable's proprietary risk score that enriches CVSS with threat intelligence.
**VPR components:**
- CVSS base metrics
- Age of vulnerability
- Exploit code maturity (PoC available? Weaponized?)
- Threat intensity (active campaigns using this CVE)
- Product coverage (number of products affected)
**VPR scoring:**
- Critical: 9.0-10.0
- High: 7.0-8.9
- Medium: 4.0-6.9
- Low: 0.1-3.9
**VPR vs. CVSS:** VPR dynamically updates as threat intelligence changes. A CVE with CVSS 7.5 may have VPR 9.2 if a new exploit kit is actively using it. Use VPR for prioritization when available; CVSS for compliance reporting baselines.
**ACR (Asset Criticality Rating):** Tenable.io assigns a 1-10 rating to assets based on business context (internet-facing? sensitive data? privilege level?). Combined with VPR: ACR × VPR exposure feeds the Asset Exposure Score (AES).
### Credentialed vs. Uncredentialed Scanning
| Aspect | Credentialed | Uncredentialed |
|---|---|---|
| **Detection rate** | 95%+ | ~40-60% |
| **Windows auth** | WMI/DCOM (port 135, 139, 445) or WinRM | None |
| **Linux auth** | SSH (port 22) | None |
| **Detects** | Patches, software inventory, config, registry | Network services, open ports, banner vulns |
| **Required ports** | Windows: 135, 139, 445; Linux: 22 | Target service ports |
**Credential types in Tenable:**
- **Windows:** Username/password, Kerberos, LM Hash, NTLM Hash
- **SSH:** Username/password, public key (preferred), certificate
- **Database:** Specific DB credentials for Oracle, MSSQL, MySQL, PostgreSQL
- **API/service:** SNMP community strings, VMware vSphere credentials, AWS/Azure/GCP API keys
**Privilege requirements:**
- Windows: Local Administrator or Domain Administrator (for registry/WMI access)
- Linux: Root or sudo with NOPASSWD for elevated plugin execution
- Best practice: Create dedicated Tenable scan accounts, never use sysadmin/root accounts
## Scan Policy Design
### Policy Templates
Tenable provides built-in scan templates as starting points:
| Template | Use Case |
|---|---|
| **Basic Network Scan** | General-purpose, recommended starting point |
| **Advanced Scan** | Full control over all settings |
| **Advanced Dynamic Scan** | Uses dynamic plugin filters instead of static families |
| **Web Application Tests** | HTTP crawling + web app vulnerability tests |
| **Credentialed Patch Audit** | Focused on patch detection with credentials |
| **Policy Compliance Auditing** | CIS/DISA STIG/PCI compliance checks |
| **Malware Scan** | Detects malware indicators |
| **MDM Config Compliance** | Mobile device management |
### Critical Policy Settings
**Discovery settings:**
- **Host discovery:** Ping sweep before scanning (reduces missed hosts, improves performance)
- **Port scanning:** SYN scan recommended (faster, less disruptive than full TCP)
- **Port range:** Default is 1-65535 for all ports; limit to common ports for faster scans
- **Service detection:** Identify services even on non-standard ports
**Assessment settings:**
- **Accuracy:** Avoid false alarms when possible (safer plugin execution)
- **Perform thorough tests:** More complete but slower; can be disruptive on fragile systems
- **Enable safe checks:** Default ON -- avoids potentially disruptive plugins (crash testing)
**Advanced settings:**
- **Max simultaneous hosts per scanner:** Default 100; reduce for slow networks or fragile systems
- **Max simultaneous checks per host:** Default 5; balance between speed and host load
- **Network timeout:** Default 5 seconds; increase for high-latency environments
- **Scan delay:** Add inter-packet delay for rate-limited devices (IDS/IPS, network equipment)
### Live Results
Available in Tenable.io -- automatically calculates scan results based on software inventory detected in previous credentialed scans, applying new plugins without re-scanning. Updated daily as plugins update. Reduces the time between plugin release and detection.
### Scan Scheduling Best Practices
- **Frequency:** Production servers weekly (credentialed), desktops daily via agent
- **Timing:** Off-hours for server scans; fragile systems (OT, legacy) during maintenance windows
- **Stagger scans:** Don't scan all assets simultaneously -- stagger by subnet to reduce network load
- **Agent vs. network for remote workers:** Nessus Agent for laptops that rarely connect to corporate network
## Tenable Nessus Agent
Lightweight agent (< 40MB) installed on endpoints that performs local vulnerability assessment.
**Agent configuration:**
- Agents link to Tenable.io or Tenable Security Center via agent keys
- Agent polling: every 24 hours by default
- Scan execution: triggered by agent group policies (scan windows, plugin sets)
- Results sync back to management platform on completion
**Agent groups:**
- Logical groupings for policy assignment and reporting
- Assign agents to groups by OS, business unit, environment, criticality
**Agent deployment methods:**
- Manual installation (MSI/RPM/DEB)
- Tenable.io bulk deployment via API
- GPO/MECM for Windows environments
- Ansible/Chef/Puppet for Linux
- Cloud-init for cloud VMs
## Tenable One Exposure Management
Tenable One unifies:
- **Tenable VM** (Nessus/Tenable.io vulnerability data)
- **Tenable Web App Scanning** (DAST for web apps)
- **Tenable Identity Exposure** (Active Directory attack path analysis)
- **Tenable Attack Surface Management** (external ASM, internet-facing asset discovery)
- **Tenable OT Security** (operational technology)
- **Tenable Cloud Security** (CNAPP: CSPM, CWPP, CIEM)
**Exposure View:** Executive dashboard showing Asset Exposure Score (AES) trends, coverage gaps, remediation effort required.
**Attack Path Analysis:** Graph-based visualization of how an attacker could move from an entry point to a target. Shows chained exploits across systems. Powered by Tenable Lumin.
**Benchmark:** Compare your exposure score against industry peers and similar organizations.
## Compliance Auditing
Tenable compliance plugins perform configuration audits against security benchmarks.
**Supported audit frameworks:**
- **CIS Benchmarks** -- Full coverage (Level 1 and 2) for Windows, Linux, cloud, network devices, databases
- **DISA STIGs** -- DoD compliance standards for US government systems
- **PCI DSS** -- Payment card industry requirements
- **HIPAA** -- Healthcare security configuration checks
- **NIST 800-53** -- Federal security controls
- **Custom .audit files** -- Write your own compliance checks in Tenable audit file format
**Audit file format (.audit):**
```
# Example: Check that password minimum length is at least 14
<custom_item>
type: REGISTRY_SETTING
description: "CIS 1.1.1 - Minimum Password Length"
value_type: POLICY_DWORD
value_data: 14
reg_key: "HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters"
reg_item: "MinimumPasswordLength"
check_type: CHECK_GREATER_THAN_OR_EQUAL
</custom_item>
```
## Tenable API
Tenable.io and Tenable Security Center expose REST APIs for automation.
**Key Tenable.io API endpoints:**
- `GET /scans` -- List scans
- `POST /scans` -- Create scan
- `POST /scans/{id}/launch` -- Launch scan
- `GET /scans/{id}/export` -- Export scan results (CSV, PDF, Nessus XML)
- `GET /workbenches/assets` -- Asset inventory
- `GET /workbenches/vulnerabilities` -- Vulnerability findings with filters
- `GET /workbenches/assets/{asset_id}/vulnerabilities` -- Vulns for specific asset
**Authentication:** API key pairs (Access Key + Secret Key) in headers:
```
X-ApiKeys: accessKey=ACCESS_KEY; secretKey=SECRET_KEY
```
**Python SDK:** `pytenable` library (pip install pytenable) provides Pythonic wrappers.
**Common automation tasks:**
- Schedule and launch scans programmatically
- Export findings to SIEM or ITSM
- Sync asset inventory with CMDB
- Generate compliance reports on schedule
## Troubleshooting Common Issues
**Issue: Low plugin count / missing vulns**
- Check credential validity (test with Nessus credential verification scan)
- Verify firewall allows scan traffic (Windows: 135, 139, 445; Linux: 22)
- Check Windows Firewall on target: File and Printer Sharing + WMI exceptions needed
- Review plugin family selections in scan policy -- ensure relevant families are enabled
**Issue: Scan performance / timeouts**
- Reduce max simultaneous hosts per scanner (try 50 instead of 100)
- Reduce max simultaneous checks per host (try 3)
- Increase network timeout for high-latency links
- Enable scan delay for rate-sensitive devices
**Issue: False positives**
- Check if plugin has been superseded by a newer version
- Verify using the specific plugin output -- does the evidence match?
- Use "Accept Risk" in Tenable.io to suppress known FPs with documentation
- Report to Tenable support for plugin quality issues
**Issue: Agents not checking in**
- Verify agent service is running (nessusagent service)
- Check agent linked status in Tenable.io (Sensors > Agents)
- Confirm outbound connectivity to cloud.tenable.com on port 443
- Review agent logs: `/opt/nessus_agent/var/nessus/logs/agent.log`
## Reference Files
Load these when you need deep knowledge for a specific area:
- `references/architecture.md` -- Scanner architecture, scanner types, cloud agent internals, plugin families, Tenable SC architecture. Read for "how does X work" questions.
- `references/best-practices.md` -- Scan policies, credentialed scanning setup, compliance auditing workflows, Tenable One exposure management, operational best practices.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!