← all integrations

Vulnerability Management

Tenable

Tenable vulnerability data folded into conversational triage and compliance evidence.

TRY ASKING:

“List vulnerabilities affecting internet-facing assets, ordered by severity.”

  • “Which critical CVEs affect assets that are reachable from the internet?”
  • “Show vulnerabilities discovered in the last 7 days, grouped by asset.”
  • “Cross-reference these findings with the services my attack surface scan found exposed.”

Kikimora pulls vulnerability listings from Tenable and correlates them with what it knows from your clouds and your attack surface, so a CVE is never just a row in a scanner.

Triage Tenable vulnerabilities from one conversation

The integration covers your Tenable vulnerability data and, crucially, what it means in context. A high-severity CVE on an internal box behind three firewalls is not the same as the same CVE on an internet-facing host. The agent filters by severity, asset, and recency, then cross-references against the exposed services it knows about, so the list you act on is ordered by real risk, not just CVSS score. Most vulnerability programs drown in volume, not signal. A raw severity list tells you a thousand things are critical and nothing about which one an attacker can actually reach today. By joining Tenable findings to the exposure data Kikimora already holds, the agent answers the question that matters: of everything critical, what is reachable, and therefore what should you fix first.

What you can do

  • List vulnerabilities filtered by severity, asset, or recency.
  • Cross-reference findings with exposed services discovered by ASM.
  • Use Tenable data as evidence in compliance briefings.

Things you might ask

  • “Which critical vulnerabilities affect assets that are actually reachable from the internet?” Reachability is what separates urgent from noise. Our guide on how to find every internet-facing asset you forgot you had explains why exposure context changes the priority order.
  • “Show me everything Tenable found in the last week, grouped by host.”
  • “Cross-reference these findings with the open ports my external scan turned up.”

Tenable handles the vulnerabilities you scan for across your estate. Pair it with the built-in Qualys WAS integration, which adds web application scanning at no extra license cost, so infrastructure and web findings get triaged in one conversation.

[ faq ]

What access does the Tenable integration need? +

A read-scoped API key pair for your Tenable platform. That lets the agent read vulnerability listings and asset data. It is read-only.

Does Kikimora run new Tenable scans? +

It reads the findings your existing Tenable scans produce and folds them into triage. The agent prioritizes and correlates the data rather than launching scans on the appliance.

How long does it take to connect Tenable? +

A few minutes. Generate an access and secret key in Tenable and paste them in. Nothing is installed on your scanners.

Can I use the data for compliance? +

Yes. Tenable findings can be summarized into compliance briefings and used as evidence that vulnerability management controls are operating.

More in Vulnerability Management