Tenable

AppViewX integrates with Tenable IO and Tenable SC to ingest existing vulnerability scan data and derive PQC readiness insights, without deploying the Agents on target endpoints. The PQC readiness analysis provides visibility across to the following areas:
  • Certificates
    • Certificates and associated metadata
    • Signature algorithms
    • Public key algorithms
    • Key sizes
    Example: A TLS certificate used by an application shows:
    • Certificate: app.company.com
    • Signature Algorithm: SHA256withRSA
    • Public Key Algorithm: RSA
    • Key Size: 2048-bit
  • Protocols and Cryptographic Configuration
    • Security and application protocols
    • Cipher suites
    • Encryption algorithms
    • Hashing algorithms
    • Key exchange algorithms
    Example: An application endpoint on port 443 is configured with:
    • Protocol: TLS 1.2
    • Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
    • Key Exchange: ECDHE
    • Authentication: RSA
    • Encryption Algorithm: AES-256-GCM
    • Hashing Algorithm: SHA-384
  • Cryptographic Libraries (Application-Associated)
    • Cryptographic libraries and versions associated with discovered applications.
    • Libraries identified only at the endpoint level without application context are not included.

    Example: A server hosts applications on ports 443 and 8443. If OpenSSL is detected and associated with the application on port 443, it is displayed. If OpenSSL is detected on the server but cannot be associated with any specific application, it is not displayed.

This topic lists the Tenable-side prerequisites for the integration: the plugins that must be enabled in the Tenable scan policy, the minimum API key role and scope, and operational guidance for production deployments.

For AppViewX configuration and usage, see the following topics:

Prerequisites

Before you configure the Tenable vendor integration in AppViewX, verify the following details from Tenable:
  • The plugins listed in Plugins required for PQC discovery are enabled in the Tenable scan policy. These plugins are enabled by default in standard Tenable IO and Tenable SC configurations.
    Note: Verify that the plugins have not been disabled in a custom scan template.
  • An API key with the role and scope listed in API key permissions is available.
    Important: For Tenable SC, the organization administrator must enable Allow API Keys under Organization > Settings.
  • The AppViewX deployment can reach the Tenable IO cloud endpoint or the on-premises Tenable SC console URL configured on the vendor integration.

Plugins Required for PQC Discovery

AppViewX uses the following Tenable plugins to collect certificate, protocol, and cryptographic data during an ASM scan. This data is used to evaluate each discovered endpoint for exposure to quantum-vulnerable algorithms and to assess alignment with post-quantum cryptography standards.
Table 1. Tenable Plugins Required for PQC Discovery
Plugin ID Plugin Name Category Description
277654 TLS Supported Groups General Collects supported TLS key exchange groups and elliptic curves exposed by the endpoint.
21643 SSL Cipher Suites Supported General Collects SSL/TLS cipher suites supported by the endpoint.
10863 SSL Certificate Information General Retrieves X.509 certificate chain details, including issuer, subject, signature algorithm, key size, and validity period.
19506 Nessus SSL/TLS Scanner General Identifies supported SSL/TLS protocol versions and cipher suites negotiated
22964 SSL/TLS Certificate Information General Collects certificate and SSL/TLS configuration information presented by the service.
10107 HTTP Server Type and Version Web Servers Identifies the web server software running on the endpoint.
24260 HyperText Transfer Protocol (HTTP) Information Web Servers Collects HTTP response headers, server metadata, and connection information.
141263 Apache Tomcat Site Enumeration Web Servers Discovers sites and applications hosted on Apache Tomcat instances.
142640 Apache HTTP Server Site Enumeration Web Servers Enumerates virtual hosts and sites configured on Apache HTTP Server.
140655 Microsoft IIS Sites Enumeration Web Servers Identifies websites and bindings configured on Microsoft IIS servers.
11219 Nessus SYN Scanner Port Scanners Discovers open TCP ports and network-accessible services using SYN scanning.
10335 Nessus TCP Scanner Port Scanners Detects services running on open TCP ports through TCP connect scanning.
14272 Netstat Portscanner (SSH) Port Scanners Retrieves active listening ports from Linux/Unix systems using SSH.
34220 Netstat Portscanner (WMI) Port Scanners Retrieves active listening ports from Windows systems using WMI.
10092 FTP Server Detection Service Detection Detects FTP and FTPS services exposed by the endpoint.
10185 POP Server Detection Service Detection Identifies POP3 and POP3S mail services.
10263 SMTP Server Detection Service Detection Identifies SMTP and SMTPS mail services.
10719 MySQL Server Detection Service Detection Detects MySQL database services and listeners.
11414 IMAP Service Banner Retrieval Service Detection Detects IMAP and IMAPS services and retrieves service banner information.
20870 LDAP Server Detection Service Detection Identifies LDAP and LDAPS directory services.
26024 PostgreSQL Server Detection Service Detection Detects PostgreSQL database services and listeners.
65914 MongoDB Detection Service Detection Identifies MongoDB database services.
130127 PostgreSQL Server Installed (Windows) Service Detection Detects PostgreSQL installations on Windows hosts.

API key permissions

The API key configured on the Tenable vendor integration must have at least the role and scope listed in the following table. AppViewX uses these permissions to invoke the export and analysis endpoints during an ASM scan.
Tenable Product Minimum Role Required Permission or Scope
Tenable IO Standard user with API key Permission to invoke the vulns/export endpoint and read scan results for the assets in scope.
Tenable SC Auditor (or equivalent) with API key Access to the Analysis endpoint and read access to the repository or asset list in scope.
Important: The organization administrator must enable Allow API Keys under Organization > Settings.

Operational Considerations

  • Concurrency and rate limits (Tenable IO): Vulnerability export jobs are subject to concurrency limits and rate limits. Schedule large ASM scans to avoid HTTP 409 (duplicate export) and HTTP 429 (throttled) responses.
  • Asset scoping: Use the assetTags JSON on the AppViewX vendor integration to limit the scan to a defined subset of Tenable assets. Tag-based filtering is recommended for large deployments to avoid pulling the full vulnerability dataset on every run. For the JSON template, see Tenable IO – dummy JSON template or Tenable SC – dummy JSON template.
  • Dedicated service account: Use a service account with the minimum role listed above instead of reusing an administrator's key. Restrict its asset or repository scope to the targets in the ASM scan.