Tenable Posture Report
Delivers a weekly report on Tenable coverage across your assets, what changed in the vulnerability backlog, and anything in the container that needs an admin, from failing scans to license use.
What this agent does
This read-only agent checks the health of a Tenable Vulnerability Management container every week. It finds assets that Tenable has never scanned, has not scanned recently, or scans only without credentials. It summarizes the Critical and High vulnerabilities that appeared, were fixed, and were accepted or recast since last week. It flags anything that needs an admin, such as a scanner that is offline, agents that stopped checking in, a scan schedule that keeps failing, or licensed asset use close to the contract.
The challenge
Tenable only finds vulnerabilities on the assets it scans, and coverage gaps raise no alert. A scanner loses its network path. An agent group stops updating. A cloud connector stops importing, and new instances never appear. A credential expires, and every scan on that subnet turns unauthenticated. Accept risk rules accumulate with no review of who accepted what. The licensed asset count grows past the contract, and admins find out at renewal.
The solution
The agent checks coverage, scan health, backlog movement, and container limits in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check coverage
Find assets with no scan, no scan in the window, or only unauthenticated scans, and compare with the cloud inventory when I grant access.
- 02
Check scan health
Check scanners, agents, cloud connectors, scan schedules, and per-asset authentication failures.
- 03
Check the backlog
Summarize Critical and High vulnerabilities opened, fixed, accepted, and recast since last week.
- 04
Report
Publish what changed, the license position, and what needs action, with the fix for each item.
Agent template
# Tenable Posture Report
## Measurable outcomes
Every week, the admin knows which assets Tenable is not covering, how the Critical and High backlog moved, and what needs action before it breaks. Track covered and uncovered assets, scan failures, and open action items on every run.
## Procedure
Once a week, list the assets Tenable Vulnerability Management knows about. Flag the ones with no scan in the last 14 days, unless I set another window, and the ones whose only recent scans ran without credentials. Judge each asset's authentication from plugins 19506 and 21745, not from the scan policy alone. When I give it read-only access to my cloud accounts, compare their running instances with the assets in Tenable and flag any instance Tenable has never seen. Flag cloud connectors whose last import failed or is older than the window. Check each scanner and scanner group and flag any that are offline or on an outdated version. Flag agents that have not checked in during the window, grouped by agent group. Flag scan schedules whose last run failed, was aborted, or scanned fewer targets than the run before. Summarize the Critical and High vulnerabilities that appeared, were fixed, and were accepted or recast since the last report. Read the accept and recast state from the findings' severity modification fields. Report who created each rule, and the comment they left, where the API exposes them. Compare licensed asset use with the contract's limit, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Replace hostnames, IP addresses, and user names with stable pseudonyms in the report. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Tenable Vulnerability Management API access to assets, vulnerabilities, scans, scanners, agents, cloud connectors, and risk rules, optional read-only access to the cloud accounts for the inventory comparison, and nothing more. It never changes scans, rules, tags, connectors, or settings. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools