This integration targets Tenable Vulnerability Management cloud APIs at
cloud.tenable.com. Self-hosted Nessus scanner APIs are not supported yet.Requirements
Create a Tenable API key pair with read access to scan and scanner data. The API key must be able to:- List scans
- Read scan history
- Read scan details
- List scanners
Setup
- Log in to Tenable Vulnerability Management.
- In the upper-right corner, click your user profile icon.
- Open My Account.
- In the left navigation, click API Keys.
- Click Generate.
- Review Tenable’s warning, then continue generating the key pair.
- Copy the values shown under Access Key and Secret Key. Tenable only shows the secret when the key is generated, so store it somewhere secure before closing the page.
- In Wirespeed, go to Settings → Integrations.
- Select Tenable Nessus.
- Enter the Tenable Access Key and Secret Key.
- Save the integration.
How Matching Works
Wirespeed checks recent Tenable scan activity around the detection timestamp. A detection is marked as correlated when Wirespeed finds an overlapping scan run and either:- The detection source IP matches a Tenable scanner IP and that scanner is the one that ran the overlapping scan (confirmed via the scan’s reported scanner name). If the scan does not report which scanner ran it, Wirespeed falls back to target matching instead.
- The affected endpoint IP or hostname appears in the overlapping scan’s host or target data.

