Purpose
Purpose
- Retrieve vulnerability findings to enrich security investigations.
- Identify assets associated with an IP address, hostname, or vulnerability.
- Export asset and vulnerability records for data collection.
- Review scan results and generate reports.
- Retrieve attack paths where the required Exposure Management capabilities are available.
Supported Versions
Supported Versions
Authentication
Authentication
X-ApiKeys: accessKey=<ACCESS_KEY>; secretKey=<SECRET_KEY>;Enter the key values separately in AirMDR. Do not include accessKey=, secretKey=, or the complete header in the credential fields.This connection uses API keys; it does not require an OAuth client ID, client secret, or interactive login session for each request. Tenable API authorization.Role and Access Considerations- Use a dedicated integration account to separate AirMDR access from personal user activity.
- Enable API-key authentication for that account.
- Assign the role and resource permissions required by the selected skills.
- Ensure that the account can access the relevant assets and scans.
- Have an administrator generate credentials for an API-only account.
Pre-requisites
An active Tenable.io subscription with access to the APIs required by your selected skills.A dedicated Tenable integration account with API-key authentication enabled and appropriate permissions to access the required assets, vulnerabilities, scans, and reports.A Tenable administrator available to configure user access when necessary.
Setup Steps
To connect Tenable.io to AirMDR, first verify API access for the integration account, generate its credentials, and identify the Base URL. Then enter these values in AirMDR and validate a skill execution.Verify API Access
- Sign in to Tenable cloud.
- Open Settings → Access Control → Users.
- Select the dedicated integration user.
- In the authentication settings, enable API Key.
- Review the user’s role and resource permissions.
- Click Save.
Generate the Access Key and Secret Key
Option A: Generate Keys for Your Own Account
Use this procedure when the integration account has interactive login access.- Sign in to Tenable.io using the integration account.
- Click the blue user circle in the upper-right corner.
- Select My Profile. The My Account page opens.
- Select the API Keys tab.
- Click Generate.
- Review the replacement warning and click Generate to confirm.
-
Copy the Access Key and Secret Key to approved credential storage before leaving the page.
If Generate is unavailable, ask the administrator to verify API access for the account.
Option B: Have an Administrator Generate the Keys
Use this procedure for an API-only account or when an administrator manages the integration credentials.- Open Settings → Access Control → Users.
- Select the integration user.
- In API Keys, click Generate API Keys.
- Review the warning and select Replace & Generate.
- Copy both keys to approved credential storage before navigating away.
Identify the Base URL
/scans in the Base URL field. The official authorization example uses this cloud hostname.Tenable Credential Reference Table
Validate Connectivity
The following optional read-only API requests validate Tenable access separately from the AirMDR connector. Run them from an authorized environment with the same network reachability as the integration.GET /api/v2/events/datasearch/alert. Permission for a Dataexport endpoint does not automatically establish permission for this endpoint.Request Sample - To validate Tenable.io connectivity
Request Sample - To validate Tenable.io connectivity
Tenable.io Expected result
Tenable.io Expected result
- HTTP status
200. - A JSON response containing the accessible scan information.
Configure Tenable in AirMDR Integrations Dashboard
- Navigate to AirMDR, provide the credentials and click Login
- Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select ADMIN → Integrations.
- Use the search option, enter the keyword “Tenable”, select the Connections tab, and click + New Connection button.
-
Use the following values in the AirMDR integration configuration screen:
Expand Advanced Configuration if required. (Optional)
- In Remote Agent, select an AirMDR Remote Agent when your Tenable deployment requires a private network connection, an approved proxy, or a controlled outbound network route.
- Tenable.io: If API IP allowlisting is enabled, ensure that the selected execution environment’s outbound IP address is permitted.
Otherwise, leave this field unselected unless instructed by your AirMDR administrator.
- Tenable.io: If API IP allowlisting is enabled, ensure that the selected execution environment’s outbound IP address is permitted.
- In Expiry, select a date according to your organization’s credential-rotation policy. Coordinate this date with the planned replacement of the Tenable Access Key and Secret Key.
Manage API-key replacement in Tenable separately from the AirMDR Expiry setting. Generating a new pair replaces the previous pair. Update both values in AirMDR promptly and validate the connection. - In Remote Agent, select an AirMDR Remote Agent when your Tenable deployment requires a private network connection, an approved proxy, or a controlled outbound network route.
- Click Save.
Skills provided by this Integration
The Tenable integration provides skills for retrieving asset information, investigating vulnerabilities, analyzing attack paths, and generating reports. The following skills are grouped by their purpose.Asset Discovery & Inventory
Asset Discovery & Inventory
Vulnerability Investigation & Enrichment
Vulnerability Investigation & Enrichment
Attack Path Analysis
Attack Path Analysis
Scan Review & Reporting
Scan Review & Reporting
Filter Discovery & Query Preparation
Filter Discovery & Query Preparation
Additional Information
🛑 Security & Access Best Practices
🛑 Security & Access Best Practices
- Use a dedicated integration account and grant only the required permissions.
- Store the Access Key and Secret Key in approved credential storage.
- Validate HTTPS certificates and confirm endpoint ownership.
- Restrict API access to approved integration outbound IP addresses where applicable.
- Coordinate key rotation, update AirMDR, and validate the connection afterward.
- Revoke unused credentials when decommissioning the integration.
- Share a personal administrator account across integrations.
- Paste credentials into tickets, messages, documentation, or screenshots.
- Disable TLS verification to bypass connection errors.
- Add broad IP ranges without reviewing the access impact.
- Regenerate keys without checking other applications using the same account.
- Leave unused integration accounts active indefinitely.
👉 Support & Maintenance
👉 Support & Maintenance
- 📧 Contact AirMDR Support through your designated support channel.
- 📧 Contact Tenable Support for Tenable account, API, or platform issues.
- 🔁 Rotate credentials regularly. Recommended cadence: As per internal security policy
- 🔄 Reconnect in AirMDR immediately when API Keys are changed.
🛑 Data Flow & Security
🛑 Data Flow & Security
- Open Settings → Access Control.
- Select API Access Security.
- Review the configured allowed addresses.
- Ensure that the integration’s approved outbound addresses are included.
- Account for IPv4 and IPv6 where applicable.
🧰 Error Handling
🧰 Error Handling
Tenable documents
401, 429, and 500 responses for the scan-list endpoint. For throttling, the cloud API returns a Retry-Aftervalue indicating how long to wait. 🔄 Monitoring & Logs
🔄 Monitoring & Logs

