Tenable Vulnerability Management (VM) Integration Guide

Tenable

Integration Guide

Synack’s Integration with Tenable

Vulnerability Management

Last updated: Nov 2025

Table of Contents

Synack Integration with Tenable

Synack’s integration with Tenable allows customers to easily import vulnerabilities found by their Tenable Vulnerability Management (VM) scanning into their Synack Penetration Testing as a Service (PTaaS) Suspected Vulnerability, or Scanner Findings, list. Once in the Synack Suspected Vulnerability or Scanner Findings List, connections between the vulnerabilities and the vulnerable assets are made, enabling testing of those assets by the Synack Red Team (SRT) and/or Synack Autonomous Red Agent (Sara). Synack triages which vulnerabilities are truly exploitable, accesses exposure of vulnerable assets, and provides remediation recommendations and patch verification. Synack testing helps you close critical security gaps before bad actors can exploit them.

Configuring the Integration

To get started with the installation, follow the steps provided below.

Step 1: Get Credentials from Tenable

Ask your Tenable administrator to generate / provide you an Access Key and a Secret Key, which Synack’s integration can use to create a connection between Tenable and Synack. You will need the following information before proceeding to next step;

Step 2: Configure Tenable integration in Synack

Login to the Synack Portal at http://login.synack.com.

Click on the Profile Icon at the Top Right corner of the Synack Portal, and then click Settings.

Next, click on the Integrations tab. Then click on the ‘Connect to Tenable’ Vulnerability Management button.

Note: your login must have a Synack Admin role in order to be able to configure Integrations.

Enter the Access Key and Secret Key information which was provided by your Tenable admin.

Optionally, you can specify Asset Tags used in your Tenable implementation, or vulnerability severity. These are used to limit the scope of the vulnerability import to a desired subset of Tenable vulnerabilities. If you omit these optional settings, vulnerabilities imported ignore Tag and Severity values.

You can then click ‘Save’ and your Tenable Integration configuration will be established.

Next, you must initiate the Import of vulnerabilities from Tenable to Synack. From the Synack Platform’s Tenable Integration screen where you just Saved your Tenable Account Details, you have 2 options to choose from:

After several minutes, the table will start to populate with Import History (note: Daily Import, or large One-Time imports may take longer to populate)

Created Activity Status Vulnerabilities Imported
01/20/2022 10:41 AM Daily Import In Progress --
01/20/2022 10:41 AM Daily Import Complete 10
01/19/2022 10:41 AM Daily Import Complete 50
01/18/2022 10:41 AM One-Time Import Complete 50

Engage Vulnerabilities imported from Tenable in Synack

From the Synack Portal, click the ‘Vulnerabilities’ tab. Then click ‘Scanner Findings’. You may Search the Scanner Findings List or apply filters such as Asset, Category. Every vulnerability will be associated with an asset that may or may not be already included in an assessment. Assets that aren’t in assessments can be added to new assessments. Once in an assessment, Synack can test the associated assets to confirm and assess their security exposure. Test offerings include human-led testing by the Synack Red Team, or AI-supported testing and triage by Synack Autonomous Red Agent (Sara). Please consult with your Synack team if you would like guidance on our test offerings.

Title & Location Status Discovered Last Seen Source Severity Asset CVE/CWE(s)
Apache OFBiz Forced Browsing Vulnerability Agent Review 06/25/2025 06/25/2025 Tenable Critical 192.168.1.28 CVE-2011-2483 +7
Apache OFBiz Forced Browsing Vulnerability Not Exploitable 06/25/2025 06/25/2025 Tenable Critical 192.168.1.28 CVE-2013-3918
Apache OFBiz Forced Browsing Vulnerability Synack Review 06/25/2025 06/25/2025 Tenable Critical 192.168.1.28 CVE-2012-2688
Citrix NetScaler ADC and Gateway Buffer Overflow Not Triaged 06/25/2025 06/25/2025 Tenable High 192.168.1.29 CVE-2014-0160
Citrix NetScaler ADC and Gateway Buffer Overflow Not Triaged 06/25/2025 06/25/2025 Tenable High 192.168.1.42 CVE-2015-1635
PHP Remote Code Execution Vulnerability Exploitable 06/25/2025 06/25/2025 Tenable High 192.168.1.67 CVE-2016-0800
PHP Remote Code Execution Vulnerability Not Triaged 06/25/2025 06/25/2025 Tenable High 192.168.1.42 CVE-2017-0144

Frequently Asked Questions

What Tenable products does Synack integrate with?

The Synack Integration works with Tenable Vulnerability Management (VM), formerly known as Tenable.io. Tenable Vulnerability Management may be running standalone, or as part of Tenable One subscription.

Note: a separate Synack guide IS available for our integration with Tenable Web Application Scanning (WAS)

Note: Synack’s integration does NOT currently work with other Tenable scanning solutions such as Tenable Security Center, or Tenable Nessus.

Why don't I see the Tenable choice in my Integrations page?

You must be a Synack Admin user to see the Integrations page.

I am a FedRAMP customer, can I use this integration?

Yes, assuming you are using the FedRAMP instance of Tenable Vulnerability Management / Tenable One. Note: In this case you will login to FedRAMP instance of the Synack Portal at https://login.synack.us.

I followed the instructions in this guide, but I am still not able to see any data. How long should this take?

If this is the initial configuration of the app, it can take some time for the initial data to be imported. Depending on the scope of vulnerabilities imported during ‘One-Time Import’, this can take anywhere from a minute to an hour. In the case of scheduled recurring imports, and depending on the time of day you ‘Enable Daily Import’, it may take up to 24 hours until the next daily import cycle kicks off.

My integration used to work but I am no longer able to import vulnerabilities.

If you see a Failed Import message, this could be because of the API token being expired or being inadvertently deleted. Please check the Tenable platform to verify the API token still exists and is active. (If the token has expired or was deleted, you will need to obtain a new token from Tenable, and then re-configure the Synack Integration for Tenable with a valid API Token and Keys.)

I see vulnerabilities in Tenable, but I do not see them (or I only see some of them) imported into the Synack Suspected Vulnerability List, why might that be?

The Synack Tenable Integration will only import vulnerabilities that are associated with assets that are present in the Asset List of the Synack Platform. Assets may be added to the Synack Platform via Synack Attack Surface Discovery, Palo Xpanse ASM Integration, Assessment creation, or manual Add. Note: you may also specify ‘Enable asset creation’ in the configuration of the Tenable integration, in which case publicly accessible assets which are associated with Tenable Vulnerability Management scanning results will be automatically added to the Synack Asset List, however this method will not add Internal Assets.

The number of Vulnerabilities reported in my Tenable VM platform differs from the number of Suspected Vulnerabilities reported in Synack, why?

The manner in which Tenable and Synack report vulnerabilities differ. Tenable reports the vulnerability count as the number of uniquely vulnerable assets impacts, each of which may be impacted by multiple CVEs. Synack on the other hand counts every vulnerability individually, even when associated with the same asset. Thus, even when comparing for the same number of Assets, the count of Vulnerabilities imported into Synack may exceed what is reported in Tenable.

I am still having trouble with my Synack Tenable integration, who do I contact?

Please reach out to help@synack.com.