Tenable Vulnerability Management (VM) Integration Guide
Tenable
Integration Guide
Synack’s Integration with Tenable
Vulnerability Management
Last updated: Nov 2025
Table of Contents
- Synack Integration with Tenable
- Configuring the Integration
- Step 1: Get Credentials from Tenable
- Step 2: Configure Tenable integration in Synack
- Engage Vulnerabilities imported from Tenable in Synack
- Frequently Asked Questions
Synack Integration with Tenable
Synack’s integration with Tenable allows customers to easily import vulnerabilities found by their Tenable Vulnerability Management (VM) scanning into their Synack Penetration Testing as a Service (PTaaS) Suspected Vulnerability, or Scanner Findings, list. Once in the Synack Suspected Vulnerability or Scanner Findings List, connections between the vulnerabilities and the vulnerable assets are made, enabling testing of those assets by the Synack Red Team (SRT) and/or Synack Autonomous Red Agent (Sara). Synack triages which vulnerabilities are truly exploitable, accesses exposure of vulnerable assets, and provides remediation recommendations and patch verification. Synack testing helps you close critical security gaps before bad actors can exploit them.
Configuring the Integration
To get started with the installation, follow the steps provided below.
Step 1: Get Credentials from Tenable
Ask your Tenable administrator to generate / provide you an Access Key and a Secret Key, which Synack’s integration can use to create a connection between Tenable and Synack. You will need the following information before proceeding to next step;
- Access Key
- Secret Key
Step 2: Configure Tenable integration in Synack
Login to the Synack Portal at http://login.synack.com.
Click on the Profile Icon at the Top Right corner of the Synack Portal, and then click Settings.
Next, click on the Integrations tab. Then click on the ‘Connect to Tenable’ Vulnerability Management button.
Note: your login must have a Synack Admin role in order to be able to configure Integrations.
Enter the Access Key and Secret Key information which was provided by your Tenable admin.
Optionally, you can specify Asset Tags used in your Tenable implementation, or vulnerability severity. These are used to limit the scope of the vulnerability import to a desired subset of Tenable vulnerabilities. If you omit these optional settings, vulnerabilities imported ignore Tag and Severity values.
- Enable asset creation (selected by default) - If a publicly accessible Host Asset is associated with a Tenable vulnerability scanning result, that Asset will be automatically added to the Synack Asset List (if it isn’t already present). Host Assets in the Asset List are available for Synack Sara Triage, or testing by the SRT.
You can then click ‘Save’ and your Tenable Integration configuration will be established.
Next, you must initiate the Import of vulnerabilities from Tenable to Synack. From the Synack Platform’s Tenable Integration screen where you just Saved your Tenable Account Details, you have 2 options to choose from:
- Option A) Click on the ‘One-Time Import’
- Option B) Check ‘Enable daily import’, then click ‘Save’
After several minutes, the table will start to populate with Import History (note: Daily Import, or large One-Time imports may take longer to populate)
| Created | Activity | Status | Vulnerabilities Imported |
|---|---|---|---|
| 01/20/2022 10:41 AM | Daily Import | In Progress | -- |
| 01/20/2022 10:41 AM | Daily Import | Complete | 10 |
| 01/19/2022 10:41 AM | Daily Import | Complete | 50 |
| 01/18/2022 10:41 AM | One-Time Import | Complete | 50 |
Engage Vulnerabilities imported from Tenable in Synack
From the Synack Portal, click the ‘Vulnerabilities’ tab. Then click ‘Scanner Findings’. You may Search the Scanner Findings List or apply filters such as Asset, Category. Every vulnerability will be associated with an asset that may or may not be already included in an assessment. Assets that aren’t in assessments can be added to new assessments. Once in an assessment, Synack can test the associated assets to confirm and assess their security exposure. Test offerings include human-led testing by the Synack Red Team, or AI-supported testing and triage by Synack Autonomous Red Agent (Sara). Please consult with your Synack team if you would like guidance on our test offerings.
| Title & Location | Status | Discovered | Last Seen | Source | Severity | Asset | CVE/CWE(s) |
|---|---|---|---|---|---|---|---|
| Apache OFBiz Forced Browsing Vulnerability | Agent Review | 06/25/2025 | 06/25/2025 | Tenable | Critical | 192.168.1.28 | CVE-2011-2483 +7 |
| Apache OFBiz Forced Browsing Vulnerability | Not Exploitable | 06/25/2025 | 06/25/2025 | Tenable | Critical | 192.168.1.28 | CVE-2013-3918 |
| Apache OFBiz Forced Browsing Vulnerability | Synack Review | 06/25/2025 | 06/25/2025 | Tenable | Critical | 192.168.1.28 | CVE-2012-2688 |
| Citrix NetScaler ADC and Gateway Buffer Overflow | Not Triaged | 06/25/2025 | 06/25/2025 | Tenable | High | 192.168.1.29 | CVE-2014-0160 |
| Citrix NetScaler ADC and Gateway Buffer Overflow | Not Triaged | 06/25/2025 | 06/25/2025 | Tenable | High | 192.168.1.42 | CVE-2015-1635 |
| PHP Remote Code Execution Vulnerability | Exploitable | 06/25/2025 | 06/25/2025 | Tenable | High | 192.168.1.67 | CVE-2016-0800 |
| PHP Remote Code Execution Vulnerability | Not Triaged | 06/25/2025 | 06/25/2025 | Tenable | High | 192.168.1.42 | CVE-2017-0144 |
Frequently Asked Questions
What Tenable products does Synack integrate with?
The Synack Integration works with Tenable Vulnerability Management (VM), formerly known as Tenable.io. Tenable Vulnerability Management may be running standalone, or as part of Tenable One subscription.
Note: a separate Synack guide IS available for our integration with Tenable Web Application Scanning (WAS)
Note: Synack’s integration does NOT currently work with other Tenable scanning solutions such as Tenable Security Center, or Tenable Nessus.
Why don't I see the Tenable choice in my Integrations page?
You must be a Synack Admin user to see the Integrations page.
I am a FedRAMP customer, can I use this integration?
Yes, assuming you are using the FedRAMP instance of Tenable Vulnerability Management / Tenable One. Note: In this case you will login to FedRAMP instance of the Synack Portal at https://login.synack.us.
I followed the instructions in this guide, but I am still not able to see any data. How long should this take?
If this is the initial configuration of the app, it can take some time for the initial data to be imported. Depending on the scope of vulnerabilities imported during ‘One-Time Import’, this can take anywhere from a minute to an hour. In the case of scheduled recurring imports, and depending on the time of day you ‘Enable Daily Import’, it may take up to 24 hours until the next daily import cycle kicks off.
My integration used to work but I am no longer able to import vulnerabilities.
If you see a Failed Import message, this could be because of the API token being expired or being inadvertently deleted. Please check the Tenable platform to verify the API token still exists and is active. (If the token has expired or was deleted, you will need to obtain a new token from Tenable, and then re-configure the Synack Integration for Tenable with a valid API Token and Keys.)
I see vulnerabilities in Tenable, but I do not see them (or I only see some of them) imported into the Synack Suspected Vulnerability List, why might that be?
The Synack Tenable Integration will only import vulnerabilities that are associated with assets that are present in the Asset List of the Synack Platform. Assets may be added to the Synack Platform via Synack Attack Surface Discovery, Palo Xpanse ASM Integration, Assessment creation, or manual Add. Note: you may also specify ‘Enable asset creation’ in the configuration of the Tenable integration, in which case publicly accessible assets which are associated with Tenable Vulnerability Management scanning results will be automatically added to the Synack Asset List, however this method will not add Internal Assets.
The number of Vulnerabilities reported in my Tenable VM platform differs from the number of Suspected Vulnerabilities reported in Synack, why?
The manner in which Tenable and Synack report vulnerabilities differ. Tenable reports the vulnerability count as the number of uniquely vulnerable assets impacts, each of which may be impacted by multiple CVEs. Synack on the other hand counts every vulnerability individually, even when associated with the same asset. Thus, even when comparing for the same number of Assets, the count of Vulnerabilities imported into Synack may exceed what is reported in Tenable.
I am still having trouble with my Synack Tenable integration, who do I contact?
Please reach out to help@synack.com.