Privilege Escalation with ARCON Credentials
Tenable.io supports the use of privilege escalation, such as su and sudo, when using SSH through the ARCON authentication method. Arcon credential privilege escalation is available for Tenable Vulnerability Management, Tenable Nessus, and Tenable Security Center.
To configure SSH integration:
- Log in to Tenable Vulnerability Management, Tenable Nessus, or Tenable Security Center.
- Click Scans
Click + New Scan.
Select a Scan Template.
The scan configuration page appears.
In the Name box, type a name for the scan.
- In the Targets box, type an IP address, hostname, or range of IP addresses.
- (Optional) Add a description, folder location, scanner location, and specify target groups.
Click the Credentials tab.
The Credentials options appear.
- In the Select a Credential menu, select the Host drop-down.
Select SSH as the Type and ARCON as the Authentication Method.
Select an option for the Elevate Privileges With field.
Note: Multiple options for privilege escalation are supported, including su, su+sudo and sudo. For example, if sudo is selected, additional fields for Escalation Account Name, Escalation Username, and Location of Sudo (Directory) are provided and can be completed to support authentication and privilege escalation through Arcon.
Note: Additional information about all of the supported privilege escalation types and their accompanying fields can be found in the Tenable.sc, Nessus, and Tenable.io user guides.