Welcome to Tenable for AWS Secrets Manager
This document provides information and steps for integrating Tenable One Vulnerability Management or Tenable Nessus with AWS Secrets Manager.
AWS Secrets Manager is an AWS service that allows you to store, rotate, and retrieve secrets such as database credentials, application credentials, OAuth tokens, API keys, usernames, and passwords. The Tenable integration with the AWS Secrets Manager API allows you to retrieve target login credentials directly from AWS at scan time, and eliminates the need to store scan credentials in Tenable. The integration acts as a PAM (Privileged Access Management) integration: Tenable One Vulnerability Management (or Tenable Security Center) passes the credential configuration to Tenable Nessus. The scanner then calls the AWS Secrets Manager API to fetch the secret value and uses the returned credentials (username, password, and/or SSH key) to authenticate to the scan target.
Tenable provides this integration as an authentication method for the following credential types:
-
Host > Windows (SMB / WMI)
-
Host > SSH
-
Database (PostgreSQL, MongoDB, Cassandra, DB2, MySQL, SQL Server, Oracle)
-
Miscellaneous > VMware ESX SOAP API
-
Miscellaneous > VMware vCenter API
-
Miscellaneous > Nutanix Prism Central
For more information about the related Tenable products, refer to the following user guides: