Scan Results Review
This section helps you interpret the results of your scans.
Plugin Families and Plugins
The Delinea Secret Server integration can be used to gather credentials for target authentication during credentialed scans through SMB, SSH, Database, vCenter, or Nutanix. Depending on the credential you use, the following Tenable plugins are relevant when you review scan results for the Delinea Secret Server integration.
Misc. plugin family:
-
Plugin #204872: Integration Status: When you use any Tenable PAM integration, the Integration Status plugin confirms whether credential retrieval succeeded or failed.
Settings plugin family:
-
Plugin #14273: SSH Settings: Reads the SSH PAM credential configuration and calls the Delinea Secret Server integration to retrieve credentials for SSH targets. This plugin is not indicative of authentication issues by itself; the credential status plugins below report authentication failures.
-
Plugin #10870: Login configurations: Reads the Windows (SMB) credential configuration and calls the Delinea Secret Server integration to retrieve credentials for Windows targets.
-
Plugin #33815: Database settings: Reads the database credential configuration and calls the Delinea Secret Server integration to retrieve credentials for database targets.
-
Plugin #160185: Nutanix Data Collection: Reports the collection of all data from Nutanix Prism Central using REST APIs.
-
Plugin #19506: Nessus Scan Information: Reports metadata about the scan, including whether credentialed checks succeeded. Check this plugin result first when you investigate authentication issues.
-
Plugin #141118: Target Credential Status by Authentication Protocol — Valid Credentials Provided: Confirms credential validity by successfully authenticating to the remote target through the available protocol. This plugin confirms that credentials sourced from Delinea Secret Server are valid for the authentication process. Expect to see "Proto: SMB" or "Proto: SSH" in the output.
-
Plugin #110095: Target Credential Issues by Authentication Protocol — No Issues Found: Indicates that credentials were provided and authentication succeeded for all targeted protocols. A result from this plugin confirms that the Delinea Secret Server integration returned credentials and the scanner authenticated successfully. When escalation has failed, or when you elect not to use escalation, you may see Plugin #110385: Target Credential Issues by Authentication Protocol — Insufficient Privilege.
-
Plugin #104410: Target Credential Status by Authentication Protocol — Failure for Provided Credentials: Indicates that credentials were provided but authentication to the target failed. This may indicate that the credentials retrieved from Delinea Secret Server are incorrect or do not have sufficient permissions on the target host.
-
Plugin #110723: Target Credential Status by Authentication Protocol — No Credentials Provided: Indicates that no credentials were available for the targeted protocol. If this appears when the Delinea Secret Server credential is configured, the integration likely failed to retrieve the secret.
-
Plugin #117885: Target Credential Issues by Authentication Protocol — Intermittent Authentication Failure: Indicates that authentication succeeded for some targets but not others, which may point to per-target credential differences or intermittent Delinea Secret Server connectivity issues.
-
Plugin #91822: Database Authentication Failures for Provided Credentials: Indicates that the database credentials retrieved from Delinea Secret Server could not authenticate to the target database. Check the credential ID and confirm that the secret contains a valid username and password for the target database.
VMware ESX Local Security Checks plugin family:
-
Plugin #57400: VMware vSphere installed VIBs: Reports the installed VIBs collected on an ESXi host after authentication.