What Information Does the Delinea Secret Server Integration Collect?
The Delinea Secret Server Privileged Access Management (PAM) integration collects the following credentials during credentialed authentication to target systems:
-
Username: The target account's username, which is retrieved from theDelinea Secret Server.
-
Password: The primary account password, which is sourced from Delinea Secret Server.
-
Escalation Password: A distinct password utilized when privilege escalation is active; escalation usernames are not retrieved automatically as they require manual entry.
-
Domain: The domain to which the user account belongs is extracted from the API response from Delinea Secret Server.
Note: If privilege escalation is configured for an SSH credential, the integration retrieves a second secret (the Escalation Credential ID) and uses its password field as the sudo/escalation password.
API Requests Per Target
The integration makes an initial API request to the Delinea Secret Server for authentication, then one API request per subsequent scan credential to retrieve the secret value(s). An extra API call is executed to fetch the secret when privilege escalation is set up using an independent escalation credential. Retrieved credentials are cached for the duration of the scan to avoid repeated requests for the same secret.
Credentialed Scans
Credentialed scans allow the Tenable scanner to log in to the target system directly and perform a deeper assessment than is possible without credentials. This includes checking installed software versions, configuration settings, patch levels, and compliance status.
What the Delinea Secret Server Integration Does Not Collect
-
The integration does not collect software inventory, device inventory, or configuration details from target systems.
-
The Delinea Secret Server integration is not designed to collect vulnerability data; it only retrieves credentials of target systems for which vulnerabilities will be detected.
Note: For compliance audits, add audit files to your scan policy. The Delinea Secret Server integration provides credentials, while the audit files define the checks performed.
Delinea Secret Server Integration Limitations
-
The Delinea Host must be network-accessible from the Tenable Nessus scanner.
-
Although static and rotated secrets are fully supported by this integration, the Dynamic secret type is currently incompatible.