Configure the Keeper Commander Integration for Tenable One Vulnerability Management

The Tenable integration with Keeper Commander exists as an authentication method within the SSH, Windows, and Database credential types in Tenable One Vulnerability Management scan policies.

Required Permissions

  • A Tenable One Vulnerability Management user account with a minimum role of Standard.

  • A Keeper Commander service instance reachable from the Tenable Nessus scanner, with the v2 async API enabled.

  • An API key configured in the Keeper Commander service. The API key must have read access to every Keeper record referenced by the scan policy.

  • The Keeper Commander record must be of type pamUser (for password authentication) or sshKeys (for SSH key authentication), and must contain a valid login field.

Scan Configuration — SSH, Windows, and Database

Complete the following steps to configure Tenable One Vulnerability Management with the Keeper Commander integration using SSH, Windows, or Database credentials.

  1. Log in to your Tenable One Vulnerability Management user interface.

  2. In the left navigation pane, click Scans.

    The Scans page appears.

  3. In the upper-right corner of the page, click Create a Scan.

    The Select a Scan Template page appears.

  4. Select a scan template.

    The scan configuration page appears.

  5. In the Name box, type a name for the scan.

  6. In the Targets box, type an IP address, hostname, or range of IP addresses.

  7. (Optional) Add a description, folder location, and scanner location, and specify target groups.

  8. Click the Credentials tab.

    The Credentials pane appears.

  9. In the Select a Credential menu, select SSH, Windows, or Database.

    The Settings pane for the selected credential appears.

  10. In the Auth Type drop-down, click Keeper Commander. The Keeper Commander options appear.

  11. Configure each option for the selected SSH, Windows, or Database credential using the following values.

    Option Description Required
    Host The IP address or hostname of the Keeper Commander service. Yes
    Port The port the Keeper Commander service listens on. For example: 8080. Yes
    Engine URL Optional base path prefix for the Keeper Commander API (for example, /commander). Leave this blank to use the root path. The integration appends the v2 async API paths (/api/v2/executecommand-async, /api/v2/status/<id>, /api/v2/result/<id>) to this prefix. No
    API Key The API key configured in the Keeper Commander service. Sent in the api-key request header for all Keeper Commander API calls. Yes
    Query Mode How the integration identifies the Keeper Commander record. Select Record UID to retrieve a specific record by its unique identifier, or Search string to find the first record whose title matches a keyword. Default: Record UID. Yes
    Credential ID The Keeper Commander record UID to retrieve. Only visible when Query Mode is set to Record UID. Yes (if Query Mode is Record UID)
    Search Text The keyword matched against Keeper Commander record titles. The first matching record is used. Only visible when Query Mode is set to Search string. Yes (if Query Mode is Search string)
    Domain (SSH and Windows only) Auto-populated from the Keeper record. If the record contains a custom field with the label domain (case-insensitive), its value is used as the Windows or SSH domain for authentication. No user interface entry is required — the value is read directly from the Keeper record at scan time. No
    Search scan target When enabled, the integration appends the scan target's IP address or hostname to the Credential ID value at scan time and performs a keyword search instead of a UID lookup. Use this when record titles include the target address (for example, a Credential ID of root SSH password resolves to root SSH password 192.168.1.100 for target 192.168.1.100). Only visible when Query Mode is set to Record UID. Default: No. No
    Use SSL When enabled, the integration connects to the Keeper Commander service over HTTPS. Default: Yes. Yes
    Verify SSL Certificate When enabled, Tenable verifies the TLS certificate of the Keeper Commander service. Disable only if the Keeper Commander instance uses a self-signed certificate not in the scanner's trust store. Default: Yes. No
    Elevate privileges with (SSH only) The privilege escalation method used after initial authentication. Options: Nothing (default), .k5login, Cisco 'enable', dzdo, pbrun, su, su+sudo, sudo. Selecting a method reveals the escalation fields described in the Optional Features section. No
    Escalation Query Mode (SSH only) How the integration identifies the escalation record. Select Record UID to retrieve a specific record by UID, or Search string to find the first record whose title matches a keyword. Default: Record UID. No
    Escalation Credential ID (SSH only) The Keeper Commander record UID of the record whose password field is used as the privilege escalation password. Only visible when Escalation Query Mode is set to Record UID. If left blank while an escalation method is selected, the primary record UID is reused and its password serves as the escalation password. No
    Escalation Search Text (SSH only) The keyword matched against Keeper Commander record titles to find the escalation record. The first matching record is used. Only visible when Escalation Query Mode is set to Search string. No
    Escalation search scan target (SSH only) When enabled, the integration appends the scan target's IP address or hostname to the Escalation Credential ID value at scan time and performs a keyword search instead of a UID lookup. Only visible when Escalation Query Mode is set to Record UID. Default: No. No
    Kerberos Target Authentication (SSH) / Use Kerberos KDC (Windows) When enabled, Kerberos authentication is used to log in to SSH or Windows targets. Selecting Yes reveals the Key Distribution Center (KDC), KDC Port (default 88), KDC Transport (tcp / udp), and Kerberos Domain fields. No
  12. Do one of the following:

    • To save without launching the scan, click Save.

    • To save and launch the scan immediately, click Save & Launch.

    Note: If you scheduled the scan to run at a later time, the Save & Launch option is not available.