Keeper Commander Integration Limitations

  • The integration requires the Keeper Commander Service Mode REST API with API key authentication.

  • The integration requires the v2 version of the API, which is present in Keeper Commander versions 17.1.7 and later.

  • The Keeper Commander service endpoint specified in Engine URL must be reachable from every Tenable Nessus scanner used in the scan.

  • When Query Mode is Search string, the integration uses the first matching record returned by the Keeper Commander search command. If multiple records match the search term, only the first result is used. Use Record UID mode to retrieve a specific record unambiguously.

  • SSH Private Key (sshKeys record type) is supported only within the SSH credential type. Windows and Database credentials always use password authentication.

  • There is no Auto-Discovery / dynamic-scanning variant for this integration. Targets must be enumerated explicitly in the scan.

  • By default, each scan credential resolves a single fixed record UID or search term for all targets covered by that credential. Enable Search scan target (or Escalation search scan target) to append the scan target's IP address or hostname to the lookup at scan time, causing the integration to retrieve a target-specific record for each host.