Optional Features

Privilege Escalation

You can configure privilege escalation to work with the Keeper Commander integration only within the SSH credential type. You can add privilege escalation while configuring an SSH credentialed scan with the Keeper Commander integration using the Elevate privileges with field option, which enables you to select the privilege account type used to gain elevated access to the target machine.

Note: The field is labeled "Elevate privileges with" in the Keeper Commander integration for both Tenable One Vulnerability Management and Tenable Nessus.

The following privilege account types are available for selection:

  • Nothing (default)

  • .k5login

  • Cisco 'enable'

  • Dzdo

  • Pbrun

  • Su

  • su+sudo

  • sudo

  • Checkpoint Gaia 'expert'

When an escalation method other than Nothing is selected and an Escalation Credential ID is supplied, the integration retrieves a second Keeper record and uses its password field as the escalation (sudo/su) password. If Escalation Credential ID is left blank, the integration reuses the primary record UID and the primary record's password serves as the escalation password.

For the sudo escalation type specifically, the standard sudo prompt expects the invoking user's own password rather than a separate root account password. In that case, leave Escalation Credential ID blank so the integration reuses the primary record's password — no additional Keeper Commander API call is made.

Each escalation type can be configured with the following additional fields.

Option Description Required
Escalation Query Mode How the integration identifies the escalation record. Select Record UID to retrieve a specific record by UID, or Search string to find the first record whose title matches a keyword. Default: Record UID. Configurable within: .k5login, Cisco 'enable', dzdo, pbrun, su, su+sudo, sudo. No
Escalation Credential ID The Keeper Commander record UID of the record that contains the escalation account credentials. The password field of that record is used as the sudo/su password. Only visible when Escalation Query Mode is Record UID. Configurable within: .k5login, Cisco 'enable', dzdo, pbrun, su, su+sudo, sudo. No
Escalation Search Text The keyword matched against Keeper Commander record titles to find the escalation record. The first matching record is used. Only visible when Escalation Query Mode is Search string. Configurable within: .k5login, Cisco 'enable', dzdo, pbrun, su, su+sudo, sudo. No
Escalation search scan target When enabled, appends the scan target's IP address or hostname to the Escalation Credential ID value at scan time and performs a keyword search instead of a UID lookup. Only visible when Escalation Query Mode is Record UID. Default: No. Configurable within: .k5login, Cisco 'enable', dzdo, pbrun, su, su+sudo, sudo. No
Location of [account type] (directory) The directory path for the escalation binary (for example /usr/bin for sudo). Configurable within: dzdo, pbrun, su, su+sudo, sudo. No