Scan Results Review

Plugin Families and Plugins

You can use the Keeper Commander integration to gather credentials for target authentication during credentialed scans through SSH, Windows (SMB), or Database credential types. The following Tenable plugins are relevant when reviewing scan results.

Misc. plugin family:

  • Plugin #204872: Integration Status: When using any Tenable PAM integration, the Integration Status plugin confirms whether credential retrieval was a success or failure.

Settings plugin family:

  • Plugin #14273: SSH settings: Reads the SSH PAM credential configuration and calls the Keeper Commander integration to retrieve credentials for SSH targets. This plugin is not indicative of authentication issues by itself; authentication failures are reported by the credential-status plugins below.

  • Plugin #10870: Login configurations: Reads the Windows (SMB) credential configuration and calls the Keeper Commander integration to retrieve credentials for Windows targets.

  • Plugin #33815: Database settings: Reads the database credential configuration and calls the Keeper Commander integration to retrieve credentials for database targets.

  • Plugin #19506: Nessus Scan Information: Reports scan metadata including whether credentialed checks succeeded. Check this plugin first when investigating authentication issues.

  • Plugin #91822: Database Authentication Failure(s) for Provided Credentials: Indicates that the database credentials retrieved from Keeper Commander could not authenticate to the target database. Check that the record UID or search term resolves to a record with a valid username and password for the target database.

  • Plugin #141118: Target Credential Status by Authentication Protocol — Valid Credentials Provided: Confirms credential validity by successfully authenticating to the remote target. Look for "Proto: SMB" or "Proto: SSH" in the output.

  • Plugin #110095: Target Credential Issues by Authentication Protocol — No Issues Found: Indicates that credentials were provided and authentication succeeded for all targeted protocols.

  • Plugin #104410: Target Credential Status by Authentication Protocol — Failure for Provided Credentials: Indicates that credentials were provided but authentication to the target failed — the values retrieved from Keeper Commander may be incorrect or may lack sufficient permission on the target.

  • Plugin #110723: Target Credential Status by Authentication Protocol — No Credentials Provided: Indicates that no credentials were available for the targeted protocol. If this appears when a Keeper Commander credential is configured, the integration likely failed to retrieve the record.

  • Plugin #117885: Target Credential Issues by Authentication Protocol — Intermittent Authentication Failure: Indicates that authentication succeeded for some targets but not others — may point to per-target credential differences or intermittent Keeper Commander service connectivity.