Inconsistencies in Attack Path Results

There may be inconsistencies when comparing the Attack Path results in Attack Path, Tenable One Identity Exposure, and Tenable One OT Exposure with the same source and target inputs. The following are some of the probable causes for such behavior:

  • Lack of MITRE ATT&CK™ coverageTenable One Identity Exposure and Tenable One OT Exposure might support attack primitives, security relationships, or configurations that are not covered in MITRE ATT&CK™ Framework and as a result their results do not match with the attack path results in Attack Path.

  • Lack of Attack Path coverageAttack Path parsing capabilities may not be on par with Tenable One Identity Exposure and Tenable One OT Exposure in some cases. Tenable is aware of the lack of support in several scenarios of special Access Control Entry (ACE) or Access Control List (ACLs) and group policy object (GPO) settings where there may be false positive or false negative.

  • Attack Path is not exploitableAttack Path only shows attack paths that are “believed” to be feasible to exploit. Some security relationships that create a vulnerability in Tenable One Identity Exposure and Tenable One OT Exposure may not be considered exploitable in Attack Path. Such scenarios include vulnerabilities that can be mitigated by other controls such as network segmentation or endpoint hardening. It is important to note that such behavior is intended and therefore it is a feature and not a bug.

  • Unsynced data — Unsynced data can cause inconsistencies between the products. Tenable One Identity Exposure and Tenable One OT Exposure have their own data collection service and are considered to be real-time. However, Attack Path relies on a data lake and receives data from various Tenable products. A delay to sync the data between Tenable One Identity Exposure, Tenable One OT Exposure, and Attack Path is expected.