Configure Credentials Settings in a Tenable Web App Scanning Scan

Required User Role: Scan Manager or Administrator

You can configure credentials in your Tenable Web App Scanning scans to allow the scanner to access protected areas of your web application. By providing authentication details, you ensure a more comprehensive vulnerability analysis of pages behind login screens, improving the depth and accuracy of your scan results.

Before you begin:

  • (Cookie authentication) Determine the cookie authentication credentials for the web application you want to scan.
Note: The Tenable-provided Selenium extension is no longer supported. The Edge and Firefox extensions provided by Selenium directly are supported.

To configure credentials settings in a Tenable Web App Scanning scan:

  1. Create or edit a scan.
  2. Click the Credentials tab.

    The credentials details appear.

  3. Do one of the following:

  4. Add user permissions.
  5. Click Save to save the credentials changes.

    Tenable Web App Scanning closes the settings plane and adds the credentials to the credentials table for the scan.

    If you created new credentials, Tenable Web App Scanning adds the credentials to the credential manager.

  6. Click Save to save the scan changes.