Tenable IO Attribute Reference
This reference lists the attributes that Device Security collects from Tenable IO,
their names as stored in Device Security, and the Device Security fields they map to.
When
Device Security integrates with Tenable.io, it enhances
vulnerability management for your devices. The attributes in this reference cover asset
records from vulnerability exports, agent data, asset export details, scanner records,
network interfaces, and individual vulnerability findings.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
Vulns Export Assets Attributes
Device Security collects vulns export assets attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
asset.hostname | tenable_io.hostname | hostname | Name of the device |
asset.mac_address | — | id; MAC | Mac address |
asset.ipv4 | tenable_io.ipv4 | IP Address | Ipv4 |
asset.operating_system | tenable_io.operating_system | raw_os | Operating system |
plugin.cpe | tenable_io.cpe | third_party_learned_installed_software | Cpe |
asset.agent_uuid | tenable_io.agent_uuid | — | Agent uuid |
asset.device_type | tenable_io.device_type | — | Device type |
asset.ipv6 | tenable_io.ipv6 | — | Ipv6 |
asset.last_authenticated_results | tenable_io.last_authenticated_results | — | Last authenticated results |
asset.last_scan_target | tenable_io.last_scan_target | — | Last scan target |
scan_details.creation_date | tenable_io.scan.creation_date | — | Creation date |
scan_details.name | tenable_io.scan.name | — | Name of the device |
scan_details.owner | tenable_io.scan.owner | — | Owner |
scan_details.schedule_uuid | tenable_io.scan.schedule_uuid | — | Schedule uuid |
scan.started_at | tenable_io.scan.started_at | — | Started at |
scan_details.status | tenable_io.scan.status | — | Status of the device |
scan_details.template_uuid | tenable_io.scan.template_uuid | — | Template uuid |
scan_details.total_targets | tenable_io.scan.total_targets | — | Total targets |
scan_details.type | tenable_io.scan.type | — | Type |
asset.tracked | tenable_io.tracked | — | Tracked |
Agents Attributes
Device Security collects agents attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
ip | tenable_io.agent.ip | IP Address; id | Ip |
last_connect | — | Last Activity | Last connect |
distro | tenable_io.agent.distro | raw_os | Distro |
asset_uuid | tenable_io.agent.asset_uuid | — | Asset uuid |
core_build | tenable_io.agent.core_build | — | Core build |
core_version | tenable_io.agent.core_version | — | Core version |
health | tenable_io.agent.health | — | Health status of the device |
health_state_name | tenable_io.agent.health_state_name | — | Health state name |
linked_on | tenable_io.agent.linked_on | — | Linked on |
name | tenable_io.agent.name | — | Name of the device |
nessus_scanning_health | tenable_io.agent.nessus_scanning_health | — | Nessus scanning health |
network_name | tenable_io.agent.network_name | — | Network name |
platform | tenable_io.agent.platform | — | Platform |
profile_name | tenable_io.agent.profile_name | — | Profile name |
runtime_scanning_health | tenable_io.agent.runtime_scanning_health | — | Runtime scanning health |
status | tenable_io.agent.status | — | Status of the device |
supports_remote_settings | tenable_io.agent.supports_remote_settings | — | Supports remote settings |
uuid | tenable_io.agent.uuid | — | Uuid |
name | tenable_io.agent_name | — | Name of the device |
Assets Export Attributes
Device Security collects assets export attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
first_seen | tenable_io.first_seen | First Seen | First seen |
last_seen | tenable_io.last_seen | Last Activity | Last seen |
mac_addresses | tenable_io.mac_addresses | MAC | Mac addresses |
operating_systems | tenable_io.operating_systems | raw_os | Operating systems |
installed_software | tenable_io.installed_software | third_party_learned_installed_software | Installed software |
network_interfaces | tenable_io.network_interfaces | third_party_learned_network_interfaces | Network interfaces |
agent_names | tenable_io.agent_names | — | Agent names |
first_scan_time | tenable_io.first_scan_time | — | First scan time |
fqdns | tenable_io.fqdns | — | Fqdns |
has_agent | tenable_io.has_agent | — | Has agent |
hostnames | tenable_io.hostnames | — | Hostnames |
ipv4s | tenable_io.ipv4s | — | Ipv4s |
ipv6s | tenable_io.ipv6s | — | Ipv6s |
last_authenticated_scan_date | tenable_io.last_authenticated_scan_date | — | Last authenticated scan date |
last_authentication_scan_status | tenable_io.last_authentication_scan_status | — | Last authentication scan status |
last_licensed_scan_date | tenable_io.last_licensed_scan_date | — | Last licensed scan date |
last_scan_id | tenable_io.last_scan_id | — | Last scan ID |
last_scan_target | tenable_io.last_scan_target | — | Last scan target |
last_scan_time | tenable_io.last_scan_time | — | Last scan time |
last_schedule_id | tenable_io.last_schedule_id | — | Last schedule ID |
netbios_names | tenable_io.netbios_names | — | Netbios names |
network_id | tenable_io.network_id | — | Network ID |
network_name | tenable_io.network_name | — | Network name |
open_ports | tenable_io.open_ports | — | Open ports |
sources | tenable_io.sources | — | Sources |
Scanners Attributes
Device Security collects scanners attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
hostname | tenable_io.scanner.hostname | hostname | Name of the device |
last_connect | tenable_io.scanner.last_connect | Last Activity | Last connect |
distro | tenable_io.scanner.distro | raw_os | Distro |
creation_date | tenable_io.scanner.creation_date | — | Creation date |
engine_version | tenable_io.scanner.engine_version | — | Engine version |
group | tenable_io.scanner.group | — | Group |
id | tenable_io.scanner.id | — | Id |
ip_addresses | tenable_io.scanner.ip_addresses | — | Ip addresses |
last_modification_date | tenable_io.scanner.last_modification_date | — | Last modification date |
linked | tenable_io.scanner.linked | — | Linked |
loaded_plugin_set | tenable_io.scanner.loaded_plugin_set | — | Loaded plugin set |
name | tenable_io.scanner.name | — | Name of the device |
network_name | tenable_io.scanner.network_name | — | Network name |
num_scans | tenable_io.scanner.num_scans | — | Num scans |
owner_name | tenable_io.scanner.owner_name | — | Owner name |
platform | tenable_io.scanner.platform | — | Platform |
scan_count | tenable_io.scanner.scan_count | — | Number of scans |
source | tenable_io.scanner.source | — | Source |
status | tenable_io.scanner.status | — | Status of the device |
supports_remote_logs | tenable_io.scanner.supports_remote_logs | — | Supports remote logs |
supports_remote_settings | tenable_io.scanner.supports_remote_settings | — | Supports remote settings |
supports_webapp | tenable_io.scanner.supports_webapp | — | Supports webapp |
type | tenable_io.scanner.type | — | Type |
user_permissions | tenable_io.scanner.user_permissions | — | User permissions |
uuid | tenable_io.scanner.uuid | — | Uuid |
Assets Export Interfaces Attributes
Device Security collects assets export interfaces attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
ipv4s | tenable_io.ipv4s | IP Address | Ipv4s |
mac_addresses | tenable_io.mac_addresses | MAC; id | Mac addresses |
network_interfaces | tenable_io.network_interfaces | third_party_learned_network_interfaces | Network interfaces |
Vulns Export Vulns Attributes
Device Security collects vulns export vulns attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
plugin.cvss_base_score | tenable_io.cvss_base_score | cvss_base_score | Cvss base score |
plugin.cvss3_base_score | tenable_io.cvss3_base_score | cvss_v3base_score | Cvss3 base score |
plugin.description | tenable_io.plugin.description | Description | Description |
first_found | tenable_io.first_found | detected_time; First Seen | First found |
asset.mac_address | — | id | Mac address |
asset.ipv4 | tenable_io.ipv4 | IP Address | Ipv4 |
last_found | tenable_io.last_found | last_seen | Last found |
plugin.exploit_available | — | public_exploit | Exploit available |
asset.operating_system | — | raw_os | Operating system |
severity | tenable_io.severity | risk_level; severity | Severity |
plugin.solution | tenable_io.plugin.solution | solution | Solution |
plugin.name | tenable_io.plugin.name | title | Name of the device |
plugin.id | — | vulnerability_id | Id |
plugin.has_patch | tenable_io.plugin.has_patch | — | Has patch |
plugin.has_workaround | tenable_io.plugin.has_workaround | — | Has workaround |
plugin.modification_date | tenable_io.plugin.modification_date | — | Modification date |
plugin.publication_date | tenable_io.plugin.publication_date | — | Publication date |
plugin.version | tenable_io.plugin.version | — | Version |
port.protocol | tenable_io.protocol | — | Protocol |
scan_details.creation_date | tenable_io.scan.creation_date | — | Creation date |
scan_details.name | tenable_io.scan.name | — | Name of the device |
scan_details.owner | tenable_io.scan.owner | — | Owner |
scan_details.schedule_uuid | tenable_io.scan.schedule_uuid | — | Schedule uuid |
scan.started_at | tenable_io.scan.started_at | — | Started at |
scan_details.status | tenable_io.scan.status | — | Status of the device |
scan_details.template_uuid | tenable_io.scan.template_uuid | — | Template uuid |
scan_details.total_targets | tenable_io.scan.total_targets | — | Total targets |
scan_details.type | tenable_io.scan.type | — | Type |
* Only some attributes map to a Device Security Common Attribute.