Tenable IO Attribute Reference
Focus
Focus
Device Security

Tenable IO Attribute Reference

Table of Contents

Tenable IO Attribute Reference

This reference lists the attributes that Device Security collects from Tenable IO, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Tenable.io, it enhances vulnerability management for your devices. The attributes in this reference cover asset records from vulnerability exports, agent data, asset export details, scanner records, network interfaces, and individual vulnerability findings.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Vulns Export Assets Attributes

Device Security collects vulns export assets attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
asset.hostname
tenable_io.hostname
hostname
Name of the device
asset.mac_address
id; MAC
Mac address
asset.ipv4
tenable_io.ipv4
IP Address
Ipv4
asset.operating_system
tenable_io.operating_system
raw_os
Operating system
plugin.cpe
tenable_io.cpe
third_party_learned_installed_software
Cpe
asset.agent_uuid
tenable_io.agent_uuid
Agent uuid
asset.device_type
tenable_io.device_type
Device type
asset.ipv6
tenable_io.ipv6
Ipv6
asset.last_authenticated_results
tenable_io.last_authenticated_results
Last authenticated results
asset.last_scan_target
tenable_io.last_scan_target
Last scan target
scan_details.creation_date
tenable_io.scan.creation_date
Creation date
scan_details.name
tenable_io.scan.name
Name of the device
scan_details.owner
tenable_io.scan.owner
Owner
scan_details.schedule_uuid
tenable_io.scan.schedule_uuid
Schedule uuid
scan.started_at
tenable_io.scan.started_at
Started at
scan_details.status
tenable_io.scan.status
Status of the device
scan_details.template_uuid
tenable_io.scan.template_uuid
Template uuid
scan_details.total_targets
tenable_io.scan.total_targets
Total targets
scan_details.type
tenable_io.scan.type
Type
asset.tracked
tenable_io.tracked
Tracked

Agents Attributes

Device Security collects agents attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
ip
tenable_io.agent.ip
IP Address; id
Ip
last_connect
Last Activity
Last connect
distro
tenable_io.agent.distro
raw_os
Distro
asset_uuid
tenable_io.agent.asset_uuid
Asset uuid
core_build
tenable_io.agent.core_build
Core build
core_version
tenable_io.agent.core_version
Core version
health
tenable_io.agent.health
Health status of the device
health_state_name
tenable_io.agent.health_state_name
Health state name
id
tenable_io.agent.id
Id
linked_on
tenable_io.agent.linked_on
Linked on
name
tenable_io.agent.name
Name of the device
nessus_scanning_health
tenable_io.agent.nessus_scanning_health
Nessus scanning health
network_name
tenable_io.agent.network_name
Network name
platform
tenable_io.agent.platform
Platform
profile_name
tenable_io.agent.profile_name
Profile name
runtime_scanning_health
tenable_io.agent.runtime_scanning_health
Runtime scanning health
status
tenable_io.agent.status
Status of the device
supports_remote_settings
tenable_io.agent.supports_remote_settings
Supports remote settings
uuid
tenable_io.agent.uuid
Uuid
name
tenable_io.agent_name
Name of the device

Assets Export Attributes

Device Security collects assets export attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
first_seen
tenable_io.first_seen
First Seen
First seen
last_seen
tenable_io.last_seen
Last Activity
Last seen
mac_addresses
tenable_io.mac_addresses
MAC
Mac addresses
operating_systems
tenable_io.operating_systems
raw_os
Operating systems
installed_software
tenable_io.installed_software
third_party_learned_installed_software
Installed software
network_interfaces
tenable_io.network_interfaces
third_party_learned_network_interfaces
Network interfaces
agent_names
tenable_io.agent_names
Agent names
id
tenable_io.asset_id
Id
first_scan_time
tenable_io.first_scan_time
First scan time
fqdns
tenable_io.fqdns
Fqdns
has_agent
tenable_io.has_agent
Has agent
hostnames
tenable_io.hostnames
Hostnames
ipv4s
tenable_io.ipv4s
Ipv4s
ipv6s
tenable_io.ipv6s
Ipv6s
last_authenticated_scan_date
tenable_io.last_authenticated_scan_date
Last authenticated scan date
last_authentication_scan_status
tenable_io.last_authentication_scan_status
Last authentication scan status
last_licensed_scan_date
tenable_io.last_licensed_scan_date
Last licensed scan date
last_scan_id
tenable_io.last_scan_id
Last scan ID
last_scan_target
tenable_io.last_scan_target
Last scan target
last_scan_time
tenable_io.last_scan_time
Last scan time
last_schedule_id
tenable_io.last_schedule_id
Last schedule ID
netbios_names
tenable_io.netbios_names
Netbios names
network_id
tenable_io.network_id
Network ID
network_name
tenable_io.network_name
Network name
open_ports
tenable_io.open_ports
Open ports
sources
tenable_io.sources
Sources
tags
tenable_io.tags
Tags

Scanners Attributes

Device Security collects scanners attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
hostname
tenable_io.scanner.hostname
hostname
Name of the device
last_connect
tenable_io.scanner.last_connect
Last Activity
Last connect
distro
tenable_io.scanner.distro
raw_os
Distro
creation_date
tenable_io.scanner.creation_date
Creation date
engine_version
tenable_io.scanner.engine_version
Engine version
group
tenable_io.scanner.group
Group
id
tenable_io.scanner.id
Id
ip_addresses
tenable_io.scanner.ip_addresses
Ip addresses
last_modification_date
tenable_io.scanner.last_modification_date
Last modification date
linked
tenable_io.scanner.linked
Linked
loaded_plugin_set
tenable_io.scanner.loaded_plugin_set
Loaded plugin set
name
tenable_io.scanner.name
Name of the device
network_name
tenable_io.scanner.network_name
Network name
num_scans
tenable_io.scanner.num_scans
Num scans
owner_name
tenable_io.scanner.owner_name
Owner name
platform
tenable_io.scanner.platform
Platform
scan_count
tenable_io.scanner.scan_count
Number of scans
source
tenable_io.scanner.source
Source
status
tenable_io.scanner.status
Status of the device
supports_remote_logs
tenable_io.scanner.supports_remote_logs
Supports remote logs
supports_remote_settings
tenable_io.scanner.supports_remote_settings
Supports remote settings
supports_webapp
tenable_io.scanner.supports_webapp
Supports webapp
type
tenable_io.scanner.type
Type
user_permissions
tenable_io.scanner.user_permissions
User permissions
uuid
tenable_io.scanner.uuid
Uuid

Assets Export Interfaces Attributes

Device Security collects assets export interfaces attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
ipv4s
tenable_io.ipv4s
IP Address
Ipv4s
mac_addresses
tenable_io.mac_addresses
MAC; id
Mac addresses
network_interfaces
tenable_io.network_interfaces
third_party_learned_network_interfaces
Network interfaces

Vulns Export Vulns Attributes

Device Security collects vulns export vulns attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
cves
cve
Cves
plugin.cvss_base_score
tenable_io.cvss_base_score
cvss_base_score
Cvss base score
plugin.cvss3_base_score
tenable_io.cvss3_base_score
cvss_v3base_score
Cvss3 base score
plugin.description
tenable_io.plugin.description
Description
Description
first_found
tenable_io.first_found
detected_time; First Seen
First found
asset.mac_address
id
Mac address
asset.ipv4
tenable_io.ipv4
IP Address
Ipv4
last_found
tenable_io.last_found
last_seen
Last found
plugin.exploit_available
public_exploit
Exploit available
asset.operating_system
raw_os
Operating system
severity
tenable_io.severity
risk_level; severity
Severity
plugin.solution
tenable_io.plugin.solution
solution
Solution
plugin.name
tenable_io.plugin.name
title
Name of the device
plugin.id
vulnerability_id
Id
plugin.has_patch
tenable_io.plugin.has_patch
Has patch
plugin.has_workaround
tenable_io.plugin.has_workaround
Has workaround
plugin.modification_date
tenable_io.plugin.modification_date
Modification date
plugin.publication_date
tenable_io.plugin.publication_date
Publication date
plugin.version
tenable_io.plugin.version
Version
port
tenable_io.port
Port
port.protocol
tenable_io.protocol
Protocol
scan_details.creation_date
tenable_io.scan.creation_date
Creation date
scan_details.name
tenable_io.scan.name
Name of the device
scan_details.owner
tenable_io.scan.owner
Owner
scan_details.schedule_uuid
tenable_io.scan.schedule_uuid
Schedule uuid
scan.started_at
tenable_io.scan.started_at
Started at
scan_details.status
tenable_io.scan.status
Status of the device
scan_details.template_uuid
tenable_io.scan.template_uuid
Template uuid
scan_details.total_targets
tenable_io.scan.total_targets
Total targets
scan_details.type
tenable_io.scan.type
Type
* Only some attributes map to a Device Security Common Attribute.