All integrations
Tenable logo
// Data Integration · Vulnerability Management

Cracken + Tenable

The same CVE carries the same Tenable VPR for every customer that has it. Cracken attacks those findings inside your environment. It proves which ones your own network and controls leave reachable.

Get started
// 01

Connecting Tenable

Connect with

A Tenable client (access) key and secret key

Cadence

Syncs on a schedule — every 6 hours by default, and the agent can force a fresh sync mid-operation

Requires

The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces

// 02

What Cracken gets from Tenable

  • Vulnerability findings with severity (critical, high, medium, low, info) and state (new, active, re-opened, fixed)

  • cve list with cvss_base_score, cvss_vector, cvss_version and cvss_temporal_score

  • port, protocol and service on the affected asset

  • device — hostnames, ipv4s, tags — landed as a Device node linked to the Finding, and resource with its type and id/name

  • first_seen, last_seen, updated_at and state_updated_at

  • solution, patchable, category and vulnerability_url

  • vendor_severity, vendor_id and vendor_scan_id — Tenable's own rating and scan identifier kept beside the normalized severity

// 03

What Tenable does not do

Trigger Scan does not launch a Tenable scan — it posts an on-demand sync job to the hosted connection service to re-pull findings, and accepts nothing but optional tags. Nothing is written back to Tenable: no finding can be accepted, recast or closed from Cracken, because the client exposes read endpoints only. Self-hosted deployments cannot connect it without the hosted connection service enabled.

// 04

How Cracken uses Tenable

  1. 01

    Connect Tenable

  2. 02

    Sync the vulnerability findings

  3. 03

    Prove what is reachable

  4. 04

    Confirm it connected

// 05

Frequently asked questions

Does connecting Tenable change anything in my Tenable account?

No: Cracken only reads Tenable's findings and assets; the refresh it triggers re-pulls that, without starting scans, editing policies, closing findings, or writing back.

How often does Cracken refresh Tenable data?

Cracken re-pulls Tenable findings roughly every six hours, and an operation can also query Tenable directly mid-run for newer data.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real Tenable context.

See how Cracken works what Tenable already knows into attack paths it proves end to end.