Creates Important Tags in Tenable.io using Navi
443
This project is a Proof of Concept to show how you can use the Tenable API and a SQLite DB to solve some powerful use cases.
Wrapping a simple python script into a docker container makes it easy to deploy and reduces deployment risks.
It also means you don't need to be a developer or a scripter to take advantage of its power.
Plugins, cross references and the output of a plugin are gold to remediators. However, they are not asset attributes and therefore are not utilized in the tagging mechanisms of Tenable.io. Utilizing navi automates the export of the data, searching and parsing for important correlations and decorating the data in Tenable.io using Tags.
We are weaponizing navi for good! This python script utilizes navi to tag assets based on "Plugin IDs", "Xref" or cross references and text found in the output of a plugin. Navi utilizes a SQLite database to store vulnerability and asset data coming from the export APIs in Tenable.io.
The script uses the built in tag functionality to tag each asset. Navi uses a SQLite database and a the Tenable.io tag assignments endpoint to accomplish everything below. To make these dynamic, put the container command or the script on a cronjob or scheduled task.
The script/service tags assets with the below characteristics: Note: The Category : Value pair follow the Tag description. This is what will be seen in Tenable.io should the tag exist. The Tag is not created if no assets match the navi search.
docker run -d packetchaos/critical_tags {your Access Key} {your secret Key}
navi deploy critical-tags
Got ideas for a great tag? Send a PR or submit a Ticket and I will add it to my backlog.
Content type
Image
Digest
sha256:2c4f6a7ad…
Size
188 MB
Last updated
about 3 years ago
docker pull packetchaos/critical_tags