Tenable One Vulnerability Management
Continuous vulnerability management within an exposure management platform.
For: CISOs and heads of security, Security teams that need a unified view of risk and other profiles
Learn more about the productWeb applications fail in ways infrastructure scanning can't see. The server can be fully patched, the operating system free of pending CVEs, and the application can still accept input it shouldn't. Tenable Web App Scanning is a dynamic application security testing (DAST) tool: it assesses the running application through its interface, the way a user — or an attacker — would encounter it.
A large share of the flaws exploited in web applications come from the application's own logic and input handling, not from an outdated package. These are problem classes that only surface with the application running — and they grow in number at the same pace the team ships new releases.
Information as stated by the vendor. See sources at the end of the page.
Crawls the application through its interface to build a site map of pages, links, and forms, defining what will be tested.
Checks aimed at the OWASP Top 10 vulnerability classes, including XSS and SQL injection.
Assessment of APIs, beyond traditional browsing interfaces.
Detecting vulnerabilities in third-party components used by the application.
Identifying problems in SSL/TLS certificates and inadequate server configurations.
Analysis of single-page applications, whose content is assembled dynamically in the browser.
Setting permissions by user role within the tool.
Automated tests on a configurable schedule, with SaaS and on-premises deployment options.
Automated scanning on a defined schedule, tracking how applications evolve between releases.
Assessment of programmatic interfaces that usually fall outside the scope of browsing-centered tests.
Application and infrastructure findings brought together on the same platform, avoiding parallel reports.
Evidence that applications go through documented, periodic technical assessment.
Defining the application to be assessed, the allowed scope, and, when applicable, authentication credentials.
The tool crawls the running application and builds the map of pages, links, and forms that will serve as the basis for testing.
Sending crafted requests to detect known vulnerability classes and observing the application's behavior.
Consolidating findings with severity information to guide the remediation queue.
Routing to the responsible team and re-running the test to confirm the fix worked.
DAST (Dynamic Application Security Testing) is security testing performed with the application running, assessing it from the outside without access to the source code. It complements SAST, which analyzes code statically, and SCA, which examines third-party components.
No. Automated dynamic testing covers known vulnerability classes well, at scale and with frequency. Business logic flaws and specific exploit chains still depend on human analysis. The approaches complement each other rather than replacing one another.
Dynamic tests generate real traffic against the application and can create records or trigger actions. The usual practice is to start in staging, adjust scope and configuration, and only then carefully define what will be tested in production — always with formal authorization from whoever owns the application.
Licensing usually varies based on the number of applications assessed and the deployment model. Check current availability and purchasing terms.
Commercial terms, availability and licensing models are defined by the vendor and may change. Check the official purchase page or talk to a specialist to assess your organization’s scenario.