Tenable Nessus Features
Administration (2)
API / Integrations
Application Programming Interface Specification for how the application communicates with other software. APIs typically enable integration of data, logic, objects, etc. with other software applications.
Extensibility
Provides the ability to extend the platform to include additional features and functionalities
Analysis (5)
Reporting and Analytics
Tools to visualize and analyze data.
Issue Tracking
Track issues as vulnerabilities are discovered. Documents activity throughout the resolution process.
Static Code Analysis
Examines application source code for security flaws without executing it.
Vulnerability Scan
Scans applications and networks for known vulnerabilities, holes and exploits.
Code Analysis
Scans application source code for security flaws without executing it.
Testing (6)
Manual Testing
Allows users to perfrom hands-on live simulations and penetration tests.
Test Automation
Runs pre-scripted security tests without requiring manual work.
Compliance Testing
Allows users to test applications for specific compliance requirements.
Black-Box Scanning
Scans functional applications externally for vulnerabilities like SQL injection or XSS.
Detection Rate
The rate at which scans accurately detect all vulnerabilities associated with the target.
False Positives
The rate at which scans falsely indicate detection of a vulnerability when no vulnerabilitiy legitimately exists.
Performance (4)
-
Detection Rate
The rate at which scans accurately detect all vulnerabilities associated with the target.
-
False Positives
The rate at which scans falsely indicate detection of a vulnerability when no vulnerabilitiy legitimately exists.
-
Automated Scans
Runs pre-scripted vulnerability scans without requiring manual work.
Anomaly/Malware Detection
Automatically identify and flag unusual behaviors and malicious software
Network (6)
-
Compliance Testing
Allows users to scan applications and networks for specific compliance requirements.
-
Perimeter Scanning
Analyzes network devices, servers and operating systems for vulnerabilities.
-
Configuration Monitoring
Monitors configuration rule sets and policy enforcement measures and document changes to maintain compliance.
Vulnerability Scanning
Discover patch statuses and vulnerabilities
Source-Code Scanning
Scan the initial code written for application development
Web Scanning
Application (3)
-
Static Code Analysis
Scans application source code for security flaws without executing it.
-
Black Box Testing
Scans functional applications externally for vulnerabilities like SQL injection or XSS.
Risk Analysis
Analyze potential risks across the organization
API Management (4)
API Discovery
Detects new and undocumented assets as they enter a network and add them to asset inventory.
API Monitoring
Detects anomalies in functionality, user accessibility, traffic flows, and tampering.
Reporting
Provides results of the simulation and reveals potential security gaps or vulnerabilitites.
Change Management
Tools to track and implement required security policy changes.
Security Testing (3)
Compliance Monitoring
Monitors data quality and send alerts based on violations or misuse.
API Verification
Allows users to set customizable API verification settings to improve security requirements.
API Testing
Runs pre-scripted security tests without requiring manual work.
Security Management (3)
Security and Policy Enforcement
Abilities to set standards for network, application, and API security risk management.
Anomoly Detection
Constantly monitors activity related to user behavior and compares activity to benchmarked patterns.
Bot Detection
Monitors for and rids systems of bots suspected of committing fraud or abusing applications.
Monitoring (6)
Gap Analysis
Analyzes data associated with denied entries and policy enforcement, giving information of better authentication and security protocols.
Vulnerability Intelligence
Stores information related to common vulnerabilities and how to resolve them once incidents occur.
Compliance Monitoring
Monitors data quality and sends alerts based on violations or misuse.
Continuous Monitoring
Aggregates real-time updates and historical data from multiplate internal and external data sources to support ongoing proactive threat response.
Server Monitoring
Continuously scan servers on a designated network to monitor health and search for any irregularities or failures
Real-Time Monitoring
Active monitoring of systems, applications, or networks
Asset Management (4)
Asset Discovery
Detects new assets as they enter cloud environments and networks to add to asset inventory.
Shadow IT Detection
Identifies unsanctioned software.
Change Management
Provides tools to track and implement required security policy changes.
Compliance Management
Track and manage adherence to policies for any service, product, process, or supplier
Risk Management (4)
Risk-Prioritization
Allows for vulnerability ranking by customized risk and threat priorities.
Reconnaissance
Gathers information about the system and potential exploits to be tested.
At-Risk Analysis
Uses machine learning to identify at-risk data.
Threat Intelligence
Stores information related to common threats and how to resolve them once incidents occur.
Generative AI (1)
AI Text Summarization
Condenses long documents or text into a brief summary.
Agentic AI - Vulnerability Scanner (2)
Autonomous Task Execution
Capability to perform complex tasks without constant human input
Proactive Assistance
Anticipates needs and offers suggestions without prompting
Additional Functionality (68)
SSL Security
Security protocol that ensures secure, encrypted communication over the internet, safeguarding sensitive data from unauthorized access
HIPAA Compliant
Compliant with HIPAA, which sets standards for sensitive patient data protection
API
Application programming interface that allows for integration with other systems/databases
Threat Response
Identifying, analyzing, and mitigating security issues and taking appropriate action to protect systems and data from potential harm
Endpoint Protection
Protect users working remotely and provide secure environments for personal devices to access company programs
Maintenance Scheduling
Schedule predetermined or ad hoc maintenance services and labor requests
Third-Party Integrations
Set up connections to third-party platforms to improve business processes
Security Auditing
Systematic evaluation of the security of a company's overall security system and situation
Application Security
Identify and respond to security threats to developed applications
Encryption
Convert data into a code for security
Network Security
Prevent and monitor unauthorized access, misuse, modification, or denial of a computer network and network-accessible resources
Real-Time Reporting
Active reporting of data and metrics
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Authentication
Verify the identity of users/devices to enable secure access
Financial Data Protection
Anti Virus
Prevents, detects and removes malware
Secure Data Storage
Securely stores data to prevent data loss or breaches
Virus Definition Update
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
VPN
Extend virtual private network over public networks to enable protected information exchange
Audit Trail
A record of all activities within the system, including user access, changes made, etc.
Anti Spam
Techniques to prevent and filter unwanted or unsolicited email spam from reaching a user's inbox
Access Controls/Permissions
Define levels of authorization for access to specific files or systems
Data Visualization
Graphical representation of data
Alerts/Escalation
System alerts about the need to escalate an issue or request
Data Security
Protect sensitive data for digital privacy
Runtime Container Security
Continuously vetting activities within the container application environment including hosts, open ports, protocols and payloads.
Asset Discovery
Threat Intelligence
Information to prevent, understand and identify cyber threats
Vulnerability Protection
Safeguards to protect network vulnerabilities
Alerts/Notifications
Alerts or notifications of various types such as pop-up messages, sounds, banners, or badges
Vulnerability/Threat Prioritization
Classify levels of threat and organize actions based on priorities
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
SQL Injections
Protect against code driven website security attack techniques
Real-Time Analytics
Analyze and gain insights into data in real-time
Threat Protection
Protect incoming and outgoing communications against malware, spam, display spoofing, and other threats
Web-Application Security
Identify and respond to security threats to web applications
Password Protection
Protect passwords from security threats
Website Crawling
Crawling and indexing web pages
Vulnerability Assessment
The process of identifying, quantifying, and prioritizing the vulnerabilities in a system.
SSL Security
Security protocol that ensures secure, encrypted communication over the internet, safeguarding sensitive data from unauthorized access
HIPAA Compliant
Compliant with HIPAA, which sets standards for sensitive patient data protection
API
Application programming interface that allows for integration with other systems/databases
Threat Response
Identifying, analyzing, and mitigating security issues and taking appropriate action to protect systems and data from potential harm
Endpoint Protection
Protect users working remotely and provide secure environments for personal devices to access company programs
Maintenance Scheduling
Schedule predetermined or ad hoc maintenance services and labor requests
Third-Party Integrations
Set up connections to third-party platforms to improve business processes
Security Auditing
Systematic evaluation of the security of a company's overall security system and situation
Application Security
Identify and respond to security threats to developed applications
Encryption
Convert data into a code for security
Network Security
Prevent and monitor unauthorized access, misuse, modification, or denial of a computer network and network-accessible resources
Real-Time Reporting
Active reporting of data and metrics
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Authentication
Verify the identity of users/devices to enable secure access
Financial Data Protection
Anti Virus
Prevents, detects and removes malware
Secure Data Storage
Securely stores data to prevent data loss or breaches
Virus Definition Update
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
VPN
Extend virtual private network over public networks to enable protected information exchange
Audit Trail
A record of all activities within the system, including user access, changes made, etc.
Anti Spam
Techniques to prevent and filter unwanted or unsolicited email spam from reaching a user's inbox
Access Controls/Permissions
Define levels of authorization for access to specific files or systems
Data Visualization
Graphical representation of data
Alerts/Escalation
System alerts about the need to escalate an issue or request
Data Security
Protect sensitive data for digital privacy
Top-Rated Alternatives



