Hey everyone! 👋 I've been deep in the Tenable Cloud Security ecosystem for a while now, primarily using it to feed vulnerability data into our broader marketing and sales operations in HubSpot and Salesforce. One recurring task for our team was manually pulling weekly summary reports for our cloud assets. It was getting tedious, so I built a PowerShell script to automate it via the API, and I thought I’d share my workflow here in case it helps anyone else.
My goal was to get a clean, consistent snapshot every Monday morning that we could automatically drop into a shared channel for our security and marketing ops teams. Marketing ops? Yes! We use these reports to understand if any critical vulnerabilities are impacting our own demo environments, which could affect prospect experiences. The script pulls a high-level asset summary and a list of findings by severity.
Here’s the basic flow of what the script does:
* Authenticates with the Tenable Cloud Security API using a stored service account credential.
* Makes a call to the `/v2/assets` endpoint with some specific filters to scope it to our active cloud environments.
* Parses the JSON response to extract the counts we care about most: total assets, assets with open findings, and then breaks down findings by High, Medium, and Low severity.
* Formats everything into a plain-text report, but also outputs a simple JSON file for potential integration into other systems (like a data warehouse or a dashboard).
* It’s set up to run as a scheduled task on a lightweight VM.
The key was getting the filtering right. I’m not pulling every single detail—just the weekly summary. For example, I filter out any assets tagged as "decommissioned" and focus on our AWS and Azure production accounts. The script also includes some basic error handling to email our team if the API call fails.
I found the API documentation pretty straightforward, but the main hurdle was managing the authentication token lifecycle and structuring the queries to avoid timeouts. If you're thinking of doing something similar, my practical advice is to start with the API Explorer in the Tenable Cloud Security UI to get your filter parameters right before coding.
Would love to hear if others have built similar integrations, especially if you’ve tied Tenable data into Salesforce for account health scoring or into an internal wiki for visibility. I’m always looking for ways to make this data more actionable across the business!
~Sarah
Data is the new oil
Nice approach! I've been down a similar road with the Tenable API for compliance checks.
How are you handling the authentication creds in your script? I found storing service account keys in plaintext a bit risky, so I switched to using Azure Key Vault for retrieval at runtime. Just a thought if you're running this in a pipeline somewhere.
Also, if you're already filtering on active cloud environments at the API call stage, you might be able to save some parsing time. The `/v2/assets` endpoint can take a pretty granular `query` parameter. Something like `{"field":"cloud.managed","operator":"eq","value":true}` might get you closer to what you need right off the bat.
Would love to see the full script if you're open to sharing it!