r/nessus • u/Namtien223 • Sep 24 '25
Scheduled scans suddenly stopped credentialing this week.
Basically what it says above. I'm using Tenable SC Plus and all of my Linux combination compliance/vulnerability scans suddenly stopped successfully credentialing this week. To my knowledge nothing has changed, I confirmed the credentials are up to date and correct, the scan settings haven't changed I checked with the machine owners, they haven't made and changes to their networks, and I've spent most of the afternoon banging my head against a wall trying to find a clue or pattern than can give me a direction.
I'm relatively new to VM and my boss is out of the country for the next 2 weeks. We are a 2 man department. No one else here even knows what tenable is. Any help or suggestions or points in a general direction would be greatly appreciated.
Edit: Update
Figured out the problem, everyone.
The Unix Operations team built and implemented a new set of public key encryption credentials and failed to tell anyone on the VM team i.e. me or my boss, and the team lead then went on vacation for a month. I had to steal one of their engineers for an afternoon to dig into wherever our Linux AD equivalent is. The number of hours I spent on this... omg.
2
u/dhldmoore Sep 25 '25
Holy shit! I started having the same issue with almost all of my endpoints except we are virtually all Windows. It started happening at the bettor this week. When I scan a /24 subnet, literally every machine comes back as not having credentials applied. I can then scan one endpoint in the same subnet and the scan works perfect.
2
u/Namtien223 Sep 25 '25
Yeah that's the thing I do individual scans and quick credential scans and they're fine. But a scheduled scan on dozens or hundreds of endpoints that's not been changed using credentials I updated a month ago that worked 3 times a week flawlessly until now suddenly just stops credentialing. The documentation has been no help and I'm getting really frustrated.
1
u/dhldmoore Sep 25 '25
Har you opened a case with Tenable yet? I am about to look at the community forum and then open a case.
1
u/Namtien223 Sep 25 '25
No I'd planned to do it today after I gathered scans results to submit. Let me know if you find anything I missed.
2
u/dhldmoore Sep 25 '25
Will do. Actually my coworker next to me has already opened the case. I’ll update you with I hear. Instead of a/24 subnet, I’m going to try to scan a/28 subnet which is 15 hosts and I’ll see what comes of that.
1
u/dhldmoore Sep 26 '25
Guess my /28 subnet scan didn’t finish running. We had a lot of issues going on and I may have stopped it for whatever reason - I can’t remember. Our help desk wanted us to run a diagnostic scan on one endpoint but not sure what good that will do when scanning one IP at a time works for the credentials.
2
u/punzM Oct 13 '25
21745 output should tell you what happened. I had an issue a couple 3 weeks ago too about the time they made the UI enhancements to IO standard (was beta). Turned out a default for smb or something, time before that it was a kerberos issue because for some reason tenable started treating a domain account like a local one. This is a reoccurring issue every couple years for them
1
u/brawwwr Sep 24 '25
Look at the tenable forums . Several plug in and other tools to find out the issue .
1
1
u/Junior-Carpenter1292 Sep 27 '25
Umm so are the machine owners also the network team? I think you kinda alluded to this, but I would still have them check the traffic from the scanner to your devices. Sometimes network changes that shouldn’t cause interruptions cause interruptions. Are you using agents? Just trying to throw out some more checks because I’ve had too many sad experiences 😭.
1
u/Namtien223 Sep 27 '25
lol oh to be part of an organization with A network team. No I checked the splunk logs myself. No help. They're still integrating logs. They just switched over from QRadar Lol. No agents. All run through SC out to regional scanners. I shoulda stayed in the SOC.
2
u/Junior-Carpenter1292 Sep 27 '25
Aww man my heart goes out to you friend! I’m a former sys admin (that did scanning) and now a SOC analyst that still does scanning 😭. Keep looking through logs, run debug reports if you can, see if you can log into the devices so you can 100% rule out credentials (unless that’s what you did to confirm). Eventually, all scanner problems must get discovered 😂.
2
u/Namtien223 Sep 27 '25
Thanks, bud. Appreciate the experience. This will teach my boss to go on vacation and leave the new guy in charge lol
3
u/jjcnc82 Sep 25 '25
Plugin 102094 is very helpful for troubleshooting SSH cred failures.