Otto  background

How Automox Matches Tenable Findings to Patches

Behind the Build: connecting vulnerability records, endpoint inventory, and installable packages

Connect With Us

See for yourself how policy-driven IT Automation saves time and eliminates risk.

A vulnerability finding is useless to Automox until it maps to an endpoint and an installable patch. Without that mapping, you're stuck cross-referencing scanner results against your patch inventory by hand.

The Automox Tenable integration, now in limited beta, brings Tenable Vulnerability Management findings into Automox. Scott Pinkelman worked on matching those findings to packages Automox can install.

From CVE to installable package

A Common Vulnerabilities and Exposures (CVE) identifier names a publicly known vulnerability. A Common Platform Enumeration (CPE) name describes a class of product, such as an application or operating system. Neither one identifies the specific package installed on one of your endpoints.

Automox correlates the Tenable asset with an Automox-managed endpoint. It then maps the vulnerability to an installable package where possible. It uses Microsoft Knowledge Base (KB) matching for Windows updates and CVE matching for supported third-party applications.

Match rates by software title

Scott Pinkelman's team built an HTML report that regenerates every few hours, with charts tracking matching performance overall and by software title. The moment a title's match rate drops, the team knows exactly where to look.

"The most effective solution we've found so far is to invest in product observability," Scott says.

The report shows which titles match, verifying any individual match still means checking the finding against the selected package.

What Scott's most proud of, though, is what that observability work fed back into: the CVE data in Automox's core product.

"We've been able to provide more accurate and more detailed CVE data to our customers, not just for those using the Tenable integration, but in the core product as well," Scott says.

Findings that need investigation

The beta separates findings with an installable package (Patchable) from those without a package match (Unmatched). Assets that don't match an Automox-managed endpoint appear under Unmanaged Devices.

An Unmatched finding may have a patch available. The integration hasn't mapped it to a package.

You choose which findings to remediate and confirm each patch or restart action before it runs.

The integration overview covers the beta workflow and how to request a demo.

Sorting findings this way doesn't replace judgment, it just makes sure you're spending it in the right place.

Sources

Frequently asked questions

Automox correlates the Tenable asset with an Automox-managed endpoint, then maps the finding to an installable package. It uses Microsoft Knowledge Base (KB) matching for Windows updates and CVE matching for supported third-party applications. Findings it can't map stay visible as Unmatched.

No. The integration presents findings as patchable when it can map them to installable Automox packages. Unmatched findings and assets that don't map to Automox-managed endpoints remain visible.

No. You review findings, select what to remediate, and confirm patch or restart actions before execution.

No. Automox tracks remediation in its own workflow. Tenable checks whether the vulnerability remains during its next scan.

Tenable Vulnerability Management cloud. The beta is currently available to a limited number of customers.

Dive deeper into this topic