Forum Discussion
New AWS Secrets Manager PAM Integration
Summary
Tenable is proud to announce our new AWS Secrets Manager Privileged Access Management (PAM) integration. Customers can store scan credentials in AWS Secrets Manager and have Tenable retrieve them at scan time directly inside Tenable. These updates are immediately available for Tenable Vulnerability Management and Tenable Nessus, with plans to release this feature at a later date for Tenable Security Center.
Change
With this addition, scans can authenticate to targets using credentials fetched from AWS Secrets Manager using AWS Signature Version 4. This integration retrieves the secrets (username, password, optional SSH key, and optional domain) at scan time and uses them for credentialed checks, eliminating the need to store target credentials in Tenable Vulnerability Management or Tenable Nessus.
AWS Secrets Manager authentication method supports the following credential types:
- Windows
- SSH
- Database (PostgreSQL, MongoDB, Cassandra, DB2, MySQL, SQL Server, Oracle)
- VMware ESX SOAP API
- VMware vCenter API
- Nutanix Prism Central
Support is provided for both long-lived IAM user access keys and temporary AWS STS session tokens. Additionally, you can utilize the Escalation Credential ID to reference a separate AWS secret for SSH credential privilege escalation.
Impact
No impact to current scans are expected; If customers encounter issues with this integration, please open a ticket with Technical Support. For comprehensive details regarding this integration, please refer to the Tenable user documentation.
Release Date
July 16 2026 for Tenable Vulnerability Management and Nessus; TBD for Tenable Security Center