Demo Series 10 minMay 20, 2025

Integrate Security Testing With Your Vulnerability Management Workflow

Integrating vulnerability scanning with human-led security testing delivers more robust and effective vulnerability management. Synack technical alliances director Greg Copeland demonstrates the benefits of breaking down silos using the new integration between Tenable Vulnerability Management and Synack Penetration Testing as a Service (PTaaS). Learn how:…

Greg Copeland Technical Alliances Director, Synack

Overview

Integrating vulnerability scanning with human-led security testing delivers more robust and effective vulnerability management. Synack technical alliances director Greg Copeland demonstrates the benefits of breaking down silos using the new integration between Tenable Vulnerability Management and Synack Penetration Testing as a Service (PTaaS). Learn how:

  • Tenable Vuln Management scan results can be imported into Synack’s PTaaS platform
  • Scan data can be searched, filtered, triaged and further tested by the Synack Red Team (SRT)
  • SRT Assessment results can isolate critical, exploitable vulnerabilities
  • Synack provides detailed remediation recommendations and patch verification

Full transcript

Read transcript

In today's Cut to the Chase, we're going to discuss the benefits of integrating vulnerability scanning and human led security testing to get more robust and effective overall vulnerability management. Now, most people in their environments, they do scanning, and and scanning is very valuable. It provides a lot of insights about potential about vulnerabilities. It tells you, things that might be out of date. And there's a lot of good information there, but it can be quite noisy.

There's a there's a lot of data. Not all of it necessarily tells a customer whether their environment is truly exploitable to bad actors. Human led security testing, on the other hand, is is very effective at triaging and detailing the most critical vulnerabilities along with providing recommendations on how to fix them and actually confirming that your security gaps are closed. They're both very important, but they fulfill different roles.

Now a challenge is is that, traditionally, vulnerability scanning and security testing have been siloed. You had the benefits of scanning on one end. You had the different benefits of human led security testing on the others, but they didn't interact with each other. They didn't benefit from synergies, that I'll talk about in the demo. SYNNAC now offers platform that enables integration between vulnerability management scanning

and security testing. And I'm gonna show this in the context of a new integration that we have with Tenable and their vulnerability management scanning platform, but the concept applies otherwise as well. So with our new integration, Tenable vulnerability management scan results can be imported into SYNNEX p task platform. Once they're there, they can be searched, filters, and and triaged so a customer can narrow down what they would like to have tested.

And then it could be sent through the platform to SYNNEX Red Team, our network of fifteen hundred plus security researchers, who can then do deep human led testing to find the critical vulnerabilities that matter most. So with that, I'd like to switch over and give a demonstration. So, this is Tenable vulnerability management. And I won't go too much into the details here, but I just wanted to point out that it's scanning a lot of

different assets in in an environment. There's thousands of suspected vulnerabilities that they're finding, things that could be a problem, things like out of date OS, CVEs that they're finding, and other vulnerabilities. So, now this kind of gives a very broad coverage. It's good at looking at the entire tax surface, and, it's very helpful, but not all of this is going to be something that necessarily

has to be tested by humans. Now if I go over now to to Synack, Synack has what we call exploitable vulnerabilities. These are the things that have been tested by our security researchers and findings provided. So if an asset is tested, a security researcher is gonna see whatever they can exploit. There's a lot of detail. Not only does it tell you, yes, this scan result got a hit, it also tells you what's the impact.

What exactly did the security researcher do to be able to exploit this? And because you have all this detail of how it was done, you also can be very explicit in how to fix it. Recommendations are provided on how to fix it. And then once something is is, provided back to the customer so for this example here, I, as a customer, have decided I I've fixed this.

I think I've done it right, but I would like to send it back to the Synacrid team and make sure that that this patch is actually closing the security gap. So, these are examples of of human led security testing results, and these are very valuable. But in order to to get to this point of undertaking security testing, you really need the context from those scan results. The scan results tell you everything that's in your attack surface that you might wanna look at, and you can triage and decide what to test.

Now if you don't have any scan results, the suspected vulnerability page in the Synack platform will be empty. So the suspected vulnerability page are the scan results. These kinda give you that broad look at the attack surface. Here in this example, I'm empty. I don't have any scan results. So what that means, it means that I, as a customer, would have to know every specific critical asset that I wanted to test. I would have to know what I would like them to test for. And that's fine, you know,

if I know what they want them to test, but sometimes I don't know. So I need that context from the scan results to help me. So, at this point, we enter the integration with a vulnerability scanner such as Tenable vulnerability management. So I'm gonna show what needs to be done to enable the integration. So firstly, I need to go in. I need to generate an API key from Tenable. I'm not gonna do this now because I did it already. But I'm gonna take that API key,

and I will then enter it into the Tenable integration page within the Synack platform. So I'll put those keys in, and I'll save. Optionally, I can put in criteria. I can say, I would only like to have the critical vulnerabilities, scan results brought over from Tenable, or maybe I wanna only look at ones with certain tags. And then I can do a one time daily import, or I can enable a daily import. So one time, as the name suggests, brings it right in at that point.

Daily checks for new scan results each day and adds the new ones to the list. So as an example here, I will do a one time import. It's gonna create this. It will kick off in a moment, and it will take a little time for all these vulnerabilities to come in because, as I mentioned earlier, there are there are many thousands of them potentially from from the, tenable scanner. So, we can come back to this later. However,

go over to, the results here, Synack. These are ones, from a previous scan result, but new ones will start to come in as well. So here we see that, we have scan results from from tenable. Source is tenable. I have different severity. I can choose to filter those. I can say I would only like to see the critical ones, for example. And I can I can then click over and and see which ones here I might wanna look at? I could also, search on particular assets that I want to look at and so forth.

So I can say, okay. This this one, you know, looks like something I'm concerned of. We get the information from Tenable. There's not a lot of detail there on that particular one. However, you know, we can look at patterns. We can say, you now this one's bubbling up to the top here. This one came, from from a tenable look. There's all kinds of hits there on the tenable scan. So there's a lot of of scan hits here. This might be one that I wanna test further. It could be something else from the asset list.

Once I get down to the point of narrowing down with the help of the triaging of the tenable scanning results in the Synack platform, and then I wanna send something to the Synack red team for testing, I can click on it in the asset list, and then I can create an assessment. Select grade an assessment. And what this is gonna do is it's gonna launch the, assessment creation wizard,

but it will repopulate it with some of the information it needs to kick off that test. So I will save the assessment. It's then going to, populate it with the list page. This is a pretty simple example. I just used one, but there might be multiple things that I want to test. So let's put that thing in there. I'll I'll finish this form. Once I do, it will go into the queue, for the Synagrid team to examine and to to provide findings.

And once they do that, if I come back, I will see and I'm back here at the exploitable vulnerability page. So I see all kinds of detail. These, providing a lot of information about the the vulnerability of the asset, how to fix them, and then you can go through that that, process that I showed earlier, for patch verification. And this allows you to close the vulnerability gap. So what we're doing here is we're we're in conclusion,

we're integrating security testing as part of the overall vulnerability management process. Vulnerability management scanning is very important. It gives you a high level view of your attack surface of things you might need to worry about. Once you bring that into the SYNECT platform, you can narrow down and triage what you would like the human led security researchers to provide. Then they will do that testing on the the smaller subset of vulnerable assets and give you the real detail that you need in order to be able to both reproduce, remediate,

and verify that the patches have been successful. So with that, I wanted to conclude today. Thank you very much for for joining Cut to the Chase. And if you would like to learn more, please contact us. And you can see more information about the Tenable integration, and Synack at w w w dot synack dot com. Thank you.

Speakers

Greg Copeland

Synack

Technical Alliances Director

Next step

Run the test instead of evaluating the idea.

Define a scope, run a Sara AI pentest against it, and see which findings are confirmed as real and exploitable. Then compare that with what your current testing returns.