Advantech Europe

Tenable integrates AI-fuelled identity security into exposure management platform

05 July 2023

To help to reduce the risk of identities being used in cyber attacks, Tenable has added several new identity-aware features that harness the power of artificial intelligence (AI) and machine learning to provide a unified view of all user identities and entitlement risks, whether on-prem or in the cloud. 

Tenable Identity Exposure now gives customers advanced vulnerability and asset risk prioritisation capabilities to identify and disrupt attack paths through Active Directory (AD). The solution is fully integrated within the Tenable One Exposure Management Platform. 


According to a study conducted by Forrester Consulting on behalf of Tenable, half (50 percent) of surveyed IT and security professionals globally say they lack an effective way to integrate user privilege data into their vulnerability management practices. This is a problem, as AD is typically the central source of truth for most critical business applications and services within an enterprise. Compromising AD and abusing access are popular methods used in ransomware and other attacks.
Traditional AD security tools provide point-in-time scans and aggregate millions of event logs only to deliver out-of-date visibility into the security posture of directory services. Tenable Identity Exposure enables organisations to address the gaps that have existed in AD security for decades. It helps customers to reduce the attack surface of their AD, providing continuous AD assessment, real-time attack detection, AI-driven exposure and risk prioritisation, and detailed remediation instructions. 


Tenable Identity Exposure now allows companies to manage their AD security posture across hybrid cloud environments at all times and visualise any active threats to their identities. New Tenable Identity Exposure features include:

• Identity Unification and Identity Explorer - a view of entitlements across on-premises and cloud-based AD deployments. This provides the most accurate assessment of identity risk and unmatched intelligence to help prevent exploited identity exposures. This feature provides the most complete understanding of how to prevent identities from being used for privilege escalation or other attack vectors
• Identity Risk Score (powered by Tenable’s Artificial Intelligence and Data Science Engine) - new capability that uses mature AI and machine language models to quantify the risk of an asset by combining the vulnerability, exposure and identity entitlements of an asset, leveraging Tenable's exposure management data
• Azure Active Directory support - extended support for protecting public and hybrid cloud Azure Active Directory deployments, so customers can unify identities across environments and manage cloud identity risk with Indicators of Exposure specific to Azure AD. With the shift of business applications to the cloud, alongside Active Directory, Azure AD has become a critical access control point


Full integration of these capabilities within the Tenable One Exposure Management Platform includes single sign-on, data sharing and app switching between solutions, providing identity awareness for vulnerability, attack path analysis, cloud posture and web application security practices.


“Access misconfiguration and weak identities are at the heart of ransomware attacks and corporate data breaches. Threat actors are only one identity vulnerability away from breaking into SaaS applications and stealing data. By leveraging modern AI techniques, Tenable can now quickly identify and prioritise identity and entitlement-related problems across AD and Azure AD,” said Nico Popp, Chief Product Officer. “The ability to safeguard identities both on-prem and in the cloud is essential for empowering customers to prevent attacks rather than just clean up the aftermath.”


More here. More on Tenable here.


Contact Details and Archive...

Print this page | E-mail this page


Stone Junction Ltd

This website uses cookies primarily for visitor analytics. Certain pages will ask you to fill in contact details to receive additional information. On these pages you have the option of having the site log your details for future visits. Indicating you want the site to remember your details will place a cookie on your device. To view our full cookie policy, please click here. You can also view it at any time by going to our Contact Us page.