> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# LevelBlue Vulnerability Scanner Guide

> This section explains how to use the LevelBlue Vulnerability Scanner powered by Tenable within LevelBlue USM, including its configuration, scanning workflows, credential management, and known limitations.

LevelBlue USM is modernizing its vulnerability scanning capabilities. The legacy jOVAL scanning engine has been replaced with Tenable Vulnerability Scanner technology, delivered through the LevelBlue Vulnerability Scanner BlueApp.

This change improves scanning accuracy and coverage, while preserving the existing LevelBlue USM user experience. No workflow changes are required for day-to-day scanning operations.

**Important considerations after enabling the scanner:**

* All assets must be visible to Tenable.
  * Public assets should use the Tenable Cloud Scanner.
  * Private assets require a locally installed Nessus scanner.
* Review and validate asset credentials before running authenticated scans.

<Note>
  By default, the LevelBlue Vulnerability Scanner is licensed for unlimited endpoints; however, there is an API limit of 8192 endpoints per scan.
</Note>

### **Configure and enable LevelBlue Vulnerability Scanner**

1. Go to **Data Sources > BlueApps > Available Apps**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/-M0wA3emmFuNghQ-/configure_lb_vulnerability_scanner_img1-1.png?fit=max&auto=format&n=-M0wA3emmFuNghQ-&q=85&s=c6f8441b8b6cbb0d0f112db6b7e1adfa" alt="" width="1340" height="1097" data-path="configure_lb_vulnerability_scanner_img1-1.png" />
</Frame>

3. Filter by **Scanner**, and then select **LevelBlue Vulnerability Scanner Powered by Tenable**. The **Authorize Apps** tab of the Blue Apps page opens.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img2-1.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=464098cfe33e860525f1c78297f09ba6" alt="" width="1527" height="881" data-path="configure_lb_vulnerability_scanner_img2-1.png" />
</Frame>

4. Click **Configure API**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/sSqPY_7biq51AWo_/configure_lb_vulnerability_scanner_img3-1.png?fit=max&auto=format&n=sSqPY_7biq51AWo_&q=85&s=24e7f7a137328229a59e46cf21d27629" alt="" width="1766" height="833" data-path="configure_lb_vulnerability_scanner_img3-1.png" />
</Frame>

5. Select the **Region** where the configuration data will be stored.
6. Click **Save**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/X5K_qsE5-6E8HmIw/images/usm-anywhere/configure_lb_vulnerability_scanner_img4.png?fit=max&auto=format&n=X5K_qsE5-6E8HmIw&q=85&s=977eebccf4eac6a2930dbfa007e95c67" alt="" width="468" height="312" data-path="images/usm-anywhere/configure_lb_vulnerability_scanner_img4.png" />
</Frame>

<Note>
  **Note:** Only users with a **Manager** role can perform this configuration.
</Note>

A Tenable tenant and user account are automatically created during configuration. Login credentials for the Tenable portal are sent to the same email address used for LevelBlue USM.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img5.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=f7ae2bff02498441cb32b725eb01916b" alt="" width="1789" height="930" data-path="configure_lb_vulnerability_scanner_img5.png" />
</Frame>

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img6.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=8de157a1befc08553e47029e3e96603b" alt="" width="1778" height="825" data-path="configure_lb_vulnerability_scanner_img6.png" />
</Frame>

Once the configuration is complete, you will receive an email confirmation.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img7.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=553a3a06ccbf673f7c138b60be4d4cab" alt="" width="1208" height="727" data-path="configure_lb_vulnerability_scanner_img7.png" />
</Frame>

7. Log into the [Tenable](https://cloud.tenable.com) portal using the temporary credentials provided.
8. Returning to the **LevelBlue Vulnerability Scanner** page > **Authorize Apps** tab, go to the **Scanner Settings** tab.
9. Select a default scan template.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img8.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=e8faa8db01732ea913e3479c27bad6bb" alt="" width="1789" height="930" data-path="configure_lb_vulnerability_scanner_img8.png" />
</Frame>

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img9.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=20cb162463fb9f21d4932d72fca72082" alt="" width="1789" height="930" data-path="configure_lb_vulnerability_scanner_img9.png" />
</Frame>

<Note>
  Only users with the **Manager** role can configure default scan templates.
</Note>

10. Navigate to the **Assets** or **Asset Groups**, and then run scans as usual.
11. Go to the **Scheduling** tab to configure periodic scans.

<Info>
  Before running authenticated scans, verify the following:

  * That assets are visible to Tenable Cloud, or they have a Nessus scanner installed
  * That credentials are valid and assigned to the correct assets
</Info>

### **Manage Asset Credentials**

Existing LevelBlue USM credentials are fully supported. If credentials have been previously configured, then no reconfiguration is required.

You can:

* Add new credentials

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img10.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=144d695dff07698792113607dfcb4b7a" alt="" width="1365" height="589" data-path="configure_lb_vulnerability_scanner_img10.png" />
</Frame>

* Assign credentials to assets

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img11.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=eb1e9efe9e95022e52f26acac4af99d9" alt="" width="1365" height="589" data-path="configure_lb_vulnerability_scanner_img11.png" />
</Frame>

### **Run an Authenticated Scan**

1. Open the **Assets** page.
2. Confirm that credentials have been assigned.
3. Click **Actions**.
4. Select **Authenticated Scan**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img12.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=30ded8869b0cdeaadbc63a06c0c284f2" alt="" width="1359" height="591" data-path="configure_lb_vulnerability_scanner_img12.png" />
</Frame>

### **Run an Asset Group Authenticated Scan**

1. Open the **Asset Group** page.
2. Confirm all assets in the group have been assigned credentials.
3. Click **Actions**.
4. Select **Authenticated Scan**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img13.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=ae007644f26e6ec411c3e2a0158b569f" alt="" width="1360" height="609" data-path="configure_lb_vulnerability_scanner_img13.png" />
</Frame>

### **Run an Asset Scan Action**

1. From the **Actions** menu, select **Run BlueApp Action**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img14.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=ce5b26343220fbda3f6ca26110c83e49" alt="" width="1360" height="590" data-path="configure_lb_vulnerability_scanner_img14.png" />
</Frame>

2. Select **Run LevelBlue Vulnerability Scanner powered by Tenable**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img15.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=bf37c48d6007626726940dc38ee64eb6" alt="" width="1359" height="590" data-path="configure_lb_vulnerability_scanner_img15.png" />
</Frame>

3. Select **Run Scan**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img16.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=bc789f645b2f455d20eea6a2f01d9464" alt="" width="1365" height="589" data-path="configure_lb_vulnerability_scanner_img16.png" />
</Frame>

4. Click **Run**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img17.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=8392fd7ff73b5e2dc7434a8f41f63336" alt="" width="1360" height="585" data-path="configure_lb_vulnerability_scanner_img17.png" />
</Frame>

### **Run a Scheduled Scan Periodically**

The user experience does not change. Refer to [Managing Credentials in USM Anywhere](https://docs.levelblue.com/documentation/usm-anywhere/user-guide/vulnerability-assessment/credentials) for more information

### **Download a Scan Result File**

1. Open the \*\*\*\*Assets \*\*\*\*or ****Asset Group****  page.
2. Go to the **Scan History** tab.
3. Locate the **Scan File** column.
4. Click the scan entry to download the file.

### **Test Credentials for an Asset**

The user experience does not change. Refer to [Managing Credentials in USM Anywhere](https://docs.levelblue.com/documentation/usm-anywhere/user-guide/vulnerability-assessment/credentials) for more information.

### **Review Authenticated Scanner Status in a Sensor**

1. Navigate to **Sensors**.
2. Select the sensor to review.
3. Open the **Authenticated Scanner** tab.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/26vKs8M7NiHcoMcJ/configure_lb_vulnerability_scanner_img18.png?fit=max&auto=format&n=26vKs8M7NiHcoMcJ&q=85&s=e9a6320d630562e54b68181c409e4f11" alt="" width="1359" height="607" data-path="configure_lb_vulnerability_scanner_img18.png" />
</Frame>

### **Install the Nessus Scanner on Assets**

1. Open the Nessus download page, and then download the Nessus scanner: [https://www.tenable.com/downloads/nessus](https://www.tenable.com/downloads/nessus).
2. Follow the installation guide: [https://docs.tenable.com/nessus/Content/InstallNessus.htm](https://docs.tenable.com/nessus/Content/InstallNessus.htm)
3. When prompted, select **Link to another Tenable product**.
4. Link the scanner to your Tenable portal using these instructions: [https://docs.tenable.com/vulnerability-management/Content/Settings/Sensors/LinkaSensor.htm](https://docs.tenable.com/vulnerability-management/Content/Settings/Sensors/LinkaSensor.htm).

### **Helpful links**

* [Vulnerability Management Scanning Best Practices](https://docs.tenable.com/vulnerability-management/Content/Scans/ScanBestPractices.htm)
* [Credentials in Tenable Vulnerability Management Scans](https://docs.tenable.com/vulnerability-management/Content/Scans/Credentials.htm)
* [Deployment Guides for Tenable Scanners](/documentation/usm-anywhere/user-guide/vulnerability-assessment/deployment-guides-for-tenable-scanners)
* [Frequently Asked Questions](/documentation/usm-anywhere/user-guide/vulnerability-assessment/level-blue-vulnerability-scanner-faqs)

<Warning>
  **Limits and Restrictions**

  1. Do not configure the LevelBlue Vulnerability Scanner on more than one sensor within the same LevelBlue USM domain. Doing so can cause scan and result errors.
  2. The Tenable license supports unlimited endpoints, but API is limited to 8192 endpoints per scan only. If you will be scanning more than the indicated endpoints, multiple scans are required.
</Warning>
