Add vulnerability scanner Nessus agent to the VM deploys

According to the data security team, all services exposed to the internet need to install:

  1. A vulnerability management solution - Nessus Vulnerability Scanner.
  2. An Endpoint Detection and Response tool. - Microsoft Defender for endpoint protection.

Nessus Agent is a security tool that provides credentialed scan fidelity for our vulnerability management solution, Tenable.io. It can be seen more as a preventative control that we utilize to secure our machines BEFORE any type of initial compromise, by helping us (and you all) identify the vectors for compromise and implement patches or mitigating controls to correct them. The Nessus Agent can enumerate software and version numbers, checking them against known vulnerable software exploits, CVEs, and other relevant information. It also identifies common misconfigurations that weaken a computer’s defenses or leave it vulnerable to exploitation. I think Scott also mentioned, but this is mandated in the Vuln Management Rule

Edited Jan 27, 2026 by Eesaan Atluri
Assignee Loading
Time tracking Loading