Skip to main content

Windows: Install via the wizard

How to set up our agent-based internal scanning solution to protect Windows devices in your internal network

Updated this week

Make sure you run all commands as Admin.

For mass deployment, have a read of this article.

Please note, each machine must have a unique device name; if you use the same name as an existing internal target, it won't link.


Step 1: Download the agent installer (but don't launch it)

1. Head to the targets page > select Add target > Internal Targets

2. Choose between a Single agent deployment (providing instructions and a link to download the agent for the machine) or Mass deployment (providing the parameters you need for your installation script).

​

If choosing Single Agent deployment:

3. Enter the details for the machine you wish to scan:

  • πŸ‘‰ Operating System

  • πŸ‘‰ Operating System version

  • πŸ‘‰ Your device name (this must be unique and contain only letters, numbers, or hyphens)

  • πŸ‘‰ Tags (optional)

➑️ Hit 'Download agent'

You should see something similar to this:


Step 2: Run the command

You should see something like this pop up:


Step 3: Reboot the machine

  • πŸ‘‰ Reboot the machine

  • πŸ‘‰ Confirm it is online and able to reach cloud.tenable.com.

Note that for a scan to run on this target, the machine will need to be online and able to reach cloud.tenable.com for the target to show as responsive.


What do the statuses mean?

Status Message

Meaning

Ready

The agent is successfully installed and linked, and the target is ready to scan.

Agent!

The target has been added to Intruder, but the agent needs to be installed and/or linked.

Agent!

There is an issue with the agent. Confirm the agent is properly installed and linked.


If you have any trouble, please click the button below:


Note: Internal vulnerability scanning is only available to users with a Pro, Enterprise, or Vanguard plan.

Did this answer your question?