Hello everyone - Which tool is everyone using to scan and detect vulnerabilities in your network as well as automatic patching of those vulnerabilities? I tried PDQ Connects which is ok, but I am wondering what others are using and if there are better tools out there

Thanks

5 Spice ups

Vulnerability scans (inside and out) are one thing…patching is another. If it’s just update pushes, PDQ Deploy + Inventory is hard to beat. You can use it to deploy everything from Adobe to…can’t think of something that starts with Z, but you get the idea.

Action1 is highly touted for MS patch management, as well as several other handy features, but I’m not using it so can’t give you a full run down (you also don’t say what your environment looks like or how big you are).

Should probably ask now, what all are you updating? Things for firmware/BIOS updates can become…tricky.

3 Spice ups

Vendors > Action1

Free automated patch management for the first 200 endpoints (Windows and macOS at the moment, Linux to follow), it also inventories the devices and their software and runs a basic vulnerability scan.

For more features, Nessus or GVM on the vulnerability side.

Note that while you can scan for vulnerabilities ,you can’t self-certify, you still need pen tests from external companies.

4 Spice ups

for Reporting we use Defender for Endpoint P2. it has a baked in Vulnerability management.
There is a specific upgrade license to get even more insights such as browser plugin vulnerabilities.

If you have MS 365 Premium or higher you have Defender for Endpoint P1 and probably have access to the Vulnerability Reporting.

For patching we use our RMM tool.

4 Spice ups

Hi Man,

We are using GFI Langurard from last few years it do both tasks like VA scan and Patching.

GFI LanGuard provides vulnerability management coupled with extensive reporting to help you comply with standards and regulations. It helps safeguard your network and gauge the effectiveness of your PCI DSS, HIPAA, SOX, GLB/GLBA or PSN CoCo compliance programs.

3 Spice ups