Vulnerability assessment tools

  • Thread starter Thread starter Cosmic Cruizer
  • Start date Start date
C

Cosmic Cruizer

I'm researching flexible, enterprise-wide vulnerability assessment tools for
the Windows 2000 and 2003 platforms. So far, I've looked at the following,
and like all solutions, each of them have their pros and cons:

SecurityExpressions from Pedestal Software
Security Analyzer from NetIQ
SecEdit from Microsoft

As it stands, I am looking for a tool to help proactively manage around
1,500 servers of various types: AD, Exchange, SMS, print and file, etc. The
tests need to be configurable so I can adjust them, where necessary, to fit
our security philosophy. I would rather purchase a vendor supplied solution
then to build something from the ground up that we would need to solely
support internally.

What are some of the other Windows vulnerability assessment tools on the
market? Is there a comparison of the various products listed somewhere?

Thanks
 
CC,

Have you at least looked at MBSA and the Software Update
Services? Using these two together can help a lot.

Opti_mystic
 
CC,

Have you at least looked at MBSA and the Software Update
Services? Using these two together can help a lot.

Opti_mystic

Thanks Opti_mystic. I'll look into your suggestion. Also, I did manage to
find three great links (amoung several others)

http://www.nwfusion.com/reviews/2002/vulnerability0204result.jsp?
_tablename=vulnerability0204 (a few years out of date)

http://www.timberlinetechnologies.com/products/vulnerability.html

http://cve.mitre.org/compatible/product_type.html

These should keep me occupied for awhile.
 
Thanks Opti_mystic. I'll look into your suggestion. Also, I did manage
to find three great links (amoung several others)

http://www.nwfusion.com/reviews/2002/vulnerability0204result.jsp?
_tablename=vulnerability0204 (a few years out of date)

http://www.timberlinetechnologies.com/products/vulnerability.html

http://cve.mitre.org/compatible/product_type.html

These should keep me occupied for awhile.

I've always found Languard Network Security Scanner by GFI to be a nice
utility - 30 day free trial with (not very)limited freeware use after the
30 days is up

--
/(bb|[^b]{2})/ that is the Question

ThePsyko
Public Enemy #7
http://prozac.iscool.net
 
Back
Top