Vulnerability assessment tools

C

Cosmic Cruizer

I'm researching flexible, enterprise-wide vulnerability assessment tools for
the Windows 2000 and 2003 platforms. So far, I've looked at the following,
and like all solutions, each of them have their pros and cons:

SecurityExpressions from Pedestal Software
Security Analyzer from NetIQ
SecEdit from Microsoft

As it stands, I am looking for a tool to help proactively manage around
1,500 servers of various types: AD, Exchange, SMS, print and file, etc. The
tests need to be configurable so I can adjust them, where necessary, to fit
our security philosophy. I would rather purchase a vendor supplied solution
then to build something from the ground up that we would need to solely
support internally.

What are some of the other Windows vulnerability assessment tools on the
market? Is there a comparison of the various products listed somewhere?

Thanks
 
O

Opti_mystic

CC,

Have you at least looked at MBSA and the Software Update
Services? Using these two together can help a lot.

Opti_mystic
 
C

Cosmic Cruizer

CC,

Have you at least looked at MBSA and the Software Update
Services? Using these two together can help a lot.

Opti_mystic

Thanks Opti_mystic. I'll look into your suggestion. Also, I did manage to
find three great links (amoung several others)

http://www.nwfusion.com/reviews/2002/vulnerability0204result.jsp?
_tablename=vulnerability0204 (a few years out of date)

http://www.timberlinetechnologies.com/products/vulnerability.html

http://cve.mitre.org/compatible/product_type.html

These should keep me occupied for awhile.
 
T

ThePsyko

Thanks Opti_mystic. I'll look into your suggestion. Also, I did manage
to find three great links (amoung several others)

http://www.nwfusion.com/reviews/2002/vulnerability0204result.jsp?
_tablename=vulnerability0204 (a few years out of date)

http://www.timberlinetechnologies.com/products/vulnerability.html

http://cve.mitre.org/compatible/product_type.html

These should keep me occupied for awhile.

I've always found Languard Network Security Scanner by GFI to be a nice
utility - 30 day free trial with (not very)limited freeware use after the
30 days is up

--
/(bb|[^b]{2})/ that is the Question

ThePsyko
Public Enemy #7
http://prozac.iscool.net
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top