Vulnerability Management Software

Posted on 2004-10-13
Last Modified: 2013-12-03
Hi Guys

Does anyone know of a product (Commercial or Freeware) that will allow you to input the details of your infrastructure (such as what software is in use etc) and then monitor for vulnerabilities and patches that match that list and alert you?

Many thanks

Question by:stewatts
  • 4
  • 2
  • 2
  • +2

Expert Comment

ID: 12296638
Dear Ste,
You may wish to use GFI LANguard Network Security Scanner (N.S.S.)
- Automatically detect security vulnerabilities on your network
- Provides in-depth information about all machines/devices
- Patch management. ...;-)


Author Comment

ID: 12296654

I am using this at the moment but I am looking for somethingt that will alert me without me having to constantly scan. For Example, I have some machines that GFI can access for various reasons, I still need to be alerted to any vulnerable software/hardware that they are running.

I need something that looks at all vendors, pulls down info on vulns, filters it to what we use and then report and alert. Not asking alot am I ;-)

Expert Comment

ID: 12296848
Maybe you should check out Retina Security Scanner.

It'll update automatically on startup and you can schedule updates, you can schedule scans and make it generate reports on each scan.

If the scans are taking too long you can manually configure (it's simple) which types of vulns it'll scan, e.g., web server, iis, etc.

You can download the demo version from

There are also another couple of scanners that may help you out - they don't provide the functionality of Retina though, they are:

Core Impact


Author Comment

ID: 12296884
As I mentioned previous I can't do scheduled scanned as some of the machines aren't reachable.

For example I have a web servers running IIS4 and IIS6. They can't be seen on the network but I need something that will alert me when a vulnerability comes out for IIS6 and IIS4.

The solutions here rely on the machines being scanned which isn't possible. Ideally I need a solution that pulls vulns from a central site or multiple vendors?

Expert Comment

ID: 12297050
Okay, my bad, I have a bad habit of not reading :)

The solution to your problem potentially lies within's website.

I remember I downloaded a tool that was supposed to periodically check with Security Focus's website for updated vulns, I'll have a hunt around and post back if I find anything - sorry I couldn't help straight up.

Network it in WD Red

There's an industry-leading WD Red drive for every compatible NAS system to help fulfill your data storage needs. With drives up to 8TB, WD Red offers a wide array of solutions for customers looking to build the biggest, best-performing NAS storage solution.  


Author Comment

ID: 12297309
No problem, I appreciate all of your help so far.
LVL 79

Accepted Solution

lrmoore earned 25 total points
ID: 12297563
You might want to look into something like the Lockdown appliance:


Expert Comment

ID: 12302384
Remember hfnetchk?  It's now been swallowed into MS Baseline Security Analyser.  But, it's still out there to be found, and I belive it still works.  When run, it outputs the results in text format.  With a little scripting, you can have this run daily on your machines, and have your script parse the output, and send you an email if it finds unpatched products.

Author Comment

ID: 12305892
Thanks sstoyanovich

As mentioned above though this won't work as I can't scan the machines!

I think LRMOORE's answer is the closest to what I was after, I also found this web site: which does what I need to a degree.

Expert Comment

ID: 12306504
No, no.  You don't use hfnetchk to scan the machines from your machine.  You set up hfnetchk ON the machines, on their c: drives.  Deploy it as you would any other app that you need on all machines.  In fact, set up a schedule task on all machines to run iyour script daily/nightly/whatever.

Once it's ON the machines themselves, it will run.  And if they're off the network or turned off no big deal; they miss a run.  But as soon as they're back on, the next time they run it, it will be able to run and alert you.

You are not doing any scanning from a central location, and it allows you to "catch" all machines.


Featured Post

Give your grad a cloud of their own!

With up to 8TB of storage, give your favorite graduate their own personal cloud to centralize all their photos, videos and music in one safe place. They can save, sync and share all their stuff, and automatic photo backup helps free up space on their smartphone and tablet.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
CA single sign on 2 75
what technologies offer Authentication over Web Services? 4 105
Recommendations for cloud-based web filtering 4 74
audit logs in excel spreadsheet 1 47
Never store passwords in plain text or just their hash: it seems a no-brainier, but there are still plenty of people doing that. I present the why and how on this subject, offering my own real life solution that you can implement right away, bringin…
Every computer eventually fails. When that happens, your valuable data is only as safe as your current backup.
Sending a Secure fax is easy with eFax Corporate ( First, Just open a new email message.  In the To field, type your recipient's fax number You can even send a secure international fax — just include t…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now