Avatar of Pau Lo
Pau Lo

asked on 

Windows security tools

Which tools do you use for security auditing of windows servers (by which I mean checking the configuration aligns with best practice and is free from administrative/configuration based vulnerabilities). Microsoft baseline security analyser seems to of been retjred and not supported on newer OS. So gauging what tools / scripts etc are common in 2018 would be interesting. I would have thought powershell scripts could replace what MBSA used to check for but couldnt find much out there.
Operating SystemsWindows OSOS SecuritySecurity

Avatar of undefined
Last Comment
btan
ASKER CERTIFIED SOLUTION
Avatar of btan
btan

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of masnrock
masnrock
Flag of United States of America image

You could look at tools like OpenVAS.
Avatar of Pau Lo
Pau Lo

ASKER

Does openvas run on windows?
Avatar of masnrock
masnrock
Flag of United States of America image

No it doesn't, but at least it is free.
Avatar of Pau Lo
Pau Lo

ASKER

Will check it out,thanks.
Avatar of btan
btan

Dont think so but it maybe done indirectly.

For info, close to OpenVAS is Greenbone Security Manager for professional users, as GCE (Community ver) for users in SOHO environments, and as source packages, which are embedded into various Linux distributions as OpenVAS. The differences between these versions and the related Security Feed.
The Greenbone Security Manager Community Edition (GSM CE) is a derivative of the GSM ONE for evaluation purposes. The GSM CE may be deployed using VirtualBox on Microsoft Windows, MacOS and Linux systems.

In contrast to the commercial version the GSM CE uses the OpenVAS Community Feed instead of the Greenbone Security Feed. While the commercial versions support seamless updates of the operating systems new versions of the GSM CE are provided as ISO images requiring a new full installation. Further differences between the other GSM models and the GSM CE are explained on https://www.greenbone.net/en/community-edition/.
https://docs.greenbone.net/GSM-Manual/gos-4/en/gsm_overview.html

But it can scan target Windows machine still
https://docs.greenbone.net/GSM-Manual/gos-4/en/vulnerabilitymanagement.html#requirements-on-target-systems-with-windows
Avatar of Pau Lo
Pau Lo

ASKER

Are there costs associated with DSCEA and DCA? Such as the baselines themselves?
Avatar of btan
btan

Nope if you are already having the Windows build licences. DSC was introduced in Windows Server 2012 R2, it is available for down-level operating systems via the Windows Management Framework (WMF) package. You should talk to your IT support team too.
Windows OS
Windows OS

This topic area includes legacy versions of Windows prior to Windows 2000: Windows 3/3.1, Windows 95 and Windows 98, plus any other Windows-related versions including Windows Mobile.

129K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo