Penetration Testing mailing list archives
Re: Vulnerability Assessment
From: "US Infosec" <usinfosec () gmail com>
Date: Mon, 23 Jul 2007 20:18:17 -0400
I have used them all extensively and would highly recommend that you use Foundstone and Nessus. Additionally one lesser known tool worth mentioning is Harris Guardian. I have never been a fan of Qualys, especially when I do third party assessments and find stuff that they miss. They also used to require that all external data be stored on their network which is a security vulnerability in itself. Whoever said that Qualys has the checks a week before everyone else.. yeah they all claim to do that. I know of many fortune 100 companies along with full state and even federal governments that rely solely on Foundstone. I can make claims all day long, but ultimately it does not matter. With that said, these days they all are getting closer and closer with their functionality. The best advice that anyone *should* give you is to do a proof of concept and compare them side by side against the same test systems. This will determine which is currently better for YOUR environment. Also, while checking out Foundstone be sure to look at Preventsys which McAfee bought as well. Coupled together the two tools meet a LOT of security departments needs for compliance and auditing. Good Luck! On 7/23/07, Deepak Parashar <deep231982 () gmail com> wrote:
Uzair, I would to say to go for Foundstone-I have worked on this solution for long and it's really good product for vuln. assessment if designed correctly and have good reporting feature as well, it'll give you options to drill down to dll versions and gives you liberty to create your own tests as well........... other best option would be Retina.... -DP http://www.linkedin.com/in/deepakparashar http://deepakparashar.blogspot.com/ "Vision is the art of seeing the invisible"...Jonathan Swift On 6/4/07, Uzair Hashmi <uzair () kse com pk> wrote: > Hello list, > > I have been evaluating an automated vulnerability assessment software, have found two of them better for the organizational needs. I need your help to select only one out of the two. > > 1- QualysGuard (http://www.qualys.com) > 2- Foundstone Enterprise (http://www.mcafee.com/us/enterprise/products/vulnerability_management/foundstone_enterprise.html) > > Please advice. > > Regards, > Uzair > > > ------------------------------------------------------------------------ > This List Sponsored by: Cenzic > > Are you using SPI, Watchfire or WhiteHat? > Consider getting clear vision with Cenzic > See HOW Now with our 20/20 program! > > http://www.cenzic.com/c/2020 > ------------------------------------------------------------------------ > > ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
Current thread:
- Re: Vulnerability Assessment Mondai Ji (Jul 23)
- <Possible follow-ups>
- Re: Vulnerability Assessment Colin Grady (Jul 23)
- Re: Vulnerability Assessment Danux (Jul 23)
- Re: Vulnerability Assessment Kish Pent (Jul 25)
- Re: Vulnerability Assessment Danux (Jul 23)
- Re: Vulnerability Assessment Deepak Parashar (Jul 23)
- Re: Vulnerability Assessment US Infosec (Jul 24)
- Re: Vulnerability Assessment jfvanmeter (Jul 24)
- Re: Vulnerability Assessment Pete Herzog (Jul 24)
- RE: Vulnerability Assessment Uzair Hashmi (Jul 25)
- Re: Vulnerability Assessment US Infosec (Jul 27)
- Re: Vulnerability Assessment Tima Soni (Jul 31)
- Re: Vulnerability Assessment Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (Jul 31)
- Re: Vulnerability Assessment Pete Herzog (Jul 25)
- Re: Vulnerability Assessment Pete Herzog (Jul 25)