Integrated vulnerability management solution
GFI LANguard Network Security Scanner (N.S.S.) is an award-winning solution that addresses the three pillars of vulnerability management: security scanning, patch management and network auditing through a single, integrated console. By scanning the entire network, it identifies all possible security issues and using its extensive reporting functionality provides you with the tools you need to detect, assess, report and rectify any threats
- Vulnerability scanning
- Patch management
- Network and software auditing
Vulnerability Scanning
During security audits, over 15,000 vulnerability assessments are made and networks are scanned IP by IP. GFI LANguard gives you the capability to perform multi-platform scans (Windows, Mac OS, Linux) across all environments including Virtual Machines and to analyze your network’s security set-up and status. This ensures that you are able to identify and rectify any threats before hackers manage to do so. NEW! – Detection of Virtual MachinesGFI LANguard can now detect whether a scanned machine is rear or virtual. Currently both VMware and Virtual PC software are supported. IMPROVED! – set-up your own custom vulnerability checksGFI LANguard allows you to easily create custom vulnerability checks through simple wizard-assisted set-up screens. The wizard is also powerful enough to allow building of complex vulnerability checks. The scripting engine is also compatible with Python and VBScript. GFI LANguard includes a script editor and debugger to help with script development. IMPROVED! – Extensive, industrial-strength vulnerabilities databaseGFI LANguard ships with a complete and thorough vulnerability assessment database, which includes standards such as OVAL (2,000+ checks) and SANS Top 20. This database is regularly updated with information from BugTraq, SANS Corporation, OVAL, CVE and others. Through its auto-update system, GFI LANguard is always kept updated with information about newly released Microsoft security updates as well as new vulnerability checks issued by GFI and other community-based information repositories such as the OVAL database. Identify security vulnerabilities and take remedial actionGFI LANguard scans computers, identifies and categorizes security vulnerabilities, recommends a course of action and provides tools that enable you to solve these issues. GFI LANguard also makes use of a graphical threat level indicator that provides an intuitive, weighted assessment of the vulnerability status of a scanned computer or group of computers. Wherever possible a web link or more information on a particular security issue is provided, such as a BugTraq ID or a Microsoft Knowledge Base article ID. Ensures that third party security applications such as anti-virus and anti-spyware offer optimum protectionGFI LANguard also checks that supported security applications such as anti-virus and anti-spyware software are updated with the latest definition files and are functioning correctly. For example, you can ensure that supported security applications have all key features (such as real-time scanning) enabled. Easily creates different types of scans and vulnerability testsYou can easily configure scans for different types of information; such as open shares on workstations, security audit/password policies and machines missing a particular patch or service pack. You can scan for different types of vulnerabilities to identify potential security issues. These include:
Easily analyze and filter scan resultsGFI LANguard enables you to easily analyze and filter scan results by clicking on one of the default filter nodes. This enables you to identify, for example, machines with high security vulnerabilities or machines that are missing a particular service pack. Custom filters can also very easily be created from scratch or customized. You can also export scan results data to XML. |
Patch management and remediation
|
Network and software auditing
|
Other featuresNEW! – A fresh, new look which allows effective use of GFI LANguardGFI LANguard now ships with a new user interface which allows network administrators to easily scan the network to perform vulnerability assessment and retrieve relevant security information, analyze the results and generate reports and remediate the security issues that were detected. NEW! – Monitoring DashboardThe GFI LANguard dashboard shows summarized results of all scans from the database and provides and overview of the most vulnerable computers and security status trends of the network. IMPROVED! – Multiply the value of GFI LANguard with powerful reportingReports are designed to satisfy the requirements of both management and technical staff. These deliver a graphical snapshot of the security health status of your network. From trend reports for management (ROI) to daily drill-down reports for technical staff; the GFI LANguard provides you with the easy-to-view information you need, to fully keep abreast of changes to your network’s security environment. Full automation and custom scheduling. Executive reports are now available directly from within GFI LANguard. Helps to comply with PCI DSS and other regulationsAs from September 2007 all businesses handling cardholder data – irrespective of size – have to be fully compliant with strict security standards drawn up by the world’s major credit card companies. GFI LANguard provides complete vulnerability management coupled with an extensive ReportPack add-on that make GFI LANguard the essential, cost-effective solution that your organization needs to safeguard your network and gauge the effectiveness of your PCI compliance program. Silent installation supportYou can perform an unattended default installation of GFI LANguard on multiple computers in the background without any user interaction or intervention. Customization of the deployment parameters is also possible through the creation of Microsoft Transform (MST) files. Predefine authentication detailsGFI LANguard allows you to store separate authentication details for every target computer on your network, avoiding the need to specify authentication credentials prior to every scan. In a single scanning session, it is possible to audit all the targets in your network, even if they require different authentication details/methods. Other features:
|



