Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Other scanners? |
|---|---|
| Date: | Tue, 22 Aug 2006 13:27:36 -0400 |
At 12:10 PM 8/22/2006, Lee Parkes wrote:
Hi, In the course of our work my colleagues and I use Nessus as the primary vulnerability assesment tool. However, in this age of 'risk management' the upper management have decided that we should use at least two distinct scanning tools. Whilst we use Qualys for remote scans, we can't use it on most on-site jobs. My question is, is there another scanner, free or payware, that people recommend as being of comparable quality to Nessus? The preference is for a tool that isn't based on Nessus so that we have two independent scans.
Hi Lee, Although I firmly respect anyone's wishes to use two scanners, I would consider the following thoughts: - You are absolutely right to make sure that the second vendor does not base their scans or data off of Nessus. And even if they don't run the "nessus" engine, you should pick the last 10 or so Bugtraq IDs or CVEs and see when the vendor added them. You may or may not be surprised how often new checks in 3rd party scanners get added once they hit the Nessus registered feed. - Instead of two scanners, I would really argue to use two or more technologies. Assume for a second that two network scanner technologies are roughly equal. What value does adding credentialed patch auditing to the mix? When Nessus connects to port 80 and starts doing web analysis, this is a completely different process then when it logs in via a domain or credentials and performs a patch audit. - If there is a question in the quality of the scans or the accuracy of the results, I would highly recommend that a passive continuous solution like our Passive Vulnerability Scanner be used. Passive network monitoring is real-time and sees everything on the network regardless of port, protocol or client-side firewalls. Ron Gula, CTO Tenable Network Security http://www.nessus.org http://www.tenablesecurity.com http://blog.tenablesecurity.com _______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Other scanners?, Bill Petersen |
|---|---|
| Next by Date: | Nessus 3.0.3 for Windows : Windows 2000, XP and 2003, isolvesystems |
| Previous by Thread: | Re: Other scanners?, Bill Petersen |
| Next by Thread: | Nessus 3.0.3 for Windows : Windows 2000, XP and 2003, isolvesystems |
| Indexes: | [Date] [Thread] [Top] [All Lists] |