|
Patch
Management for Microsoft Operating
Systems and Applications GFI
LANguard’s patch management feature
scans automatically, or on demand, your
network and gives you all the
functionality and tools you need to
effectively install and manage patches
on all machines across different
Microsoft operating systems and products
in all languages supported by the
vendor. GFI LANguard allows
auto-downloads of missing patches as
well as patch roll-back, resulting in a
consistently configured environment that
is secure against vulnerabilities.
Patch
Management for Other Applications
GFI LANguard offers
patch management support for other
(non-Microsoft) software, enabling
administrators to detect, download and
deploy missing patches for supported
applications in the same way as is done
for Microsoft updates. GFI LANguard
offers patch management support for many
popular applications like Apple
QuickTime, Adobe Acrobat, Adobe Flash
Player, Adobe Reader, Adobe Shockwave
Player, Mozilla Firefox, Mozilla
Thunderbird, Java Runtime and others.
With GFI LANguard,
not only is it possible to patch third
party applications, but also to upgrade
to their latest versions (i.e., if an
old version of Adobe Flash is detected,
GFI LANguard will provide an option to
either upgrade to the latest version or
to apply all patches for that version).
GFI LANguard is the
first solution that automates patching
for all major web browsers running on
Windows systems: Microsoft Internet
Explorer, Mozilla Firefox, Google
Chrome, Apple Safari and Opera Browser.
Deploys
Custom and Third Party Software
and Patches Network-wide
Besides
deploying patches and service packs,
GFI LANguard also enables you to easily
deploy third party software or patches
network-wide. You can use this feature
to deploy client software, and update
software, virus updates and more;
practically any application that can run
silently can be pushed in the network
using GFI LANguard.
Agents
Technology GFI LANguard can
be configured to run either in
agent-less or agent-based mode. The
agents technology enables automated
audits and distributes the scanning load
across client machines. The
administrator simply needs to define the
network perimeter and provide
credentials to enable automatic network
discovery, agent deployment and auditing
of the client machines. Manual
intervention is necessary only when
fine-tuning is required. This feature
provides the following benefits:
Automatic
Remediation of Unauthorized Applications
Remediation operations can be triggered
automatically at the end of scheduled
scans. Apart from reporting on all
installed applications, GFI LANguard
allows the user to define which
applications are authorized or not
authorized to be installed on the
network. This list of applications can
be easily defined for each scanning
profile using the Applications Inventory
Tool. During a scan, any unauthorized
applications are identified and
(optionally) uninstalled automatically
by GFI LANguard. An integrated
Auto-Uninstall Validation tool is
provided to help identify which of the
detected applications support silent
uninstall and can thus be safely and
automatically uninstalled.
Remote
Desktop Connection GFI
LANguard allows the useful option of a
remote desktop connection to fix
security issues on scanned computers
that cannot be fixed automatically.
Vulnerability Assessment
During security
audits, over 45,000 vulnerability
assessments are made - scanning the
network IP by IP. GFI LANguard gives you
the capability to perform multi-platform
scans (Windows, Mac OS, Linux) across
all environments - including Virtual
Machines and to analyze your network’s
security set-up and status. GFI LANguard
gives you the power to identify and
correct any threats before hackers can
exploit them.
Set up your
own Custom Vulnerability Checks
GFI LANguard allows you to easily create
custom vulnerability checks through
simple wizard-assisted set-up screens.
The wizard is powerful enough to allow
building of complex vulnerability checks
and the scripting engine is compatible
with Python and VBScript. GFI LANguard
includes a script editor and debugger to
help with script development.
Extensive,
Industrial Strength Vulnerabilities
Database GFI LANguard ships
with a complete and thorough
vulnerability assessment database,
including standards such as OVAL (5,000+
checks) and SANS Top 20. This database
is regularly updated with information
from BugTraq, SANS Corporation, OVAL,
CVE and others. Through its auto-update
system, GFI LANguard is always kept
up-to-date with information about newly
released Microsoft security updates as
well as new vulnerability checks issued
by GFI Software and other
community-based information repositories
such as the OVAL database.
Identify
Security Vulnerabilities and Take
Remedial Action GFI LANguard
scans computers, identifies and
categorizes security vulnerabilities,
recommends a course of action and
provides tools that enable you to solve
the problem. GFI LANguard comes with a
graphic threat level indicator that
provides an intuitive, weighted
assessment of the vulnerability status
of a scanned computer or group of
computers. Wherever possible, a web link
or more information on a particular
security issue is provided - such as a
BugTraq ID or a Microsoft Knowledge Base
article ID.
Helps Ensure
Third Party Security Applications Offer
Optimum Protection GFI
LANguard integrates with over
1,500 critical security applications of
the following categories: antivirus,
antispyware, firewall, anti-phishing,
backup client, VPN client, URL
filtering, patch management, web
browser, instant messaging,
peer-to-peer, disk encryption, data loss
prevention and device access control. It
provides reports on their status, e.g.,
if antivirus is enabled and up-to-date,
the firewall is turned on, the status of
backup software, a list of which instant
messaging or peer-to-peer applications
are installed in your network, etc. It
also rectifies any issues that require
attention, e.g., trigger
antivirus/antispyware update, start
antivirus/antispyware scans, enable
antivirus/firewall, or uninstall
peer-to-peer, etc.
Easily
Creates Different Types of Scans and
Vulnerability Tests You can
easily configure scans for different
types of information, such as open
shares on workstations, security audit
and password policies, and machines
missing a particular patch or service
pack. You can scan for different types
of vulnerability to identify potential
security issues. These include:
-
Open
ports: GFI LANguard scans
for unnecessary open ports and
checks that no port hijacking is in
force
-
Unused
local users and groups: GFI
LANguard removes or disables User
Accounts which are no longer in use
-
Blacklisted applications:
With GFI LANguard, you can identify
unauthorized or dangerous software
and add to blacklists of
applications you want to associate
with a high security vulnerability
alert
-
Dangerous USB devices, wireless
nodes and links: GFI
LANguard scans all devices connected
to USB or wireless links and alerts
you of any suspicious activit
Netowrk and softare auditing
GFI LANguard’s
Network Auditing gives you a
comprehensive view of your network
- what USB devices are connected, what
software is installed, any open shares,
open ports and weak passwords in use,
and hardware information. The solution's
in-depth reports give you an important
and real-time snapshot of your network's
status. Scan results can be easily
analyzed using filters and reports,
enabling you to proactively secure the
network by closing ports, deleting users
or groups which are no longer in use, or
disabling wireless access points.
Hardware
Auditing GFI LANguard shows
detailed information about the hardware
configuration of all the scanned
machines on your network. All devices
from the Device Manager tool from
Windows operating systems are retrieved,
including motherboard, processors,
memory, storage devices, display
adapters and much more. U
Automatically Receive Alerts of New
Security Holes By default,
GFI LANguard generates a daily digest
report that contains all relevant
security changes that occurred on your
network that day. Any new security holes
or security set-up changes discovered on
your network are emailed to you for
analysis. This enables you to quickly
identify newly-created shares, installed
services, installed applications, added
users, newly-opened ports and more. GFI
LANguard will generate specific reports
and email notification whenever there
are software or hardware changes
detected within the audited network.
Check to
Ensure Security Auditing is Enabled
Network-wide GFI LANguard
checks if each XP/2003/VISTA/2008/2008
R2/7 machine has security auditing
enabled. If not, GFI LANguard alerts you
and allows you to enable auditing
remotely. Security event auditing is
highly recommended as it detects
intruders in real time.
Scan and
Retrieve OS data from Linux Systems
It is possible to remotely extract OS
data from Linux-based systems and scan
results are presented in the same way as
for Windows-based computers. This means
that both Linux and Windows-based
computers can be analyzed in a single
scanning session! GFI LANguard includes
numerous Linux security checks including
rootkit detection.
New!
Powerful Interactive Dashboard
GFI LANguard has a new powerful and
interactive dashboard that processes all
security audits ever made to the
network. It provides a summary of
current network security status and a
history of all relevant changes in the
network over time. It also drills down
through information starting from
network-wide security sensors to
individual security scan results.
Multiply the
Value of GFI LANguard with Powerful
Reporting Reports are
designed to satisfy the requirements of
both management and technical staff. In
the latest version of GFI LANguard,
reports are integrated within the main
application. All reports are based on a
computer’s current status, and not on
specific scans. These reports can be
exported to popular formats like PDF,
HTML, XLS, XLSX, RTF and CVS, and can be
scheduled and sent by email. They can
also be used as a template to create new
custom reports and are fully
re-brandable.
Helps You
Comply with PCI DSS and Other
Regulations All businesses
handling cardholder data, regardless of
size, have to be fully compliant with
strict security standards drawn up by
the world’s major credit card companies.
GFI LANguard provides complete
vulnerability management coupled with an
extensive reporting. That makes GFI
LANguard an essential, highly
cost-effective solution for your
organization to safeguard your network
and gauge the effectiveness of your PCI
compliance program.
Silent
Installation Support You can
perform an unattended default
installation of GFI LANguard on multiple
computers in the background without any
user interaction or intervention.
New! Network
Discovery Not Bound by License
Limitations With the latest
version of GFI LANguard, license slots
are no longer required for all computers
and devices in the scan results
database. Only the ones that are scanned
beyond network discovery are bound by
license limitations.
Predefine
Authentication Details GFI
LANguard allows you to store separate
authentication details for every target
computer on your network, avoiding the
need to specify authentication
credentials prior to every scan. In a
single scanning session, it is possible
to audit all the targets in your
network, even if they require different
authentication details and/or methods.
New! Full
Text Search Support GFI
LANguard makes it possible for users to
instantly locate the information they
are interested in. Searching the scan
results is now as easy as searching on
the Internet. The search displays
instant results with links to relevant
items. You can search for both current
and past events and for specific items
like vulnerabilities, installed
applications, missing patches etc.
Support for
Virtual Environments
Organizations that use or plan to use
virtualization on their network can
install and use a range of GFI products
with confidence. GFI LANguard supports
and runs on the most common
virtualization technologies in use,
namely VMware, Microsoft Virtual Server,
Microsoft Hyper-V, Citrix and Parallel.
It also offers detection of virtual
machines hosted by the scanned computer.
News Section
GFI LANguard features a news section –
an easy way to find out about product
updates. This section informs you about
any new patches that will be supported
by GFI LANguard, any new applications
that have become available for patch
management, and any new vulnerabilities
that have been added to the database.
|