Categories
Welcome Center
Education & Development
Cyber Security
Virtualization
General
Certification Preparation
Project Management
Posts
Groups
Training Resources
Infosec
IT & Security Bootcamps
Practice Exams
Security Awareness Training
About Us
Home
General
Off-Topic
external security scan
ajs1976
Can anyone recommend an external scan tool or service that can be used as an as needed check between annual pen tests? I have looked into Qualys and Nessus and they seem a little expensive for what i'm trying to accomplish.
Find more posts tagged with
Comments
MSP-IT
OpenVAS?
docrice
Qualys and Tenable are probably priced the way they are because they are actively updating their vuln sigs, etc.. It's been forever since I've looked into OpenVAS, but I'm unsure how much it has matured and its signature quality. There's also Rapid7, although I haven't used their solution yet.
A vuln scan is something you generally don't want to do only once a year, let alone once a month. I'm a proponent of continuously scanning and detecting unexpected changes or new vulnerabilities in your environment as issues come up (like Shellshock and Heartbleed).
NightShade03
I'm sorry but this isn't an area where you want to "cheap out". Docrice has a great point that you shouldn't be doing this once a year, but a continuous thing (weekly if possible / automated). Every single product you look at in this space - Rapid7, whitehat, nessus, Qualys, etc - are all going to be very pricey. You can go the OpenVAS route, but you'll always be behind in signatures and latest features because it's open source. It's a good product but it semi-defeats the purpose of being up to date and scanning for the latest vulnerabilities.
Quick Links
All Categories
Recent Posts
Activity
Unanswered
Groups
Best Of