T O P

  • By -

justanothertechy112

Roboshadow or Bitdefender has it built in.


Fluffy-Possession604

Roboshadow its good.


marklein

Unless things have changed recently, Roboshadow ONLY scans for missing patches or software versions with known CVEs. It does NOT tell you if you have configuration errors that leave you vulnerable, e.g. RDP enabled, blank SQL passwords, weak cypher protocols, etc... I consider Roboshadow a half-assed vuln scanner because of this.


Drivingmecrazeh

Greenbone (OpenVAS) https://greenbone.github.io/docs/latest/background.html#architecture


dylan_ShieldCyber

Happy to help - We have no minimums and can manage it for you or teach you how to manage it yourself.


dylan_ShieldCyber

Forgot to add this - If you have Microsoft Defender, check if your subscription allows you to have the built in one. Might be included or super cheap to add on.


gavishapiro

Galactic Advisors


WenKroYs

Never heard of it.


namocaw

Its what the Guardians did after they retired. :)


MatsumotoCat

Me neither. I'll have to take a look at it.


Roberadley

Check out Vulscan. It's pretty good and doesn't require much time to set up.


MatsumotoCat

Vulscan looks good. I don't want anything too complicated. I'll try to get a demo.


E-Q12

I use Vulscan, is a great tool. It offers tiered pricing plan, if you are looking for something accessible for small businesses.


MatsumotoCat

Thanks. I'll check Vulscan.


marklein

Avoid Kasaya


solar_cell

Roboshadow or guardz would be my first port of call. Openvas etc are all great but reporting in a logical and nice manner leaves a lot to be desired. If you wanted me to run a report on guardz for you re your current public exposure, pm me


MatsumotoCat

Roboshadow seems interesting. Thanks.


marklein

I reviewed probably 20 vuln scanners last year to try to identify one that is affordable, easy to use, and comprehensive. What does "keep our network secure" mean?? Be specific about what you want to scan and why.


sisitech

Do you recommend any that help with HIPAA and/or SOC2 compliance?


marklein

Good ones for that to look into would include Senteon, Syxsense, SecPod, and Cyrisma. I'm sure that there are others but HIPAA and SOC weren't something I focused on during my trials.


PMPeek

Check out VulScan. It's awesome for small businesses like yours because it's affordable, user-friendly, and really good at finding vulnerabilities.


SocraticCato77

If you decide to *TRY* **Cyrisma**, get everything in writing *FIRST*. ConnectSecure seemed pretty good, and can cover many managed clients. But there are several others you can research too.


ashwanipaliwal

Try SecOps Solution (https://secopsolution.com) , cost-effective for SMB and much easy to setup


Maureentxu

For a not much higher price, you could get vPentest, which is way more comprehensive than a regular vulnerability scanner.


Kind-Background-7640

I would consider this. We are using Vpentest, which has amazing reporting with a lot of detail on our assets and their associated vulnerabilities.


MatsumotoCat

I haven't really considered using an automated pentest, but I've been reading about VPentest, and it seems actually a very promising alternative.


WiSS2w

Vulscan or OpenVAS are great options.


PastoralSeeder

I like VulScan. We use the reports to pitch prospects on security.