GFI
English Deutsch Français Italiano Nederlands Español
Products > GFI LANguard > Features  Print this page  |  Datasheet

Integrated vulnerability management solution

GFI LANguard is an award-winning solution that addresses the three pillars of vulnerability management: security scanning, patch management and network auditing through a single, integrated console. By scanning the entire network, it identifies all possible security issues and using its extensive reporting functionality provides you with the tools you need to detect, assess, report and rectify any threats.

 Vulnerability scanning

During security audits, over 15,000 vulnerability assessments are made and networks are scanned IP by IP. GFI LANguard gives you the capability to perform multi-platform scans (Windows, Mac OS, Linux) across all environments including Virtual Machines and to analyze your network’s security set-up and status. This ensures that you are able to identify and rectify any threats before hackers manage to do so.

NEW! – Detection of Virtual Machines

GFI LANguard can now detect whether a scanned machine is rear or virtual. Currently both VMware and Virtual PC software are supported.

IMPROVED! –  set-up your own custom vulnerability checks

GFI LANguard allows you to easily create custom vulnerability checks through simple wizard-assisted set-up screens. The wizard is also powerful enough to allow building of complex vulnerability checks. The scripting engine is also compatible with Python and VBScript. GFI LANguard includes a script editor and debugger to help with script development.

IMPROVED! – Extensive, industrial-strength vulnerabilities database

GFI LANguard ships with a complete and thorough vulnerability assessment database, which includes standards such as OVAL (2,000+ checks) and SANS Top 20. This database is regularly updated with information from BugTraq, SANS Corporation, OVAL, CVE and others. Through its auto-update system, GFI LANguard is always kept updated with information about newly released Microsoft security updates as well as new vulnerability checks issued by GFI and other community-based information repositories such as the OVAL database.

Identify security vulnerabilities and take remedial action

GFI LANguard scans computers, identifies and categorizes security vulnerabilities, recommends a course of action and provides tools that enable you to solve these issues. GFI LANguard also makes use of a graphical threat level indicator that provides an intuitive, weighted assessment of the vulnerability status of a scanned computer or group of computers. Wherever possible a web link or more information on a particular security issue is provided, such as a BugTraq ID or a Microsoft Knowledge Base article ID. View screenshot.

Ensures that third party security applications such as anti-virus and anti-spyware offer optimum protection

GFI LANguard also checks that supported security applications such as anti-virus and anti-spyware software are updated with the latest definition files and are functioning correctly. For example, you can ensure that supported security applications have all key features (such as real-time scanning) enabled.

Easily creates different types of scans and vulnerability tests

You can easily configure scans for different types of information; such as open shares on workstations, security audit/password policies and machines missing a particular patch or service pack. You can scan for different types of vulnerabilities to identify potential security issues. These include:

  • Open ports: GFI LANguard scans for unnecessary open ports and checks that no port hijacking is in force.
  • Unused local users and groups: Remove or disable User accounts no longer in use.
  • Blacklisted applications: Identify unauthorized or dangerous software and add to blacklists of applications you want to associate with a high security vulnerability alert.
  • Dangerous USB devices, wireless nodes and links: Scans all devices connected to USB or wireless links and alerts you of any suspicious activity.
  • And much more! View screenshot.

Easily analyze and filter scan results

GFI LANguard enables you to easily analyze and filter scan results by clicking on one of the default filter nodes. This enables you to identify, for example, machines with high security vulnerabilities or machines that are missing a particular service pack. Custom filters can also very easily be created from scratch or customized. You can also export scan results data to XML. View screenshot.

 Patch management and remediation

When a scan is complete, GFI LANguard gives you all the functionality and tools you need to effectively install and manage patches on all machines across different Microsoft operating systems and products in 38 languages. Click here to view a full list. GFI LANguard also allows auto-downloads of missing patches as well as patch roll-back. Custom software can also be deployed. This results in a consistently configured environment that is secure against all vulnerabilities.

IMPROVED! – Automatically deploy network-wide patch and service pack management

With GFI LANguard you can easily deploy missing service packs and patches network-wide. GFI LANguard is the ideal tool to monitor that Microsoft WSUS is doing its job properly and it performs tasks WSUS does not such as deploying Microsoft Office and custom software patches. GFI LANguard also provides you with new features such as patch auto-download and patch rollback. It is also Unicode compliant and able to support patch management in all the 38 languages currently supported by Microsoft. The network administrator also has the option to either to manually approve each patch or set all Microsoft updates as approved. If patches are approved manually the network administrator can choose to receive email notifications when new Microsoft updates are available.View screenshot.

NEW! –  Automatic remediation of unauthorized applications

Remediation operations can be triggered automatically at the end of scheduled scans. Apart from reporting on all installed applications, GFI LANguard 9 allows the user to define which applications are authorized or not authorized to be installed on the network. This list of applications can be easily defined for each scanning profile using the Applications Inventory Tool. During a scan, any unauthorized applications are identified and (optionally) uninstalled automatically by GFI LANguard. An integrated Auto-Uninstall Validation tool is provided to help identify which of the detected applications support silent uninstall and can thus be safely and automatically uninstalled.

NEW! – Remote Desktop Connection

GFI LANguard allows the useful option of a remote desktop connection to fix security issues on scanned computers that cannot be fixed automatically.

Deploys custom/third party software and patches network-wide

Besides deploying patches and service packs, GFI LANguard enables you to easily deploy third party software or patches network-wide. You can use this feature to deploy client software, update custom or non-Microsoft software, virus updates and more. The custom software deployment feature means you can do without Microsoft SMS, which is too complex and expensive for small to medium sized networks. View screenshot.

 Network and software auditing

GFI LANguard’s auditing function tells you all you need know about your network – what USB devices are connected, what software is installed, any open shares, open ports and weak passwords in use and hardware information. The solution’s in-depth reports gives you an important and real-time snapshot of your network’s status. Scan results can be easily analyzed using filters and reports, enabling you to proactively secure the network by closing ports, deleting users or groups no longer in use or disabling wireless access points.

NEW! – Extended Hardware auditing facility

GFI LANguard can now show detailed information about the hardware configuration of all the scanned machines on your network. All devices from the “Device Manager” tool from windows operating systems are retrieved including motherboard, processors, memory, storage devices, display adapters, and much more. Using baseline comparisons you can now check whether any hardware was added/removed since last scan.

Automatically receive alerts of new security holes

GFI LANguard can perform scheduled scans (for instance daily or weekly) and can automatically compare results to previous scans. Any new security holes or security set-up changes discovered on your network are emailed to you for analysis. This enables you to quickly identify newly-created shares, installed services, installed applications, added users, newly-opened ports and more. GFI LANguard will generate specific reports and email notification whenever there are software or hardware changes detected within the audited network. Specific reports also show what remediation operations were performed. View screenshot.

Check if security auditing is enabled network-wide

GFI LANguard checks if each NT/2000/XP/VISTA machine has security auditing enabled. If not, GFI LANguard alerts you and allows you to enable auditing remotely. Security event auditing is highly recommended because it detects intruders in real-time.

Scan and retrieve OS data from Linux systems

It is possible to remotely extract OS data from Linux-based systems and scan results are presented in the same way as for Windows-based computers. This means that both Linux and Windows-based computers can be analyzed in a single scanning session! GFI LANguard includes numerous Linux security checks including rootkit detection. GFI LANguard can use SSH Private Key files instead of the conventional password string credentials to authenticate to Linux-based target computers.

 Other features

NEW! – A fresh, new look which allows effective use of GFI LANguard

GFI LANguard now ships with a new user interface which allows network administrators to easily scan the network to perform vulnerability assessment and retrieve relevant security information, analyze the results and generate reports and remediate the security issues that were detected.

NEW! – Monitoring Dashboard

The GFI LANguard dashboard shows summarized results of all scans from the database and provides and overview of the most vulnerable computers and security status trends of the network.

IMPROVED! – Multiply the value of GFI LANguard with powerful reporting

Reports are designed to satisfy the requirements of both management and technical staff. These deliver a graphical snapshot of the security health status of your network. From trend reports for management (ROI) to daily drill-down reports for technical staff; the GFI LANguard provides you with the easy-to-view information you need, to fully keep abreast of changes to your network’s security environment. Full automation and custom scheduling. Executive reports are now available directly from within GFI LANguard.

Helps to comply with PCI DSS and other regulations

As from September 2007 all businesses handling cardholder data – irrespective of size – have to be fully compliant with strict security standards drawn up by the world’s major credit card companies. GFI LANguard provides complete vulnerability management coupled with an extensive ReportPack add-on that make GFI LANguard the essential, cost-effective solution that your organization needs to safeguard your network and gauge the effectiveness of your PCI compliance program. More information about PCI DSS.

Silent installation support

You can perform an unattended default installation of GFI LANguard on multiple computers in the background without any user interaction or intervention. Customization of the deployment parameters is also possible through the creation of Microsoft Transform (MST) files. More information about MST files!

Predefine authentication details

GFI LANguard allows you to store separate authentication details for every target computer on your network, avoiding the need to specify authentication credentials prior to every scan. In a single scanning session, it is possible to audit all the targets in your network, even if they require different authentication details/methods.

Other features:

  • Automatically checks the password policy for all machines on the network
  • Checks for programs that run automatically (potential trojans)
  • Finds out if the OS is advertising too much information
  • Performs simultaneous scans through the multithread scan engine
  • Provides NetBIOS hostname, currently logged username and MAC address
  • Provides a list of shares, users (detailed info), services, sessions, remote TOD (time of day) and registry information from remote computer (Windows)
  • SNMP device detection, SNMP Walk for inspecting network devices like routers, network printers and more
  • Offers alternative command line deployment tool
  • Identifies all installed Windows services
  • Support for Microsoft Windows Vista.

You're in good company...

Many leading companies have chosen GFI LANguard Here are just a few: Daimler Chrysler, NATO, Siemens Communications Limited, EDS, United Overseas Bank Ltd, Virgin Mobile, Medical Research Council (UK), Anglicare, KLM, and many more. Customer list and customer testimonials.

System requirements

Windows 2000 (SP4), XP (SP2), 2003, VISTA operating system
Internet Explorer 5.1 or higher
Client for Microsoft Networks component – included by default in Windows 95 or higher
Secure Shell (SSH) – this is included by default in every Linux OS distribution pack.
 

For more detailed system requirements, please see the installation chapter.



 Quick Links
>   GFI LANguard screenshots
>   What is the difference with MBSA?
>   What's new in GFI LANguard 9?
>   If I use Microsoft SUS, do I still need GFI LANguard?
>   How does GFI LANguard compare to other patch management solutions?
>   Vulnerability databases; does size matter?
>   What applications can GFI LANguard update?
>   View installation instructions & system requirements
>   More frequently asked questions


 Screenshots

GFI LANguard

Launch a new scan

Launch a new scan


GFI LANguard full scan in progress

GFI LANguard full scan in progress


GFI LANguard scan results

GFI LANguard scan results


Indicates vulnerabilities found

Indicates vulnerabilities found


Uninstall unauthorized applications

Uninstall unauthorized applications


GFI LANguard - Scanning profile management

GFI LANguard - Scanning profile management


GFI LANguard - Configuring the vulnerabilities to scan

GFI LANguard - Configuring the vulnerabilities to scan


GFI LANguard - Configuring which patches to scan

GFI LANguard - Configuring which patches to scan



 Screenshots

GFI LANguard ReportPack

Executive report showing network vulnerability summary

Executive report showing network vulnerability summary


Executive report showing network vulnerability trend

Executive report showing network vulnerability trend


Statistical report showing operating system and service pack distribution

Statistical report showing operating system and service pack distribution


   © 2008. All rights reserved. GFI Software Home Products Download trials Support Ordering Site map About us Contact us
GFI solutions: Exchange anti spam filter - exchange anti virus - isa server - network vulnerability scanner - event log management - USB security software - exchange archiving - fax server software