|
Features
GFI offers a freeware version of GFI LANguard™ for non-commercial use. The freeware version allows you to scan up to five IPs for free using the product’s full feature set, with the exception of patch management for non Microsoft applications, which is only available in the commercial version.
Patch Management and Remediation Across Different Microsoft OSs and Products
GFI LANguard performs a scan of your network and gives you all the functionality and tools you need to effectively install and Manage Patches on all machines across different Microsoft operating systems and products in 38 languages. Click here to view a full list.
GFI LANguard also allows auto-downloads of missing patches as well as patch roll-back and custom software can be deployed, resulting in a consistently configured environment that is secure against vulnerabilities.
Patch Management for Non-Microsoft Software
GFI LANguard also offers patch management support for non-Microsoft software, enabling administrators to detect, download and deploy missing patches for supported applications in the same way as is done for Microsoft updates. GFI LANguard offers patch management support for many popular applications like Apple Quicktime, Adobe Acrobat, Adobe Flash Player, Adobe Reader, Adobe Shockwave Player, Mozilla Firefox, Mozilla Thunderbird, Java Runtime and others. Click here for a full list
With GFI LANguard, it is possible not just to patch third party applications, but also to upgrade to their latest versions (i.e. if an old version of Adobe Flash is detected, GFI LANguard will provide an option to either upgrade to the latest version or to apply all patches for that version).
GFI LANguard is the first solution that automates patching for all major web browsers running on Windows systems: Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Apple Safari and Opera Browser.
Automatically Deploy Network-wide Patch and Service Pack Management
With GFI LANguard you can easily deploy missing service packs and patches network-wide. GFI LANguard is the ideal tool to ensure that Microsoft WSUS is working properly and it performs tasks WSUS does not, such as patching third party applications and deploying custom software patches. GFI LANguard also provides you with new features such as patch auto-download and patch rollback. It is also Unicode compliant and able to support patch management in all languages supported by Microsoft. The network administrator has the option to either manually approve each patch or set all Microsoft updates as approved. If patches are approved manually the network administrator can choose to receive email notifications when new Microsoft updates are available.
Automatic Remediation of Unauthorized Applications
Remediation operations can be triggered automatically at the end of scheduled scans. Apart from reporting on all installed applications, GFI LANguard allows the user to define which applications are authorized or not authorized to be installed on the network. This list of applications can be easily defined for each scanning profile using the Applications Inventory Tool. During a scan, any unauthorized applications are identified and (optionally) uninstalled automatically by GFI LANguard. An integrated Auto-Uninstall Validation tool is provided to help identify which of the detected applications support silent uninstall and can thus be safely and automatically uninstalled.
Remote Desktop Connection
GFI LANguard allows the useful option of a remote desktop connection to fix security issues on scanned computers that cannot be fixed automatically.
Deploys Custom and Third Party Software and Patches Network-wide
Besides Deploying Patches and Service Packs, GFI LANguard enables you to easily deploy third party software or patches network-wide. You can use this feature to deploy client software, update custom or non-Microsoft software, virus updates and more; practically any application that can run silently can be pushed in the network using GFI LANguard. This custom software deployment feature means you can do without Microsoft SMS, which is complex and too expensive for small to medium-sized networks.
Vulnerability Scanning
During security audits, over 15,000 vulnerability assessments are made - scanning the network IP by IP. GFI LANguard gives you the capability to perform multi-platform scans (Windows, Mac OS, Linux) across all environments - including Virtual Machines and to analyze your network’s security set-up and status. GFI LANguard gives you the power to identify and correct any threats before hackers can exploit them.
Set up your own Custom Vulnerability Checks
GFI LANguard allows you to easily create custom vulnerability checks through simple wizard-assisted set-up screens. The wizard is powerful enough to allow building of complex vulnerability checks and the scripting engine is compatible with Python and VBScript. GFI LANguard includes a script editor and debugger to help with script development.
Extensive, Industrial Strength Vulnerabilities Database
GFI LANguard ships with a complete and thorough vulnerability assessment database, including standards such as OVAL (2,000+ checks) and SANS Top 20. This database is regularly updated with information from BugTraq, SANS Corporation, OVAL, CVE and others. Through its auto-update system, GFI LANguard is always kept up-to-date with information about newly released Microsoft security updates as well as new vulnerability checks issued by GFI Software and other community-based information repositories such as the OVAL database.
Identify Security Vulnerabilities and Take Remedial Action
GFI LANguard scans computers, identifies and categorizes security vulnerabilities, recommends a course of action and provides tools that enable you to solve the problem. GFI LANguard comes with a graphic threat level indicator that provides an intuitive, weighted assessment of the vulnerability status of a scanned computer or group of computers. Wherever possible, a web link or more information on a particular security issue is provided - such as a BugTraq ID or a Microsoft Knowledge Base article ID.
Ensures Third Party Security Applications (Antivirus and Anti-Spyware) Offer Optimum Protection
GFI LANguard ensures that supported security applications such as antivirus and anti-spyware software are updated with the latest definition files and are functioning correctly. For example, you can check to be certain that supported security applications have all key features (such as real-time scanning) enabled.
Easily Creates Different Types of Scans and Vulnerability Tests
You can easily configure scans for different types of information, such as open shares on workstations, security audit and password policies, and machines missing a particular patch or service pack. You can scan for different types of vulnerability to identify potential security issues. These include:
- Open ports: GFI LANguard scans for unnecessary open ports and checks that no port hijacking is in force
- Unused local users and groups: GFI LANguard removes or disables User Accounts which are no longer in use
- Blacklisted applications: With GFI LANguard, you can identify unauthorized or dangerous software and add to blacklists of applications you want to associate with a high security vulnerability alert
- Dangerous USB devices, wireless nodes and links: GFI LANguard scans all devices connected to USB or wireless links and alerts you of any suspicious activity
And much more!
Easily Analyze and Filter Scan Results
GFI LANguard enables you to easily analyze and filter scan results by clicking on one of the default filter nodes. This enables you to identify, for example, machines with high security vulnerabilities or machines that are missing a particular service pack. Custom filters can also very easily be created from scratch or customized from and existing script. Also, you can export scan results data to XML.
Network and Software Auditing
GFI LANguard’s Network Auditing gives you a comprehensive view of your network - what USB devices are connected, what software is installed, any open shares, open ports and weak passwords in use, and hardware information. The solution's in-depth reports give you an important and real-time snapshot of your network's status. Scan results can be easily analyzed using filters and reports, enabling you to proactively secure the network by closing ports, deleting users or groups which are no longer in use, or disabling wireless access points.
Hardware Auditing
GFI LANguard shows detailed information about the hardware configuration of all the scanned machines on your network. All devices from the Device Manager tool from Windows operating systems are retrieved, including motherboard, processors, memory, storage devices, display adapters and much more. Using baseline comparisons you can now check whether any hardware was added or removed since the last scan.
Automatically Receive Alerts of New Security Holes
GFI LANguard can perform routine scheduled scans and can automatically compare results to previous scans. Any new security holes or security set-up changes discovered on your network are emailed to you for analysis. This enables you to quickly identify newly-created shares, installed services, installed applications, added users, newly-opened ports and more. GFI LANguard will generate specific reports and email notification whenever there are software or hardware changes detected within the audited network. Our reports also show what remediation operations were performed.
Check to Ensure Security Auditing is Enabled Network-wide
GFI LANguard checks if each NT/2000/XP/2003/VISTA/2008/2008 R2/7 machine has security auditing enabled. If not, GFI LANguard alerts you and allows you to enable auditing remotely. Security event auditing is highly recommended as it detects intruders in real time.
Scan and Retrieve OS data from Linux Systems
It is possible to remotely extract OS data from Linux-based systems and scan results are presented in the same way as for Windows-based computers. This means that both Linux and Windows-based computers can be analyzed in a single scanning session! GFI LANguard includes numerous Linux security checks including rootkit detection. GFI LANguard can use SSH Private Key files instead of the conventional password string credentials to authenticate to Linux-based target computers.
Additional Features
Dashboard
The GFI LANguard dashboard shows summarized results of all scans from the database and provides an overview of the most vulnerable computers and security status trends of the network.
Multiply the Value of GFI LANguard with Powerful Reporting
Reports are designed to satisfy the requirements of both management and technical staff. GFI LANguard delivers a graphical snapshot of the security status of your network. From trend reports for management (ROI) to daily drill-down reports for technical staff, GFI LANguard provides you with the easy-to-view information you need to fully keep on top of your network’s security environment. Executive reports are now available directly from within GFI LANguard.
Helps You Comply with PCI DSS and Other Regulations
All businesses handling cardholder data, regardless of size, have to be fully compliant with strict security standards drawn up by the world’s major credit card companies. GFI LANguard provides complete vulnerability management coupled with an extensive reporting ReportPack add-on. That makes GFI LANguard an essential, highly cost-effective solution for your organization to safeguard your network and gauge the effectiveness of your PCI compliance program.
Silent Installation Support
You can perform an unattended default installation of GFI LANguard on multiple computers in the background without any user interaction or intervention.
Predefine Authentication Details
GFI LANguard allows you to store separate authentication details for every target computer on your network, avoiding the need to specify authentication credentials prior to every scan. In a single scanning session, it is possible to audit all the targets in your network, even if they require different authentication details and/or methods.
Support for Virtual Environments
Organizations that use or plan to use virtualization on their network can install and use a range of GFI products with confidence. GFI LANguard supports and runs on the most common virtualization technologies in use, namely VMware, Microsoft Virtual Server and Microsoft Hyper-V. It also offers detection of virtual machines hosted by the scanned computer.
New! News Section
GFI LANguard features a news section – an easy way to find out about product updates. This section informs you about any new patches that will be supported by GFI LANguard, any new applications that have become available for patch management, and any new vulnerabilities that have been added to the database.
Localization
GFI LANguard is also available in Italian and German.
Other Features:
- Automatically checks the password policy for all machines on the network
- Checks for programs that run automatically (potential trojans)
- Finds out if the OS is advertising too much information
- Performs simultaneous scans through the multithread scan engine
- Provides NetBIOS hostname, currently logged username and MAC address
- Provides a list of shares, users (detailed info), services, sessions, remote TOD (time of day) and registry information from remote computer (Windows)
- SNMP device detection, SNMP Walk for inspecting network devices like routers, network printers and more
- Offers alternative command line deployment tool
- Identifies all installed Windows services
- Supports Microsoft Windows 7 and Microsoft Windows Server 2008 R2
|