cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
ErikT
Lansweeper Tech Support
Lansweeper Tech Support

Security Insights is a feature in Lansweeper Cloud currently in Preview mode. It provides insights into which assets are potentially vulnerable. It will not replace a scanner. Features in Preview mode are still being actively worked on in the background, but we feel are already mature enough for you to experience and use while we take your valuable feedback to further improve for the final launch. 

Currently, when we calculate the vulnerabilities, we only take the CPEs (CPE: Common Platform Enumerator) we receive from NIST into account. For example, updating the version of a software/library is something easy to track, so if that is the case, it will be reflected once it is updated in the CVE. Still, things like a change in a configuration or a combination of several actions can be complicated to track.

Another example is when a Windows KB (quick-fix) patches a vulnerability but does not change CPE; we will still mark the asset as vulnerable. We currently do not consider Windows KBs if they do not modify the CPE. The CPE is typically only updated when the Windows build number changes.

We are currently working to improve our analysis capabilities, so we can expect to see fewer false positives in the future



Was this post helpful? Leave a Kudo!
Did you have a similar issue and a different solution? Share your work in the comments below and help your fellow IT Hero's!
More questions? Browse our  Quick Tech Solutions  or  Community Forum.


If you can't find what you're looking for, create a post in our Community Forum.



2 Comments
kobed
Engaged Sweeper

Hi Erik

In the future, is the goal to have fewer and fewer false positives and thus replace a vulnerability scanner or is this not where you guys want to go with the Security Insights component?

I also notice that there are only CVEs from the year 2020 onwards, are older CVEs not included?

 

ErikT
Lansweeper Tech Support
Lansweeper Tech Support

Hi all,

Our Security Insights feature is switched from preview mode into general availability (GA) and rebranded to Risk Insights. Check out the key highlights here:  Risk insights is going into General Availability NOW! 

New to Lansweeper?

Try Lansweeper For Free

Experience Lansweeper with your own data.
Sign up now for a 14-day free trial.

Try Now