GFI LanGuard is software used to manage and maintain end-point protection across a network. It provides visibility into all the elements in the network, helping to assess where there may be potential vulnerabilities, and enables the administrator to patch them. It is a patch management and network auditing solution.
N/A
ManageEngine Patch Manager Plus
Score 8.3 out of 10
N/A
Patch Manager Plus is an automated patch management software that provides enterprises with a single interface for all patch management tasks. The vendor claims it works across platforms, helping users patch Windows, Mac, Linux & 300+ third-party applications. With Automated Patch Deployments, users can automate the entire process of patch management:…
$245
50 endpoints
Rapid7 InsightVM
Score 8.3 out of 10
N/A
InsightVM is presented as the next evolution of Nexpose, by Rapid7. This Insight cloud-based solution features everything included in Nexpose, such as Adaptive Security and the proprietary Real Risk score, and extends visibility into cloud and containerized infrastructure. InsightVM also offers advanced remediation, tracking, and reporting capabilities not included in Nexpose.
SolarWinds was not selected because it runs on top of
SCCM which in itself is problematic and unreliable. We need an application that
runs in standalone mode and does not rely on any other application. SolarWinds
ManageEngine Patch Manager Plus was easier to use, and you can basically set it and forget it. The performance is very good and we had way less failed patch than competing product.
-To track the vulnerability level of a windows network. -To push windows and other application updates from a central location. -Produce reports to highlight work being done to protect a network. In some organizations, you may have to prove for audit reasons you are enforcing policies put into place around cyber-security. This software can help you track work done on an ongoing basis for such purposes.
If you are managing a very large number of computers, I would say 1000+, the standard patching tools provided by Microsoft will fail to do their job properly. This is where you will benefit from ManageEngine PATCH MANAGER Plus, being agent-based it is fast, easy to manage, and reliable. If you require functionality more than just patching, like security auditing, you have to look elsewhere.
InsightVM is great for finding all devices on your network and where the misconfigurations exist. We all have to patch our systems and applications, but it can be difficult to keep track of which systems are up to date. This tool is very helpful in filling in this gap and helping you organize that information. It is easy to get a big picture view of how your organization is doing from a vulnerability perspective, and it is equally as easy to drill down and get specific details that you need. Prioritization is crucial when it comes to this space, because you can never address every vulnerability, so you need to make sure the highest priority items are being remediated. R7's tool excels in this area and highlights items you weren't even aware of.
It could be a bit of information overload which some things are shown can become noise. Maybe different levels of "security" for lack of a better term may be better where you have a summary vs detailed level when it comes to rating the vulnerability of the entire network.
I find I sometimes have issues with PCs on a different network accessed across a VPN where timeouts often occur with very large updates. This aspect can be improved.
From my experience of using this tool, sometimes it gives more false positives. A few times I had performed the scan on the same IP address using QualysGuard and Nexpose, but after comparing the scan results I had found that QualysGuard had provided more accurate vulnerability information.
The overall usability for the application is great precisely for the ease of use the application provides, if i would go in a different organisation, i would suggest implementing ManageEngine Patch Manager Plus or Endpoint Central due to its features, and productivity.
While I think it is a great tool and platform, I believe it (like all tools and solutions) is always evolving and the needs for clients are changing as the industry evolves and threats are upgraded. Cost is good, and support is helpful. Some things could be more granular and others could be easier to understand
I only tried to access there support once and it was a relatively pain-free process. They also have a lot of documentation available online which can be used to learn and tailor the software to suit your needs. It just takes time and effort to plan, execute and monitor going forward.
The support team at Patch Manager Plus has been awesome. Very responsive and knowledgeable. There are times when there is confusion between different tickets but there is still good service.
I gave it a seven due to the functionality and general ease of use after the initial setup headaches, but compared to Qualys, Rapid7 Nexpose falls short on features and ease of use. Their support drags this rating down a point as well. I have gone weeks with no update on semi-critical issues and typically have to make call after call to get a semi-coherent response.
WSUS was the other alternative I considered but I believe GFI takes updates, reporting, and functionality to a different level for an enterprise/medium-size business environment.
We were talking to Action1 and Adaptiva about their solutions of patch management. The main factor of choosing ManageEngine was pricing, which was considerably lower compared to these tools. Also, for Action1, it didn't featured some important features (like Linux patching), and it looked like a solution that is getting started in the market, even being more expensive than Patch Manager Plus.
Rapid7 InsightVM is a more professional tool than Nessus because historically, it was based on metasploit which is a powerful pentesting and exploiting tool. InsightVM covers more attacking scenarios and vulnerabilities than competitors and still a leader in this domain.cloud capability is also not available forNesuus and some other products. Rapid7 InsightVM is a way better as a pentesting tool in my opinion
Certainty. It allows you to know where on your network needs attention.
Peace of mind. As security professionals, we can only put the necessary things in place to prevent malicious persons from exploiting a network. The software allows you to know whether or not your risk of exploitation is high or low. and if high what to do with it.
ManageEngine Patch Manager Plus provides an excellent return on investment. We were able to get our systems fully patched, which we'd never been able to complete before. This provided excellent security to our organization.
ManageEngine Patch Manager Plus saved us a lot of time as most of our patching was fully automated.
ManageEngine took any issues we found and looked for solutions to further improve their product.
After spending 2 years configuring, tuning, troubleshooting, and ultimately having nothing but regrets, we migrated away from the tool and accepted the loss.
Support had a variety of opinions, none of them consistent. No best practices. Lots of secret tricks known by support, none documented or shared until after problems are found.
Consulting services are available to come out and do a health check of your deployment, for a fee.