Snow Atlas is a cloud-native platform built from the ground up to provide Technology Intelligence for today’s hybrid enterprises. Based on a microservices architecture and standardized APIs, Snow Atlas provides a unified foundation for Snow’s IT asset management, SaaS management and FinOps solutions. It can be used to display all of the technology in an enterprise's IT stack, or to find opportunities to enhance, optimize and efficiently manage technology assets and share data with…
N/A
Tenable Nessus
Score8.8 out of 10
N/A
Tenable headquartered in Columbia offers Nessus, a vulnerability scanning and security assessment solution used to analyze an entity's security posture, vulnerability testing, and provide configuration assessments.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
It is an excellent tool for scanning servers, workstations, and network devices to identify missing patches and misconfiguration; we regularly use it to confirm patch effectiveness after the update; it also helps us for preparing audits such as iso 27001, and regulatory requirements, it also helps us to identify open ports and services that violate security.
Nessus is best at performing vulnerability scans, in fact, it gives findings and moreover accurate findings of the assessments. It does not do penetration testing or exploit the vulnerabilities because it is concerned about scanning the systems/applications.
In fact, Nessus has multiple profiles/policies to perform different types of scans such as, scans oriented for PCI-DSS, malware scans, web application scans, bad shell shock detection scan to name a few.
Nessus has the ability to classify the vulnerabilities into risk-based categories from critical to even informational which I think is one of the things that separates Nessus from other vulnerability scanners.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
SaaS connectors are not always kept up to date usually when Publishers make changes to their Portal API's. Appears to be little active monitoring on Flexera/Snow Atlas' side unless a customer reports an issue with the data being returned. Fixes are normally implemented as as quickly as possible, depending on whether it is considered a Bug Fix or a Feature Enhancement.
Users - Snow on SAM - No ability to add or bulk import manually. Completely reliant on AD Discovery or Entra ID Discovery
Users - SaaS module - No ability for bulk update of Users for things line 'Online only' or 'Qualified' user accounts. This is an issue in larger companies where you have thousands of SaaS Users being reported through connectors like Microsoft E365.
SaaS module Dashboard does not allow for filtering of insights to a specific Publisher.
Not all Back end SMACC functionality form Snow License Manager have been exposed to the front-end access, as Snow Atlas does not allow customer Administrators access to the back end or SQL databases.
If you are migrating from on-prem Snow License Manager to Atlas, migration tools have not been created by Snow and will require a Project to handle your migration. Without Migration tools, we had to use a Managed Service Partner who had to manually create a lot of their own scripts to retrieve data that cannot be downloaded via reports and imported into Atlas. Any attachments documentation on Agreement or License Records has to be manually re-attached/uploaded to the relevant Agreement/License records in Atlas as the migration was performed.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The tool has lots of options for setting up before scanning any device, this methodology could be simplified further with default configuration for various devices predefined, anyhow we can use this technique by making use of policies.
For advanced users we cannot disable the plugins inside the plugin groups, we can enable the whole set of plugins at a time, for few hundreds its ok, but thousands of plugins are of waste of resource and time.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Nessus is best and easy to use application for Vulnerabilities finding and reporting, it has multiple platforms and wide scope covering almost all devices for security improvement so far, thus we are very likely to continue its services.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Tenable Nessus is a great product and provides a lot of value, but it is difficult to set up and use and the amount of data it generates can be overwhelming. It does help us prioritize based on the severity of the detection, however there are sometimes mitigating factors that we have implemented that Nessus does not account for, which causes lots of noise in the reports.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Front line support staff done always understand the issue you are explaining or the need to escalate to back end/higher up areas for resolutions and can often require use of the Escalate function or emailing to your Account/Customer Success Manager. That said, once an issue properly is understood, it is handled well.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
I haven't needed to contact support yet. But issues are easily solved with a quick internet search which means support and by extension, the larger community are involved and knowledgeable.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
We should have spun up a Project to manage the implementation. Snow indicated to us the ease in which Snow Atlas could be implemented, however this did not factor in that we were migrating from their on-prem product Snow License Manager hosted through a Managed Servicer Partner. For a clean installation, your implementation can be quick and likely not require a Project. If you are migrating from another products or are a company that can have lots of stakeholders, fingers in the pie, hurdles/business processes that need to be adhered to, definitely use a Project to perform your implementation.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Sometimes when we identify a vulnerability with Nessus that has an exploit, we made a proof of concept with Metasploit in order to show to the IT managers the importance of the software/hardware hardening.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Nessus certainly has a positive impact while me while performing my job, either as security research, or performing vulnerability assessments for clients. It gives a lot of information about the system/application after performing scans. The number of false positives is also less compared to other vulnerability scanners.
The professional edition is very useful as policy templates available in this edition are very handy and useful even to perform compliance scan like PCI DSS scan.
Also, the ability to export the scan results into reports in formats like HTML, PDF is very useful which could be for performing system/application reviews.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info