Continuous Vulnerability Management

Eliminate False Positives and Address Discovered Issues

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

VerSprite, Delivers Custom Remediation Information to Your Environment

By using the approach listed below, VerSprite provides continuous vulnerability management to eliminate false positives, deliver custom remediation information to your environment, and address newly discovered issues:

Does the vulnerability make sense in the given environment? 
The issue can be quickly identified as a false positive if the scanner incorrectly detected the OS or server software installed (e.i. Apache vulnerability detected on IIS system).

Does the system have frequent false positives?
For example, RHEL systems with backported security patches often trigger vulnerability scanners based on version numbers even though the issue may be patched.

Does the scanner provide output that shows the issue was exploited?
With the right output it is often possible to determine the validity of an issue right away. If the scanner does not provide much output or simply detected the issue based on version number, then testing is required.

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /