Complementing Network and Web Vulnerability Scanning with
Penetration Testing
To effectively protect your organization's information assets, a vulnerability management strategy must encompass multiple steps - from scanning to remediation:
- Scan network servers, workstations, firewalls, routers and various applications for vulnerabilities.
- Identify which vulnerabilities pose real threats to your network.
- Determine the potential impact of exploited vulnerabilities.
- Prioritize and execute remediation efforts.
Scanning applications can provide a key component to the vulnerability management process by helping you to understand your organization's potential vulnerabilities. Penetration testing with CORE IMPACT builds on this process by identifying which vulnerabilities are real, while determining if and how they can be exploited. This gives you the information you need to intelligently prioritize remediation efforts and effectively allocate security resources.
The following steps describe how scanner integration works with CORE IMPACT:
- Run a vulnerability scan to identify and report on vulnerabilities
- Import the scan results into CORE IMPACT
- Run the exploits against critical vulnerabilities identified in the scan results
- Reveal which vulnerabilities pose critical risks
- Safely demonstrate the consequences of a breach – including multistaged threats to backend systems
- Run CORE IMPACT vulnerability validation reports. These reports are available with specific information for FISMA and PCI reporting.
- Focus remediation on critical issues first
- Re-test patched and updated systems
- Run CORE IMPACT delta and trend reports
- Repeat above steps as desired
CORE IMPACT Pro currently is integrated with the following network vulnerability scanners:
- eEye Retina Network Security Scanner
- GFI LANguard
- IBM Internet Scanner
- Lumension Scan
- nCircle IP360
- Qualys QualysGuard
- Tenable Nessus
- SAINT Scanner
- McAfee Vulnerability Manager (was Foundstone Scanner)
… and with the following web vulnerability scanners:
Ensure Comprehensive Vulnerability Management, with or without a Scanner
CORE IMPACT integrates with the most widely-used vulnerability scanners, allowing you to import scan results and run exploits to test identified vulnerabilities. However, you don't need to have a vulnerability scanner to use IMPACT. In the Information Gathering phase, IMPACT will independently identify servers, services, etc., enabling it to intelligently determine the appropriate exploits to run.











