Core
 

Complementing Vulnerability Scans with Real-World Security Testing

To effectively protect your organization's information assets, a vulnerability management strategy must encompass multiple steps - from scanning to remediation:

  • Scan network servers, workstations, firewalls, routers and various applications for vulnerabilities.
  • Identify which vulnerabilities pose real threats to your network.
  • Determine the potential impact of exploited vulnerabilities.
  • Prioritize and execute remediation efforts.

Scanning applications can provide a key component to the vulnerability management process by helping you to understand your organization's potential vulnerabilities. Penetration testing with CORE IMPACT builds on this process by identifying which vulnerabilities are real, while determining if and how they can be exploited. This gives you the information you need to intelligently prioritize remediation efforts and effectively allocate security resources.

CORE IMPACT allows you to address each step of the vulnerability management process:

  • Safely mimic the actions of hackers and worms to identify vulnerabilities.
  • Discern vulnerabilities that pose actual threats to network resources, thereby eliminating false positives.
  • Exploit trust relationships between network components to demonstrate actual attack paths.
  • Assess the potential risks of specific vulnerabilities to assist with remediation efforts.
  • Test the ability other security investments to detect and prevent attacks.
Ensure Comprehensive Vulnerability Management, with or without a Scanner

CORE IMPACT integrates with the most widely-used vulnerability scanners, allowing you to import scan results and run exploits to test identified vulnerabilities. However, you don't need to have a vulnerability scanner to use IMPACT. In the Information Gathering phase, IMPACT will independently identify servers, services, etc., enabling it intelligently determine the appropriate exploits to run.

Related Content

Security Testing Webcasts

Core Security White Papers

The Rise of Security Testing
Learn why comprehensive security testing is critical to proactive IT risk management.

Smarter Security Spending
Learn how comprehensive testing helps to drive increased security ROI in a stormy economy.

Success Story


"I used to get 30 pages of data from my scanner and it always required guesswork to sort out the real threats from the false positives. With IMPACT we get straightforward information about actual, proven vulnerabilities in about 5 pages - no guesswork required."

Howard Scott
IT Manager
MERS

Solutions | Products and Services | CoreLabs | News and Events | Partners | Company
Core Security Technologies © 2008 All rights reserved       Disclaimer     Privacy Statement