Vulnerability Groups are logical grouping of vulnerability knowledge base. You
can form vulnerability groups from the existing Complete Scan list
of vulnerability test cases based on risk level, vulnerability type or services
affected. SANS TOP 20 is one such pre-defined
standard vulnerability group which lets you scan for the ten most commonly exploited vulnerable services in Windows and the ten most commonly exploited elements in UNIX and Linux environments in your
enterprise.
Create custom vulnerability group
You can create your own custom vulnerability groups, from the existing vulnerabilities
list that ScanFi maintains in its vulnerability database, based on type, risk and
service affected . To create custom vulnerability group follow these instructions :
- Visit the 'Groups' tab.
- Click on the 'Edit
Vulnerability Groups' link present in the left hand side of the screen.
This, by default, displays a complete list of all vulnerabilities that
is scanned by ScanFi. SANS Top 20 Internet Security Vulnerabilities are
grouped by default in ScanFi, under the 'Sans Top 20' group.
- For example, if you would like to create a group, say for HTTP service vulnerabilities
,you can use either of the following ways to create your HTTP vulnerability group
:
- From the Complete Scan list
search
for the Service HTTP .
- From the displayed Search
Results you can specifically select vulnerabilities of your choice or you
can use the select all check-box option, available at the top left hand corner of the table,
to select the list of vulnerabilities displayed for that page.
- Now click on
'New Group' link and enter a descriptive name for the 'Vulnerability Group
Name' field and Press OK.
- A new group is created with only
the selected records, of the particular search result page, added to the group.
Note : For adding the rest of the search results to this newly created
group, provided the search results has spanned more than one page,
you need to repeat Step 2(only) for each of the search result page and
then click on 'Add to Group' and select the newly created
group.
[0R]
- Click on
'New Group' link and enter a descriptive name for the
'Vulnerability Group Name' field and Press OK. An empty group is created.
- From the Complete Scan
list search
for the Service HTTP .
- From the displayed Search
Results you can specifically select vulnerabilities of your choice or you
can use the select all check-box option, available at the top left hand corner of the table,
to select the list of vulnerabilities displayed for that page.
- Then click on 'Add to Group' and select the newly created
group.
- Repeat the above Step 4
for adding the rest of the search results to this group, provided the search results has spanned more than one
page.
 
Copyright © 2005, AdventNet Inc. All Rights Reserved.