The equipment list : your machines
132 Views •A machine's detail page
121 Views •Alerts : the list of what was noticed
126 Views •Risk analysis : a score, and why
144 Views •Vulnerabilities : the updates that are missing
134 Views •The asset inventory : everything you own
94 Views •Activity : the running thread of what happens
121 Views •Checking a suspicious address, and outside intelligence
126 Views •The cybersecurity dictionary
160 Views •Defence : the blocked addresses
155 Views •Who is watching while you work
147 Views •Risk analysis : a score, and why
144 Views •The crisis room: the button never to press
143 Views •The help centre and the explanation bubbles
140 Views •Opening a support ticket
139 Views •Exclusions : silencing what is normal at your site
138 Views •Your three habits, and what comes next
137 Views •The dashboard : ten seconds to know
137 Views •Companies : the administrative record
136 Views •My organisation : companies and licences
135 Views •Vulnerabilities : the updates that are missing
134 Views •Who it is for
133 Views •Creating your workspace and accepting the terms
133 Views •Signing in : and what if I lost my password
133 Views •The equipment list : your machines
132 Views •Backups : verified, not just launched
129 Views •The audit log : who did what
128 Views •The insurability score : answering insurers
128 Views •Vulnerabilities : the updates that are missing
"Vulnerabilities" page
A vulnerability is a known flaw in a piece of software, published by its vendor with a number. It is not an attack: it is a door the vendor has flagged, and for which it offers a repair. This page lists the ones still present on your machines.
What the screen shows
Four counters at the top: how many critical, high, medium and low flaws. Below, a table: the flaw's number, its severity, the machine concerned, the software, its version, and the publication date.
Sorting is by severity and by machine, and a search box finds a specific number. Everything can be exported, which is handy for handing the list to whoever will apply the updates.
A non-zero figure is normal, and even healthy. Every IT fleet in the world has vulnerabilities pending: vendors publish new ones every week. What matters is that the critical ones go down quickly, and that there is an update rhythm. At Les Ateliers, security updates are applied on Fridays.
Turning detection on
A button at the top right starts or stops the scan. On first activation, the screen honestly warns that results will take about twelve hours to arrive, the time of the first full pass. An empty table on day one is therefore not a bad sign.
Three messages that look alike
"Detection not enabled": the button was never pressed. "No vulnerability detected": the scan is running and found nothing. "Data unavailable": the scan has not finished its first round. None of these three messages is an alert.
In closing
A vulnerability is not an attack: it is a door flagged by the vendor, with its fix. Deal first with those that are critical and exposed; the others can wait for the next patching round.
Commenting is not enabled on this course.