Skip Navigation
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)BF
Baron von Fajita @ CAWright @infosec.pub
Posts
1
Comments
5
Joined
2 yr. ago

Permanently Deleted

  • In the laws references in the article, the need for #1 and #3 were caused by social media. Yet we target the individual rather than the social media company for the fix. Let's don't fix the source of the problem but we can make life more difficult for many millions of people. How dumb are we in this country?

  • Blue Team @infosec.pub
    Baron von Fajita @infosec.pub

    Vulnerability Management Software

    I need some help here. I'm looking for vulnerability management software that accepts data from vulnerability scanners (Tenable.io and Nessus in my case) and allows for analysts to review the scanned vulnerabilities for further action. This will mostly be in creating tickets, but I want analysts to be able to group vulns together where appropriate (e.g., one system has a ton of vulns because it's obviously been left out of an automated patching program, the solution is not to patch each vulnerability but to include it in the automation) and create tickets appropriately. It also need to support simple Risk Acceptance workflows (no giant approval chains, but likely more just analysts grouping and marking sets of vulns as RA). Finally, it needs to be multi-tenant or at least have some siloing capabilities.

    We are currently using Tenable.io for on-going vulnerability scanning in some smaller clients, but the vulnerability management functionality is severely lacking. I've looked at Nucle