REDDIT 原始帖子
Qualys Patch Managment
Hey everyone, not a sys admin but got tagged to work with my sys admin on the above. He’s a pretty smart guy and I want to not show up unprepared, I took some of the free sessions/classes that Qualys offers but lookin for any tips and tricks you might have.
Hey everyone, not a sys admin but got tagged to work with my sys admin on the above. He’s a pretty smart guy and I want to not show up unprepared, I took some of the free sessions/classes that Qualys offers but lookin for any tips and tricks you might have.
已收录讨论
Qualys patch management does some of the basic Windows patching and third party patching but it's not very robust in my opinion. We currently use it but will be phasing it out for PDQ Connect. We used it as a supplement for those laptops that didn't connect to the VPN much. We're currently using Deploy an Inventory but moving to connect.
How intuitive is the syntax for QQL if you had any experience with that
Right on appreciate the in depth, from a brief 30,000 foot view I learned we use VMDR and PM together so that’s a win. A wrinkle in all of this seems to be a recent cut over of on prem to AWS where we are seeing some servers duplicative so that’s something I’ll track down to make remediation easier. Deployment reliability, from his purview, does seem to be a pain point but he’s about a few months ahead of the learning curve than me so I’ll make up ground quickly. Truly, thank you for your time and insight.
I work for PDQ, but was a CTO up until a month ago. Qualys was built as a vulnerability scanner. The patch management is real, but it was layered on top of that scanning foundation, not purpose built as a deployment tool. Where it actually earns its keep is the connection between detection and remediation. If your shop uses VMDR and PM together, that closed loop is genuinely useful. You find the vulnerability, you can act on it from the same platform. Where your sysadmin is probably frustrated is third-party app patching and deployment reliability. The catalog isn't as deep as tools built purely for patching, and the deployment side takes more hands-on management than the scanning side does. If they're hitting a ceiling there, that's Qualys PM being what it is, not a config problem. PDQ has a vulnerability scanner, in house build patches for most vulnerabilities, software deployment, remote management, and more. If you are looking for something beyond Qualys I suggest looking at PDQ, Action1, ect.
Patch management in qualys is bolted on. Its never done what we needed it to do. We moved to intune for endpoint and AUM for servers. AUM is great, intune is a joke.