r/blueteamsec
Ive been ignoring that our two scanners disagree on thousands of criticals for a while. Last week I finally looked.
- upvotes
- 6
- comments
- 7
Post
If you ask me how many critical vulnerabilities we have, you will get different numbers. Ive been ignoring it for a year because dealing with it looked worse than not knowing. We run two scanners. Last week I finally compared them properly. Tenable flagged 12,400 criticals, Qualys flagged 9,800, and they agreed on about 6,000. Ive been reporting whichever console I happened to have open. Two days into this and Im not done. Their CVE sources dont line up, so some of this is them describing the same thing two ways. But a decent chunk is the same box turning up as two assets. One tool knows it by hostname, the other by IP and a shortened name. Two identities, two different finding sets. Thats the bit I cant reconcile, because I dont know which record is the real one. Anyone cracked the asset side of this without it turning into a full time job?
Extracted from these lines
[comment u/Sad-Technician-5552] You cant pick which scanner is right about a box, so stop matching on hostname. Its a label somebody typed, it drifts the moment a box gets reimaged or dns goes stale. Match on something the machine owns, the serial.
[comment u/Sad-Technician-5552] We run that join in axonius, every sync rebuilds it so both scanners land on one asset record instead of two name strings.