Patch management, vulnerability assessment, network audit
Secure your network comprehensively
Help prove compliance with security standards, e.g., PCI DSS
Increase productivity - for your IT staff and end users
Secure your network comprehensively
Help prove compliance with security standards, e.g., PCI DSS
Increase productivity - for your IT staff and end users
![]()
GFI LanGuard’s patch management feature scans your network automatically, or on demand, and gives you all the functionality and tools you need to effectively install and manage patches on all machines across different Microsoft and Mac OS X operating systems and products in all supported languages.
Click here to view a full list.
Both security and non-security patches from Microsoft are supported.
GFI LanGuard allows auto-downloads of missing patches as well as patch roll-back, resulting in a consistently configured environment that is secure against vulnerabilities.
GFI LanGuard offers patch management support for other (non-Microsoft) software, enabling administrators to detect, download and deploy missing patches for supported applications in the same way as is done for Microsoft or Mac OS X updates.
GFI LanGuard offers patch management support for many popular applications like Apple QuickTime, Adobe Acrobat, Adobe Flash Player, Adobe Reader, Adobe Shockwave Player, Mozilla Firefox, Mozilla Thunderbird, Java Runtime and others. Click here for a full list
With GFI LanGuard, not only is it possible to patch third party applications, but also to upgrade to their latest versions (i.e., if an old version of Adobe Flash is detected, GFI LanGuard will provide an option to either upgrade to the latest version or to apply all patches for that version).
GFI LanGuard is the first solution that automates patching for all major web browsers running on Windows systems: Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Apple Safari and Opera Browser.
Besides deploying patches and service packs, GFI LanGuard also enables you to easily deploy third party software or patches network-wide.
You can use this feature to deploy client software, and update software, virus updates and more; practically any application that can run silently can be pushed in the network using GFI LanGuard.
GFI LanGuard can be configured to run either in agent-less or agent-based mode.
The agent technology enables automated audits and distributes the scanning load across client machines. The administrator simply needs to define the network perimeter and provide credentials to enable automatic network discovery, agent deployment and auditing of the client machines. Manual intervention is necessary only when fine-tuning is required. This feature provides the following benefits:
An agent may be designated a relay agent in order to distribute the remediation load across multiple machines.
By storing a copy of the patch data on the relay agent, agents may be configured to obtain required patches from the local relay agent rather than from the remote GFI LanGuard server. This is particularly useful in multi-site networks where you should have at least one relay agent per site, or in very large networks.
Remediation operations can be triggered automatically at the end of scheduled scans.
Apart from reporting on all installed applications, GFI LanGuard allows the user to define which applications are authorized or not authorized to be installed on the network. This list of applications can be easily defined for each scanning profile using the Applications Inventory Tool. During a scan, any unauthorized applications are identified and (optionally) uninstalled automatically by GFI LanGuard. An integrated Auto-Uninstall Validation tool is provided to help identify which of the detected applications support silent uninstall and can thus be safely and automatically uninstalled.
GFI LanGuard allows the useful option of a remote desktop connection to fix security issues on scanned computers that cannot be fixed automatically.
During security audits, over 50,000 vulnerability assessments are made - scanning the network IP by IP. GFI LanGuard gives you the capability to perform multi-platform scans (Windows, Mac OS, Linux) across all environments - including Virtual Machines and to analyze your network’s security set-up and status. GFI LanGuard gives you the power to identify and correct any threats before hackers can exploit them.
GFI LanGuard allows you to easily create custom vulnerability checks through simple wizard-assisted set-up screens.
The wizard is powerful enough to allow building of complex vulnerability checks and the scripting engine is compatible with Python and VBScript. GFI LanGuard includes a script editor and debugger to help with script development.
GFI LanGuard ships with a complete and thorough vulnerability assessment database, including standards such as OVAL (5,000+ checks) and SANS Top 20.
This database is regularly updated with information from BugTraq, SANS Corporation, OVAL, CVE and others. Through its auto-update system, GFI LanGuard is always kept up-to-date with information about newly released Microsoft security updates as well as new vulnerability checks issued by GFI Software and other community-based information repositories such as the OVAL database.
GFI LanGuard scans computers, identifies and categorizes security vulnerabilities, recommends a course of action and provides tools that enable you to solve the problem.
It comes with a graphic threat level indicator that provides an intuitive, weighted assessment of the vulnerability status of a scanned computer or group of computers. Wherever possible, a web link or more information on a particular security issue is provided - such as a BugTraq ID or a Microsoft Knowledge Base article ID.
GFI LanGuard integrates with over 2,500 critical security applications of the following categories: antivirus, antispyware, firewall, anti-phishing, backup client, VPN client, URL filtering, patch management, web browser, instant messaging, peer-to-peer, disk encryption, data loss prevention and device access control.
It provides reports on their status, e.g., if antivirus is enabled and up-to-date, the firewall is turned on, the status of backup software, a list of which instant messaging or peer-to-peer applications are installed in your network, etc. It also rectifies any issues that require attention, e.g., trigger antivirus/antispyware update, start antivirus/antispyware scans, enable antivirus/firewall, or uninstall peer-to-peer, etc.
You can easily configure scans for different types of information, such as open shares on workstations, security audit and password policies, and machines missing a particular patch or service pack.
You can scan for different types of vulnerability to identify potential security issues. These include:
And much more!
As well as running the a vulnerability check on computers on your network, GFI LanGuard also supports a number of network devices, such as printers, routers and switches from manufacturers such as HP and Cisco.
GFI LanGuard’s network auditing gives you a comprehensive view of your network - what USB devices are connected, what software is installed, any open shares, open ports and weak passwords in use, and hardware information. The solution's in-depth reports give you an important and real-time snapshot of your network's status. Scan results can be easily analyzed using filters and reports, enabling you to proactively secure the network by closing ports, deleting users or groups which are no longer in use, or disabling wireless access points.
GFI LanGuard shows detailed information about the hardware configuration of all the scanned machines on your network.
All devices from the Device Manager tool from Windows operating systems are retrieved, including motherboard, processors, memory, storage devices, display adapters and much more. Using network history view, you can now check whether any hardware was added or removed since the last scan.
By default, GFI LanGuard generates a daily digest report that contains all relevant security changes that occurred on your network that day.
Any new security holes or security set-up changes discovered on your network are emailed to you for analysis. This enables you to quickly identify newly-created shares, installed services, installed applications, added users, newly-opened ports and more. GFI LanGuard will generate specific reports and email notification whenever there are software or hardware changes detected within the audited network. The reports also show what remediation operations were performed.
GFI LanGuard checks if each XP/2003/VISTA/2008/2008 R2/7 machine has security auditing enabled.
If not, GFI LanGuard alerts you and allows you to enable auditing remotely. Security event auditing is highly recommended as it detects intruders in real time.
It is possible to remotely extract OS data from Linux-based systems and scan results are presented in the same way as for Windows-based computers.
This means that both Linux and Windows-based computers can be analyzed in a single scanning session. GFI LanGuard includes numerous Linux security checks including rootkit detection. It can use SSH Private Key files instead of the conventional password string credentials to authenticate to Linux-based target computers.
GFI LanGuard can detect iPhones, iPads, Android phones and tablets that have been added to your network. This ensures you have full visibility of the devices on your network.
GFI LanGuard has a powerful and interactive dashboard that processes all security audits ever made to the network.
It provides a summary of current network security status and a history of all relevant changes in the network over time. It also drills down through information starting from network-wide security sensors to individual security scan results.
Reports are designed to satisfy the requirements of both management and technical staff.
Reports are integrated within the main GFI LanGuard application. All reports are based on a computer’s current status, and not on specific scans. These reports can be exported to popular formats like PDF, HTML, XLS, XLSX, RTF and CVS, and can be scheduled and sent by email. They can also be used as a template to create new custom reports and are fully re-brandable.
All businesses handling cardholder data, regardless of size, have to be fully compliant with strict security standards drawn up by the world’s major credit card companies.
GFI LanGuard provides complete vulnerability management coupled with extensive reporting. That makes GFI LanGuard an essential, highly cost-effective solution for your organization to safeguard your network and gauge the effectiveness of your PCI , HIPAA, SOX, GLB/GLBA or PSN CoCo compliance program.
You can perform an unattended default installation of GFI LanGuard on multiple computers in the background without any user interaction or intervention.
License slots are not required for all computers and devices in the scan results database. Only those that are scanned beyond network discovery are bound by license limitations.
GFI LanGuard allows you to store separate authentication details for every target computer on your network, avoiding the need to specify authentication credentials prior to every scan.
In a single scanning session, it is possible to audit all the targets in your network, even if they require different authentication details and/or methods.
GFI LanGuard makes it possible for users to instantly locate the information they are interested in.
Searching the scan results is now as easy as searching on the Internet. The search displays instant results with links to relevant items. You can search for both current and past events and for specific items like vulnerabilities, installed applications, missing patches etc. Moreover, you can save and print search reports.
Organizations that use or plan to use virtualization on their network can install and use a range of GFI products with confidence.
GFI LanGuard supports and runs on the most common virtualization technologies in use, namely VMware, Microsoft Virtual Server, Microsoft Hyper-V, Citrix and Parallel. It also offers detection of virtual machines hosted by the scanned computer.
GFI LanGuard features a news section – an easy way to find out about product updates.
This section informs you about any new patches that will be supported by GFI LanGuard, any new applications that have become available for patch management, and any new vulnerabilities that have been added to the database.
![]()
Leading companies all over the world have chosen GFI LanGuard.
Click here to view case studies and testimonials
"This is a very well-integrated vulnerability management system. It is our selection for Recommended – on-premises product."
GFI LanGuard places second in the network auditing category of the WindowSecurity.com Readers’ Choice Awards. - WindowSecurity.com, December 2012
GFI LanGuard places 2nd runner-up in the patch management category of the WindowSecurity Readers’ Choice Awards. - WindowSecurity.com, August 2012
In a review by Firewall.cx, GFI LanGuard receives top marks and the site’s ‘100% Firewall.cx Approved’ badge. “The real-world benefits of a tool like this are undeniable, but the beauty of LanGuard 2011 is in the way those benefits are delivered. GFI has drawn together all the elements of this complicated and important task into one seamless, intuitive and comprehensive whole and left nothing out,” the reviewers state – Firewall.cx, April 2012
In a group test of vulnerability products, GFI LanGuard achieved top marks in all categories. Highly recommended.
GFI LanGuard is named preferred product in the ‘best intrusion-detection product’ category of Redmond Magazine’s Best of the Best Readers Choice Awards 2011.
Redmond - December, 2011
GFI LanGuard has been shortlisted for SC Magazine'...
GFI LanGuard has been shortlisted for SC Magazine's Europe Awards