GFI LanGuard® - Features

full-width-line

Top features

Improved! Patch management for Microsoft® and Mac OS X operating systems and applications

GFI LanGuard’s patch management feature scans your network automatically, or on demand, and gives you all the functionality and tools you need to effectively install and manage patches on all machines across different Microsoft and Mac OS X operating systems and products in all supported languages.


Click here to view a full list.

Both security and non-security patches from Microsoft are supported.

GFI LanGuard allows auto-downloads of missing patches as well as patch roll-back, resulting in a consistently configured environment that is secure against vulnerabilities.

Read more

Improved! Patch management for other applications

GFI LanGuard offers patch management support for other (non-Microsoft) software, enabling administrators to detect, download and deploy missing patches for supported applications in the same way as is done for Microsoft or Mac OS X updates.

GFI LanGuard offers patch management support for many popular applications like Apple QuickTime, Adobe Acrobat, Adobe Flash Player, Adobe Reader, Adobe Shockwave Player, Mozilla Firefox, Mozilla Thunderbird, Java Runtime and others. Click here for a full list

With GFI LanGuard, not only is it possible to patch third party applications, but also to upgrade to their latest versions (i.e., if an old version of Adobe Flash is detected, GFI LanGuard will provide an option to either upgrade to the latest version or to apply all patches for that version).

GFI LanGuard is the first solution that automates patching for all major web browsers running on Windows systems: Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Apple Safari and Opera Browser.

Read more

Deploys custom and third party software and patches network-wide

Besides deploying patches and service packs, GFI LanGuard also enables you to easily deploy third party software or patches network-wide.

You can use this feature to deploy client software, and update software, virus updates and more; practically any application that can run silently can be pushed in the network using GFI LanGuard.

Read more

Agent technology

GFI LanGuard can be configured to run either in agent-less or agent-based mode.

The agent technology enables automated audits and distributes the scanning load across client machines. The administrator simply needs to define the network perimeter and provide credentials to enable automatic network discovery, agent deployment and auditing of the client machines. Manual intervention is necessary only when fine-tuning is required. This feature provides the following benefits:

  • High speed: Scan hundreds or thousands of machines in just a few minutes
  • Automation: Agents update the client status on the server on a regular schedule. Every time the application is opened, users can analyze a complete and up-to-date network security overview
  • Scalability: Due to distributed load, it is possible to scan more machines in one go, even in WAN environments
  • Accuracy: Local scans have less failure points than remote scans; agents will continue to work even when computers are not connected to the network.
Read more

Relay agent

An agent may be designated a relay agent in order to distribute the remediation load across multiple machines.

By storing a copy of the patch data on the relay agent, agents may be configured to obtain required patches from the local relay agent rather than from the remote GFI LanGuard server. This is particularly useful in multi-site networks where you should have at least one relay agent per site, or in very large networks.

Read more

Automatic remediation of unauthorized applications

Remediation operations can be triggered automatically at the end of scheduled scans.

Apart from reporting on all installed applications, GFI LanGuard allows the user to define which applications are authorized or not authorized to be installed on the network. This list of applications can be easily defined for each scanning profile using the Applications Inventory Tool. During a scan, any unauthorized applications are identified and (optionally) uninstalled automatically by GFI LanGuard. An integrated Auto-Uninstall Validation tool is provided to help identify which of the detected applications support silent uninstall and can thus be safely and automatically uninstalled.

Read more

Remote desktop connection

GFI LanGuard allows the useful option of a remote desktop connection to fix security issues on scanned computers that cannot be fixed automatically.

Vulnerability assessment

During security audits, over 50,000 vulnerability assessments are made - scanning the network IP by IP. GFI LanGuard gives you the capability to perform multi-platform scans (Windows, Mac OS, Linux) across all environments - including Virtual Machines and to analyze your network’s security set-up and status. GFI LanGuard gives you the power to identify and correct any threats before hackers can exploit them.

Set up your own custom vulnerability checks

GFI LanGuard allows you to easily create custom vulnerability checks through simple wizard-assisted set-up screens.

The wizard is powerful enough to allow building of complex vulnerability checks and the scripting engine is compatible with Python and VBScript. GFI LanGuard includes a script editor and debugger to help with script development.

Read more

Extensive, industrial strength vulnerabilities database

GFI LanGuard ships with a complete and thorough vulnerability assessment database, including standards such as OVAL (5,000+ checks) and SANS Top 20.

This database is regularly updated with information from BugTraq, SANS Corporation, OVAL, CVE and others. Through its auto-update system, GFI LanGuard is always kept up-to-date with information about newly released Microsoft security updates as well as new vulnerability checks issued by GFI Software and other community-based information repositories such as the OVAL database.

Read more

Identify security vulnerabilities and take remedial action

GFI LanGuard scans computers, identifies and categorizes security vulnerabilities, recommends a course of action and provides tools that enable you to solve the problem.

It comes with a graphic threat level indicator that provides an intuitive, weighted assessment of the vulnerability status of a scanned computer or group of computers. Wherever possible, a web link or more information on a particular security issue is provided - such as a BugTraq ID or a Microsoft Knowledge Base article ID.

Read more

Helps ensure third party security applications offer optimum protection

GFI LanGuard  integrates with over 2,500 critical security applications of the following categories: antivirus, antispyware, firewall, anti-phishing, backup client, VPN client, URL filtering, patch management, web browser, instant messaging, peer-to-peer, disk encryption, data loss prevention and device access control.

It provides reports on their status, e.g., if antivirus is enabled and up-to-date, the firewall is turned on, the status of backup software, a list of which instant messaging or peer-to-peer applications are installed in your network, etc. It also rectifies any issues that require attention, e.g., trigger antivirus/antispyware update, start antivirus/antispyware scans, enable antivirus/firewall, or uninstall peer-to-peer, etc.

Read more

Easily creates different types of scans and vulnerability tests

You can easily configure scans for different types of information, such as open shares on workstations, security audit and password policies, and machines missing a particular patch or service pack.

You can scan for different types of vulnerability to identify potential security issues. These include:

  • Open ports: GFI LanGuard scans for unnecessary open ports and checks that no port hijacking is in force
  • Unused local users and groups: GFI LanGuard removes or disables User Accounts which are no longer in use
  • Blacklisted applications: With GFI LanGuard, you can identify unauthorized or dangerous software and add to blacklists of applications you want to associate with a high security vulnerability alert
  • Dangerous USB devices, wireless nodes and links: GFI LanGuard scans all devices connected to USB or wireless links and alerts you of any suspicious activity

And much more!

Read more

Network device vulnerability checks

As well as running the a vulnerability check on computers on your network, GFI LanGuard also supports a number of network devices, such as printers, routers and switches from manufacturers such as HP and Cisco.

Network and software auditing

GFI LanGuard’s network auditing gives you a comprehensive view of your network - what USB devices are connected, what software is installed, any open shares, open ports and weak passwords in use, and hardware information. The solution's in-depth reports give you an important and real-time snapshot of your network's status. Scan results can be easily analyzed using filters and reports, enabling you to proactively secure the network by closing ports, deleting users or groups which are no longer in use, or disabling wireless access points.

Hardware auditing

GFI LanGuard shows detailed information about the hardware configuration of all the scanned machines on your network.

All devices from the Device Manager tool from Windows operating systems are retrieved, including motherboard, processors, memory, storage devices, display adapters and much more. Using network history view, you can now check whether any hardware was added or removed since the last scan.

Read more

Automatically receive alerts of new security holes

By default, GFI LanGuard generates a daily digest report that contains all relevant security changes that occurred on your network that day.

Any new security holes or security set-up changes discovered on your network are emailed to you for analysis. This enables you to quickly identify newly-created shares, installed services, installed applications, added users, newly-opened ports and more. GFI LanGuard will generate specific reports and email notification whenever there are software or hardware changes detected within the audited network. The reports also show what remediation operations were performed.

Read more

Check to ensure security auditing is enabled network-wide

GFI LanGuard checks if each XP/2003/VISTA/2008/2008 R2/7 machine has security auditing enabled.

If not, GFI LanGuard alerts you and allows you to enable auditing remotely. Security event auditing is highly recommended as it detects intruders in real time.

Read more

Scan and retrieve OS data from Linux systems

It is possible to remotely extract OS data from Linux-based systems and scan results are presented in the same way as for Windows-based computers.

This means that both Linux and Windows-based computers can be analyzed in a single scanning session. GFI LanGuard includes numerous Linux security checks including rootkit detection. It can use SSH Private Key files instead of the conventional password string credentials to authenticate to Linux-based target computers.

Read more

Smartphone and tablet detection

GFI LanGuard can detect iPhones, iPads, Android phones and tablets that have been added to your network. This ensures you have full visibility of the devices on your network.

Additional features

Powerful interactive dashboard

GFI LanGuard has a powerful and interactive dashboard that processes all security audits ever made to the network.

It provides a summary of current network security status and a history of all relevant changes in the network over time. It also drills down through information starting from network-wide security sensors to individual security scan results.

Read more

Multiply the value of GFI LanGuard with powerful reporting

Reports are designed to satisfy the requirements of both management and technical staff.

Reports are integrated within the main GFI LanGuard application. All reports are based on a computer’s current status, and not on specific scans. These reports can be exported to popular formats like PDF, HTML, XLS, XLSX, RTF and CVS, and can be scheduled and sent by email. They can also be used as a template to create new custom reports and are fully re-brandable.

Read more

Helps you comply with PCI DSS and other regulations

All businesses handling cardholder data, regardless of size, have to be fully compliant with strict security standards drawn up by the world’s major credit card companies.

GFI LanGuard provides complete vulnerability management coupled with extensive reporting. That makes GFI LanGuard an essential, highly cost-effective solution for your organization to safeguard your network and gauge the effectiveness of your PCI , HIPAA, SOX, GLB/GLBA or PSN CoCo compliance program.

Read more

Silent installation support

You can perform an unattended default installation of GFI LanGuard on multiple computers in the background without any user interaction or intervention.

Network discovery not bound by license limitations

License slots are not required for all computers and devices in the scan results database. Only those that are scanned beyond network discovery are bound by license limitations.

Predefine authentication details

GFI LanGuard allows you to store separate authentication details for every target computer on your network, avoiding the need to specify authentication credentials prior to every scan.

In a single scanning session, it is possible to audit all the targets in your network, even if they require different authentication details and/or methods.

Read more

Full text search support

GFI LanGuard makes it possible for users to instantly locate the information they are interested in.

Searching the scan results is now as easy as searching on the Internet. The search displays instant results with links to relevant items. You can search for both current and past events and for specific items like vulnerabilities, installed applications, missing patches etc. Moreover, you can save and print search reports.

Read more

Support for virtual environments

Organizations that use or plan to use virtualization on their network can install and use a range of GFI products with confidence.

GFI LanGuard supports and runs on the most common virtualization technologies in use, namely VMware, Microsoft Virtual Server, Microsoft Hyper-V, Citrix and Parallel. It also offers detection of virtual machines hosted by the scanned computer.

Read more

News section

GFI LanGuard features a news section – an easy way to find out about product updates.

This section informs you about any new patches that will be supported by GFI LanGuard, any new applications that have become available for patch management, and any new vulnerabilities that have been added to the database.

Read more

Other features:

  • Automatically checks the password policy for all machines on the network
  • Checks for programs that run automatically (potential trojans)
  • Finds out if the OS is advertising too much information
  • Performs simultaneous scans through the multithread scan engine
  • Provides NetBIOS hostname, currently logged username and MAC address
  • Provides a list of shares, users (detailed information), services, sessions, remote TOD (time of day) and registry information from remote computer (Windows)
  • SNMP device detection, SNMP Walk for inspecting network devices like routers, network printers and more
  • Offers alternative command line deployment tool
  • Identifies all installed Windows services
  • Supports Microsoft Windows 7, Windows 8 (Beta) and Microsoft Windows Server 2008 R2

full-width-line

You're in great company...

Leading companies all over the world have chosen GFI LanGuard.
Click here to view case studies and testimonials

Awards and reviews

Previous Next