Security Assessment Tools Paula Kiernan Senior Consultant Ward Solutions
Session Prerequisites Hands-on experience with Windows 2000 or Windows Server 2003 Working knowledge of networking, including basics of security Basic knowledge of network security-assessment strategies Level 200
Session Overview Free Security Assessment Tools from Microsoft Alternative Assessment Methods
Security Assessment Tools Free Security Assessment Tools from Microsoft Alternative Assessment Methods
Free Security Assessment Tools Free Security Assessment Tools from Microsoft include: MBSA Microsoft Update ExBPA MSRSAT Port Query MBSA Microsoft Update ExBPA MSRSAT Port Query
MBSA Microsoft Baseline Security Analyzer can examine one or more computers for the following: Missing Security Updates Missing Office Updates Vulnerabilities in Windows, IIS, SQL and Exchange (depending on MBSA version) Vulnerabilities in Internet Explorer Weak passwords, Auditing, Shares and much more… Missing Security Updates Missing Office Updates Vulnerabilities in Windows, IIS, SQL and Exchange (depending on MBSA version) Vulnerabilities in Internet Explorer Weak passwords, Auditing, Shares and much more…
Demonstration 1: Using the MBSA Analyze a computer using the MBSA
Microsoft Update Main site for obtaining updates for: Windows Office Internet Explorer All other Microsoft applications Will replace Windows and Office Update sites
Exchange Best Practices Analyzer ExBPA can examine your Exchange servers to: Generate a list of issues, such as misconfigurations or unsupported or non-recommended options Judge the general health of a system Help troubleshoot specific problems
Demonstration 2: Analyzing Configuration Settings on Exchange Server 2003 Analyze Exchange Server using the ExBPA Tool
MSRSAT Microsofts’ Security Risk Self-Assessment Tool: Assess compliance with Microsoft Security Risk Management Discipline guidelines Baseline for assessing security status of an organization Obtain advice on areas requiring improvement that may otherwise have been missed
Demonstration 3: Using the MSRSAT Using the MSRSA tool
Port Query Port Query can be used to: Examine specified ports to determine their state LISTENING FILTERED NOT LISTENING PortqryUI.exe Portqry.exe Examine specified ports to determine their state LISTENING FILTERED NOT LISTENING PortqryUI.exe Portqry.exe portqry -n microsoft.com -p tcp -e 25 portqry -n p tcp -o 143,110,25 -l portqry.txt portqry -n microsoft.com -p tcp -e 25 portqry -n p tcp -o 143,110,25 -l portqry.txt
Port Query UI
Demonstration 4: Using the Port Query UI Analyze a computer using Port Query
Other Free Security Assessment Tools Other free software available from Microsoft: Malicious Software Removal Tool Windows AntiSpyware (in Beta) Application Threat Modeling Tool Malicious Software Removal Tool Windows AntiSpyware (in Beta) Application Threat Modeling Tool
Malicious Software Removal Tool
Demonstration 5: Using the Malicious Software Removal Tool Analyze a computer using MSRT
Security Assessment Tools Free Security Assessment Tools from Microsoft Alternative Security Assessment Methods
Other methods for assessing your network security include: Purchase advanced security assessment tools e.g. NetIQs’ Vulnerability Manager Have a professional Penetration Test carried out by security experts Purchase advanced security assessment tools e.g. NetIQs’ Vulnerability Manager Have a professional Penetration Test carried out by security experts
Session Summary Take advantage of the free security assessment tools from Microsoft Check regularly for new free tools Sign up for the Security Bulletin service from Microsoft Follow a Defense in Depth approach to security and security assessments Keep systems up-to-date on security updates and service packs
Next Steps Find additional security training events: Sign up for security communications: Find additional e-learning clinics / Find additional tools and downloads:
Questions and Answers Clinic
Security Clinic Questions Patch Management Anti-Virus Firewalls and Perimeter Security Server Hardening Group Policy Security Assessment Policies and Procedures