<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Things I would look for in a new vulnerability detection program]]></title><description><![CDATA[<p dir="auto">Most of my wish list comes from PSI v2</p>
<ul>
<li>Categorize programs that have security vulnerabilities separately from those that are just bug fixes and feature updates. Best would be a simple filter. I could look at just security vulnerabilities normally, but would flip a switch to see bug fixes/ feature updates</li>
<li>scan entire system by default, not just installed programs ( in order to pick up things like portable apps, apps not yet installed, etc)</li>
<li>ability to scan only selected parts of the file system, should I choose to</li>
<li>ability to exclude anything signed by Microsoft (or any certificate of my choosing) based on the idea that Microsoft will make any fixed programs available through Windows Update anyway, so I don't really need to be bothered by a vulnerability detection program</li>
<li>group multiple instances of a vulnerable program in the listing and allow me to expand that section when I want</li>
<li>flag programs that have built-in auto-update capabilities. I could then choose to white-list them if I wanted to configure them properly to receive updates by themselves.</li>
<li>ability to see exactly where any program is located in the file system</li>
<li>ability to "white-list" or ignore any program I want</li>
<li>ability to send details of any program not currently being monitored to the vulnerability detection company for possible inclusion in an update</li>
<li>ability to query the vulnerability system to see if any program is included in their detection</li>
<li>option of having updates installed automatically.</li>
<li>when an update cannot be installed automatically, guidance in where to go / how to install the required update</li>
<li>report on programs with security vulnerabilities for which a patch is not yet available (zero-days). This should be categorized separately from other things (patches available or bugfix/feature updates.</li>
<li>automatic scanning once a week with ability to manually call for a scan</li>
<li>tray icon that has different states such as "scan not performed in xx days", "programs with zero-day vulnerability detected", "programs with feature updates / bug fixes available"</li>
</ul>
]]></description><link>https://vulndetect.org/topic/5/things-i-would-look-for-in-a-new-vulnerability-detection-program</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 01:38:32 GMT</lastBuildDate><atom:link href="https://vulndetect.org/topic/5.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 14 Mar 2018 14:08:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Things I would look for in a new vulnerability detection program on Mon, 23 Oct 2023 08:18:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/wacojohn" aria-label="Profile: WacoJohn">@<bdi>WacoJohn</bdi></a> My apologies for this.</p>
<p dir="auto">Please see this response:<br />
<a href="https://vulndetect.org/post/6673">https://vulndetect.org/post/6673</a></p>
]]></description><link>https://vulndetect.org/post/6675</link><guid isPermaLink="true">https://vulndetect.org/post/6675</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Mon, 23 Oct 2023 08:18:54 GMT</pubDate></item><item><title><![CDATA[Reply to Things I would look for in a new vulnerability detection program on Mon, 23 Oct 2023 01:15:07 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/vulndetect" aria-label="Profile: VulnDetect">@<bdi>VulnDetect</bdi></a> su  support.  I  just got here and all my posts are rejected.  WTF?</p>
]]></description><link>https://vulndetect.org/post/6674</link><guid isPermaLink="true">https://vulndetect.org/post/6674</guid><dc:creator><![CDATA[WacoJohn]]></dc:creator><pubDate>Mon, 23 Oct 2023 01:15:07 GMT</pubDate></item><item><title><![CDATA[Reply to Things I would look for in a new vulnerability detection program on Fri, 20 Apr 2018 02:41:21 GMT]]></title><description><![CDATA[<p dir="auto">As mentioned by others, my wish is another vote to concentrate on programs where the current version has a security vulnerability.  There are many other update managers that list any program with a newer version  where many times that newer version is a PAID upgrade), but I'm perfectly happy with the current version and don't see any need to update unless there's a security issue.</p>
<p dir="auto">And if my version has a security issue, I'd prefer being pointed to the next secure version rather than the newest version, in case that version doesn't require a paid update.  (This may be more difficult to automate, so I'm not making it a major priority, just a nice to have.)</p>
]]></description><link>https://vulndetect.org/post/41</link><guid isPermaLink="true">https://vulndetect.org/post/41</guid><dc:creator><![CDATA[BillT52]]></dc:creator><pubDate>Fri, 20 Apr 2018 02:41:21 GMT</pubDate></item><item><title><![CDATA[Reply to Things I would look for in a new vulnerability detection program on Mon, 16 Apr 2018 22:46:27 GMT]]></title><description><![CDATA[<p dir="auto">Below are the key items I would like to see in a security checker replacing PSI:</p>
<ul>
<li>Focus on security and end of life status, if you decide to include bug fixes and updates please provide a toggle to filter in/out the bug fixes and updates so security and end of life can be viewed together by themselves</li>
<li>If initialization takes longer than a few seconds, show a progress bar to indicate program is still initializing and not hung</li>
<li>Provide security score, it motivates user to get the security fixes installed</li>
<li>Have a colored ICON in the taskbar that reflects status, ie green is 100% secure, yellow/red security needs attention, grey scan is needed</li>
<li>Provide a listing of all programs and their status: Program Name, Number Installed, Installed Version, Secure Version, Security Criticality, Status (all similar to PSI v3)</li>
<li>UI should be GUI not line</li>
<li>Provide an ignore capability to exclude programs from reporting and put them at the bottom of the program list</li>
<li>Provide ability to ignore reporting on Microsoft security patches</li>
<li>Provide ability to have program install security patches as individually requested</li>
<li>Provide a log of patches installed by the program</li>
<li>Provide weekly scans automatically and manual scans as requested by user</li>
</ul>
]]></description><link>https://vulndetect.org/post/39</link><guid isPermaLink="true">https://vulndetect.org/post/39</guid><dc:creator><![CDATA[Alex.Connolly]]></dc:creator><pubDate>Mon, 16 Apr 2018 22:46:27 GMT</pubDate></item><item><title><![CDATA[Reply to Things I would look for in a new vulnerability detection program on Thu, 15 Mar 2018 22:44:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ctaylor" aria-label="Profile: ctaylor">@<bdi>ctaylor</bdi></a> said in <a href="/post/6">Things I would look for in a new vulnerability detection program</a>:</p>
<blockquote>
<p dir="auto">tray icon that has different states such as "scan not performed in xx days", "programs with zero-day vulnerability detected", "programs with feature updates / bug fixes available"</p>
</blockquote>
<p dir="auto">Yes, and with changes of colour depending on status.</p>
<p dir="auto">One thing I liked about PSI, was the system score. A nice big green 100% when all patched. This was a great feature for the non-techies that I help, prompting them to take action when a program had a update required...</p>
]]></description><link>https://vulndetect.org/post/14</link><guid isPermaLink="true">https://vulndetect.org/post/14</guid><dc:creator><![CDATA[nimo]]></dc:creator><pubDate>Thu, 15 Mar 2018 22:44:49 GMT</pubDate></item><item><title><![CDATA[Reply to Things I would look for in a new vulnerability detection program on Wed, 14 Mar 2018 14:11:58 GMT]]></title><description><![CDATA[<p dir="auto">This is awesome suggestions. Much appreciated :D</p>
]]></description><link>https://vulndetect.org/post/7</link><guid isPermaLink="true">https://vulndetect.org/post/7</guid><dc:creator><![CDATA[VulnDetect]]></dc:creator><pubDate>Wed, 14 Mar 2018 14:11:58 GMT</pubDate></item></channel></rss>