From: David M. Zendzian (dmz@dmzs.com)
Date: Sat May 19 2007 - 08:49:46 EDT
<plug>
I'd like to add my .02 :) I would highly recommend if you get a chance
to at least demo this tool. I have tried it out and wish I had more
opportunities to actually use my copy. To take many configurations and
nessus/qualys scans and put them together into a graphical
representation has been quite nice, and the user interface is well
thought out for an initially released product. It is fast and makes
firewall rule analysis across many devices, subnets and regions easily
managable.
</plug>
dmz
Foster, Matt wrote:
> Hi All,
>
> I'm posting to this list as I think that there will be a few members who
> may be interested in a free offer we are launching next week for security
> consultants, pen testers and auditors
>
> Redseal develops a product called Security Risk Manager (SRM), it does the
> following - (non sales overview)
>
> 1. Imports firewall and router configuration files
> 2. Audits and checks them for errors, mis configurations, redundant rules,
> checks against best practices etc
> 3. Draws a network topography map from the configs (you can move this
> around, save layouts, export to Visio)
> 4. Builds a network blueprint of all permitted traffic flows which you can
> query (i.e. can traffic from internet get to my PCI servers etc)
> 5. Built in "inference intelligence" auto populates what applications are
> running on the network and gives them asset values (you can customize and
> define as much as you want)
> 6. Has a built in Threat Reference Library to provide vulnerability info,
> currently over 23,000 and updated on a weekly basis (you can also load in
> Nessus, Qualys and Foundstone scan data if you have it as well)
> 7. Analyzes the network and security data to identify what vulnerabilities
> are the most important to fix based on network access and importance.
> 8. Shows unique graphical ways to quickly view and drill down through huge
> sets of data to find the most important information.
>
> The product has been referenced by some consultants as the first way to
> perform a passive pen test as it is completely unobtrusive, you just need
> to load in configs, no scanning required.
>
> We have launched a license for Consultants to use out in the field and to
> promote it we are offering security consultants and auditors free and full
> use of the product for 30 days. We are keen for consultants to use the
> product and prove out it's capabilities and values in the field and we
> want to hear feedback and so if anyone would like to take us up on this
> offer please email consultants@redseal.net to sign up for the program,
> it's quick, easy and free.
>
>
> If anyone wants to know more about Redseal let me know or you can check
> out some of the latest news at the below link
>
> http://www.redseal.net/News-PressReleases.shtml
>
>
> Also below is a short white paper.
> http://www.redseal.net/solutions/___Reduce_Your_Risk_In_3_Steps.pdf
>
>
>
> Thanks
> Matt
>
>
> Matt Foster
>
> VP of Sales
>
> Cell: +1 650 515 5739
>
> Direct: +1 650 413 4161
>
> Redseal Systems Inc - <http://www.redseal.net/> www.redseal.net
>
> Instant Visibility - Threats Averted
>
>
> ------------------------------------------------------------------------
> This List Sponsored by: Cenzic
>
> Are you using SPI, Watchfire or WhiteHat?
> Consider getting clear vision with Cenzic
> See HOW Now with our 20/20 program!
>
> http://www.cenzic.com/c/2020
> ------------------------------------------------------------------------
>
>
>
------------------------------------------------------------------------
This List Sponsored by: Cenzic
Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!
http://www.cenzic.com/c/2020
------------------------------------------------------------------------
This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:57:49 EDT