Search by Solution - Low Hanging Fruit

Anyone have a SQL to find fixable asset by Solution?

This may or may not turn out to be a low hanging fruit, but need to see if there is a good Return on Investment (ROI) for deploying by solution.

Like when you see 1 asset, with 1 solution that fixes 400+ CVE’s - seems like a great opportunity!

So, this will be every Microsoft monthly update from now on based on the last few months vuln rate :grinning_face:

I know you’ve specifically asked for a SQL solution, and I probably do have something I could provide if needed although this will require some digging on my part.

Before I do that, I’ll play devils advocate a bit - are you already approaching vulnerabilities based on risk (which is better than approaching it by count)? A couple of options, if you don’t specifically want a SQL solution, are the built-in Top Remediations with Details report or using Remediation Projects. These work based on biggest impact to risk rather than count specifically but these do go hand-in-hand a lot of the time.

If you do specifically need a SQL solution then let me know.

I was leaning towards SQL report as the options in Power Query don’t have the finesse I am looking for to draw out the related software by asset.

If the solution says “upgrade to xx.x version, but the software version is already above that - then thats a potential false positive.

If its below, then the details will benefit the stakeholders to complete impact assessments for the upgrade.

Thanks!

You can check here to see if any of these fit: insightvm-sql-queries/sql-query-export at master · rapid7/insightvm-sql-queries · GitHub

sorry, i didn’t receive an alert that you’d replied to my earlier message. I’ll have a look at what reports I have and will let you know (although they may well be based on reports already in the GitHub linked by CW in this thread so you might already have something)