Dashboard Toolbox - VM DASHBOARD BETA: 2019 September Microsoft Out of Band (OOB) Security Updates

Document created by DMFezzaReed Employee on Oct 7, 2019Last modified by DMFezzaReed Employee on Oct 8, 2019
Version 2Show Document
  • View in full screen mode

This page contains information to create a 2019 September Microsoft Out of Band (OOB) Security Updates VM Dashboard leveraging data in your Qualys Vulnerability Management subscription. 

This dashboard is part of the New VM Dashboard Beta program is not intended for production use, and subject to modification without notice.  If you have any questions regarding the content, please comment below or Contact Support - Technical Assistance Inquiry Form | Qualys, Inc.

Related Post: https://blog.qualys.com/laws-of-vulnerabilities/2019/09/24/microsoft-releases-out-of-band-security-updates 

 

The widgets in this dashboard are based on the following base query:

 

VULNERABILITY: 

2019 September OOB QIDs:

vulnerabilities.vulnerability.qid:91577
vulnerabilities.vulnerability.qid:100388
vulnerabilities.vulnerability:(qid:91577 OR qid:100388)

 

VULNERABILITY: These QIDs provide supporting details related to the two (2) QIDs above

Windows Pending Reboot: vulnerabilities.vulnerability.qid:90126

Windows Authentication Not Attempted: vulnerabilities.vulnerability.qid:105296

Windows Authentication Failed: vulnerabilities.vulnerability.qid:105015

Windows Defender Installed: vulnerabilities.vulnerability.qid:105310

Internet Explorer Installed: vulnerabilities.vulnerability.qid:90295

 

ASSET:

trackingMethod:QAGENT
aws.ec2.instanceState:"RUNNING"
azure.vm.state:"RUNNING"
provider:"GCP"

 

Consider the possibilities for this dashboard.  It could be updated to report by status (vulnerabilities.status: [NEW,ACTIVE,REOPENED,FIXED]), or patchable vs. configuration (vulnerabilities.vulnerability.patchAvailable: TRUE/FALSE).  For examples of widgets using these tokens, please visit Dashboard Toolbox - Top 10 Vulnerabilities Scorecard BETA.

 

To create the query string I leverage our Blog and our monthly Security Alerts posts that include the QIDs. 

 

 

Demonstration Image

 

 

 

 

Back to Dashboard Toolbox - New Vulnerability Management (VM) Dashboard BETA 

Back to Dashboards and Reporting Resources - Start Here 

Outcomes