Vulnerability scan workflow
Use the Run Vulnerability Scan action to update vulnerability data for selected endpoints without waiting for the next scheduled scan.
Why run a vulnerability scan on demand?
Vulnerability scans run according to the configured scan schedule. After deploying patches, updating applications, or running remediation actions, you may need to verify the results immediately instead of waiting for the next scheduled scan. Running a vulnerability scan on demand updates vulnerability data for selected endpoints so that you can confirm whether vulnerabilities have been resolved and identify any issues that require additional remediation.
Follow this Vulnerability scan workflow
Use this workflow to determine when to run a vulnerability scan on demand, assess the updated vulnerability findings, and decide whether further remediation is required.
1. Review detected vulnerabilities
Review vulnerability findings to identify endpoints that require investigation or corrective action. You might run a vulnerability scan after:
- Deploying a patch
- Updating an application
- Removing vulnerable software
- Running a remediation action
- Investigating newly discovered vulnerabilities
2. Remediate vulnerabilities
Take the appropriate action to address the detected vulnerabilities. Depending on the issue, remediation might include:
- Installing updates
- Deploying patches
- Removing software
- Running a remediation workflow
After completing remediation, run a vulnerability scan to collect updated vulnerability information.
3. Run a vulnerability scan
For details on how to run an on-demand scan, see Run the Vulnerability scan. For information on scan schedules, see Vulnerability Management scan schedule.
4. Review updated results
After the scan completes, review the updated vulnerability information.
- Compare the updated results with previously detected vulnerabilities.
- Verify whether remediation actions were successful.
- Identify any vulnerabilities that require additional investigation or remediation.
5. Continue remediation if required
If vulnerabilities are still detected, review the affected endpoints and take additional corrective action as needed.
- Investigate unresolved vulnerabilities.
- Apply additional remediation measures.
- Run another vulnerability scan to verify the results.
Example
The following example shows how to use a vulnerability scan to validate remediation results:
- Identify a vulnerability on an endpoint.
- Deploy a patch or run a remediation action to address the vulnerability.
- Run a vulnerability scan on demand to collect updated vulnerability data.
- Review the updated vulnerability findings.
- Verify that the vulnerability is no longer detected.
- If vulnerabilities remain, investigate the findings and take additional remediation actions as needed.
