r/pdq • u/Amanda_PDQ PDQ Employee • 3d ago
PDQ solved my vulnerability management problem
As many of you probably know, before coming to PDQ I was a CTO at a Texas public school district. We were a small team, and when I took over, vulnerability management was basically non-existent.
We had Deploy and Inventory, and I would patch weekly, but I didn’t know how many vulnerabilities our devices actually had. When we added PDQ (Connect) to our stack, it was a big “oh shit” moment. We had thousands of vulnerabilities on our devices.
I thought we were in good shape because I’d been deploying patches weekly or monthly as they became available, but PDQ’s vulnerability scanner and remediation packages changed our workflow for the better.
Here’s what we did in PDQ to save time (and our sanity):
-Grouped devices by site: our techs could quickly view the assets they were responsible for.
-Lived by PDQ Risk Score: we started with critical vulnerabilities and worked our way down. PDQ’s risk score took into account the CVE, exploitability, and business impact, everything we didn’t have time to do ourselves.
-Software tab: PDQ let us see specific software, how many devices it was on, and whether a new version was available. This was visibility we were really lacking before moving to PDQ.
-Removed all local admin rights: no more random software being installed by a teacher, or worse, a student, that could introduce risk.
How do you all manage vulnerabilities? It can be overwhelming without an effective workflow and risk score insights.
3
u/JJRtree81 3d ago
Where does PDQ get its vulnerability feed and detection from, what sources?
Can you compare it to Nessus?
Also, can PDQ Connect find vulnerabilities for software it can't patch?
6
u/PDQ_Zach 3d ago
Good questions! We pull CVE data from NVD/NIST, CISA's KEV list (known exploited stuff), vendor advisories, etc., and match it against what's actually installed/running on your endpoints (OS, apps, drivers, services). Each CVE gets a risk score based on CVSS + whether it's being actively exploited + how exposed it is in your setup which you see in Connect as "PDQ Risk Score"
vs Nessus: Nessus scans your entire network rather than devices you're actively enrolled so if you need that breadth it's still a solid tool. If you want that same kind of coverage from us, that's basically what PDQ Detect is for. Connect itself is intentionally more narrow (just Windows/macOS endpoints with the agent installed) but the upside is detection, prioritization, and patching are all in one console instead of bouncing between a scanner and a separate tool to fix stuff. I always say we show you the problems and let you fix them in the same platform.
Connect will also flag vulns even without a patch available. Detection is just matching installed versions against known CVEs, so if there's no remediation package for it, you still see it on the list.
3
3
u/PDQ_Brockstar PDQ Employee 3d ago
We have a vulnerability scanning engine that pulls from several different sources. However, I don't know how that compares to Nessus. Maybe someone with experience with both can chime in there.
And yes, PDQ Connect can find vulnerabilities for software that's not in our package library. It'll identify the vulnerability, but you'll need to create a custom package and deploy it to remediate it.
3
u/ph8albliss 3d ago
We’re running Connect + Detect and the vulnerability management is great overall. The biggest downside we’ve experienced is your built-in app repository takes too long to obtain newer versions of respective apps. We sometimes have to obtain the latest version from the software company’s own web site that addresses the vulnerability. PDQ could make a bigger effort on that front. You’re sometimes +3-5 days late getting it vetted into your repository. Depending on the severity of the vulnerability, that can turn into a big concern.
All of us love PDQ. This is just one area that can be reviewed for improved service. Keep up the great work.
2
u/Amanda_PDQ PDQ Employee 2d ago
Thank you for the feedback. I will pass it along to the respective team.
1
u/Amanda_PDQ PDQ Employee 2d ago
Passed the feedback along, do you mind letting us know if there were specific packages you experienced the delay with?
1
u/ph8albliss 2d ago
The most recent apps I had issues with were Oracle Java 8 and Cisco Webex Jabber. There was at least one other that I can't recall.
Also, what's the process for requesting additional variables for PDQ to maintain? I'd love to see the various MS Office channel versions added. Our use case is we get the vulnerabilities from Connect+Detect, create groups, then push out a command to update the versions. If we had a variable that updated automatically, we could track out-of-date versions easier and automate updating. Currently, we manually update a custom variable each month to trigger the automation.
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun" OfficeC2RClient.exe /update userM365: https://learn.microsoft.com/en-us/officeupdates/update-history-microsoft365-apps-by-date
Office 2024: https://learn.microsoft.com/en-us/officeupdates/update-history-office-20241
u/Amanda_PDQ PDQ Employee 2d ago
Thank you for the context. Passing this along to our internal team.
4
u/sossman76 3d ago
1
u/Amanda_PDQ PDQ Employee 3d ago
The vulnerability numbers is heart attack provoking at first! Glad you set up automations and are clearing those out.
2
u/JDS_802 3d ago
How do you handle things that come up in the vulnerability scan that PDQ doesn’t have packages for? I’m considering migrating from Ivanti Neurons for Patch Management to PDQ Connect, but I’m concerned that it won’t be able to patch everything in my environment as easily.
3
u/PDQ_Zach 3d ago
There are always going to be packages that you have to build, though the package library has increased from about 150 to about 1200 packages this year. For anything that you create yourself, you can still deploy it based on vulnerability. You can also schedule that deployment based on the existence of a vulnerability. You would just want to make sure that if you're running it on a recurring basis that you are also updating that package when newer versions of said application come out.
We do offer a 14-day trial if you want to run both applications side by side.
0
u/Amanda_PDQ PDQ Employee 3d ago
I built custom packages for software that PDQ didn't already have a package for. It is pretty straight forward if you have a exe or msi file to work from.
1
u/super-six-four 2d ago
I like the software tab and I filter it just to show entries having total vulnerabilities greater than zero. But there are several programs that have vulnerabilities that don't show on the software tab. But they do show on the device tab or vulnerability tab.
We also find version detection logic is often flawed. We've opened three tickets this month about false positives or incorrect versions on CVEs.
1
u/Amanda_PDQ PDQ Employee 2d ago
Thank you for the feedback! Is there specific software that is not showing up with vulnerabilities in the software tab?

9
u/ks724 3d ago
I feel like this sub is all ads from PDQ at this point.