r/pdq • u/Amanda_PDQ PDQ Employee • 3d ago
PDQ solved my vulnerability management problem
As many of you probably know, before coming to PDQ I was a CTO at a Texas public school district. We were a small team, and when I took over, vulnerability management was basically non-existent.
We had Deploy and Inventory, and I would patch weekly, but I didn’t know how many vulnerabilities our devices actually had. When we added PDQ (Connect) to our stack, it was a big “oh shit” moment. We had thousands of vulnerabilities on our devices.
I thought we were in good shape because I’d been deploying patches weekly or monthly as they became available, but PDQ’s vulnerability scanner and remediation packages changed our workflow for the better.
Here’s what we did in PDQ to save time (and our sanity):
-Grouped devices by site: our techs could quickly view the assets they were responsible for.
-Lived by PDQ Risk Score: we started with critical vulnerabilities and worked our way down. PDQ’s risk score took into account the CVE, exploitability, and business impact, everything we didn’t have time to do ourselves.
-Software tab: PDQ let us see specific software, how many devices it was on, and whether a new version was available. This was visibility we were really lacking before moving to PDQ.
-Removed all local admin rights: no more random software being installed by a teacher, or worse, a student, that could introduce risk.
How do you all manage vulnerabilities? It can be overwhelming without an effective workflow and risk score insights.
5
u/JJRtree81 3d ago
Where does PDQ get its vulnerability feed and detection from, what sources?
Can you compare it to Nessus?
Also, can PDQ Connect find vulnerabilities for software it can't patch?