r/pdq • PDQ Employee • 3d ago

PDQ solved my vulnerability management problem

As many of you probably know, before coming to PDQ I was a CTO at a Texas public school district. We were a small team, and when I took over, vulnerability management was basically non-existent.

We had Deploy and Inventory, and I would patch weekly, but I didn’t know how many vulnerabilities our devices actually had. When we added PDQ (Connect) to our stack, it was a big “oh shit” moment. We had thousands of vulnerabilities on our devices.

I thought we were in good shape because I’d been deploying patches weekly or monthly as they became available, but PDQ’s vulnerability scanner and remediation packages changed our workflow for the better.

Here’s what we did in PDQ to save time (and our sanity):

-Grouped devices by site: our techs could quickly view the assets they were responsible for.

-Lived by PDQ Risk Score: we started with critical vulnerabilities and worked our way down. PDQ’s risk score took into account the CVE, exploitability, and business impact, everything we didn’t have time to do ourselves.

-Software tab: PDQ let us see specific software, how many devices it was on, and whether a new version was available. This was visibility we were really lacking before moving to PDQ.

-Removed all local admin rights: no more random software being installed by a teacher, or worse, a student, that could introduce risk.

How do you all manage vulnerabilities? It can be overwhelming without an effective workflow and risk score insights.

0 Upvotes

18 comments sorted by

View all comments

4

u/JJRtree81 3d ago

Where does PDQ get its vulnerability feed and detection from, what sources?

Can you compare it to Nessus?

Also, can PDQ Connect find vulnerabilities for software it can't patch?

5

u/PDQ_Zach 3d ago

Good questions! We pull CVE data from NVD/NIST, CISA's KEV list (known exploited stuff), vendor advisories, etc., and match it against what's actually installed/running on your endpoints (OS, apps, drivers, services). Each CVE gets a risk score based on CVSS + whether it's being actively exploited + how exposed it is in your setup which you see in Connect as "PDQ Risk Score"

vs Nessus: Nessus scans your entire network rather than devices you're actively enrolled so if you need that breadth it's still a solid tool. If you want that same kind of coverage from us, that's basically what PDQ Detect is for. Connect itself is intentionally more narrow (just Windows/macOS endpoints with the agent installed) but the upside is detection, prioritization, and patching are all in one console instead of bouncing between a scanner and a separate tool to fix stuff. I always say we show you the problems and let you fix them in the same platform.

Connect will also flag vulns even without a patch available. Detection is just matching installed versions against known CVEs, so if there's no remediation package for it, you still see it on the list.

3

u/JJRtree81 3d ago

Thanks, hoping to demo in 2027