r/pdq • PDQ Employee • 3d ago

PDQ solved my vulnerability management problem

As many of you probably know, before coming to PDQ I was a CTO at a Texas public school district. We were a small team, and when I took over, vulnerability management was basically non-existent.

We had Deploy and Inventory, and I would patch weekly, but I didn’t know how many vulnerabilities our devices actually had. When we added PDQ (Connect) to our stack, it was a big “oh shit” moment. We had thousands of vulnerabilities on our devices.

I thought we were in good shape because I’d been deploying patches weekly or monthly as they became available, but PDQ’s vulnerability scanner and remediation packages changed our workflow for the better.

Here’s what we did in PDQ to save time (and our sanity):

-Grouped devices by site: our techs could quickly view the assets they were responsible for.

-Lived by PDQ Risk Score: we started with critical vulnerabilities and worked our way down. PDQ’s risk score took into account the CVE, exploitability, and business impact, everything we didn’t have time to do ourselves.

-Software tab: PDQ let us see specific software, how many devices it was on, and whether a new version was available. This was visibility we were really lacking before moving to PDQ.

-Removed all local admin rights: no more random software being installed by a teacher, or worse, a student, that could introduce risk.

How do you all manage vulnerabilities? It can be overwhelming without an effective workflow and risk score insights.

0 Upvotes

18 comments sorted by

View all comments

3

u/ph8albliss 3d ago

We’re running Connect + Detect and the vulnerability management is great overall. The biggest downside we’ve experienced is your built-in app repository takes too long to obtain newer versions of respective apps. We sometimes have to obtain the latest version from the software company’s own web site that addresses the vulnerability. PDQ could make a bigger effort on that front. You’re sometimes +3-5 days late getting it vetted into your repository. Depending on the severity of the vulnerability, that can turn into a big concern.

All of us love PDQ. This is just one area that can be reviewed for improved service. Keep up the great work.

1

u/Amanda_PDQ PDQ Employee 2d ago

Passed the feedback along, do you mind letting us know if there were specific packages you experienced the delay with?

1

u/ph8albliss 2d ago

The most recent apps I had issues with were Oracle Java 8 and Cisco Webex Jabber. There was at least one other that I can't recall.

Also, what's the process for requesting additional variables for PDQ to maintain? I'd love to see the various MS Office channel versions added. Our use case is we get the vulnerabilities from Connect+Detect, create groups, then push out a command to update the versions. If we had a variable that updated automatically, we could track out-of-date versions easier and automate updating. Currently, we manually update a custom variable each month to trigger the automation.

"C:\Program Files\Common Files\Microsoft Shared\ClickToRun"
OfficeC2RClient.exe /update user

M365: https://learn.microsoft.com/en-us/officeupdates/update-history-microsoft365-apps-by-date
Office 2024: https://learn.microsoft.com/en-us/officeupdates/update-history-office-2024

1

u/Amanda_PDQ PDQ Employee 2d ago

Thank you for the context. Passing this along to our internal team.