What is the difference between GFI LANguard and Microsoft Baseline Security Analyser (MBSA)?

The information in this article applies to:

  • GFI LANguard 9.0
  • GFI LANguard Network Security Scanner 3
  • GFI LANguard Network Security Scanner 5
  • GFI LANguard Network Security Scanner 6
  • GFI LANguard Network Security Scanner 7
  • GFI LANguard Network Security Scanner 8

Article ID: KBID001441

Query keywords: features

GFI LANguard has many more security scanning features:

  • Target computers
    MBSA only scans Windows NT + computers
    GFI LANguard scans Windows 9X (Windows 95, 98, SE, Me)  & NT+ computers. GFI LANguard also scans Unix machines & network devices (such as routers, switches, network printers, ...)
     
  • Port scanning
    MBSA does not do port scanning
    GFI LANguard does TCP & UDP port scanning
     
  • Operating system identification
    MBSA identifies only Windows NT, 2k, XP computers
    GFI LANguard determines all Windows variants (9x, NT, 2k, XP), most Unixes and many network devices (switches, routers, printers, ...)
     
  • Information gathering
    GFI LANguard gathers much more information compared to MBSA, such as : users, shares, services, running processes, security policies, snmp information, open ports, and more.
     
  • Deploy missing patches
    MBSA only discovers missing patches
    GFI LANguard discovers missing patches AND deploys missing patches on remote computers.
     
  • CGI scanning
    MBSA does not do CGI scanning
    GFI LANguard searches for known vulnerable CGIs on websites
     
  • SNMP scanning and auditing
    MBSA does not do SNMP
    GFI LANguard allows scanning/auditing of SNMP devices
     
  • Result comparison & Scheduled scanning
    MBSA does not support result comparison, neither scheduled scanning
    GFI LANguard allows comparison of scanning results with previous results for discovering new security problems. This can be done automatically using Scheduled scans feature.
     
  • Alerts database
    MBSA does not allow new security alerts to be added
    GFI LANguard allows easy addition of new security alerts. Also, GFI LANguard includes LANS (GFI LANguard Scripting) for defining custom security scripts.
     
  • Update security alerts
    MBSA does not allow security alerts to be updated.
    With GFI LANguard, the user is be up-to-date with the latest security problems.
     
  • Support for Anti-Virus\Anti-Spyware (GFI LANguard N.S.S. 8 and later)
    MBSA does not check Anti-Virus and Anti-Spyware definition files. 
    GFI LANguard version 8 and later notifies when Anti-Virus and Anti-Spyware definition files are not up to date. 
     
  • USB & Network Cards (GFI LANguard N.S.S. 8 and later)
    • MBSA does not do Network card scanning.
      GFI LANguard provides a list of enumerated Network Cards. 
    • MBSA does not allow whitelisting and blacklisting.
      GFI LANguage Network Security Scanner allows the whitelisting and blacklisting of USB and network cards.
       
  • Customize reports
    MBSA does not allow for customisation of reports
    GFI LANguard allows customization of generated reports, selecting only necessary/wanted information
     
  • Report/query generator
    Not possible under MBSA
    With GFI LANguard you can define queries on generated reports to extract certain information;
    for example: Which windows computers are running an ftp server.