Vulnerability management
Cloud and dedicated servers
We recommend scanning servers for vulnerabilities. This can be done using network vulnerability scanners or software agents on the hosts.
Network scanners check hosts that are accessible over the network, and some scanners also support authentication configuration for more accurate analysis.
You can use free network scanners:
An example of a free scanner that runs as an agent on hosts is Wazuh. To run the scanner, install it on each host:
- shared Wazuh server — for details, see the Quickstart article in the Wazuh documentation;
- Wazuh agents — for details, see the Wazuh agent article in the Wazuh documentation.
You can create a cloud server with a pre-installed Wazuh application.
On Linux servers, you can also use Lynis — a security auditing and compliance tool at the host level. Lynis ensures operating system and application security by checking configurations, permissions, vulnerabilities and outdated packages, firewall settings, and critical system parameters.
On cloud servers, scanners can be installed in the form of custom images.