Frequently asked questions

By focusing on Security Patch Management, we strive to be the best in the industry and always keep our customer feedback a top priority.

General

By scanning for missing security and regular patches, organizations can gain the intelligence needed to eliminate the threat posed by insecure and end-of-life software within the corporate environment.

The vulnerability issue cannot be denied. Every organization has the knowledge that vulnerabilities in the IT infrastructure can be used to compromise security. It represents an extra challenge for the teams responsible for IT.

How can you protect your IT infrastructure more effectively? How can you make sure that computers do not have software installed that lacks the latest security patches? And how can you do this without spending vast amounts of time and effort checking dozens of vendor sites for software updates?

By scanning for missing security and regular patches, organizations can gain the intelligence needed to eliminate the threat posed by insecure and end-of-life software within the corporate environment.

The vulnerability issue cannot be denied. Every organization has the knowledge that vulnerabilities in the IT infrastructure can be used to compromise security. It represents an extra challenge for the teams responsible for IT.

How can you protect your IT infrastructure more effectively? How can you make sure that computers do not have software installed that lacks the latest security patches? And how can you do this without spending vast amounts of time and effort checking dozens of vendor sites for software updates?

A vulnerability scanner is a computer program designed to scan for vulnerabilities that are present within your network.

SecTeer was founded in 2017 by its current principals. SecTeer is a privately held, financially stable, and profitable company with a strong track record.

SecTeer VulnDetect is a proactive solution used in addition to firewalls, IDS and other network security systems. It will help you secure and monitor your network against new threats that are otherwise not monitored.

The file signatures and software packages used by SecTeer are maintained and updated daily.

We cover approx. 1800 + applications. Our customers can request software to be added to our database for detection, patching, and deployment. We cover the majority of popular software. There may be less-known software that we don’t detect. This can be requested through our support portal

You can request new software for detection/patching/deployment through the “Contact Support” on your account here: https://corporate.vulndetect.com/#/support.

We will then add detection and if applicable, add the package and support the software in the future.

Customers can suggest new applications to be detected. The applications are reviewed and added if the following criteria are met:

The application must have an EXE, DLL, JAR or similar executable file on the system, which is used for creating a detection rule. Please, provide the name of the primary executable and a link to the vendor or product website when suggesting new apps.

To properly track the security state of the software and be able to recommend the latest and most up-to-date version reliably, it is required that the vendor makes public announcements about releases and security fixes.

A few vendors are very secretive or outright hide such announcements on pages only accessible by customers or partners. Such software is usually flagged as “Untracked”. The state is updated on a “reasonable effort” basis.

For all software with formal announcements, we intend to monitor and review official sources for information upon each new release and will update the status of the software based on publicly available information.

Customers can suggest new applications to be deployable or upgradable via VulnDetect. The applications will be reviewed and tested if the following criteria are met:

The installer must be publicly available from the vendor website or other official distribution site, i.e. the download should not require credentials or license keys.

If the installation or upgrade requires a license key or similar, you may need to provide us with a key while creating and testing the package.

Upgrading the application must be supported by the official installer supplied by the vendor; a few vendors prevent upgrades and only support upgrading via built-in updating mechanisms, e.g. Microsoft Teams and OpenWebStart.

The installation and/or upgrade must be fully silent (i.e. support silent parameters).

If all the above requirements are met, then it is very likely that VulnDetect can support upgrading and installing the application.

It should be noted that requests are prioritized based on prevalence across all customers.

Applications that don’t meet the above criteria may still be supported through the “custom software” feature. If you wish to know more about our “custom software” deployment and update mechanism, please contact your SecTeer account representative.

Yes, Our implementation uses TOTP (RFC 6238) (the Authenticator standard), and is compatible with many popular Authenticator apps.

SecTeer is used across multiple segments, enterprise, small to medium businesses, consultants and managed service providers. Regardless of the environment, the scalable, secure end-to-end solution is unchanged.

General - Technical

We only download installers from official sources mentioned on the vendors website. This may in some cases be CDN sources, Github/Gitlab, or the vendors own download site. 
The packages from VulnDetect are compiled and tested in Denmark, which is part of the EU.
We create a package which downloads the installer directly from the vendor (or in a few cases our archive).
All downloads are checked using a sha256 checksum which we embed in the package.
When possible, we always check the AuthentiCode signature of the installer.
When this isn‘t available, we seek out official sources for sha256sum, GPG signatures, or as a last resort we upload and check the files on VirusTotal for the very few vendors that doesn’t provide proper means of vetting the installers.
It should be noted that VulnDetect caches installers to improve the reliability of downloads, all files that we cache (and all files we download from vendors too) are checked against a sha256sum of the file, which are stored for each version and installer type, to ensure that no files has been altered based on errors on the network, storage, or other reasons.
Our agent downloads the package (PowerShell script) from our server via HTTPS and verifies that the retrieval was conducted through our server.

We only download installers from official sources mentioned on the vendors website. This may in some cases be CDN sources, Github/Gitlab, or the vendors own download site. 
The packages from VulnDetect are compiled and tested in Denmark, which is part of the EU.
We create a package which downloads the installer directly from the vendor (or in a few cases our archive).
All downloads are checked using a sha256 checksum which we embed in the package.
When possible, we always check the AuthentiCode signature of the installer.
When this isn‘t available, we seek out official sources for sha256sum, GPG signatures, or as a last resort we upload and check the files on VirusTotal for the very few vendors that doesn’t provide proper means of vetting the installers.
It should be noted that VulnDetect caches installers to improve the reliability of downloads, all files that we cache (and all files we download from vendors too) are checked against a sha256sum of the file, which are stored for each version and installer type, to ensure that no files has been altered based on errors on the network, storage, or other reasons.
Our agent downloads the package (PowerShell script) from our server via HTTPS and verifies that the retrieval was conducted through our server.

We only download installers from official sources and verify the Authenticode Signature. 
Software like Mozilla Firefox is verified based on the official GPG signed SHA256SUM lists.
However, for a few applications, like 7-Zip which aren‘t signed, we rely on services like VirusTotal and Jotti.org.
We also deploy such apps to a few test systems which run up-to-date anti-malware / endpoint protection software, before approving it for customers.
This is also the primary reason why there is certain proprietary software we don‘t support, when the official installers aren‘t publicly available from official sources.
Before running any installer that is downloaded via our proxy / CDN, the SHA256SUM of the file is checked against the entry we have stored in our database, both to prevent Man-in-the-Middle attacks as well as avoiding to execute a corrupted installer due to network issues.

You can reset your password by clicking on the link below:
https://vulndetect.com/#/forgot-password

If you still encounter issues, please contact support at: support@secteer.com 

1) Open Edge browser

2) Open the website that you want a shortcut to 

3) Open the Edge main menu (three dots on far top right)

4) Hover on the “Apps” menu option

5) Click on the “Install this site as a web app” option > click “Install”

6) Tick the boxes for creating a Desktop shortcut and pinning the app to the Taskbar and/or Start Menu, then click “Allow”

That’s it! Instead of creating a shortcut to a website URL on Edge, you have installed that page as a Web App (PWA), and added a shortcut to it.

SecTeer relies on the original installers provided by the software vendors themselves when performing installations and patching activities. This means that SecTeer does not repackage, modify, or rebuild third-party software. Installers are deployed as provided by the vendor and executed using silent options where available. All installers and execution methods are tested and validated prior to being made available for public release.

Customer data is stored in SQL databases. We operate with an individual database per customer. This guarantees against data leaks and allows us to easily scale our setup, by e.g. distributing individual customers to different hardware instances. It also allows us to easily purge customer data, if or when a contract is cancelled.

You can send your question directly to support@secteer.com, and a solution specialist will be assigned to you and assist with your query.

VulnDetect - General

SecTeer VulnDetect is an authenticated internal vulnerability and application scanner, capable of assessing the security status of programs that run on Microsoft Windows, enabling you to fix the vulnerabilities before they are actively exploited.

SecTeer VulnDetect is an authenticated internal vulnerability and application scanner, capable of assessing the security status of programs that run on Microsoft Windows, enabling you to fix the vulnerabilities before they are actively exploited.

SecTeer VulnDetect is a software solution. An agent is installed locally and has a minimal footprint on the system. The agent installation files are approximately 4MB and use negligible CPU resources and around 4MB of memory when running. At scheduled times, typically once per day, the agent will run a system inspection that temporarily increases the CPU and memory usage. An inspection usually takes only a few seconds.

SecTeer VulnDetect utilizes agent-based scans with minimal resource usage.

Yes. Our internal advisory for the signatures within VulnDetect always includes a link to the CVE reference.

A scan consists of 2 parts; the first part is third-party applications that SecTeer VulnDetect scans for, the second part is matching to the correct updates. Also, you may want to check if the hosts are added to an “approval group”.

A download link is always included to verify the validity of the update.

Only hosts that are in groups are patched. Once a host is in a group, approvals will be automatically created for any discovered software that can be patched. 

Approve the recommended version of the software that an approval applies to and all the hosts in that group that have that software installed will be updated automatically.

You can refer to the VulnDetect Setup guide or contact our support personnel for assistance.

Yes. SecTeer VulnDetect is designed to deploy standard and security patches that were found missing from the scan results. This integration of SecTeer VulnDetect allows network administrators to easily handle the entire vulnerability management life cycle.

Yes, see system requirements for more details.

The SecTeer VulnDetect API allows corporate users to access their SecTeer VulnDetect data outside the web-based user-interface. 
API Tokens are used to authenticate requests to the SecTeer VulnDetect API.

No, the agent only requires an internet connection to deploy, patch and update the applications. 

See system requirements for more details.

VulnDetect - Technical

Yes. All the communication between the SecTeer VulnDetect Agent or the SecTeer VulnDetect Graphical User Interface and SecTeer is made through port 443, and by using SSL protocol with 256-bit encryption.

Yes. All the communication between the SecTeer VulnDetect Agent or the SecTeer VulnDetect Graphical User Interface and SecTeer is made through port 443, and by using SSL protocol with 256-bit encryption.

Yes, VulnDetect uses BITS (Background Intelligent Transfer Service) from Microsoft and allows system administrators to download packages/updates with little impact on the network traffic and bandwidth.

VulnDetect can support an unlimited number of hosts through the multi-site and single-site structure.

The number of systems that can be scanned by SecTeer VulnDetect is dependent on the license that you have purchased from SecTeer. If you reach your license limit, deleting old systems from SecTeer VulnDetect will release the corresponding number of licenses. If you need additional licenses, please contact your SecTeer Sales Representative.

SecTeer VulnDetect is capable of scanning any Windows system, virtual machine and terminal server.

No. Due to its lightweight design, SecTeer VulnDetect is able to run in the most common Windows systems. For more detailed information, please refer to the system requirements for running the SecTeer VulnDetect Centralised Dashboard.

Using SecTeer VulnDetect, you have access to 2 different scan approaches:

  • On-Demand Scanning
    From the VulnDetect GUI, you can easily create scan groups manually. The groups can then scan immediately.
  • VulnDetect Agent – Single Mode
    The SecTeer VulnDetect Agent is a standalone executable file that can run as a local service. The agent can be configured to scan the system at regular intervals available under “configuration”.

Yes, all our packages rely on PowerShell 5.1, the default version on Windows 10 and Windows 11 and modern Windows Server releases. Our PowerShell scripts are digitally signed.

The VulnDetect TSPM packages are all PowerShell scripts. 
These scripts are all signed, and we recommend whitelisting/allowing all scripts that are signed by SecTeer VulnDetect.
SecTeer recommend using the built-in AllSigned security policy, as this improves your general security posture, if it is compatible with your other applications and management tools that use PowerShell.
If your 3rd party security solution doesn’t support whitelisting based on digitally signatures, you may be able to whitelist certain locations:
C:\Programs Files (x86)\SecTeer VulnDetect\
C:\ProgramData\SecTeer VulnDetect\
C:\Users\\AppData\Local\SecTeer VulnDetect\
The user path is based on Env:\LOCALAPPDATA, so it may differ from system to system though this is rare.
Note that scripts running in Program Files and ProgramData all run as SYSTEM.
Scripts running in the user’s folder always run with the users’ privileges, as reported by the operating system.
Most tasks are launched via the Windows Task Scheduler; however, some may be initiated directly via the agent.

We support a particular setting, ensuring that updates are distributed over a specific time interval. The default is a 7.5-hour window, during which all agents will conduct scheduled inspections also will run the “approved” update tasks. This window can be slightly expanded but ensures the evenest distribution should be aligned with the most common work hours. 

Actual inspections are randomly distributed over an interval of up to 10 hours, starting at the selected time.
Applicable updates will run shortly after an inspection is completed.

No. SecTeer VulnDetect does not scan removable or network drives such as USB sticks or other types of removable drives.

When an agent is installed on a host, it generates a unique token and saves it in the Windows Registry on that host. 

That unique token identifies that host to SecTeer VulnDetect.

When the agent is upgraded, it preserves the unique token and thus preserves its identity.

Although the login of concurrent sessions is possible, SecTeer VulnDetect is designed to allow only one session per account. If you wish to have several SecTeer VulnDetect accounts, please ask your SecTeer Sales Representative about an additional Admin license.

Yes.
For this to work, the MSI needs to be run with the following options:
msiexec.exe /quiet /i secteerSetup.msi WRAPPED_ARGUMENTS=”/options=group=groupname”
groupname must be replaced with the group’s full name in VulnDetect.

If the group name has spaces, then the options we recommend are the following:
msiexec.exe /quiet /i secteerSetup.msi WRAPPED_ARGUMENTS=”/options=group=””group name with spaces”””

Those are regular double quotes, first 1, then 2, and then 3 at the end.
Also, note that the agent will remain ungrouped if the named group does not exist.

The SecTeer VulnDetect Agent can be downloaded from your Dashboard under “configuration”.

No, this requires that the old Agent is uninstalled first.
When the agent is successfully installed, a unique auth-token is added to the registry.
This auth-token is associated with the supplied email and used to identify the agent when it communicates with the SecTeer VulnDetect backend servers. The auth-token will remain until the agent is uninstalled.
Upgrading will always preserve the existing auth-token.
In order to get a new auth-token, and associate the agent with a different account, the agent must be manually uninstalled, and then the admin can deploy the MSI, which will create a new auth-token that is associated with the correct account.

The most likely explanation is that an antivirus program uploaded the secteerSetup.msi file and a researcher at that antivirus company installed the program. You can safely hide the agent in the interface. It’s important to note that the MSI file you have received is keyed to your account, so anyone who receives it can run it, and the resulting agent will also be keyed to your account. There is no security issue here because the agent doesn’t receive any significant information from the server.

When an agent is uninstalled, the unique token is deleted from the Windows Registry and cannot be recovered. 

If the agent is installed again on that host, it generates a new unique token and a new identity.

This shows up on the Hosts page as multiple instances of the same host.

All results are counted for all the duplicate hosts while they are present on the Hosts page.

We strive to provide accurate and useful information about the current state of each product, e.g., if it is “OK” or “Insecure” and what type of update we are dealing with, i.e., “Plain/Bugfix Update” or “Security Update”. Unfortunately, not all vendors provide this information, although other parties may have published security information at some point in the past.

Therefore “Untracked” doesn’t mean that we don’t detect the application. It means based on our in-house research, the security and release information from the vendor is not considered reliable.

In general, all beta/alpha/insiders/canary/nightly and other pre-release channels for software is considered *Untracked* as most vendors don’t provide information for this kind of release.

An application version is marked as “Unknown” when VulnDetect cannot reliably determine its current security state based on available information. This typically happens in one of two cases:
 
Unknown + End-of-Life (EoL):
The version was considered secure when it reached EoL, but since it no longer receives updates, it may become insecure over time. We recommend replacing it with a supported version if possible.
 
Unknown + Untracked:
The vendor does not provide sufficient public information to assess security status. In such cases, VulnDetect typically marks the latest version as OK, and older versions as Unknown.
 
In both cases, the “Unknown” label reflects a lack of reliable data not confirmation of either secure or insecure status. When in doubt, updating to a supported version is the safest choice.

VulnDetect supports updating per-user based applications, including Cisco Webex, Microsoft PowerToys, Microsoft Visual Studio Code, Opera, Vivaldi, WinSCP and many more, however, there are a few, yet significant apps, like Firefox and Chrome, which don’t provide installers that support silent upgrade of user based installations nor do they support converting / upgrading user based installations to system based ones, which typically have better support for centralized management and silent options. 

We recommend that you uninstall the user based installations of Firefox and Chrome, if you wish to manage the upgrade, otherwise you have to rely on the built-in updater or the user to update it.

Yes, that is possible by going to Groups -> Edit Selected Group -> Custom Inspect & Update Schedule

“Work-in-Progress” means that the Approval cannot be automated by the Automate New Approvals setting, it requires a manual confirmation.

Packages are initially marked as WIP to indicate that they are new and may not yet be fully tested in production environments.
Despite the package updating with no issues on our test hosts, we will still mark it WiP and will review the updates after a period of time to check if the patch is working as expected to eventually removing the “Work-in-Progress” flag.
We strongly recommend testing new packages on a few (test) systems before updating a large number of hosts.

There is no fixed timeline for removing the WIP flag.
It is based on customer feedback or lack there off and the success rate we see in our logs. It also depends on the frequency of releases and the install base in general. And, we also take a lot longer for e.g. licensed software and VPN software, than we do for well known software that is freely available and easy to test in an ordinary desktop environment.

The most common reason is that the host is offline or hibernates. 
Other times, the package may be waiting for the Windows Installer database, it will wait for up to two hours, before abandoning the update. The update will not be retried until the next regular or manual inspection.
In rare cases an installer may hang, this can be due to local configuration issues, conflicts or unexpected dialogues (which usually will be invisible to the user).
The package will time out after 59 minutes.
The update will not be retried until the next regular or manual inspection.
Also, only one package task can run, despite the Applying state in Package Activities, the other package tasks will wait for the first package to complete or exit due to one of the above mentioned timeouts.
The order in Package Activity is not indicative of the order in which multiple packages are attempted.

Note: In rare cases the Windows Installer database is locked for a very long time, this may be due to other installers running including Windows Updates. In some cases a restart of the host may be required to free the Windows Installer database again.

In some cases, due to the update requiring a restart, we specify that the app requires an “app restart” under “Patching activity.” 

The applications that have the “App Restart Required” are still vulnerable / running the old version, until the app or system has been restarted.

While we do support host restarts, we don’t support restarting individual applications. Host restarts offer a consistent, reliable way to apply updates across the entire system.

Restarting apps individually would require complex, tailored logic for each application, something that adds risk and more frequent user interaction. To keep things safe and maintainable, we avoid app-specific restarts and rely on full system reboots instead.

Microsoft 365 Apps (Office) are updated differently from most other applications. They are not installed or patched as traditional packages. Instead, updates are handled by Microsoft’s built-in Office Click-to-Run service.

When an update is triggered, we instruct Click-to-Run to check with Microsoft for available updates and apply them if they exist. In most cases, Click-to-Run will download and prepare the updates promptly. However, the final application of those updates is fully controlled by Microsoft.

Because Office applications – most notably Outlook – are often running continuously, updates cannot always be applied completely while the system is in use. This can leave a device in a temporary or partially updated state until the system is restarted. A reboot resolves this in most cases, though not all.

For this reason, we strongly recommend that customers implement a reboot policy to reboot Windows devices a few days after each monthly Patch Tuesday. This ensures that pending updates for Windows, Microsoft 365 Apps, and third-party software can be fully applied.

Microsoft Copilot is marked as “Untracked” because Microsoft does not publish sufficiently detailed and reliable release information identifying which vulnerabilities are fixed in each Copilot release, including vulnerabilities affecting the underlying Microsoft Edge components used to render Copilot content.

Previously, Copilot releases closely followed the Microsoft Edge release cadence, allowing the Edge version to serve as a useful indicator of Copilot’s security state. Since late July 2026, the Copilot and Edge release cycles no longer appear to be closely synchronized. Consequently, the installed Copilot version cannot be reliably mapped to a particular Edge security release or its resolved vulnerabilities.

Without an authoritative mapping or suitable release notes from Microsoft, VulnDetect cannot reliably determine the security state of Copilot. The product therefore remains marked as “Untracked”.

VulnDetect offers the option ‘Automatically group new hosts based on their Active Directory groups.’ which will mirror the pre-configured groups present on customers AD. 
The option is only available to System Administrators. To group existing hosts you will have to make a request to support@secteer.com

The integration of Azure Active Directory (AAD) with SecTeer VulnDetect enables automatic grouping of hosts based on their Active Directory (AD) groups. This feature mirrors the pre-configured groups in the customer’s AD, ensuring that hosts in VulnDetect are organized according to the existing directory structure. The integration syncs every 3 hours, keeping group assignments up to date as changes occur in Active Directory, with the option to trigger a manual sync when needed.

The difference between Hidden and Dormant hosts, is that Hidden hosts are based on an admin action, whereas Dormant is 100% automated.
This also means that a Dormant host that becomes active, will be revived automatically, whereas a Hidden host requires an active admin action. 
Whenever possible, rely on Dormant hosts, it‘s much easier.
All hosts will stop counting license wise after 45 days, if they are inactive. Hidden hosts will stop counting license wise within 24 hours.

Note: Per policy we accept temporarily exceeding the license count without additional charges when e.g. replacing a large number of devices, despite the old devices remaining Dormant for 45 days.

Yes, in most cases this will not be an issue. However, you should ensure that the applicability rules for packages applied via other means accept newer versions of the applications, so the applications aren’t downgraded by your deployment tool.

There are two different ways of hiding results.
Using the Ignore Rules feature located in the Configuration page here: 
https://corporate.vulndetect.com/#/configuration

Or by deploying a customizable registry file using Custom Software:
https://vulndetect.org/topic/2388/registry-files-and-the-custom-software-feature

The ignore feature in the UI and the one in the registry are fundamentally different as the purpose of ignoring things using the registry, is to adhere to local privacy regulations, ignore backup drives, and let developers compile apps that may be detected by the agent.

This means that the registry ignore feature completely hides the underlying data from SecTeer VulnDetect, whereas the feature in the UI just hides data we already have stored.

1) Set a string value in the registry, under HKLM\Software\WOW6432Node\SecTeer\Agent
2) The value name is overrideGroup, the value itself is the name of the group that the agent should be in
3) The agent service must be restarted for the agent to read the value and submit it to the backend
4) The backend looks up the group by name, case-insensitive, and if found, it moves the agent to that group
If no group is found with the given name, then the setting has no effect
If multiple groups are found that match the name, then one will be chosen. Which group is chosen is arbitrary, but consistent (it is the first one, ordered by their uuid)
5) The overrideGroup setting persists in the registry, so if the agent is later manually moved to a different group, then it will revert back to the overrideGroup the next time the agent service starts, unless the registry setting is cleared. This will be altered in a future agent release, so that the agent itself will clear the setting, after sending it to the backend.

Do let us know if you have further questions or experience issues. Bear in mind, that this is a new feature, currently only used by one other customer.

VulnDetect - Reporting

A weekly report is sent to you, which provides a Dashboard overview with the following information: 

Summary of the number of applications which are/have:

# Out-of-Date Approvals

# Groups

# Hosts

# Products

# Versions

# Installations

# 0-Day

# Insecure

# End-of-Life

# Ok

A weekly report is sent to you, which provides a Dashboard overview with the following information: 

Summary of the number of applications which are/have:

# Out-of-Date Approvals

# Groups

# Hosts

# Products

# Versions

# Installations

# 0-Day

# Insecure

# End-of-Life

# Ok

SecTeer VulnDetect can generate PDF reports; however, it is possible to extract custom made reports from SecTeer VulnDetect. Use Export to export the data into the Clipboard or into a .CSV file.

There are 2 data types in the dashboard: live data and historical data. 

The Vulnerability Status Breakdown, Updates Deployed Automatically, and the Summary show real-time data, while the Software Installations and non-Live Updates under Updates Deployed Automatically (dropdown menu) show historical data.

Historical data is compiled in the backend every 3 hours. The Dashboard page fetches data from the backend every 60 seconds. When the Dashboard page fetches data from the backend, this refreshes the live data and the historical data in the UI. The live data will be up to date at the time it is fetched, while the historical data may be up to 3 hours old.

VulnDetect - Windows Updates

The Windows Update feature pulls available updates via the currently configured Windows Update service, this means that it will query your WSUS if this is configured. If WSUS isn‘t updated with the most recent updates, these will not be visible in VulnDetect. In short, it will use the configured Windows Update on the host, if that is WSUS, then we query WSUS, if not, then it will typically be the public one.
The Windows Update feature pulls available updates via the currently configured Windows Update service, this means that it will query your WSUS if this is configured. If WSUS isn‘t updated with the most recent updates, these will not be visible in VulnDetect. In short, it will use the configured Windows Update on the host, if that is WSUS, then we query WSUS, if not, then it will typically be the public one.

The Windows Updates page only shows the updates that are available and not yet applied. 
The Windows Update Approvals page show some of the recently applied updates, but those covered in cumulative updates or other major updates of the OS seems to be hidden by the WU API, because these larger updates already include the smaller more specific updates. The data shown is based on the Windows Update API and should closely reflect what you see in the local UI of the Host.
So the Windows Updates page shows the current status of windows updates across the environment, while the Windows Update Approvals gives the user options to apply or block updates.

Windows Update Approvals cannot be automated because Windows updates are not versioned, so a Windows Update Approval is never Out-of-Date. 
Setting a Windows Update Approval to approve updates is sufficient to make the system apply that Windows Update to all applicable hosts.

In essence, all updates in VulnDetect are run within minutes of a scheduled or manual inspection. This, is also true for Windows Updates. Only updates that has been rescheduled to run during startup or login are exempt from this logic, i.e. this is irrelevant for Windows Updates.

The use of Windows Update approvals within VulnDetect does not prevent Windows Updates to be installed by other means, e.g. the built-in Windows Update Agent in Windows or other tools.

To fully manage Windows Updates with SecTeer VulnDetect, an Active Directory Group Policy can be configured to disable automatic application of Windows updates by the Microsoft Windows Update service.

There is an option to approve ALL future Windows Updates by default by editing a group setting and turning on the “Default Status for new Windows Update Approvals”. Note that this will not apply to existing WU Approvals, you will have to manually approve them.

Drivers are supported via Windows Update, to the extent that the drivers are available via the Windows Update (server) endpoint that is configured on the host.

PatchPro

We will always provide the latest version through PatchPro for deployment, hence there won’t be supersedence required where you update or replace something. In Intune, supersedence enables you to update and replace existing Win32 apps with newer versions of the same app or an entirely different Win32 app.

We will always provide the latest version through PatchPro for deployment, hence there won’t be supersedence required where you update or replace something. In Intune, supersedence enables you to update and replace existing Win32 apps with newer versions of the same app or an entirely different Win32 app.

When you use “Publish New Version of Selected Applications”, then it will only publish the ones that are selected, in this case, it should only update the EXE and not the MSI. But it is important to remember, that we only update apps that were originally published via PatchPro, we cannot hijack other apps, which were created manually or by other parties.

Supersedence isn’t required but it is to be used only in special scenarios. And fortunately we do not need it, as it would make things a lot more complicated, plus it has some arbitrary limitations, which may or may not be an issue after a long time. Instead, we update the currently published application and its detection rules, including its version. For most applications this suffices.

Yes, it is the same as for VulnDetect. Please see System Requirements.

Currently, we only have English-US and Danish, in 32-bit and 64-bit. We are planning to add support for all languages soon, it is required to Publish each language and architecture that needs to be available inside Intune and then use Intune to assign it to the appropriate groups. If more languages are needed, please do let us now, and we will add them before we make the proper solution with all languages.

The packages for PatchPro show up in Intune as “Windows app (Win32)”.

Stop attacks before they happen

One exposed device is all it takes. Protect your endpoints against evolving cyber threats with advanced security patch management solutions.