Ernst & Young Pvt Ltd
Details of the IT Security Audit Tools
Freeware
- Nmap - Port scanner
- Nessus - Vulnerability scanner
- Nikto - Web server/application vulnerability scanner
- Ethereal - Protocol analyzer
- Somersoft - Security configuration, registry entries and access control lists on systems running the Windows operating system.
Commercial
- App Detective - Vulnerability assessment and review of security configuration of MySQL, Oracle, Sybase, IBM DB2, MS SWQL Server, Lotus Notes/Domino, Oracle Application Server, Web Applications.
- Bv-Control Suite - Security assessment -Microsoft Windows, Active Directory, Microsoft Exchange, Microsoft SQL Server, UNIX (Sun Solaris, HP-UX, AIX, Red Hat and SUSe Linux), Internet Security, Check Point Firewall I
- HP WebInspect - Web Application Security assessment
- IPLocks VA - Database configuration and vulnerability assessment
- eEye Retina - Network Security scans and IT infrastructure vulnerability assessment
- Immunity Canvas - Vulnerability exploitation framework for penetration tests
- eTrust - Online vulnerability management framework.
- Bv-Control - Security and segregation of duty review for SAP
Proprietary
- iNTerrogator - Review of security configuration of systems running the windows operating system.
- *nix scripts - A collection of scripts to assess the security configuration including file level ACLs on *nix systems (SCO OpenServer, Linux, HP-Ux, AIX, Solaris, *BSD).
- Spider - Web application security assessment
- FakeOra - Security assessment of 2-tier applications that use Oracle 8i (and above) as RDBMS.
- S-SAT - A travelling SAP Security tool.
- Permit - ERP risk assessment and control solution tool.
- Assessor - Configuration review of Oracle Financials system.
- WebSmack - Web Application inventory and vulnerability assessment .
- EY/Mercury - Web based technical work plan generator to perform security configuration review of IT infrastructure.