February 01, 2006
$2,195 for Class C
- Ease of Use:
- Value for Money:
- Overall Rating:
- Strengths: Simple to use, very comprehensive tests, good performance, well supported.
- Weaknesses: Could use some more functions, such as patch management and scripting. This is a very strong, bare bones product, but it is bare bones.
- Verdict: Great scanner with a very good interface and established credentials.
Saint is a venerable product with its roots in the earliest days of automated vulnerability assessment. It has been dressed up in a new suit of clothes since becoming a commercial product, but retains its strong Unix roots.
Saint is, first and foremost, a vulnerability scanner. In that regard, it is very similar to Nessus, but its user interface is about as clean as one would expect and it is web-based, making any web browser the platform for the GUI.
Saint is available in a variety of configurations, including software for installation on a Unix or Linux computer, SaintBox, an appliance, and WebSaint, a remote scanning service that allows the organization to initiate scanning over the web and then log back in to view results.
Finally, an optional remote console, SaintManager, enables users to manage medium-to-large networks, including scan, policy and results management and reporting using an SQL database.
Support is acceptable and there is a strong web presence adding to the support in an on-demand fashion. Saint is generally easy to use, although not all Linuxes behave well. RedHat 7.2 went very smoothly, even in a VMWare environment, but Mandrake 10.2 did not allow a clean installation and Saint had to be uninstalled.
Features, considered in the contest of this type of scanner were very good. However, some additions, such as an API and scripting language that allows users to write vulnerability tests would be useful. We understand that is in the pipeline.
Generally, Saint is an extremely strong workhorse vulnerability assessment tool, quite scalable and true to its mature vulnerability assessment roots, while presenting an easy-to-use and configure user environment.
Performance was strong and the scanner made quick work of our test network, identifying all of the devices, real and virtual, and delivering a very credible scan report. Generally, we view Saint as a very strong, although plain vanilla, vulnerability assessment tool worthy of recommendation.
Sign up to our newsletters
SC Magazine Articles
- APT operation 'Double Tap' exploits serious Windows OLE bug
- 'DoubleDirect' MitM attack affects iOS, Android and OS X users
- Android malware 'NotCompatible' evolves, spawns resilient botnet
- Vulnerabilities identified in three Advantech products
- The Internet of Things (IoT) will fail if security has no context
- Operators disable firewall features to increase network performance, survey finds
- DDoS attacks cost organizations $40,000 per hour, survey finds
- Waste no time patching Windows Schannel, OLE bugs, experts warn
- Study: 68 percent of healthcare breaches caused by loss or theft of devices, files
- Spin.com redirects to Rig Exploit Kit, infects users with malware, Symantec observes
- Study: 'High priority' issues hamper endpoint security solution implementation
- Researchers identify POS malware targeting ticket machines, electronic kiosks
- Pirated Joomla, WordPress, Drupal themes and plugins contain CryptoPHP backdoor
- DDoS attacks grew in size, threats became more complex, Q3 reports say
- Man gets 18 months in prison for accessing Subway POS devices, loading up gift cards