Posted on January 13, 2011.
What is the best program to detect network vulnerability? GFI LANguard or Nmap? Nmap does not do anything except find the open ports, operating systems, and do scans TCP and UDP. It does not tell you if a service is vulnerable. Although very useful for finding this information, it will not help you determine if the software version, it works (which he will report to you) is vulnerable. GFI LANguard is not a vulnerability scanner at all. I think you mean GFI Network Security Scanner (NSS), which only scan for vulnerabilities. If these are the tools you use to compare to each other, GFI NSS is much better because that's what he serves. However, if you compare with NSS GFI eEye Retina or Core Impact, GFI would lose. It is a medium security scanner, where the retina and Core Impact are much better at doing what they do.
I think both are good tools to get an overview of your network and very useful in vulnerability testing to get "the lay of the land." You can use Nmap to find out which ports are open and then do a more complete scan using GFI NSS. However, if you want an open source software, you should use your Nessus vulnerability scanner. GFI is cheap, starting at $ 249, but without assets> $ 1 more than Nessus is probably the best of both. Of course, if you need technical support cheap, go with GFI that their product is much cheaper than a contract Tenable Network Security Support.
WG