SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Custom Scripting in SanerNow to Remediate Zero-day Vulnerabilities

Custom Scripting in SanerNow to Remediate Zero-day Vulnerabilities

Mar 12, 2023By Shivathmaja PS4 min read

A Zero-day vulnerability is a security risk that’s unknown to the developer or the vendor but already out in public. Since the vendors themselves just found out, a patch for the vulnerability doesn’t exist, leaving your network exposed and at risk. This makes zero-day vulnerabilities some of the most dangerous security risks that could be crawling into your environment. Cybercriminals want to exploit these vulnerabilities as soon as possible, significantly increasing the potential risk. A good Vulnerability Management tool can resolve these issues.

So how do you combat zero days and mitigate the security risk it brings? Use a Vulnerability Management Tool to combat these issues.

Combating Zero days with SanerNow

Manually mitigating zero days isn’t easy, but an advanced vulnerability management solution like SanerNow can make your life significantly easier.

SanerNow is an advanced vulnerability management solution that can automatically detect dangerous vulnerabilities and security risks like zero-days, misconfigurations, posture anomalies, and more and instantly fix them with patches and custom remediation controls.

Zero-day vulnerabilities, in particular, don’t have a patch. So, they require remediation controls like custom scripting, misconfiguration controls, or firewall configurations to reduce the potential risk since it cannot be completely eliminated. SanerNow, with its advanced remediation controls and custom scripting, can reduce the overall risk your network is under.

How does Custom Scripting Work?

Scripts are special batch files that consist of code to perform a particular functionality. Custom scripting in SanerNow, as the name suggests, allows you to write custom code with a particular functionality to achieve the necessary result. It allows you to modify the settings and configurations of your IT network as needed.

Typically, desktop applications like web browsers(Chrome, Firefox, etc.) and productivity apps(MS Office) do not use services to function. On the other hand, server-based applications like SQL, Apache, and others use services to function.

With SanerNow’s custom scripting, you can block a desktop application to ensure it doesn’t cause harm, and you can also disable the service a server-based application uses to ensure it doesn’t lead to an attack.

Remediating a Zero-day in SanerNow with Custom Scripting

SanerNow can perform the action in two different ways, either by using a custom script in the Software Deployment menu or by stopping the service in the Service menu.

    • Disabling a service using custom scripts:


      In the EM dashboard, select Software Deployment under the Actions menu.





      Here, you can upload batch files(in zip files) by clicking the upload button. The batch file should consist of code that stops the service being used by the Zero-day application.







      Then, you can choose the uploaded batch file and click on Install to apply it to your network. You can also choose the assets in which you want SanerNow to run the script.







      You can also customize the application of the script according to your needs. You can either schedule it when needed or apply it immediately, which is always suggested.




    • Blocking the service automatically using the SanerNow Service feature:


      In the SanerNow Endpoint Management module, under the Actions menu, select the Service button.







      In the Service dashboard, you can select the zero-day application’s service and select the devices in which the application is to be stopped. You can also schedule the response, but it’s recommended to block the apps immediately. 


    • Blocking an application using SanerNow Application Block:


      In the SanerNow Endpoint Management module, under the Actions menu, select the Application and Device Control button.







      In the Application and Device Control dashboard, you can choose any application with a zero-day vulnerability and select the devices in which you want it to be blocked. You can also schedule the response, but it’s recommended to block the apps immediately.




Conclusion

Zero-day vulnerabilities are the last thing you want to see in your network, but you must always be prepared and ready for them. SanerNow, with its advanced security controls like custom scripting and application blocking, can help you stop vulnerability from becoming an attack until a patch is available. So, vigilance and proactiveness in mitigating risks can go a long way in preventing cyberattacks.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026