In previous versions of the Cyberwatch platform, it was possible to automatically deploy patches for Windows and Microsoft applications supported by KB. With the 14.6 update, it is now possible to deploy patches for third-party software using the Windows Package Manager, also known as WinGet.
Let's take a look at what this new feature entails and how to optimize patch management for Windows applications.
Improving patch management for Windows applications
What is patch management?
Patch management is the process of distributing and applying software updates. Having a strategy and the right tools allows you to:
- Fix vulnerabilities present on systems;
- Optimize the time spent deploying updates;
- Ensure that the entire fleet has been patched.
What is Windows Package Manager?
Windows Package Manager is a package manager released by Microsoft that allows you to install, update, and uninstall software, even if it wasn't originally installed using Windows Package Manager.
It complements existing patch management capabilities for Windows environments directly within the Cyberwatch interface. So, how do you use it, and how can you effectively update Windows applications?
Implementing patch management with the Cyberwatch platform
Third-party applications on Windows can now also be updated directly from the Cyberwatch platform. This new feature is compatible with all existing update functionalities.
Since third-party applications installed on Windows environments are not updated via Windows Update, they are harder to keep current and are often overlooked, especially if they were installed outside of a centralized deployment process. Vulnerabilities associated with these applications increase the cyber exposure of your information system.
Combining the use of the Cyberwatch platform with Windows Package Manager is therefore an effective way to remediate vulnerabilities related to these applications.
What are the prerequisites?
Windows Package Manager is installed by default on Windows 11, modern versions of Windows 10, and Windows Server 2025. No additional configuration is required for these operating systems.
Which applications can be deployed?
To use this feature, the application must be supported by both the Cyberwatch platform and the Windows Package Manager. This includes most common applications such as browsers, office suites, development tools, databases, and other widely used software.
To verify that an application is covered by patch deployment, you can check that the software is supported by Cyberwatch (List of covered software) and by the Windows Package Manager (winget-pkgs).
4 steps to use Windows Package Manager in Cyberwatch
Let's walk through these four steps to use the Windows Package Manager on your Cyberwatch instance:
- Monitor the target asset with the Cyberwatch platform.
- Windows Package Manager is automatically detected during the asset scan.
- In the "Administration" menu, authorize patch deployment as well as patch deployment via the Windows Package Manager.
- On the asset details page, under the "Patch management" menu, you can now see that supported Windows applications can be updated from the interface.
Optimizing Windows application patch management
Patch management is an integral part of the vulnerability management cycle offered by Cyberwatch.
To optimize patch deployment, you can leverage the tools provided by Cyberwatch while adhering to the patch management policy established within your organization.
Patches can be deployed from an asset page as seen previously, or from the asset inventory using bulk actions. You can also create a deployment policy to automatically schedule update actions during your maintenance windows.
This policy allows you to define the days and time slots during which assets are permitted to install patches. With Windows Package Manager, this will include cumulative Windows updates, Microsoft updates, and third-party application updates.
To create a deployment policy, go to the "Settings" menu in Cyberwatch, then to "Deployment and reboot policies."
Tip: You can create different policies for your servers and Windows workstations to respect the update schedules for these two asset categories. These policies can be automatically assigned to assets via an asset rule based on the asset's characteristics.
Finally, you can supplement this deployment with a reboot policy to finalize the installation of patches. This is set up in the same way.
Using patch management to better prioritize applications
To optimize the time spent fixing vulnerabilities, you can automatically patch a portion of your IT infrastructure to focus on the most critical assets.
Third-party software installed on Windows assets is traditionally the most vulnerable type of application. To address this, you can implement a deployment policy as described above to automatically reduce the number of vulnerabilities on this non-critical group of assets. The deployed patches will include updates via the Windows Package Manager.
The vulnerability management process is simplified: you automate vulnerability remediation on Windows and Linux for these assets, which reduces remediation time and the number of high-priority vulnerabilities to address in your information system. This allows you to make the best use of your team's time on other tasks, such as monitoring your most critical assets.
In summary
Support for the Windows Package Manager has significantly increased the number of applications that can be updated natively from Cyberwatch. With deployment policy tools, all that's left is to configure your instance and start hunting for vulnerabilities on Windows!
Feel free to share this article, and if you would like to learn more or request a demo, contact our experts, and we will get back to you within 24 hours.
