Originally posted here by SDK
For the basic free stuff, SUS and Microsoft Baseline Security Analyzer SHOULD be in your admin toolbox!
That along with some perl scripts has worked ok for me.

Check out these perl scripts
http://pantheon.yale.edu/%7Ekjh27/sus-scripts.html

You can modify them to make them work for you. So, you have more than one method of verifying what boxes are being patched without giving yourself a headache looking through the http logs. Just make sure that your http log is rotating monthly, not daily...