Qualys Posture Report
Delivers a weekly report on Qualys coverage across your hosts, what changed in the detection backlog, and anything in the subscription that needs an admin, from stale agents to license use.
What this agent does
This read-only agent checks the health of a Qualys VMDR subscription every week. It finds hosts that Qualys has never scanned, has not scanned recently, or scans only without credentials. It summarizes the Severity 4 and 5 detections that appeared, were fixed, and were ignored since last week. It flags anything that needs an admin, such as a scanner appliance that is offline, Cloud Agents that stopped checking in, a scheduled scan that keeps failing, or license use close to the contract.
The challenge
Qualys only finds vulnerabilities on the hosts it scans, and coverage gaps raise no alert. A scanner appliance loses its network path. An activation key runs out, and new hosts never get an agent. A cloud connector stops running, and new instances never appear. A credential record expires, and every scan on that subnet turns unauthenticated. Ignored detections accumulate with no review of who ignored what. The licensed host count grows past the contract, and admins find out at renewal.
The solution
The agent checks coverage, scan health, backlog movement, and subscription limits in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check coverage
Find hosts with no scan, no scan in the window, or only unauthenticated scans, and compare with the cloud inventory when I grant access.
- 02
Check scan health
Check scanner appliances, Cloud Agent check-ins, activation keys, cloud connectors, scan schedules, and authentication failures.
- 03
Check the backlog
Summarize Severity 4 and 5 detections opened, fixed, and ignored since last week.
- 04
Report
Publish what changed, the license position, and what needs action, with the fix for each item.
Agent template
# Qualys Posture Report
## Measurable outcomes
Every week, the admin knows which hosts Qualys is not covering, how the Severity 4 and 5 backlog moved, and what needs action before it breaks. Track covered and uncovered hosts, scan failures, and open action items on every run.
## Procedure
Once a week, list the hosts Qualys VMDR knows about. Flag the ones with no scan in the last 14 days, unless I set another window, and the ones whose only recent scans ran without credentials. Judge authentication from the scan's authentication results, not from the option profile alone. When I give it read-only access to my cloud accounts, compare their running instances with the hosts in Qualys and flag any instance Qualys has never seen. Flag AWS, Azure, and Google Cloud connectors whose last run failed or is older than the window. Check each scanner appliance and flag any that are offline or on an outdated version. Flag Cloud Agents that have not checked in during the window, and activation keys that are expired or out of capacity. Flag scheduled scans whose last run ended in Error or Interrupted, was Canceled, or scanned fewer hosts than the run before. Summarize the Severity 4 and 5 detections that appeared, were fixed, and were ignored since the last report, with who ignored each one and the comment they left. Compare licensed host use with the contract's limit, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Replace hostnames, IP addresses, and user names with stable pseudonyms in the report. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Qualys VMDR API access to hosts, detections, scans, scanner appliances, Cloud Agents, activation keys, and cloud connectors, optional read-only access to the cloud accounts for the inventory comparison, and nothing more. It never changes scans, detections, tags, connectors, or settings. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools