Skip to main content
{ Vulnerability Management }

Qualys Vulnerability Triage

Writes an evidence-based judgment for each open Severity 4 and 5 Qualys detection and ignores the ones the evidence shows are false positives.

What this agent does

This agent triages open Severity 4 and 5 detections in Qualys VMDR. It reads each detection's results and type, the QID's description and solution, and the host it sits on, with the host's tags and exposure. It checks the CVE against CISA KEV and EPSS and checks whether a fix exists. It marks each detection fix now or normal cycle in its report. It ignores a false positive in Qualys with the evidence in the comment.

The challenge

Qualys reports the same QID on hundreds of hosts. The QDS scores the QID. TruRisk only weighs the host once someone sets its asset criticality, and most teams never do. A QID fires on a package version while the distribution shipped the fix as a backport. Analysts copy each QID into KEV and EPSS by hand and look up the host's role in a spreadsheet, while the oldest Severity 5 detections sit.

The solution

The agent pulls the knowledge base entry, the host's tags, and the threat data into one judgment an analyst can confirm in a minute. It weighs a Confirmed detection from an authenticated scan above a Potential one. It verifies each Potential detection before it calls anything a false positive. It ignores a detection only on strong evidence, and it never accepts a risk on the team's behalf. Provides a ready-to-act judgment on every detection it reviews.

Workflow

  1. 01

    Pick detections

    Take a bounded number of open Severity 4 and 5 detections, oldest first, spread across hosts, skipping ones already triaged and not yet due for a recheck.

  2. 02

    Read the evidence

    Read each detection's results and Confirmed or Potential type, the QID's description and solution, and the host's details, tags, and last authenticated scan.

  3. 03

    Judge exposure

    Decide whether the host is internet-facing, production, or sensitive, from Qualys asset tags and from the cloud account when I grant read access.

  4. 04

    Record

    Write the judgment with its evidence, and ignore the detection in Qualys only when the evidence proves it is a false positive.

Agent template

# Qualys Vulnerability Triage

## Measurable outcomes

Every detection the agent reviews has one judgment and the evidence behind it. Detections that are false positives are ignored in Qualys with a specific comment. Track how many detections were triaged, marked fix now, deferred to the normal cycle, and ignored on each run.

## Procedure

Each run, take a bounded number of open Severity 4 and 5 detections from Qualys VMDR, oldest first, and work across hosts rather than through one host. Skip detections already triaged that are not yet due for a recheck. For each detection, read the detection results, its Confirmed or Potential type, the QID's description, solution, and CVE list, and the host's details, asset tags, operating system, and last authenticated scan. Write "the scan matched the package version", not "the host is vulnerable". Treat a Potential detection as a claim to verify, and weigh a Confirmed detection from an authenticated scan as stronger evidence. For a Potential detection, read the results for what the scan actually saw. Look for a distribution backport the version check cannot see. Then check the other common explanations, such as a service that is installed but never listens, or a detection from a scan that could not authenticate to the host. Check the CVE against CISA KEV and EPSS, and note whether a patch or vendor workaround exists. Judge the host's exposure from its Qualys asset tags, which I map to internet-facing, production, and sensitive. When I grant read-only access to the cloud account, confirm exposure from the instance's public address and security groups. Treat a host whose exposure it cannot tell as production. Mark a detection fix now when it is on KEV and the host is internet-facing, production, or sensitive. Also mark it fix now when its EPSS score is above a threshold I set and the host is internet-facing or sensitive. Mark it for the normal cycle otherwise. Ignore a detection in Qualys only when the evidence shows the scan is wrong, with a comment that names the deciding fact. Recheck an ignored detection after an interval I set. Never ignore a detection as an accepted risk. Accepting a risk is a decision for the team. Never change a QID's severity. Write each judgment with the QID, the host, the deciding fact, and the fix, so a reviewer can check it later. In reports outside Qualys, replace hostnames and IP addresses with stable pseudonyms. Start in a report-only mode so I can review its judgments before it ignores anything.

## Requirements

It needs Qualys VMDR API access to read hosts, detections, and the knowledge base and to ignore detections, optional read-only access to the cloud accounts in scope, and nothing more. An ignore is host-specific and keeps the comment on the detection. It never changes scans, option profiles, asset tags, or severities, and never changes cloud resources.