Skip to main content
{ Reporting and Compliance / Vulnerability Management }

Qualys Posture Report

Delivers a weekly report on Qualys coverage across your hosts, what changed in the detection backlog, and anything in the subscription that needs an admin, from stale agents to license use.

What this agent does

This read-only agent checks the health of a Qualys VMDR subscription every week. It finds hosts that Qualys has never scanned, has not scanned recently, or scans only without credentials. It summarizes the Severity 4 and 5 detections that appeared, were fixed, and were ignored since last week. It flags anything that needs an admin, such as a scanner appliance that is offline, Cloud Agents that stopped checking in, a scheduled scan that keeps failing, or license use close to the contract.

The challenge

Qualys only finds vulnerabilities on the hosts it scans, and coverage gaps raise no alert. A scanner appliance loses its network path. An activation key runs out, and new hosts never get an agent. A cloud connector stops running, and new instances never appear. A credential record expires, and every scan on that subnet turns unauthenticated. Ignored detections accumulate with no review of who ignored what. The licensed host count grows past the contract, and admins find out at renewal.

The solution

The agent checks coverage, scan health, backlog movement, and subscription limits in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    Find hosts with no scan, no scan in the window, or only unauthenticated scans, and compare with the cloud inventory when I grant access.

  2. 02

    Check scan health

    Check scanner appliances, Cloud Agent check-ins, activation keys, cloud connectors, scan schedules, and authentication failures.

  3. 03

    Check the backlog

    Summarize Severity 4 and 5 detections opened, fixed, and ignored since last week.

  4. 04

    Report

    Publish what changed, the license position, and what needs action, with the fix for each item.

Agent template

# Qualys Posture Report

## Measurable outcomes

Every week, the admin knows which hosts Qualys is not covering, how the Severity 4 and 5 backlog moved, and what needs action before it breaks. Track covered and uncovered hosts, scan failures, and open action items on every run.

## Procedure

Once a week, list the hosts Qualys VMDR knows about. Flag the ones with no scan in the last 14 days, unless I set another window, and the ones whose only recent scans ran without credentials. Judge authentication from the scan's authentication results, not from the option profile alone. When I give it read-only access to my cloud accounts, compare their running instances with the hosts in Qualys and flag any instance Qualys has never seen. Flag AWS, Azure, and Google Cloud connectors whose last run failed or is older than the window. Check each scanner appliance and flag any that are offline or on an outdated version. Flag Cloud Agents that have not checked in during the window, and activation keys that are expired or out of capacity. Flag scheduled scans whose last run ended in Error or Interrupted, was Canceled, or scanned fewer hosts than the run before. Summarize the Severity 4 and 5 detections that appeared, were fixed, and were ignored since the last report, with who ignored each one and the comment they left. Compare licensed host use with the contract's limit, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Replace hostnames, IP addresses, and user names with stable pseudonyms in the report. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Qualys VMDR API access to hosts, detections, scans, scanner appliances, Cloud Agents, activation keys, and cloud connectors, optional read-only access to the cloud accounts for the inventory comparison, and nothing more. It never changes scans, detections, tags, connectors, or settings.