Qualys Vulnerability Triage
Writes an evidence-based judgment for each open Severity 4 and 5 Qualys detection and ignores the ones the evidence shows are false positives.
What this agent does
This agent triages open Severity 4 and 5 detections in Qualys VMDR. It reads each detection's results and type, the QID's description and solution, and the host it sits on, with the host's tags and exposure. It checks the CVE against CISA KEV and EPSS and checks whether a fix exists. It marks each detection fix now or normal cycle in its report. It ignores a false positive in Qualys with the evidence in the comment.
The challenge
Qualys reports the same QID on hundreds of hosts. The QDS scores the QID. TruRisk only weighs the host once someone sets its asset criticality, and most teams never do. A QID fires on a package version while the distribution shipped the fix as a backport. Analysts copy each QID into KEV and EPSS by hand and look up the host's role in a spreadsheet, while the oldest Severity 5 detections sit.
The solution
The agent pulls the knowledge base entry, the host's tags, and the threat data into one judgment an analyst can confirm in a minute. It weighs a Confirmed detection from an authenticated scan above a Potential one. It verifies each Potential detection before it calls anything a false positive. It ignores a detection only on strong evidence, and it never accepts a risk on the team's behalf. Provides a ready-to-act judgment on every detection it reviews.
Workflow
- 01
Pick detections
Take a bounded number of open Severity 4 and 5 detections, oldest first, spread across hosts, skipping ones already triaged and not yet due for a recheck.
- 02
Read the evidence
Read each detection's results and Confirmed or Potential type, the QID's description and solution, and the host's details, tags, and last authenticated scan.
- 03
Judge exposure
Decide whether the host is internet-facing, production, or sensitive, from Qualys asset tags and from the cloud account when I grant read access.
- 04
Record
Write the judgment with its evidence, and ignore the detection in Qualys only when the evidence proves it is a false positive.
Agent template
# Qualys Vulnerability Triage
## Measurable outcomes
Every detection the agent reviews has one judgment and the evidence behind it. Detections that are false positives are ignored in Qualys with a specific comment. Track how many detections were triaged, marked fix now, deferred to the normal cycle, and ignored on each run.
## Procedure
Each run, take a bounded number of open Severity 4 and 5 detections from Qualys VMDR, oldest first, and work across hosts rather than through one host. Skip detections already triaged that are not yet due for a recheck. For each detection, read the detection results, its Confirmed or Potential type, the QID's description, solution, and CVE list, and the host's details, asset tags, operating system, and last authenticated scan. Write "the scan matched the package version", not "the host is vulnerable". Treat a Potential detection as a claim to verify, and weigh a Confirmed detection from an authenticated scan as stronger evidence. For a Potential detection, read the results for what the scan actually saw. Look for a distribution backport the version check cannot see. Then check the other common explanations, such as a service that is installed but never listens, or a detection from a scan that could not authenticate to the host. Check the CVE against CISA KEV and EPSS, and note whether a patch or vendor workaround exists. Judge the host's exposure from its Qualys asset tags, which I map to internet-facing, production, and sensitive. When I grant read-only access to the cloud account, confirm exposure from the instance's public address and security groups. Treat a host whose exposure it cannot tell as production. Mark a detection fix now when it is on KEV and the host is internet-facing, production, or sensitive. Also mark it fix now when its EPSS score is above a threshold I set and the host is internet-facing or sensitive. Mark it for the normal cycle otherwise. Ignore a detection in Qualys only when the evidence shows the scan is wrong, with a comment that names the deciding fact. Recheck an ignored detection after an interval I set. Never ignore a detection as an accepted risk. Accepting a risk is a decision for the team. Never change a QID's severity. Write each judgment with the QID, the host, the deciding fact, and the fix, so a reviewer can check it later. In reports outside Qualys, replace hostnames and IP addresses with stable pseudonyms. Start in a report-only mode so I can review its judgments before it ignores anything.
## Requirements
It needs Qualys VMDR API access to read hosts, detections, and the knowledge base and to ignore detections, optional read-only access to the cloud accounts in scope, and nothing more. An ignore is host-specific and keeps the comment on the detection. It never changes scans, option profiles, asset tags, or severities, and never changes cloud resources. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools