Qualys WAS Integration
Connect Qualys Web Application Scanning to Guard to import web application findings into your unified attack surface.
Guard integrates with Qualys Web Application Scanning (WAS) to import web application scan findings into your attack surface. Once connected, Qualys WAS findings appear alongside Guard-native findings, enabling consistent triage and remediation workflows from a single view.
How it works
After you connect Qualys WAS, Guard periodically pulls findings from the Qualys WAS API and surfaces them as risks on the relevant assets. Imported findings are treated the same as Guard-native findings — they appear in the risk list, can be triaged, and participate in remediation workflows.
Prerequisites
- A Qualys account with Web Application Scanning enabled.
- A Qualys API username and password (or API token, if your Qualys subscription supports token-based access) with sufficient permissions to read WAS findings.
Connect Qualys WAS to Guard
- In Guard, go to Integrations > Vulnerability Management > Qualys WAS.
- Enter your Qualys API credentials.
- Save the configuration.
Guard will begin importing findings on the next scheduled sync. Newly discovered findings from subsequent Qualys scans are picked up automatically on each subsequent sync.
Viewing imported findings
Imported Qualys WAS findings appear in the Risks list alongside findings from other sources. Use the Source filter to isolate Qualys WAS findings when needed.
Related integrations
- Qualys — imports host-based vulnerability findings from Qualys VMDR.