Skip to main content
Vulnerability Management (VM)

Qualys WAS Integration

Connect Qualys Web Application Scanning to Guard to import web application findings into your unified attack surface.

Guard imports web application findings from Qualys Web Application Scanning (WAS) through the Qualys integration. There is no separate Qualys WAS integration card: the same Qualys connection imports both VMDR host data and WAS data.

How it works

On each sync, the Qualys integration:

  • Imports each Qualys WAS web application as a web application asset.
  • Imports WAS findings of type Vulnerability that are open (status New, Active, Reopened, or Protected) and not ignored in Qualys.
  • Imports only findings last detected within the sync window: the past 90 days on the first sync, and since the previous sync (at least 24 hours) after that.
  • Imports each finding as an open risk (not into triage), with the Qualys WAS severity (1–5) mapped to the risk severity: 1 is Info, 2 is Low, 3 is Medium, 4 is High, and 5 is Critical.
  • Attaches the finding details as proof, and records the finding's CWE codes and first-detected, last-detected, and last-tested dates.

If your Qualys subscription includes WAS but not VMDR, the WAS import still runs.

Prerequisites

  • A Qualys account with Web Application Scanning enabled.
  • A Qualys username and password with permission to read WAS web applications and findings.

Connect Qualys WAS to Guard

  1. In Guard, go to Integrations > Vulnerability Management > Qualys.
  2. Enter your Qualys API Server URL, Username, and Password.
  3. Click Connect. Guard checks the credentials against the Qualys VM API and, if that fails, against the WAS API. The integration is saved if either check passes.

Viewing imported findings

Imported Qualys WAS findings appear on the Vulnerabilities page with findings from other sources. Filter by source to show only Qualys findings.

  • Qualys — setup details and the VMDR host import.

Still need help? Ask the team