The Swiss Army Knife of SecTools
Use Cases and Deployment Scope
The question to ask this is - what DOESN'T Qualys VMDR not do? Here are the widgets I have used: - Vuln scans of devices (server/PC/network) - Patch mgmt - Threat intel feed (with prioritization & use of MITRE) - Asset mgmt - PCI ASV onboard
Pros
- Seamless reporting across the different widgets (i.e. TruRisk)
- DEEP-DIVE into an asset's info/vulns
- Baked-in PCI ASV scans that a Qualys QSA can approve
Cons
- Add the container feature a little better
- Less of use API's & more connectors to keep it simple for onboarding data
- Agent for network devices - akin to what I get for server/desktop
Return on Investment
- Taking the man-hours out & doing it with Qualys VMDR Vuln scans (i.e. CAPAT)
- Same for patch mgmt
- TruRisk gives super info on what your attack surface looks like
Usability
Alternatives Considered
Tenable Nessus, Metasploit, BeyondTrust Network Security Scanner and powered by Retina (Legacy)
Other Software Used
Tenable Nessus, Google Workspace, Google Cloud Platform



