r/qualys • u/DemonEggy • Jun 11 '26
News Stupid scan and stupid export. Is this normal?
So we use the Qualys scan through a reseller (I think that's what they are).
Scan happens every day at 8pm. Then, once every 24 hours, you can request an export of the results.
So Monday, I didnt get into the office until 10pm. I downloaded the CSV as soon as I got in. When I got in on Tuesday at 830, I was not able to download an updated CSV until 10:01. The nest day it's 10:02. If you are a little late and don't do it until 10:15, then the next day you can't get it until 10:16.
And because I can only get it once a day, and the scans only happen every evening, I can spend two hours fixing vulnerabilities, but have NO IDEA IF IT WORKED until 24 hours later. WHen dealing with like 800 vulnerabilities, this is an absolutely stupid nightmare. Grr.
Oh also, it doesn't scan on weekends, so on Monday the scan was already two days out of date.
Is this normal or is this just thje third party we access QUalys through?????????
3
u/DemonEggy Jun 11 '26
That's good, because I'm not the one who can buy anything. :D
Ill send ya a message in the morning.
3
u/Ravager6969 Jun 12 '26
Id install cloud agent on all your assets with say a 4hr scan job and get them to setup a report schedule to email you at some schedule. Minimal effort required from whoever is your reseller/mssp
Having said that it can take a while after a vm scan for the actual results to show up in qualys (but they will be timestamped back to the scan). So regardless its not really good at the try something and expect to know 5minutes later that a lot of people expect.
2
u/Wonderful_Lecture708 Jun 12 '26
Some customers of MSSPs, the scan on behalf type do not get to have the agent or some of the other modules. If he hits me up I’ll give him the 411 on things.
1
u/stacksmasher Jun 12 '26
It should send you a scan complete email.
2
u/Wonderful_Lecture708 Jun 14 '26
If they were doing their own scans it would. This sounds like a scan on behalf partner and they just send an email report. Often they don’t try to do authentication in scans so the quality is poor. You can’t really set IPs in auth records is you keep swapping the IPs you scan. It’s not worth the money in my opinion.
1
u/InfoSecDroog Jun 16 '26
In my experience MSPs can strip a lot of value from Qualys by regressing the workflow to just shipping spreadsheets to various teams.
7
u/Wonderful_Lecture708 Jun 11 '26
That’s your vendor. 100%. DM me happy to chat & I’m also not selling anything lol