skip to content

Qualys

Qualys is a managed cloud platform: Cloud Agents and connectors keep an asset inventory continuously scanned, with QIDs and TruRisk scoring. It fits when the task is proving compliance at scale.

on this pageshow

explore

questions

5

In Qualys VMDR, what is a QID, and why is it not the same thing as a CVE?

level: juniorimportance: must knowfreq 30%

answer

  1. the KnowledgeBase entry, not the advisory
  2. one detection, possibly several CVEs
  3. Confirmed, Potential, Information
  4. Qualys severity versus your severity
  5. inventory QIDs carry no CVE

basics

~20 s

A QID (Qualys ID) is the number of one detection in the Qualys KnowledgeBase. A CVE names a published flaw; a QID is Qualys's test and verdict, may list several CVEs, and can carry none at all.

solid answer

~40 s

A **QID** is the unique Qualys ID of one detection in the Qualys **KnowledgeBase**; Qualys maintains more than 100,000 of them. It is the unit everything in VMDR counts: a finding is "QID X on asset Y". A CVE is an industry identifier for a published flaw, while a QID is Qualys's own check plus its result, so one QID can list several CVEs in `vulnerabilities.vulnerability.cveIds`, and many QIDs have none. Each finding has a detection type (**Confirmed**, **Potential** or **Information**), a Qualys severity from 1 to 5 that you can override with your own severity, and a Qualys Detection Score. Information-gathered QIDs such as 45141 (installed packages on Unix and Linux) record facts, not flaws. You can also write **custom QIDs** for in-house software.

go deeper

for a junior

Recall that a QID is a KnowledgeBase detection, not a CVE, and name the three detection types: Confirmed, Potential and Information.

for a middle

Explain the mapping: zero, one or several CVEs per QID, the highest-scoring CVE driving QDS, and Qualys severity beside customer severity.

for a senior

Show you use the detection type and information-gathered QIDs in triage and reporting, and when a custom QID fits in-house software.

for a principal

Discuss the reporting unit: QIDs internally, CVEs for external audiences, and governance over customer-severity overrides that change every dashboard.

## What a QID is Qualys VMDR (Vulnerability Management, Detection and Response) does not count findings in CVEs. It counts them in **QIDs**: Qualys IDs, unique numbers assigned to each detection in the **Qualys KnowledgeBase**. The VMDR onboarding guide says Qualys maintains more than 100,000 QIDs, kept up to date by its Threat Research team. Every row in the Vulnerabilities tab is a QID found on an asset, and every query, report and widget groups on that number. A QID bundles three things: - **A test.** How the scanner appliance or Cloud Agent decides the condition is present. The vulnerability details page calls this the detection logic. - **A description.** Title, category, the CVEs it relates to, the vendor references and the solution. - **Scoring metadata.** A Qualys severity from 1 to 5, and the inputs to the Qualys Detection Score (QDS). You can search for it directly in the Qualys Query Language (QQL): ``` vulnerabilities.vulnerability.qid: 90405 ``` ## Why a QID is not a CVE A CVE identifies a published flaw. A QID identifies Qualys's way of detecting something on a host. The two are related, but they do not map one to one. | | CVE | QID | |---|---|---| | Who assigns it | A CVE numbering authority | Qualys | | What it names | A disclosed flaw | A detection: a test and its result | | CVEs per item | One | Zero, one or several (`cveIds`) | | Can you author one | No | Yes, as a custom QID | Three consequences matter when you report on QIDs: 1. **One QID can carry several CVEs.** When it does, the QDS calculation uses the CVE with the highest score. If you count CVEs instead of QIDs, the numbers will not match VMDR's. 2. **Some QIDs carry no CVE.** Information-gathered QIDs record facts about a host. QID 45141 lists installed packages on Unix and Linux. QID 90235 lists applications enumerated from Windows Installer. The Vulnerability Predictions feature needs both to have run in an authenticated scan at least once. An option profile with "Complete" vulnerability detection includes them; a custom profile has to add them. 3. **You can write your own.** A **custom QID** is defined with Custom Assessment and Remediation (CAR) scripts, written in languages such as PowerShell or Python, which detect issues in first-party or open-source software. Custom QIDs live in the KnowledgeBase under the Custom QID category. They need a subscription enabled for Vulnerability Management Scan Processing (VMSP) and CAR 1.8.0.0 or later. ## Detection type, severity and score Each finding carries a **detection type**, searchable as `vulnerabilities.typeDetected`: - **Confirmed**: the test proved the condition. - **Potential**: the evidence points to the condition, but the test could not confirm it. - **Information**: an information-gathered fact, not a weakness. The VMDR Prioritization report includes only confirmed vulnerabilities. The `vulnerabilities.vulnerability.risk` token is ten times the severity for confirmed and potential findings, and equals the severity for information-gathered ones. Two severity values exist side by side. The **Qualys severity** (1 to 5, `vulnerabilities.vulnerability.severity`) is the KnowledgeBase value. The **customer severity** (`vulnerabilities.severity`) is one your subscription can set. If you never set it, it equals the Qualys value. The severity bar shows an arrow when you have raised or lowered a QID. Grouping by vulnerability lists the QID at your updated level, while vulnerability counts show it after the next asset scan. Separately, each detection gets a **QDS** from 1 to 100, which feeds the asset's TruRisk Score. ## Reading one QID's page From the QID column of the Vulnerabilities tab, open a QID to see two panels: - **Detection Summary**: the asset details and tags, the vulnerability result returned on that host, the description and the detection logic. The result is the evidence to read before anyone disputes a finding. - **QDS Details**: the contributing factors behind the score, namely the highest-contributing CVE, associated malware and threat actors, and when exploitability last trended. Reading the result field first often settles an "is this real?" question without re-running a scan. ## How to talk about it in an interview - Report on QIDs, and translate them to CVEs only for an external audience. - Read the detection type before you escalate. A Potential finding needs verification before it is treated as proven. - Treat a customer-severity change as a governed decision. It changes what your subscription's dashboards and counts show, not the KnowledgeBase entry other customers see.

  • A stakeholder's spreadsheet counts 40 CVEs where VMDR shows 25 QIDs on the same host. Is one of them wrong?
    Not necessarily. A QID can list several CVEs in `cveIds`, so 25 QIDs can easily cover 40 CVEs. Information-gathered and custom QIDs carry no CVE at all. Reconcile by exporting the QIDs with their CVE lists. VMDR's Vulnerabilities tab can download data based on CVE or QID. Then report in the unit the audience needs.
  • When would you write a custom QID rather than wait for Qualys to publish one?
    Write one for your own software or a niche component that Qualys's KnowledgeBase will never cover: an in-house agent, or a vulnerable internal library version. A custom QID uses CAR detection scripts, so the finding lands in the same inventory, prioritization and reporting as vendor QIDs. It needs VMSP enabled and CAR 1.8.0.0 or later, and you own its accuracy.

saying these in an interview costs you the question

  • A QID is just Qualys's number for a CVE, one to one
  • Every QID describes a vulnerability that needs patching
  • Changing a QID's severity edits the shared KnowledgeBase entry
  • Potential findings are proven flaws, just like Confirmed ones
  • Counting CVEs gives the same total as counting QIDs
open as a page

Before replacing Qualys scanner appliance scans with Cloud Agents, how do you check which QIDs the agents can actually detect?

level: middleimportance: should knowfreq 22%

basics

~10 s

Search the Qualys KnowledgeBase with Supported Modules set to CA-Windows Agent or CA-Linux Agent, or query vulnerabilities.vulnerability.supportedBy. Any QID you rely on that is missing from that list still needs scanner appliance scans.

open as a page

Two Qualys VMDR assets carry the same critical QIDs, yet one has a TruRisk Score of 900 and the other 350 — what explains the gap?

level: seniorimportance: should knowfreq 18%

basics

~20 s

TruRisk Score multiplies the asset's criticality (ACS, 1 to 5) by severity-weighted QDS averages, capped at 1000. Identical QIDs on an ACS 5 and an ACS 2 asset differ about 2.5 times. Mitigation controls and external exposure explain the rest.

open as a page

A scheduled Qualys scan of 10.20.0.0/16 fails with 'A virtual or physical scanner appliance is needed' — why, and what fixes it?

level: middleimportance: nice to knowfreq 12%

basics

~20 s

Qualys's external cloud scanners scan from the internet and will not scan private addresses. A 10.x target needs an internal scanner appliance, deployed where it can route to that range and selected for the scan.

open as a page

A Qualys AWS connector lists 1,200 running EC2 instances, but only 900 have VMDR findings — how do you find and close the gap?

level: seniorimportance: nice to knowfreq 9%

basics

~20 s

Query the connector's inventory for running instances without an agent (aws.ec2.hasAgent: false AND aws.ec2.instanceState: RUNNING). Then find installed agents that stopped checking in. Close the gap by provisioning agents through the connector, and scan from appliances what cannot host one.

open as a page