How other Qualys customers are using the SN integrations

Joe Kline
Kilo Guru

Wondering how other folks out there are using the details from Qualys to import and utilize Information Gathered QIDs, and how you might use those to highlight if the last vulnerability scan properly authenticated (or not) to set expectations of how much "trust" you have with the reported vulnerabilities to then act on mitigating them.  We have customized our implementation to attempt to share with our Systems Administrators to work with the scan team to fix authentication records and credentials when a scan results in failed or not attempted to authenticate.  SN pushed back on us at the start stating that IGs are not in their design for VR.

 

Anybody doing this sort of thing out there that we can perhaps compare notes with?

 

Thanks in advance for your time and consideration,

Joe