# Qualys

> Your estate keeps changing. Your list of what’s exposed keeps up.

Qualys finds what is exposed across your whole estate, and keeps finding it as the estate changes.

**Key points**

- Continuous discovery, so the inventory stays true
- Network, web, cloud and containers in one view
- Findings scored and tracked to a verified fix

## The estate you have today, not the one in the diagram

### An inventory that stays true

Assets discovered continuously rather than listed once, which is the only way the count survives contact with a cloud environment.

### Vulnerability detection at estate scale

Authenticated and unauthenticated scanning across operating systems, applications and network devices, with detections kept current as new ones are published.

### Web applications and cloud posture

The public web estate tested for its own class of weakness, and cloud accounts checked against benchmark configuration.

## What Qualys actually looks at

- **Servers and workstations** — Authenticated scanning of Windows, Linux and macOS: missing patches, weak configuration, and software nobody has updated since the day it was installed.
- **Network devices** — Firewalls, switches, routers and the appliances that arrived with someone else’s default credentials and still have them.
- **Public web applications** — The sites and portals anyone can reach, tested for injection, broken authentication and the misconfigurations a network scan cannot see.
- **Cloud accounts** — AWS, Azure and Google configuration against benchmark: storage left public, keys that never expire, and roles holding more permission than the job needs.
- **Containers and images** — What is inside the images you deploy and what is already running in the registry, so a vulnerability is caught before production rather than after it.
- **Certificates and what is expiring** — Every TLS certificate across the estate, including the ones issued by somebody who has since left and renewed by nobody.
- **Assets nobody declared** — The hosts answering on your ranges that appear in no inventory: test environments, forgotten virtual machines, and equipment a department plugged in without asking.

## What you get

**An exposure register, ranked by what is actually reachable** — Ordered by exploitability and exposure rather than by raw severity, so the top of the list is worth doing first. Every finding carries the asset it sits on, the fix, and the rescan that proves it closed. We run the platform and hand you the validated list, not the raw one.

---

Canonical: https://centio.bg/reshenia/qualys