The Swiss Army Knife of SecTools
Use Cases and Deployment Scope
The question to ask this is - what DOESN'T Qualys VMDR not do? Here are the widgets I have used: - Vuln scans of devices (server/PC/network) - Patch mgmt - Threat intel feed (with prioritization & use of MITRE) - Asset mgmt - PCI ASV onboard
Pros
- Seamless reporting across the different widgets (i.e. TruRisk)
- DEEP-DIVE into an asset's info/vulns
- Baked-in PCI ASV scans that a Qualys QSA can approve
Cons
- Add the container feature a little better
- Less of use API's & more connectors to keep it simple for onboarding data
- Agent for network devices - akin to what I get for server/desktop
Likelihood to Recommend
For any company that does not have a bottomless budget & endless resources this is perfect. Which is most companies - you get multiple features OOTB for an incredibly reasonable cost. I look forward to using Qualys VMDR again.
