Cloud Agent Remote Detection
Using a separate scanner for remote detection increases the operational complexity of asset management. Also, sometimes user environments are not compatible for deploying scanner appliances or virtual machines. These restrictions pose significant challenges to continuously safeguarding assets.
To overcome these challenges, we have developed new capabilities for Cloud Agent. The Qualys Cloud Agent can now be configured and used as a scanner. Cloud Agent, as a scanner appliance, caters to the following important use case.
Remote Detection by Cloud Agent on Its Host
Cloud Agent supports remote detection on the asset where it is installed. You no longer need to deploy scanner appliances for assets already running Cloud Agents.
The Cloud Agent automatically downloads a lightweight, headless scanner binary based on configuration settings and executes remote detection tasks such as TLS inspection, banner collection, and packet‑based vulnerability detection.
To enable the remote detection for Cloud Agent perform the following steps:
- In the Cloud Agent user interface, navigate to Configuration > Configuration Profile.
- Select a configuration profile to enable the remote detection or create a new profile.
- In the Configuration Profile workflow, open the Scan Configuration section.
- Switch the Remote Detections toggle to ON.
- Configure the following settings for remote detections:
Data Collection Interval: This setting specifies the time duration between two successive remote detection scans for Cloud Agent hosts. You can configure the remote detection data collection interval in days or hours.
Exclusions: This setting specifies the assets to be excluded from the remote detection. Currently, you can exclude the network ports from remote scan detection. Enter the comma-separated list of ports you want to exclude from remote detections.
Benefits
Enabling Cloud Agent remote detection on host assets offers the following benefits:
- Eliminates dependency on scanner appliances for agent‑managed hosts.
- Reduces operational overhead (no authentication records, firewall rules, or scan windows required).
- Provides complete vulnerability coverage by deploying Cloud Agents.
How Cloud Agent Remote Detection Works
The following is the high-level workflow of using Cloud Agent as scanner for remote detection:
- Enable Remote Detection in the Cloud Agent Configuration Profile.
- The profile instructs the Cloud Agent to download the headless scanner binary.
- During the next scheduled scan, the agent launches the scanner with required job metadata.
- Scan results are collected locally, then sent directly to Qualys platform.
- Final results are processed by Gateway and VMSP, and displayed in the user interface.