TruRisk™ Insights & Attack Path

Qualys TruRisk™ Insights provides toxic combinations of remediation-worthy risk that combine different security factors including exploitable vulnerabilities, asset exposure, business criticality, secrets, malware, and more. These toxic combinations are also mapped to attack paths that security teams can act on for remediation purposes.  

Key Pre-Requisites  

  • Attack Paths Are Supported For  
    • Kubernetes & OpenShift containers only including Amazon EKS, Azure AKS, Google GKE/GKE Autopilot, Red Hat OpenShift, and any Self-Managed Kubernetes Cluster.  
    • Registry Scanned Images 
  • Risk Factors come from a combination of different insights that may come from different sensors.
  • You need to enable Qualys TotalCloud 

Contributing Risk Factors Supported 

The following table lists the risk factors supported and the scan/sensor that is required. For containers, Qualys combines risk factors from sensors as well as registry scans from the associated image of that container. 

Risk Factor  Sensor Required 
Internet Exposure Cluster Sensor 
Excessive Permissions Cluster Sensor
EOL/EOS Software Registry Scan
AI Software Registry Scan
Secrets Registry Scan
Malware Registry Scan
MCP Server/AI Model File Detection General Sensor

Example Use Case 

Let’s say there is a publicly exposed container with root privilege and excessive permissions. TruRisk™ Insights highlights this as a critical insight. Since this insight is supported with Attack Path visualization, you can view the downstream resources that could be affected, allowing an analyst to: 

  • Assess the full exposure chain 
  • Identify the most effective remediation step 
  • Implement changes directly from the visualization 

Viewing Insights  

When clicking on the Insights Tab you can see a list of each Insight and the count of resources (containers or images) found for each risk combination. Insights can be filtered based on severity criteria as well as registry, cluster, etc.  

Viewing Details Of An Insight And Attack Path 

Upon clicking an insight, security teams can view the details of the insight including Contributing Risk Factors, Overview Summary, Mitigation Steps and more. Security teams can also see the list of containers affected.  

Dashboards For Insights 

You can use the TruRisk™ Insight widget type to show Insights/Attack Paths for Containers.  

  1. On the Dashboard tab, click the Add Widget  button. The widget library is displayed. 
  2. Search for TruRisk™ Insights. Click Customize
  3. You can update the Widget Name from TruRisk Insights to a desired name. Optionally, you can check the 'Show description on widget' if you want to display the widget description. 
  4. This widget by default supports all insights coming from TotalCloud as well. To filter the insights from containers, in the QQL enter insight.title:"container" or insight.title:"image"