TruRisk™ Insights & Attack Path
TruRisk™ Insights is a report on the contributing factors of a TruRisk™ Score. Each TruRisk™ Insight is typically defined by a combination of contributing factors that, when present together, can exponentially increase the risk of the asset. These insights provide a detailed understanding of the risk landscape, enabling more effective risk management and mitigation strategies.
The Insights tab showcases a list of TruRisk™ Insights and the count of resources impacted by them. As you click any available insights, you learn about their contributing factors, the resources impacted, the insight details, and the possible mitigations.
You can also use tokens to narrow down insights related to the assets or specifications you require. Refer to Search for Insights to learn more about available tokens.
Qualys TruRisk Insights provides toxic combinations of remediation-worthy risk that combine different security factors including exploitable vulnerabilities, asset exposure, business criticality, secrets, malware, and more. These toxic combinations are also mapped to attack paths that security teams can act on for remediation purposes.
Key Pre-Requisites
- Attack Paths Are Supported For
- Kubernetes & OpenShift containers only including Amazon EKS, Azure AKS, Google GKE/GKE Autopilot, Red Hat OpenShift, and any Self-Managed Kubernetes Cluster.
- Registry Scanned Images
- Risk Factors come from a combination of different insights that may come from different sensors.
Contributing Risk Factors Supported
The following table lists the risk factors supported and the scan/sensor that is required. For containers, Qualys combines risk factors from sensors as well as registry scans from the associated image of that container.
Table??
| Risk Factor | Sensor Required |
Internet Exposure
Cluster Sensor
Excessive Permissions
Cluster Sensor
EOL/EOS Software
Registry Scan
AI Software
Registry Scan
Secrets
Registry Scan
Malware
Registry Scan
MCP Server/AI Model File Detection
General Sensor
Example Use Case
Let’s say there is a publicly exposed container with root privilege and excessive permissions. TruRisk Insights highlights this as a critical insight. Since this insight is supported with Attack Path visualization, you can view the downstream resources that could be affected, allowing an analyst to:
Assess the full exposure chain.
Identify the most effective remediation step.
Implement changes directly from the visualization.
SS??
Viewing Insights
When clicking on the Insights Tab you can see a list of each Insight and the count of resources (containers or images) found for each risk combination. Insights can be filtered based on severity criteria as well as registry, cluster, etc.
Viewing Details Of An Insight And Attack Path
Upon clicking an insight, security teams can view the details of the insight including Contributing Risk Factors, Overview Summary, Mitigation Steps and more. Security teams can also see the list of containers affected.
Dashboards For Insights
You can use the TruRisk Insight widget type to show Insights/Attack Paths for Containers.
On the Dashboard tab, click the Add Widget button. The widget library is displayed.
Search for TruRisk Insights. Click Customize.
You can update the Widget Name from TruRisk Insights to a desired name. Optionally, you can check the 'Show description on widget' if you want to display the widget description.
This widget by default supports all insights coming from TotalCloud as well. To filter the insights from containers, in the QQL enter insight.title:"container" or insight.title:"image"