TruRisk™ Insights & Attack Path

TruRisk™ Insights is a report on the contributing factors of a TruRisk™  Score. Each TruRisk™ Insight is typically defined by a combination of contributing factors that, when present together, can exponentially increase the risk of the asset. These insights provide a detailed understanding of the risk landscape, enabling more effective risk management and mitigation strategies.

The Insights tab showcases a list of TruRisk™ Insights and the count of resources impacted by them. As you click any available insights, you learn about their contributing factors, the resources impacted, the insight details, and the possible mitigations.

You can also use tokens to narrow down insights related to the assets or specifications you require. Refer to Search for Insights to learn more about available tokens.

Qualys TruRisk Insights provides toxic combinations of remediation-worthy risk that combine different security factors including exploitable vulnerabilities, asset exposure, business criticality, secrets, malware, and more. These toxic combinations are also mapped to attack paths that security teams can act on for remediation purposes.  

Key Pre-Requisites  

  • Attack Paths Are Supported For  
    • Kubernetes & OpenShift containers only including Amazon EKS, Azure AKS, Google GKE/GKE Autopilot, Red Hat OpenShift, and any Self-Managed Kubernetes Cluster.  
    • Registry Scanned Images 
  • Risk Factors come from a combination of different insights that may come from different sensors.

Contributing Risk Factors Supported 

The following table lists the risk factors supported and the scan/sensor that is required. For containers, Qualys combines risk factors from sensors as well as registry scans from the associated image of that container. 

Table??

Risk Factor  Sensor Required 

Internet Exposure 

Cluster Sensor 

Excessive Permissions 

Cluster Sensor 

EOL/EOS Software 

Registry Scan  

AI Software 

Registry Scan  

Secrets 

Registry Scan  

Malware 

Registry Scan 

MCP Server/AI Model File Detection 

General Sensor 

Example Use Case 

Let’s say there is a publicly exposed container with root privilege and excessive permissions. TruRisk Insights highlights this as a critical insight. Since this insight is supported with Attack Path visualization, you can view the downstream resources that could be affected, allowing an analyst to: 

Assess the full exposure chain. 

Identify the most effective remediation step. 

Implement changes directly from the visualization. 

SS??

Viewing Insights  

When clicking on the Insights Tab you can see a list of each Insight and the count of resources (containers or images) found for each risk combination. Insights can be filtered based on severity criteria as well as registry, cluster, etc.  

Viewing Details Of An Insight And Attack Path 

Upon clicking an insight, security teams can view the details of the insight including Contributing Risk Factors, Overview Summary, Mitigation Steps and more. Security teams can also see the list of containers affected.  

Dashboards For Insights 

You can use the TruRisk Insight widget type to show Insights/Attack Paths for Containers.  

On the Dashboard tab, click the Add Widget  button. The widget library is displayed. 

Search for TruRisk Insights. Click Customize. 

You can update the Widget Name from TruRisk Insights to a desired name. Optionally, you can check the 'Show description on widget' if you want to display the widget description. 

This widget by default supports all insights coming from TotalCloud as well. To filter the insights from containers, in the QQL enter insight.title:"container" or insight.title:"image"