Enterprise TruRisk Management Release 1.10

June 29, 2026

Introduced Agent Val

Agent Val is an autonomous risk remediation agent integrated into the Qualys TruRisk platform. It leverages real attacker techniques in a controlled environment to validate exploitability, prioritize remediation, and mitigate. Agent Val ensures that organizations can focus on confirmed risks, enhancing their security posture with actionable insights and streamlined workflows.

Introduction page of Agent Val

The Problem Agent Val Solves

Traditional vulnerability management often relies on theoretical risk scores, leading to inefficiencies in prioritization and remediation. Security teams face challenges in identifying which vulnerabilities are actively exploitable and require immediate attention. This results in efforts on low-priority issues while critical vulnerabilities remain unaddressed. Agent Val addresses this gap by autonomously validating exploitability using real-world attacker techniques. It enables teams to focus on vulnerabilities that pose the highest risk to their environment. It also then autonomously mitigates or patches findings.

Safe Validation with TruConfirm Modified Benign Payloads

When automating exposure validation, Agent Val utilizes TruConfirm to deploy modified benign payloads. Unlike traditional exploits that attempt to gain unauthorized access or exfiltrate data, these payloads are production-safe. They are purpose-built interactions designed exclusively to elicit a harmless, observable signal to confirm whether a vulnerable code path is reachable.

Based on the expected behavior of the target, TruConfirm automatically selects one of the three payload types:

  • Direct Response Payloads: A request sent directly to the target service that is engineered to elicit a predictable, non-harmful response, proving the vulnerability is active.
  • Cryptographic Verification Payloads: A payload that delivers a unique, cryptographically signed marker to the target. The platform then uses signature verification on the response to provide tamper-proof confirmation that the payload executed.
  • Out-of-Band or Silent Callbacks: A payload designed for blind vulnerabilities that do not return a direct response. Instead, it instructs the target system to perform a controlled callback, such as an outbound DNS query or HTTP request, to a secure Qualys listener.

Key Capabilities of Agent Val

Agent Val has the following key capabilities:

  • Autonomous Exploit Validation
    • Description: Validates whether vulnerabilities are actively exploitable using real attacker techniques in a safe, and controlled manner.
    • Benefit: Reduces uncertainty by confirming exploitability, allowing teams to prioritize critical risks.
  • Remediation Options
    • Description: Offers two remediation options: deploy AI-recommended and deploy only patch (If available) / deploy only mitigations, enabling users to customize the level of automation.
    • Benefit: Provides flexible remediation options, allowing users to choose the right balance of automation, speed, and operational control.
  • Real-Time Risk Analysis
    • Description: Analyzes trending CVEs relevant to the user’s industry and identifies vulnerabilities actively exploited in the wild.
    • Benefit: Delivers industry-specific insights for targeted remediation.
  • Post-Mitigation Revalidation
    • Description: Revalidates vulnerabilities after mitigation to ensure they are no longer exploitable.
    • Benefit: Confirms the effectiveness of applied mitigations, providing assurance of risk reduction.

What You Get

With the help of Agent Val, you can refine your outputs in the form of:

  • Threat-Informed Exposure Summaries
    Clear identification of actively exploited vulnerabilities, affected assets, and associated business entities.
  • Prioritization Plans
    Remediation strategies ordered by exploitation likelihood, business impact, and industry relevance.
  • Remediation Recommendations
    Actionable patch and mitigation options with potential TruRisk score reductions.

When to Use Agent Val

  • During vulnerability management cycles to validate exploitability and prioritize remediation.
  • To assess and mitigate risks associated with trending CVEs and actively exploited vulnerabilities.
  • For compliance and audit purposes, providing evidence-based validation of exploitability and remediation actions.

Best Suited For

Agent Val is best suited for the following teams:

  • Security Operations Teams: Seeking to validate exploitability and prioritize remediation efforts.
  • Vulnerability Management Teams: Managing critical vulnerabilities and ensuring compliance.
  • Incident Response Teams: Addressing actively exploited vulnerabilities with evidence-based insights.
  • CISOs and Security Leaders: Demonstrating risk reduction and remediation effectiveness to stakeholders.

Core Strengths of Agent Val

  • Exploit-Driven Risk Validation: Validates vulnerabilities using real attacker techniques, ensuring focus on confirmed risks.
  • Human-in-the-Loop Workflow: Ensures human oversight at critical decision points, maintaining control and compliance.
  • Industry-Specific Insights: Analyzes vulnerabilities in the context of the industry, delivering targeted recommendations.

Schedule TruConfirm Scans

This release introduces the schedule scan feature, providing greater control and automation for your TruConfirm vulnerability scans. This allows you to configure precise scan schedules to launch automated scans without manual intervention. The key capabilities include:

  • Customizable scan schedules: When configuring a TruConfirm scan, the platform now shows a Schedule step to configure and schedule your vulnerability scan. In this step, you can:
    • Configure the scan details.
    • Create the following types of scan schedules:
      • Run Now
      • Single Occurrence (a one-time scan at a defined date and time)
      • Recurring (scans that run on a set cadence). For recurring scans, you can set schedules to run daily, weekly, or monthly and specify which days of the week scans should run.
    set schedule for the scan
  • Time zone support: The platform supports various global time zones, allowing precise execution across distributed environments.
  • Introduced Schedules tab: This new tab provides a unified view of your automated assessments. After a scan is scheduled, you can see it in the Schedules tab. In this tab, you can:
    • Filter scheduled scans by status (active, inactive, or expired) and schedule type (recurring or single occurrence).
    • Manage scans (view, activate, deactivate, and delete scheduled scans).

    If a scan is already in progress when a schedule is deactivated, the ongoing scan will continue without interruption; only upcoming scheduled runs will be impacted.

    new schedule scan tab added

  • Risk Management Integration: You can launch TruConfirm Assessments and configure their schedules directly from specific findings or CVE details within the Risk Management page. You can also schedule the scans from Risk Workbench.

Usability Enhancements in TruConfirm

Following are the usability enhancements in TruConfirm tab:

  • Introduced Scan Relaunch Capability: If you click the drop-down arrow, you can see the new Relaunch option that allows you to re-run an existing on-demand scan using its current configuration without needing to set it up again.

    This capability makes it significantly easier to repeat or reuse existing scans, removing the need to manually recreate assessments while maintaining consistency across your scan configurations.

    relaunch and clone feature

  • Open TruConfirm Scan details in a new tab

    Scan titles in the TruConfirm > Scan tab now behave like standard hyperlinks. You can use Ctrl+Click, middle-click, or right-click to open scan details in a new tab.

Issues Addressed

The following reported issues are fixed in this release.

Component Description

ETM Business Entities

Resolved an issue where users received a business entity limit exceeded error after their configured limit unexpectedly reverted to a lower value (for example, from 75 to 50). The issue was caused by the application applying a default limit instead of the customer-specific configured limit. The logic has been corrected to consistently use the customer-configured limit, allowing users to create business entities up to their entitled capacity without encountering errors.

ETM Dashboard

Fixed an issue where dashboard widgets displayed inconsistent asset counts, while drill-down views showed accurate values. This was caused by incorrect aggregation or data calculation in widget rendering. Dashboard widgets now display accurate and consistent asset counts, aligning with detailed views and eliminating misleading reporting trends.

ETM Dashboard

Updated the How to Search links in dashboard widgets to ensure they direct users to the appropriate help documentation, providing a more consistent and reliable help experience across applications.

ETM Dashboard Resolved an issue where dashboard widgets did not provide an option to view unique vulnerability counts, making it difficult to analyze distinct vulnerabilities across assets. Users can now choose to display unique vulnerability counts in widgets, enabling more accurate and consistent reporting.
ETM Dashboard Resolved an issue where some users with a UAI-enabled account could view historical trend data beyond the assets and findings they were authorized to access. Historical trend data is now filtered by user permissions, ensuring that dashboard trends display only data within each user's assigned scope and provide more accurate, secure reporting.