Enterprise TruRisk Management Release 1.12
August 03, 2026
Introduced Agent Insta: AI Speed Detection Without Scanning
We introduced Agent Insta, which enables InstaScan. InstaScan, powered by Agent Insta, is the industry’s first scanless detection capability. It continuously correlates every new vendor advisory against the software and asset telemetry, exposure, and threat context that Qualys already holds (collected from Qualys and 3rd-party tools), detecting new vulnerabilities at AI speed with no scan window and no dependence on which scanner an organization runs. The result is scanless detection, triggered as new security advisories are published, rather than relying on traditional scan cycles.
Prerequisite
This feature is available on request. To access it, connect with your TAM or Qualys support.
Agent Insta
Agent Insta detects vulnerabilities across your environment. Once configured, it works continuously in the background to identify vulnerabilities within its defined scope.

How Detection Works
Once configured, InstaScan provides seamless, continuous monitoring without requiring manual intervention or scheduled runs. It automatically responds to incoming vulnerability advisories in real time.
- Vendor advisories (for example, from Microsoft, Google, Mozilla, or Red Hat) are checked continuously
- When the new advisory is published by the vendor, Agent Insta looks for the affected assets and flags a finding
- Findings are displayed automatically in the vulnerability findings view
Supported Advisories
Currently, we support the following advisories:
- Mozilla
- Google Chrome
- Red Hat
- Adobe
- Apple
- Anthropic
- Oracle Linux Errata
- Oracle CPU
- Ubuntu
- Debian
- Microsoft
InstaScan Findings
InstaScan findings can be identified and filtered throughout the platform:
- A new query token,
finding.isInstaScan: TRUE, lets you filter for InstaScan-detected findings directly in search. - A dedicated InstaScan card lets you quickly view and filter InstaScan findings.
- Each finding displays a source icon indicating it was detected via InstaScan, along with the originating scan source.

Configuration Options
You need to configure InstaScan settings through the Configuration tab.

Agent Insta can be scoped and tuned using the following settings:
| Setting | Description |
|---|---|
| Tags / Business Entities | Select the tags or business entities that define which assets are in scope. |
|
Last Seen (days) |
Select the time range to include only assets seen within the specified number of days through a Qualys scan or connector refresh. |
|
Asset Criticality Score (ACS) |
Filter assets by criticality score, combined with an AND/OR condition alongside the Last Seen setting (for example, ACS of 4 or greater). |
Key benefits of InstaScan are:
- Continuous, scanless vulnerability detection with near-real-time detection.
- Broad coverage across supported technologies.
- Easy filtering and visibility via a dedicated InstaScan card and search token.
- Flexible scoping using tags, business entities, asset activity window (for example, last 3 days), and criticality scores.
- Extends detection value to assets sourced from third-party connectors, not just first-party scans.
- Automatic, advisory-driven detection that requires no manual scan scheduling.
To know more about Agent Insta and InstaScan, visit our blog.
You can visit our video library to view Qualys InstaScan: Scanless Scanning for Zero-Hour CVE Detection.
Real-Time Reasoning Visibility in Cyber Assistant Chatbot ROCky
You can now see what ROCky is doing behind the scenes while it processes your complex queries. This release adds real-time reasoning transparency to the Cyber Assistant Chatbot, showing you each processing stage, tool call, and execution status as it happens, along with the ability to interact with those steps directly.
Real-Time Reasoning Display
You can now see a live, stage-by-stage breakdown of how the chatbot arrives at an answer, including:
- Tool execution details (name, input/output, endpoint, and status)
- Progress tracking for multi-step operations
- Timestamps for each reasoning step
- Capability and tool count tracking
Interactive Reasoning Actions
You can now interact directly with reasoning steps to:
- View detailed information about a specific tool call
- Retry a failed operation
- Request an explanation for a specific step
- Trigger custom actions based on the reasoning context
The following image illustrates one example.

AI-based Findings Consolidation Engine 2.0
We introduced the AI-based Findings Consolidation Engine 2.0, which uniquely identifies, deduplicates, and normalizes vulnerability data reported across all your connected sources, such as Qualys VMDR, CrowdStrike, Microsoft Defender, Tenable, and other scanners and agents. Instead of one vulnerability generating a separate console record for every tool that happens to see it, the engine reconciles overlapping detections into a single, trustworthy finding while keeping genuinely distinct installations apart.
With this release, ETM applies the following consolidation logic:
- Identifier attributes like CVE, Vendor, Product, and Version retain the most complete details available across all contributing sources. If one source reports a value and another leaves it blank, the finding keeps the known value rather than discarding it; a missing value is treated as unknown, never as different.
- Non-identifier attributes such as install path, status, and first/last seen timestamps are merged using system-defined aggregation rules and source trust ranking, so the consolidated finding reflects the most reliable and current evidence available at any point in time.
This engine powers two related capabilities: static consolidation (reconciling the set of records seen today) and lifecycle-aware consolidation (tracking how a finding's contributors change as new scans arrive over time).
AI-based Findings Consolidation Engine 2.0 currently applies to vulnerability findings only. Merge rules for misconfigurations remain unchanged and continue to operate as before.
This capability is being rolled out in a phased manner. Once Consolidation Engine 2.0 is deployed on your platform, the Merge Rules tab will no longer list rules for vulnerabilities. The vulnerability consolidation is now handled automatically by the engine. Only misconfiguration merge rules will continue to appear in that tab.
The following scenarios illustrate how the consolidation engine handles various detections.
| Scenario | CVE | Outcome |
|---|---|---|
| Two scanners (Qualys, CrowdStrike) detect the same install | CVE-2023-44487 | Merged into 1 finding |
| Two EDR agents (CrowdStrike, Defender) report the same browser build | CVE-2024-0519 | Merged into 1 finding |
| A sparse network scan merges with a detailed authenticated scan | CVE-2024-4741 | Merged into 1 finding, richer detail retained |
| Three tools (Qualys, CrowdStrike, Tenable) report the same package | CVE-2023-38545 | Merged into 1 finding |
| Two sparse network scans with no product detail | CVE-2021-44228 | Merged into 1 finding (no conflicting evidence) |
| Two tools at different levels of detail | CVE-2021-26855 | Merged into 1 finding; most complete version retained |
| Same CVE affects two different products (Chrome, Edge) | CVE-2023-4863 | Kept as 2 findings |
| One source reports the same library at three separate paths | CVE-2024-6119 | Kept as 3 findings (never de-duplicated within a single source) |
To know more about how the rules are merged, refer to ETM Online help.
Unified Asset Inventory (UAI) Enhancements
This release introduces several enhancements to Unified Asset Inventory (UAI), making it easier to organize and manage your assets. One key feature is the expansion of asset tagging options, which now include new types of dynamic tags. You can now assess an asset's importance using consistent Asset Criticality Scoring and improve auditing through the Action Log for both tags and tag sets.
Tag sets are a new feature that lets you group multiple tags together, simplifying how you organize your Compute assets.
UAI also introduces Asset Purge Rules for non-compute assets, allowing you to set rules to automatically remove unused assets from your inventory. You have flexible settings to control how and when this purging occurs, including a built-in rule to clear out inactive container instances.
This feature is available on request; contact Qualys support or your Technical Account Manager (TAM) to activate it for your account.
Extended Support for Container Cluster, Registry, and Resource
We introduced three new sub-tabs in the Inventory for Container, namely Cluster, Registry, and Resource. Together, they give you a complete, layered view of your containerized environment: the platforms hosting your workloads, the registries storing your images, and the workload units running inside them. The new tabs are:
- Container Cluster
View and manage orchestrated groups of compute resources, such as Kubernetes or Amazon ECS clusters, that host your containerized workloads.
- Container Registry
View and manage the repositories or services that store container images, such as Docker Hub or Azure Container Registry.
- Container Resource
View and manage the workload units running within your clusters, such as Kubernetes pods and deployments.
To view the Container inventory, navigate to Inventory > Container, and select the tab for the required inventory such as Cluster, Registry, or Resource.

Key benefits include:
- Complete container visibility
View your entire container stack in one place, from the orchestration layer down to individual workloads, without switching tools.
- Risk-based prioritization
Identify and prioritize the clusters, registries, and resources that carry the most risk using Qualys TruRisk™ scores.
- Faster investigation
Filter and group assets by cloud provider, business unit, owner, or tag to focus on what matters most to your team.
- Clear ownership and accountability
Trace any container asset back to an owner or support group using business context and tagging.
- Download
Export the conatiner inventory list as CSV, HTML, XML, or PDF.
Extended Support for Identity Policy and Tenant
We introduced two new sub-tabs in the Inventory for Identity, namely Policy and Tenant. You get a centralized view of the security rules and organizational boundaries governing your identity landscape. The policies enforce access and configuration standards, and the tenants represent the top-level directories they apply to:
- Identity Policy
View and manage the security rules, access controls, and configuration settings enforced by identity providers and directory services, such as Microsoft Entra ID.
- Identity Tenant
View and manage top-level directories, or organizational boundaries, in identity providers, such as Microsoft Entra ID.
To view the Identity inventory, navigate to Inventory > Identity, and select the tab for the required inventory, such as Policy or Tenant.

Key benefits are:
- Complete Identity Inventory
Get a centralized, layered view of your identity landscape, from directory-level tenants down to the policies enforced within them.
- Risk Posture
Evaluate risk posture for identity tenants using TruRisk™ scores and criticality ratings.
- Group By
Group and filter policies and tenants by cloud provider, business context, tags, and risk range to prioritize remediation.
- Asset Details
Correlate identity assets with Inventory, Security, and Sources data in one consolidated Asset Details view.
-
Download
Export the Identity list as CSV, HTML, XML, or PDF.
Extended Support for Compute Image
We introduced a new Compute Image tab. This tab provides visibility into discovered compute images. These images include reusable templates or machine images. They are used to create virtual machines, cloud instances, or workloads. This applies across cloud and virtualized environments. It provides a complete view of each image's configuration, cloud metadata, security posture, business context, and installed software.
To view the Compute inventory, navigate to Inventory > Assets > Compute > Image.

Key highlights are:
- Image Inventory
View key details for each compute image, including Name, Image ID, Criticality, TruRisk™ Score, Version, Architecture, Platform, Image Format, Hypervisors, Sources, and Tags.
- Group By
Organize images by cloud provider (AWS, Azure, GCP, OCI, IBM, Alibaba), Business Information, Architecture, Platform, Hypervisor, Image Format, Tags, or TruRisk™ Score Range.
- Compute Image Details
Drill into an image's Inventory, Security, and Sources sections for full configuration, risk, and discovery information.
- Tag Management
Add or remove tags directly from the image details page.
- Asset Purge
Purge stale or inactive compute image assets.
- Download
Export the compute image list as CSV, HTML, XML, or PDF.
Introduced Tag Sets for Asset Grouping
Tag Sets let you group static and dynamic tags together to organize assets more efficiently. A tag set can include or exclude both tag types, and assets matching the selected tags are automatically grouped under the set.
To create a Tag Set, navigate to Inventory > Tags > Create New > Tag Set.

Key highlights are:
- Combine up to 20 include tags and 20 exclude tags per tag set, with All/Any filter logic.
- Create up to 100 tag sets per account.
- Test rule applicability against selected assets before saving (Pass/Fail results).
- Evaluate Rule on Creation option to immediately assign previously scanned assets that match the rule.
- Assign an Asset Criticality Score (1–5) to the tag set, with a default of 2 if unassigned.
Tag Sets are currently supported only for the Compute asset class.
Enhanced Filtering for Asset Purge Rules for Other Assets
A new filter has been added to the Asset Purge Rules for Other Assets, allowing rules to be categorized and viewed by type: User-Defined, Qualys-Recommended, and System-Defined.
The filter makes it easy to quickly locate and manage rules by type, improving visibility and control when working with a large number of purge rules.
You can view all configured purge rules on Rules > Purge > Other Assets. Select the Filter Rule by as required.

Enhanced Asset Criticality Scoring for Tags
Asset Criticality Score behavior is now consistently defined across both individual tags and tag sets.
Key highlights are:
- Score range: 1 (lowest) to 5 (highest); default is 2 if not assigned
- When an asset carries multiple tags with different scores, the highest score applies.
Example: An asset tagged with scores 3, 4, and 2 receives a resulting score of 4. - Criticality score changes take effect only after the asset's next scan, not immediately.
Enhanced Auditing with Action Log for Tags and Tag Sets
Tag Details and Tag Set Details pages now include an Action Log section, providing a full activity history for auditing and monitoring.
Logged details are:
| Column | Description |
|---|---|
| Message | Description of the action performed |
| User | User who performed the action |
| Timestamp | Date and time of the action |
| Source | Application/module where the action originated |
| Event Type | Type of activity performed |
| IP Address | IP address of the user |
| Browser | Browser used |
| OS | Operating system used |
Enhanced Bulk Tag Management
Tags can be added or removed from multiple assets simultaneously via bulk actions.
Key highlights are:
- Add tags to multiple assets at once by selecting the assets and clicking Actions, then Add Tags.
- Remove tags from multiple assets at once in the same way by selecting the assets and clicking Actions, then Remove Tags.
Introduced Asset Purge Rules for Other Assets
You can now create Asset Purge Rules to automate the purging of non-compute assets from your inventory. Rules can be created, viewed, edited, deleted, disabled, and enabled from the Asset Purge Rules > Other Assets tab, with execution status and outcomes visible directly on the same screen.
Key highlights are:
- Automated purging on a fixed six-hour execution interval
- Once a rule runs, matching assets are deleted and no longer shown in inventory
- Full lifecycle management (create, view, edit, delete, disable, enable) from a single tab
To access this feature, go to Rules > Purge > Other Assets.

New Tokens for Assets for UAI
We have introduced the following new tokens to filter assets based on these classes.
| Token | Description | Example |
|---|---|---|
| user.id | Use the token to filter users by their unique user identifier. | user.id: 10293 |
| user.username | Use the token to filter users by their login username. | user.username: jdoe |
| user.email | Use the token to filter users by their registered email address. | user.email: [email protected] |
| user.firstName | Use the token to filter users by their first name. | user.firstName: John |
| user.lastName | Use the token to filter users by their last name. | user.lastName: Doe |
| user.name | Use the token to filter users by their full display name. | user.name: John Doe |
| user.phone | Use the token to filter users by their registered phone number. | user.phone: +1-555-1234 |
| user.jobTitle | Use the token to filter users by their job title. | user.jobTitle: Security Analyst |
| user.isMfaActivated | Use the token to filter users based on whether multi-factor authentication (MFA) is activated. | user.isMfaActivated: true |
| user.lastSuccessfulLoginTime | Use the token to filter users by the timestamp of their last successful login. | user.lastSuccessfulLoginTime: 2024-11-15T10:30:00Z |
| user.passwordLastChangedTime | Use the token to filter users by when the user's password was last changed. | user.passwordLastChangedTime: 2024-09-20T08:00:00Z |
| user.accountExpirationTime | Use the token to filter users by the date when the user account is scheduled to expire. | user.accountExpirationTime: 2025-12-31T23:59:59Z |
| user.failedPasswordAttemptCount | Use the token to filter users by the number of failed password attempts. | user.failedPasswordAttemptCount: 3 |
| user.status | Use the token to filter users by their current account status (active, locked, disabled). | user.status: Active |
| user.type | Use the token to filter users by their account type (standard user, admin, API user). | user.type: Admin |
| user.currentAddress.city | Use the token to filter users by the city in their current address. | user.currentAddress.city: New York |
| user.currentAddress.state | Use the token to filter users by the state or region in their current address. | user.currentAddress.state: NY |
| user.currentAddress.country | Use the token to filter users by the country in their current address. | user.currentAddress.country: US |
| user.tenant.domain | Use the token to filter users by the domain of the tenant associated with the user. | user.tenant.domain: "example.com" |
| user.tenant.id | Use the token to filter users by the ID of the tenant associated with the user. | user.tenant.id: "73921048" |
| user.tenant.name | Use the token to filter users by the name of the tenant associated with the user. | user.tenant.name: "Contoso" |
| Token | Description | Example |
|---|---|---|
| group.id | Use the token to filter groups by their unique identifier. | group.id: grp-1023 |
| group.name | Use the token to filter groups by their internal system name. | group.name: security-team |
| group.displayName | Use the token to filter groups by their readable or user-friendly display name. | group.displayName: Security Team |
| group.type | Use the token to filter groups by their classification type (for example, user group, admin group, or system group). | group.type: AdminGroup |
| group.visibility | Use the token to filter groups based on their visibility setting (public, private, or restricted). | group.visibility: Private |
| group.description | Use the token to filter groups by the descriptive text associated with them. | group.description: Handles all security-related operations. |
| group.owners | Use the token to filter groups by the usernames of their assigned owners or administrators. | group.owners: jdoe |
| group.tenant.domain | Use the token to filter groups by the domain of the tenant associated with the group. | group.tenant.domain: "example.com" |
| group.tenant.id | Use the token to filter groups by the ID of the tenant associated with the group. | group.tenant.id: "73921048" |
| group.tenant.name | Use the token to filter groups by the name of the tenant associated with the group. | group.tenant.name: "Contoso" |
| Token | Description | Example |
|---|---|---|
| role.id | Use the token to filter roles by their unique role identifier. | role.id: role-204 |
| role.name | Use the token to filter roles by their internal system name. | role.name: security_admin |
| role.displayName | Use the token to filter roles by their user-friendly display name. | role.displayName: Security Administrator |
| role.description | Use the token to filter roles based on their descriptive text. | role.description: Manages security operations and configurations. |
| role.type | Use the token to filter roles by their type (for example, predefined role or custom role). | role.type: Custom |
| role.scope | Use the token to filter roles by the scope they apply to (for example, global, subscription, or project-level). | role.scope: Global |
| role.tenant.domain | Use the token to filter roles by the domain of the tenant associated with the role. | role.tenant.domain: "example.com" |
| role.tenant.id | Use the token to filter roles by the ID of the tenant associated with the role. | role.tenant.id: "73921048" |
| role.tenant.name | Use the token to filter roles by the name of the tenant associated with the role. | role.tenant.name: "Contoso" |
| Token | Description | Example |
|---|---|---|
| tenant.accountQuota | Use the token to filter tenants by their configured account quota. | tenant.accountQuota: "500" |
| tenant.description | Use the token to filter tenants by their description. | tenant.description: "Production domain controller" |
| tenant.distinguishedName | Use the token to filter tenants by their distinguished name. | tenant.distinguishedName: "DC=example,DC=com" |
| tenant.domain | Use the token to filter tenants by their associated domain. | tenant.domain: "example.com" |
| tenant.domainLevel | Use the token to filter tenants by the functional level of their domain. | tenant.domainLevel: "Windows2016Domain" |
| tenant.fsmoRoleOwner | Use the token to filter tenants by their FSMO role owner. | tenant.fsmoRoleOwner: "dc01.example.com" |
| tenant.id | Use the token to filter tenants by their tenant ID. | tenant.id: "73921048" |
| tenant.isCritical | Use the token to filter tenants by whether they are marked as critical. | tenant.isCritical: "true" |
| tenant.lockoutThreshold | Use the token to filter tenants by their configured account lockout threshold. | tenant.lockoutThreshold: "5" |
| tenant.name | Use the token to filter tenants by their name. | tenant.name: "Contoso" |
| tenant.sid | Use the token to filter tenants by their security identifier (SID). | tenant.sid: "S-1-5-21-3623811015-3361044348-30300820" |
| tenant.status | Use the token to filter tenants by their status. | tenant.status: "active" |
| tenant.behaviorVersion | Use the token to filter tenants by their behavior version. | tenant.behaviorVersion: "Windows2016Domain" |
| tenant.city | Use the token to filter tenants by their associated city. | tenant.city: "San Jose" |
| tenant.country | Use the token to filter tenants by their associated country. | tenant.country: "US" |
| tenant.dn | Use the token to filter tenants by their distinguished name (DN). | tenant.dn: "DC=example,DC=com" |
| tenant.isCryticalSystemObject | Use the token to filter tenants by whether they are marked as a critical system object. | tenant.isCryticalSystemObject: "true" |
| tenant.postalCode | Use the token to filter tenants by their associated postal code. | tenant.postalCode: "95110" |
| tenant.state | Use the token to filter tenants by their associated state. | tenant.state: "California" |
| tenant.whenChanged | Use the token to filter tenants by the date they were last changed. | tenant.whenChanged: "2024-05-10" |
| tenant.whenCreated | Use the token to filter tenants by the date they were created. | tenant.whenCreated: "2023-11-20" |
| Token | Description | Example |
|---|---|---|
| policy.description | Use the token to filter policies by their description. | policy.description: "Default domain password policy" |
| policy.distinguishedName | Use the token to filter policies by their distinguished name. | policy.distinguishedName: "CN=Default Domain Policy,CN=Policies,CN=System,DC=example,DC=com" |
| policy.id | Use the token to filter policies by their policy ID. | policy.id: "28371094" |
| policy.isCritical | Use the token to filter policies by whether they are marked as critical. | policy.isCritical: "true" |
| policy.name | Use the token to filter policies by their name. | policy.name: "Default Domain Policy" |
| policy.status | Use the token to filter policies by their status. | policy.status: "enabled" |
| policy.systemVolumeFilePath | Use the token to filter policies by their system volume file path. | policy.systemVolumeFilePath: "\\example.com\sysvol\example.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}" |
| policy.tenant.domain | Use the token to filter policies by the domain of the tenant associated with the policy. | policy.tenant.domain: "example.com" |
| policy.tenant.id | Use the token to filter policies by the ID of the tenant associated with the policy. | policy.tenant.id: "73921048" |
| policy.tenant.name | Use the token to filter policies by the name of the tenant associated with the policy. | policy.tenant.name: "Contoso" |
| policy.dn | Use the token to filter policies by their distinguished name (DN). | policy.dn: "CN=Default Domain Policy,CN=Policies,CN=System,DC=example,DC=com" |
| policy.gpcFileSysPath | Use the token to filter policies by their Group Policy Container file system path. | policy.gpcFileSysPath: "\\example.com\sysvol\example.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}" |
| policy.isCriticalSystemObject | Use the token to filter policies by whether they are marked as a critical system object. | policy.isCriticalSystemObject: "true" |
| policy.isDeleted | Use the token to filter policies by whether they have been deleted. | policy.isDeleted: "false" |
| policy.isSystemDefined | Use the token to filter policies by whether they are system-defined. | policy.isSystemDefined: "true" |
| policy.whenChanged | Use the token to filter policies by the date they were last changed. | policy.whenChanged: "2024-05-10" |
| policy.whenCreated | Use the token to filter policies by the date they were created. | policy.whenCreated: "2023-11-20" |
| Token | Description | Example |
|---|---|---|
| container.resource.apiVersion | Use the token to filter container resource by the API version. | container.resource.apiVersion: "v1" |
| container.resource.cluster.name | Use the token to filter container resource by the name of the cluster associated with it. | container.resource.cluster.name: "prod-cluster-01" |
| container.resource.containerSchedulingType | Use the token to filter container resource by the scheduling type of the resource. | container.resource.containerSchedulingType: "kubernetes" |
| container.resource.daemon.name | Use the token to filter container resource by the name of the daemon associated with it. | container.resource.daemon.name: "node-exporter" |
| container.resource.deployment.replicaCount | Use the token to filter container resource by the replica count of the container resource deployment. | container.resource.deployment.replicaCount: "3" |
| container.resource.endpoint.name | Use the token to filter container resource by the name of the endpoint associated with it. | container.resource.endpoint.name: "api-endpoint" |
| container.resource.name | Use the token to filter container resource by its name. | container.resource.name: "nginx-container" |
| container.resource.namespace | Use the token to filter container resource by its namespace. | container.resource.namespace: "production" |
| container.resource.network.name | Use the token to filter container resource by the name of the network associated with the resource. | container.resource.network.name: "prod-network" |
| container.resource.network.type | Use the token to filter container resource by the type of network associated with the container resource. | container.resource.network.type: "overlay" |
| container.resource.node.label | Use the token to filter container resource by the label of the node associated with the resource. | container.resource.node.label: "env=production" |
| container.resource.node.name | Use the token to filter container resource by the name of the node associated with the resource. | container.resource.node.name: "worker-node-01" |
| container.resource.node.role | Use the token to filter container resource by the role of the node associated with the resource. | container.resource.node.role: "worker" |
| container.resource.node.status | Use the token to filter container resource by the status of the node associated with the container resource. | container.resource.node.status: "Ready" |
| container.resource.pod.nodeSelector | Use the token to filter container resource by the node selector of the container resource pod. | container.resource.pod.nodeSelector: "disktype=ssd" |
| container.resource.pod.serviceAccount | Use the token to filter container resource by the service account of the resource pod. | container.resource.pod.serviceAccount: "default" |
| container.resource.replica.replicaCount | Use the token to filter container resource by the replica count of the container resource replica set. | container.resource.replica.replicaCount: "5" |
| container.resource.secret.name | Use the token to filter container resource by the name of the secret associated with the container resource. | container.resource.secret.name: "db-credentials" |
| container.resource.service.endpoint | Use the token to filter container resource by the endpoint of the container resource service. | container.resource.service.endpoint: "10.0.0.15:8080" |
| container.resource.service.type | Use the token to filter container resource by the type of the container resource service. | container.resource.service.type: "LoadBalancer" |
| container.resource.statefulSet.name | Use the token to filter container resource by the name of the stateful set associated with the resource. | container.resource.statefulSet.name: "postgres-statefulset" |
| container.resource.znpc.namespace | Use the token to filter container resource by the namespace of the ZNPC associated with the container resource. | container.resource.znpc.namespace: "zscaler-system" |
| container.resource.znpc.zone.name | Use the token to filter container resource by the zone name of the ZNPC associated with the resource. | container.resource.znpc.zone.name: "us-west-zone" |
Agent-Based Scans for TruConfirm
You now have more flexibility when validating vulnerabilities with TruConfirm. With this release, the ETM platform supports Cloud Agent-based TruConfirm scans, giving you another way to confirm real, exploitable risk across your environment.
For targets on which Cloud Agent is installed, the platform allows bulk activation of the TruConfirm module through an Activate Now. You can find it on the Risk Management tab > Findings > Vulnerabilities tab.

Additionally, if you want to manually activate the TruConfirm module on cloud agent, you can do that from the Cloud Agent UI.
What's New
Choose your validation source: When you set up a TruConfirm scan, you can now pick either Cloud Agent or Scanner Appliance. If you already have Cloud Agents installed on your hosts (and TruConfirm module is activated), you can use them directly to validate vulnerabilities.
Where to Find It
You can configure this option when you launch a scan from:
- TruConfirm tab > Scan tab

- Risk Management tab > Vulnerabilities tab.

What to Do
- Start setting up a TruConfirm scan from the TruConfirm tab or Vulnerabilities tab.
- Select your validation source: Cloud Agent.
When you select Cloud Agents, you must choose the applicable assets, tags, or Business Entities as part of the scan setup. You can only select the assets, tags, or Business Entities for which TruConfirm module is activated, and Cloud Agent is installed.
Enhancements
- On the Findings Details page, you can see the TruConfirm card that:
- Shows the validation source as Cloud Agent or Scanner Appliance.

- If you click View Evidence, the platform displays information about environmental checks, safe exploits, and TTP assessment that help you comprehensively understand the TruConfirm assessment details.

- Shows the validation source as Cloud Agent or Scanner Appliance.
- The Risk Management tab > Findings > Vulnerabilities tab contains the TruConfirm Validation Available card, which clearly shows the findings count for Cloud Agents and for Scanner appliances. If you click either, the platform filters and displays the respective findings.

- The Exploitability column now shows icons that indicate the exploit validation source as cloud agent or scanner appliance.

- The Scans tab now includes an Exploit Validation Source column. This column shows the basis on which you configured the scans, whether on Cloud Agent or Scanner Appliance.

- The Schedule step in the TruConfirm assessment workflow is now renamed to Configuration. For now, the Run Now schedule type is available; the other two types will be available in subsequent releases.

- While configuring a TruConfirm scan, you can see an Assessment Timeout section in the Configuration step. This configuration ensures that the TruConfirm assessment is started within the specified scan window.

Introduced New Tokens
We added new tokens to help you refine your searches.
|
Token |
Tab |
Description |
|---|---|---|
|
finding.patchReleasedDate |
Risk Management > Findings tab > ALL Risk Management > Findings tab > Vulnerabilities |
Use the token to search findings by specifying the date or date range when the associated patch became available.
|
|
finding.isRebootRequired |
Risk Management > Findings tab > ALL Risk Management > Findings tab > Vulnerabilities |
Use the finding to search findings based on whether a reboot is required to complete remediation.
|
| finding.control.id |
Risk Management > Findings tab > ALL Risk Management > Findings tab > Misconfigurations |
Use the token to search controls using their unique control IDs (CIDs).
|
Issues Addressed
The following reported issues are fixed in this release.
| Component | Description |
|---|---|
| ETM-UI | Resolved a TruRisk score inconsistency between ETM and VMDR. Some assets displayed valid TruRisk scores in ETM while showing blank or zero values in VMDR due to different asset data sources across modules. After the fix, TruRisk score information is displayed consistently across ETM, VMDR, and related applications. |
| ETM-UI | Resolved an issue where Business Applications and Organization tabs were incorrectly displayed for accounts which are not enabled for UAI subscriptions, causing users to see Business Apps with zero associated assets for functionality that was not supported in their environment. The visibility logic is corrected so that these tabs are displayed only for supported UAI-enabled subscriptions. |
| ETM-Business Entities | Resolved an issue where the Risk Appetite widget on the ETM homepage displayed incorrect asset counts due to a calculation mismatch. Users saw assets exceeding the configured risk threshold in Business Entities, while the homepage widget incorrectly showed zero assets. The Risk Appetite widget now displays accurate counts and remains synchronized with Business Entities data. |
| ETM-Inventory | Resolved an issue where users encountered 404 errors while exporting Asset Inventory data in CSV format. The problem occurred because under certain conditions, the export request was not routed correctly, causing the download to fail. Asset inventory exports now complete successfully, and CSV files download as expected. |
| ETM-UI | Resolved incorrect navigation behavior in Risk Management vulnerability views. When customers clicked asset counts or opened vulnerability counts in a new tab from Group By CVE results, they were redirected to the ETM homepage instead of the expected asset or findings pages. Navigation and filtering now work correctly and route users to the appropriate results pages. |
| ETM-UI | Resolved a UI layout issue on the Finding Details page where long container image names overlapped the Impacted Assets section, making some information difficult to view. Asset names are now displayed correctly, and the page layout remains clear and readable. |
| ETM-UI | Resolved an issue where the CISA Known Exploited Vulnerabilities (KEV) count on the TruRisk dashboard homepage was displayed incorrectly. In some cases, the dashboard showed fewer KEV findings than expected, resulting in an incomplete view of the organization's risk exposure. The dashboard now displays accurate CISA KEV counts and provides a consistent view of affected findings. |
| ETM-Business Entities | Resolved an issue in Business Entities where duplicate entries appeared across multiple pages and pagination displayed incorrect page counts. Business Entities now display correctly without duplication, and pagination accurately reflects the total number of available entities. |
| ETM-QQL Query | Resolved an issue where Risk Acceptance rules were not applied correctly for certain asset and vulnerability queries. In some cases, query matching did not evaluate the criteria as expected, preventing applicable rules from taking effect. Risk Acceptance rules are now processed correctly, ensuring matching assets and vulnerabilities are evaluated and updated as expected. |