Enterprise TruRisk Management Release 1.12

August 03, 2026

Introduced Agent Insta: AI Speed Detection Without Scanning

We introduced Agent Insta, which enables InstaScan. InstaScan, powered by Agent Insta, is the industry’s first scanless detection capability. It continuously correlates every new vendor advisory against the software and asset telemetry, exposure, and threat context that Qualys already holds (collected from Qualys and 3rd-party tools), detecting new vulnerabilities at AI speed with no scan window and no dependence on which scanner an organization runs. The result is scanless detection, triggered as new security advisories are published, rather than relying on traditional scan cycles. 

Prerequisite

This feature is available on request. To access it, connect with your TAM or Qualys support.

Agent Insta

Agent Insta detects vulnerabilities across your environment. Once configured, it works continuously in the background to identify vulnerabilities within its defined scope.

View Agent Insta.

How Detection Works

Once configured, InstaScan provides seamless, continuous monitoring without requiring manual intervention or scheduled runs. It automatically responds to incoming vulnerability advisories in real time.

  • Vendor advisories (for example, from Microsoft, Google, Mozilla, or Red Hat) are checked continuously
  • When the new advisory is published by the vendor, Agent Insta looks for the affected assets and flags a finding
  • Findings are displayed automatically in the vulnerability findings view 

Supported Advisories

Currently, we support the following advisories:

  • Mozilla
  • Google Chrome
  • Red Hat
  • Adobe
  • Apple
  • Anthropic
  • Oracle Linux Errata
  • Oracle CPU
  • Ubuntu
  • Debian
  • Microsoft

InstaScan Findings

InstaScan findings can be identified and filtered throughout the platform:

  • A new query token, finding.isInstaScan: TRUE, lets you filter for InstaScan-detected findings directly in search.
  • A dedicated InstaScan card lets you quickly view and filter InstaScan findings.
  • Each finding displays a source icon indicating it was detected via InstaScan, along with the originating scan source.

Configuration Options

You need to configure InstaScan settings through the Configuration tab.

View configuration settings.

Agent Insta can be scoped and tuned using the following settings:

Setting Description
Tags / Business Entities Select the tags or business entities that define which assets are in scope.

Last Seen (days)

Select the time range to include only assets seen within the specified number of days through a Qualys scan or connector refresh.

Asset Criticality Score (ACS)

Filter assets by criticality score, combined with an AND/OR condition alongside the Last Seen setting (for example, ACS of 4 or greater).

Key benefits of InstaScan are:

  • Continuous, scanless vulnerability detection with near-real-time detection.
  • Broad coverage across supported technologies.
  • Easy filtering and visibility via a dedicated InstaScan card and search token.
  • Flexible scoping using tags, business entities, asset activity window (for example, last 3 days), and criticality scores.
  • Extends detection value to assets sourced from third-party connectors, not just first-party scans.
  • Automatic, advisory-driven detection that requires no manual scan scheduling.

To know more about Agent Insta and InstaScan, visit our blog.

You can visit our video library to view Qualys InstaScan: Scanless Scanning for Zero-Hour CVE Detection. 

Real-Time Reasoning Visibility in Cyber Assistant Chatbot ROCky

You can now see what ROCky is doing behind the scenes while it processes your complex queries. This release adds real-time reasoning transparency to the Cyber Assistant Chatbot, showing you each processing stage, tool call, and execution status as it happens, along with the ability to interact with those steps directly.

Real-Time Reasoning Display

You can now see a live, stage-by-stage breakdown of how the chatbot arrives at an answer, including:

  • Tool execution details (name, input/output, endpoint, and status)
  • Progress tracking for multi-step operations
  • Timestamps for each reasoning step
  • Capability and tool count tracking

Interactive Reasoning Actions

You can now interact directly with reasoning steps to:

  • View detailed information about a specific tool call
  • Retry a failed operation
  • Request an explanation for a specific step
  • Trigger custom actions based on the reasoning context

The following image illustrates one example.

AI-based Findings Consolidation Engine 2.0

We introduced the AI-based Findings Consolidation Engine 2.0, which uniquely identifies, deduplicates, and normalizes vulnerability data reported across all your connected sources, such as Qualys VMDR, CrowdStrike, Microsoft Defender, Tenable, and other scanners and agents. Instead of one vulnerability generating a separate console record for every tool that happens to see it, the engine reconciles overlapping detections into a single, trustworthy finding while keeping genuinely distinct installations apart.

With this release, ETM applies the following consolidation logic:

  • Identifier attributes like CVE, Vendor, Product, and Version retain the most complete details available across all contributing sources. If one source reports a value and another leaves it blank, the finding keeps the known value rather than discarding it; a missing value is treated as unknown, never as different.
  • Non-identifier attributes such as install path, status, and first/last seen timestamps are merged using system-defined aggregation rules and source trust ranking, so the consolidated finding reflects the most reliable and current evidence available at any point in time.

This engine powers two related capabilities: static consolidation (reconciling the set of records seen today) and lifecycle-aware consolidation (tracking how a finding's contributors change as new scans arrive over time).

AI-based Findings Consolidation Engine 2.0 currently applies to vulnerability findings only. Merge rules for misconfigurations remain unchanged and continue to operate as before.

This capability is being rolled out in a phased manner. Once Consolidation Engine 2.0 is deployed on your platform, the Merge Rules tab will no longer list rules for vulnerabilities. The vulnerability consolidation is now handled automatically by the engine. Only misconfiguration merge rules will continue to appear in that tab.

The following scenarios illustrate how the consolidation engine handles various detections.

Scenario CVE Outcome
Two scanners (Qualys, CrowdStrike) detect the same install CVE-2023-44487 Merged into 1 finding
Two EDR agents (CrowdStrike, Defender) report the same browser build CVE-2024-0519 Merged into 1 finding
A sparse network scan merges with a detailed authenticated scan CVE-2024-4741 Merged into 1 finding, richer detail retained
Three tools (Qualys, CrowdStrike, Tenable) report the same package CVE-2023-38545 Merged into 1 finding
Two sparse network scans with no product detail CVE-2021-44228 Merged into 1 finding (no conflicting evidence)
Two tools at different levels of detail CVE-2021-26855 Merged into 1 finding; most complete version retained
Same CVE affects two different products (Chrome, Edge) CVE-2023-4863 Kept as 2 findings
One source reports the same library at three separate paths CVE-2024-6119 Kept as 3 findings (never de-duplicated within a single source)

 To know more about how the rules are merged, refer to ETM Online help.

Unified Asset Inventory (UAI) Enhancements

This release introduces several enhancements to Unified Asset Inventory (UAI), making it easier to organize and manage your assets. One key feature is the expansion of asset tagging options, which now include new types of dynamic tags. You can now assess an asset's importance using consistent Asset Criticality Scoring and improve auditing through the Action Log for both tags and tag sets.

Tag sets are a new feature that lets you group multiple tags together, simplifying how you organize your Compute assets.

UAI also introduces Asset Purge Rules for non-compute assets, allowing you to set rules to automatically remove unused assets from your inventory. You have flexible settings to control how and when this purging occurs, including a built-in rule to clear out inactive container instances.

This feature is available on request; contact Qualys support or your Technical Account Manager (TAM) to activate it for your account.

Extended Support for Container Cluster, Registry, and Resource

We introduced three new sub-tabs in the Inventory for Container, namely ClusterRegistry, and Resource. Together, they give you a complete, layered view of your containerized environment: the platforms hosting your workloads, the registries storing your images, and the workload units running inside them. The new tabs are:

  • Container Cluster

    View and manage orchestrated groups of compute resources, such as Kubernetes or Amazon ECS clusters, that host your containerized workloads.

  • Container Registry

    View and manage the repositories or services that store container images, such as Docker Hub or Azure Container Registry.

  • Container Resource

    View and manage the workload units running within your clusters, such as Kubernetes pods and deployments.

To view the Container inventory, navigate to Inventory > Container, and select the tab for the required inventory such as Cluster, Registry, or Resource.

View UAI Container inventory.

Key benefits include:

  • Complete container visibility

    View your entire container stack in one place, from the orchestration layer down to individual workloads, without switching tools.

  • Risk-based prioritization

    Identify and prioritize the clusters, registries, and resources that carry the most risk using Qualys TruRisk™ scores.

  • Faster investigation

    Filter and group assets by cloud provider, business unit, owner, or tag to focus on what matters most to your team.

  • Clear ownership and accountability

    Trace any container asset back to an owner or support group using business context and tagging.

  • Download

    Export the conatiner inventory list as CSV, HTML, XML, or PDF.

Extended Support for Identity Policy and Tenant

We introduced two new sub-tabs in the Inventory for Identity, namely Policy and Tenant. You get a centralized view of the security rules and organizational boundaries governing your identity landscape. The policies enforce access and configuration standards, and the tenants represent the top-level directories they apply to:

  • Identity Policy

    View and manage the security rules, access controls, and configuration settings enforced by identity providers and directory services, such as Microsoft Entra ID.

  • Identity Tenant

    View and manage top-level directories, or organizational boundaries, in identity providers, such as Microsoft Entra ID.

To view the Identity inventory, navigate to Inventory > Identity, and select the tab for the required inventory, such as Policy or Tenant.

Key benefits are:

  • Complete Identity Inventory

    Get a centralized, layered view of your identity landscape, from directory-level tenants down to the policies enforced within them.

  • Risk Posture

    Evaluate risk posture for identity tenants using TruRisk™ scores and criticality ratings.

  • Group By

    Group and filter policies and tenants by cloud provider, business context, tags, and risk range to prioritize remediation.

  • Asset Details

    Correlate identity assets with Inventory, Security, and Sources data in one consolidated Asset Details view.

  • Download

    Export the Identity list as CSV, HTML, XML, or PDF.

Extended Support for Compute Image

We introduced a new Compute Image tab. This tab provides visibility into discovered compute images. These images include reusable templates or machine images. They are used to create virtual machines, cloud instances, or workloads. This applies across cloud and virtualized environments. It provides a complete view of each image's configuration, cloud metadata, security posture, business context, and installed software.

To view the Compute inventory, navigate to Inventory > Assets  > Compute > Image.

View Compute image.

Key highlights are:

  • Image Inventory

    View key details for each compute image, including Name, Image ID, Criticality, TruRisk™ Score, Version, Architecture, Platform, Image Format, Hypervisors, Sources, and Tags.

  • Group By

    Organize images by cloud provider (AWS, Azure, GCP, OCI, IBM, Alibaba), Business Information, Architecture, Platform, Hypervisor, Image Format, Tags, or TruRisk™ Score Range.

  • Compute Image Details

    Drill into an image's Inventory, Security, and Sources sections for full configuration, risk, and discovery information.

  • Tag Management

    Add or remove tags directly from the image details page.

  • Asset Purge

    Purge stale or inactive compute image assets.

  • Download

    Export the compute image list as CSV, HTML, XML, or PDF.

Introduced Tag Sets for Asset Grouping

Tag Sets let you group static and dynamic tags together to organize assets more efficiently. A tag set can include or exclude both tag types, and assets matching the selected tags are automatically grouped under the set.

To create a Tag Set, navigate to Inventory > Tags > Create New > Tag Set.

View the tag set.

Key highlights are:

  • Combine up to 20 include tags and 20 exclude tags per tag set, with All/Any filter logic.
  • Create up to 100 tag sets per account.
  • Test rule applicability against selected assets before saving (Pass/Fail results).
  • Evaluate Rule on Creation option to immediately assign previously scanned assets that match the rule.
  • Assign an Asset Criticality Score (1–5) to the tag set, with a default of 2 if unassigned.

Tag Sets are currently supported only for the Compute asset class.

Enhanced Filtering for Asset Purge Rules for Other Assets

A new filter has been added to the Asset Purge Rules for Other Assets, allowing rules to be categorized and viewed by type: User-Defined, Qualys-Recommended, and System-Defined.

The filter makes it easy to quickly locate and manage rules by type, improving visibility and control when working with a large number of purge rules.

You can view all configured purge rules on Rules > Purge > Other Assets. Select the Filter Rule by as required.

View Filter Rule by  option.

Enhanced Asset Criticality Scoring for Tags

Asset Criticality Score behavior is now consistently defined across both individual tags and tag sets.

Key highlights are:

  • Score range: 1 (lowest) to 5 (highest); default is 2 if not assigned
  • When an asset carries multiple tags with different scores, the highest score applies.
    Example: An asset tagged with scores 3, 4, and 2 receives a resulting score of 4.
  • Criticality score changes take effect only after the asset's next scan, not immediately.

Enhanced Auditing with Action Log for Tags and Tag Sets

Tag Details and Tag Set Details pages now include an Action Log section, providing a full activity history for auditing and monitoring.

Logged details are:

Column Description
Message Description of the action performed
User User who performed the action
Timestamp Date and time of the action
Source Application/module where the action originated
Event Type Type of activity performed
IP Address IP address of the user
Browser Browser used
OS Operating system used

Enhanced Bulk Tag Management

Tags can be added or removed from multiple assets simultaneously via bulk actions.

Key highlights are:

  • Add tags to multiple assets at once by selecting the assets and clicking Actions, then Add Tags.
  • Remove tags from multiple assets at once in the same way by selecting the assets and clicking Actions, then Remove Tags.

Introduced Asset Purge Rules for Other Assets

You can now create Asset Purge Rules to automate the purging of non-compute assets from your inventory. Rules can be created, viewed, edited, deleted, disabled, and enabled from the Asset Purge Rules > Other Assets tab, with execution status and outcomes visible directly on the same screen.

Key highlights are:

  • Automated purging on a fixed six-hour execution interval
  • Once a rule runs, matching assets are deleted and no longer shown in inventory
  • Full lifecycle management (create, view, edit, delete, disable, enable) from a single tab

To access this feature, go to Rules > Purge  > Other Assets.

View Purge rules for other asset.

New Tokens for Assets for UAI 

We have introduced the following new tokens to filter assets based on these classes.

UserUser

Token Description Example
user.id Use the token to filter users by their unique user identifier. user.id: 10293
user.username Use the token to filter users by their login username. user.username: jdoe
user.email Use the token to filter users by their registered email address. user.email: [email protected]
user.firstName Use the token to filter users by their first name. user.firstName: John
user.lastName Use the token to filter users by their last name. user.lastName: Doe
user.name Use the token to filter users by their full display name. user.name: John Doe
user.phone Use the token to filter users by their registered phone number. user.phone: +1-555-1234
user.jobTitle Use the token to filter users by their job title. user.jobTitle: Security Analyst
user.isMfaActivated Use the token to filter users based on whether multi-factor authentication (MFA) is activated. user.isMfaActivated: true
user.lastSuccessfulLoginTime Use the token to filter users by the timestamp of their last successful login. user.lastSuccessfulLoginTime: 2024-11-15T10:30:00Z
user.passwordLastChangedTime Use the token to filter users by when the user's password was last changed. user.passwordLastChangedTime: 2024-09-20T08:00:00Z
user.accountExpirationTime Use the token to filter users by the date when the user account is scheduled to expire. user.accountExpirationTime: 2025-12-31T23:59:59Z
user.failedPasswordAttemptCount Use the token to filter users by the number of failed password attempts. user.failedPasswordAttemptCount: 3
user.status Use the token to filter users by their current account status (active, locked, disabled). user.status: Active
user.type Use the token to filter users by their account type (standard user, admin, API user). user.type: Admin
user.currentAddress.city Use the token to filter users by the city in their current address. user.currentAddress.city: New York
user.currentAddress.state Use the token to filter users by the state or region in their current address. user.currentAddress.state: NY
user.currentAddress.country Use the token to filter users by the country in their current address. user.currentAddress.country: US
user.tenant.domain Use the token to filter users by the domain of the tenant associated with the user. user.tenant.domain: "example.com"
user.tenant.id Use the token to filter users by the ID of the tenant associated with the user. user.tenant.id: "73921048"
user.tenant.name Use the token to filter users by the name of the tenant associated with the user. user.tenant.name: "Contoso"

GroupGroup

Token Description Example
group.id Use the token to filter groups by their unique identifier. group.id: grp-1023
group.name Use the token to filter groups by their internal system name. group.name: security-team
group.displayName Use the token to filter groups by their readable or user-friendly display name. group.displayName: Security Team
group.type Use the token to filter groups by their classification type (for example, user group, admin group, or system group). group.type: AdminGroup
group.visibility Use the token to filter groups based on their visibility setting (public, private, or restricted). group.visibility: Private
group.description Use the token to filter groups by the descriptive text associated with them. group.description: Handles all security-related operations.
group.owners Use the token to filter groups by the usernames of their assigned owners or administrators. group.owners: jdoe
group.tenant.domain Use the token to filter groups by the domain of the tenant associated with the group. group.tenant.domain: "example.com"
group.tenant.id Use the token to filter groups by the ID of the tenant associated with the group. group.tenant.id: "73921048"
group.tenant.name Use the token to filter groups by the name of the tenant associated with the group. group.tenant.name: "Contoso"

RoleRole

Token Description Example
role.id Use the token to filter roles by their unique role identifier. role.id: role-204
role.name Use the token to filter roles by their internal system name. role.name: security_admin
role.displayName Use the token to filter roles by their user-friendly display name. role.displayName: Security Administrator
role.description Use the token to filter roles based on their descriptive text. role.description: Manages security operations and configurations.
role.type Use the token to filter roles by their type (for example, predefined role or custom role). role.type: Custom
role.scope Use the token to filter roles by the scope they apply to (for example, global, subscription, or project-level). role.scope: Global
role.tenant.domain Use the token to filter roles by the domain of the tenant associated with the role. role.tenant.domain: "example.com"
role.tenant.id Use the token to filter roles by the ID of the tenant associated with the role. role.tenant.id: "73921048"
role.tenant.name Use the token to filter roles by the name of the tenant associated with the role. role.tenant.name: "Contoso"

TenantTenant

Token Description Example
tenant.accountQuota Use the token to filter tenants by their configured account quota. tenant.accountQuota: "500"
tenant.description Use the token to filter tenants by their description. tenant.description: "Production domain controller"
tenant.distinguishedName Use the token to filter tenants by their distinguished name. tenant.distinguishedName: "DC=example,DC=com"
tenant.domain Use the token to filter tenants by their associated domain. tenant.domain: "example.com"
tenant.domainLevel Use the token to filter tenants by the functional level of their domain. tenant.domainLevel: "Windows2016Domain"
tenant.fsmoRoleOwner Use the token to filter tenants by their FSMO role owner. tenant.fsmoRoleOwner: "dc01.example.com"
tenant.id Use the token to filter tenants by their tenant ID. tenant.id: "73921048"
tenant.isCritical Use the token to filter tenants by whether they are marked as critical. tenant.isCritical: "true"
tenant.lockoutThreshold Use the token to filter tenants by their configured account lockout threshold. tenant.lockoutThreshold: "5"
tenant.name Use the token to filter tenants by their name. tenant.name: "Contoso"
tenant.sid Use the token to filter tenants by their security identifier (SID). tenant.sid: "S-1-5-21-3623811015-3361044348-30300820"
tenant.status Use the token to filter tenants by their status. tenant.status: "active"
tenant.behaviorVersion Use the token to filter tenants by their behavior version. tenant.behaviorVersion: "Windows2016Domain"
tenant.city Use the token to filter tenants by their associated city. tenant.city: "San Jose"
tenant.country Use the token to filter tenants by their associated country. tenant.country: "US"
tenant.dn Use the token to filter tenants by their distinguished name (DN). tenant.dn: "DC=example,DC=com"
tenant.isCryticalSystemObject Use the token to filter tenants by whether they are marked as a critical system object. tenant.isCryticalSystemObject: "true"
tenant.postalCode Use the token to filter tenants by their associated postal code. tenant.postalCode: "95110"
tenant.state Use the token to filter tenants by their associated state. tenant.state: "California"
tenant.whenChanged Use the token to filter tenants by the date they were last changed. tenant.whenChanged: "2024-05-10"
tenant.whenCreated Use the token to filter tenants by the date they were created. tenant.whenCreated: "2023-11-20"

PolicyPolicy

Token Description Example
policy.description Use the token to filter policies by their description. policy.description: "Default domain password policy"
policy.distinguishedName Use the token to filter policies by their distinguished name. policy.distinguishedName: "CN=Default Domain Policy,CN=Policies,CN=System,DC=example,DC=com"
policy.id Use the token to filter policies by their policy ID. policy.id: "28371094"
policy.isCritical Use the token to filter policies by whether they are marked as critical. policy.isCritical: "true"
policy.name Use the token to filter policies by their name. policy.name: "Default Domain Policy"
policy.status Use the token to filter policies by their status. policy.status: "enabled"
policy.systemVolumeFilePath Use the token to filter policies by their system volume file path. policy.systemVolumeFilePath: "\\example.com\sysvol\example.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}"
policy.tenant.domain Use the token to filter policies by the domain of the tenant associated with the policy. policy.tenant.domain: "example.com"
policy.tenant.id Use the token to filter policies by the ID of the tenant associated with the policy. policy.tenant.id: "73921048"
policy.tenant.name Use the token to filter policies by the name of the tenant associated with the policy. policy.tenant.name: "Contoso"
policy.dn Use the token to filter policies by their distinguished name (DN). policy.dn: "CN=Default Domain Policy,CN=Policies,CN=System,DC=example,DC=com"
policy.gpcFileSysPath Use the token to filter policies by their Group Policy Container file system path. policy.gpcFileSysPath: "\\example.com\sysvol\example.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}"
policy.isCriticalSystemObject Use the token to filter policies by whether they are marked as a critical system object. policy.isCriticalSystemObject: "true"
policy.isDeleted Use the token to filter policies by whether they have been deleted. policy.isDeleted: "false"
policy.isSystemDefined Use the token to filter policies by whether they are system-defined. policy.isSystemDefined: "true"
policy.whenChanged Use the token to filter policies by the date they were last changed. policy.whenChanged: "2024-05-10"
policy.whenCreated Use the token to filter policies by the date they were created. policy.whenCreated: "2023-11-20"

ContainerContainer

Token Description Example
container.resource.apiVersion Use the token to filter container resource by the API version. container.resource.apiVersion: "v1"
container.resource.cluster.name Use the token to filter container resource by the name of the cluster associated with it. container.resource.cluster.name: "prod-cluster-01"
container.resource.containerSchedulingType Use the token to filter container resource by the scheduling type of the resource. container.resource.containerSchedulingType: "kubernetes"
container.resource.daemon.name Use the token to filter container resource by the name of the daemon associated with it. container.resource.daemon.name: "node-exporter"
container.resource.deployment.replicaCount Use the token to filter container resource by the replica count of the container resource deployment. container.resource.deployment.replicaCount: "3"
container.resource.endpoint.name Use the token to filter container resource by the name of the endpoint associated with it. container.resource.endpoint.name: "api-endpoint"
container.resource.name Use the token to filter container resource by its name. container.resource.name: "nginx-container"
container.resource.namespace Use the token to filter container resource by its namespace. container.resource.namespace: "production"
container.resource.network.name Use the token to filter container resource by the name of the network associated with the resource. container.resource.network.name: "prod-network"
container.resource.network.type Use the token to filter container resource by the type of network associated with the container resource. container.resource.network.type: "overlay"
container.resource.node.label Use the token to filter container resource by the label of the node associated with the resource. container.resource.node.label: "env=production"
container.resource.node.name Use the token to filter container resource by the name of the node associated with the resource. container.resource.node.name: "worker-node-01"
container.resource.node.role Use the token to filter container resource by the role of the node associated with the resource. container.resource.node.role: "worker"
container.resource.node.status Use the token to filter container resource by the status of the node associated with the container resource. container.resource.node.status: "Ready"
container.resource.pod.nodeSelector Use the token to filter container resource by the node selector of the container resource pod. container.resource.pod.nodeSelector: "disktype=ssd"
container.resource.pod.serviceAccount Use the token to filter container resource by the service account of the resource pod. container.resource.pod.serviceAccount: "default"
container.resource.replica.replicaCount Use the token to filter container resource by the replica count of the container resource replica set. container.resource.replica.replicaCount: "5"
container.resource.secret.name Use the token to filter container resource by the name of the secret associated with the container resource. container.resource.secret.name: "db-credentials"
container.resource.service.endpoint Use the token to filter container resource by the endpoint of the container resource service. container.resource.service.endpoint: "10.0.0.15:8080"
container.resource.service.type Use the token to filter container resource by the type of the container resource service. container.resource.service.type: "LoadBalancer"
container.resource.statefulSet.name Use the token to filter container resource by the name of the stateful set associated with the resource. container.resource.statefulSet.name: "postgres-statefulset"
container.resource.znpc.namespace Use the token to filter container resource by the namespace of the ZNPC associated with the container resource. container.resource.znpc.namespace: "zscaler-system"
container.resource.znpc.zone.name Use the token to filter container resource by the zone name of the ZNPC associated with the resource. container.resource.znpc.zone.name: "us-west-zone"

Agent-Based Scans for TruConfirm

You now have more flexibility when validating vulnerabilities with TruConfirm. With this release, the ETM platform supports Cloud Agent-based TruConfirm scans, giving you another way to confirm real, exploitable risk across your environment.

For targets on which Cloud Agent is installed, the platform allows bulk activation of the TruConfirm module through an Activate Now. You can find it on the Risk Management tab > Findings > Vulnerabilities tab.

Activate the Agent from Risk Management

Additionally, if you want to manually activate the TruConfirm module on cloud agent, you can do that from the Cloud Agent UI.

What's New

Choose your validation source: When you set up a TruConfirm scan, you can now pick either Cloud Agent or Scanner Appliance. If you already have Cloud Agents installed on your hosts (and TruConfirm module is activated), you can use them directly to validate vulnerabilities.

Where to Find It

You can configure this option when you launch a scan from:

  • TruConfirm tab > Scan tab

    Select the scan using source

  • Risk Management tab > Vulnerabilities tab.

    Select the Cloud Agent option

What to Do

  1. Start setting up a TruConfirm scan from the TruConfirm tab or Vulnerabilities tab.
  2. Select your validation source: Cloud Agent.

When you select Cloud Agents, you must choose the applicable assets, tags, or Business Entities as part of the scan setup. You can only select the assets, tags, or Business Entities for which TruConfirm module is activated, and Cloud Agent is installed.

Enhancements

  • On the Findings Details page, you can see the TruConfirm card that:
    • Shows the validation source as Cloud Agent or Scanner Appliance.

      Validation source is also given in finding details

    • If you click View Evidence, the platform displays information about environmental checks, safe exploits, and TTP assessment that help you comprehensively understand the TruConfirm assessment details.

      Additional details for Assessment are given

  • The Risk Management tab > Findings > Vulnerabilities tab contains the TruConfirm Validation Available card, which clearly shows the findings count for Cloud Agents and for Scanner appliances. If you click either, the platform filters and displays the respective findings.

    A validation card is introduced

  • The Exploitability column now shows icons that indicate the exploit validation source as cloud agent or scanner appliance.

    Icons available for source

  • The Scans tab now includes an Exploit Validation Source column. This column shows the basis on which you configured the scans, whether on Cloud Agent or Scanner Appliance.

    Now a new column is introduced Exploit Validation Source

  • The Schedule step in the TruConfirm assessment workflow is now renamed to Configuration. For now, the Run Now schedule type is available; the other two types will be available in subsequent releases.

    Set the schedule for a scan

  • While configuring a TruConfirm scan, you can see an Assessment Timeout section in the Configuration step. This configuration ensures that the TruConfirm assessment is started within the specified scan window.

    Gives information about the Assessment Timeout

Introduced New Tokens 

We added new tokens to help you refine your searches.

Token

Tab

Description

finding.patchReleasedDate

Risk Management > Findings tab > ALL

Risk Management > Findings tab > Vulnerabilities

Use the token to search findings by specifying the date or date range when the associated patch became available.

finding.patchReleaseDate: [2025-10-21 .. Now-1M]

finding.isRebootRequired

Risk Management > Findings tab > ALL

Risk Management > Findings tab > Vulnerabilities

Use the finding to search findings based on whether a reboot is required to complete remediation.

finding.isRebootRequired: TRUE

finding.control.id 

Risk Management > Findings tab > ALL

Risk Management > Findings tab > Misconfigurations

Use the token to search controls using their unique control IDs (CIDs).

finding.control.id: 1147

Issues Addressed

The following reported issues are fixed in this release.

Component Description
ETM-UI Resolved a TruRisk score inconsistency between ETM and VMDR. Some assets displayed valid TruRisk scores in ETM while showing blank or zero values in VMDR due to different asset data sources across modules. After the fix, TruRisk score information is displayed consistently across ETM, VMDR, and related applications.
ETM-UI   Resolved an issue where Business Applications and Organization tabs were incorrectly displayed for accounts which are not enabled for UAI subscriptions, causing users to see Business Apps with zero associated assets for functionality that was not supported in their environment. The visibility logic is corrected so that these tabs are displayed only for supported UAI-enabled subscriptions. 
ETM-Business Entities Resolved an issue where the Risk Appetite widget on the ETM homepage displayed incorrect asset counts due to a calculation mismatch. Users saw assets exceeding the configured risk threshold in Business Entities, while the homepage widget incorrectly showed zero assets. The Risk Appetite widget now displays accurate counts and remains synchronized with Business Entities data. 
ETM-Inventory  Resolved an issue where users encountered 404 errors while exporting Asset Inventory data in CSV format. The problem occurred because under certain conditions, the export request was not routed correctly, causing the download to fail. Asset inventory exports now complete successfully, and CSV files download as expected.
ETM-UI Resolved incorrect navigation behavior in Risk Management vulnerability views. When customers clicked asset counts or opened vulnerability counts in a new tab from Group By CVE results, they were redirected to the ETM homepage instead of the expected asset or findings pages. Navigation and filtering now work correctly and route users to the appropriate results pages. 
ETM-UI Resolved a UI layout issue on the Finding Details page where long container image names overlapped the Impacted Assets section, making some information difficult to view. Asset names are now displayed correctly, and the page layout remains clear and readable.
ETM-UI Resolved an issue where the CISA Known Exploited Vulnerabilities (KEV) count on the TruRisk dashboard homepage was displayed incorrectly. In some cases, the dashboard showed fewer KEV findings than expected, resulting in an incomplete view of the organization's risk exposure. The dashboard now displays accurate CISA KEV counts and provides a consistent view of affected findings. 
ETM-Business Entities Resolved an issue in Business Entities where duplicate entries appeared across multiple pages and pagination displayed incorrect page counts. Business Entities now display correctly without duplication, and pagination accurately reflects the total number of available entities. 
ETM-QQL Query Resolved an issue where Risk Acceptance rules were not applied correctly for certain asset and vulnerability queries. In some cases, query matching did not evaluate the criteria as expected, preventing applicable rules from taking effect. Risk Acceptance rules are now processed correctly, ensuring matching assets and vulnerabilities are evaluated and updated as expected.