Risk Elimination Overview

The Overview page for TruRisk​™ Eliminate presents a consolidated view of your organization's vulnerability exposure and patch readiness across Windows, Linux, and Mac assets. It summarizes the vulnerabilities in your environment that TruRisk​™ Eliminate can address, shows how many of those vulnerabilities you can close with high-reliability patches or permanent fixes, and recommends the remediation actions that reduce the most risk for the least effort.

The Overview page contains the following cards with various data. 

Welcome to TruRisk​™ Eliminate

This section identifies the application and describes its purpose. 

TruRisk​™ Eliminate Report

The TruRisk​™ Eliminate Report is the in-depth companion to the Overview dashboard. While the dashboard summarizes your addressable risk, the report expands each metric into a full in-depth details of your vulnerability exposure, remediation speed, and the elimination options available to you. 

To generate and download the report:

  1. Go to TruRisk™ Eliminate > Home > Overview.
  2. Click TruRisk Eliminate Report in the upper-right corner of the page.
  3. Enter a name for the report and confirm.
  4. Go to the Reports tab and download the generated report.

 The report reflects the data available at the time of generation. Generate a new report to capture the latest scan and remediation data.

Report Contents

The following are the scetions the report contains, along with its description:

Report Section Description
Enterprise TruRisk™ Total vulnerabilities, risky vulnerabilities, affected assets, and internet-facing assets, with risky vulnerabilities broken down by threat indicators such as CISA KEV, weaponized, publicly exploitable, ransomware, and associated threat actors.
Vulnerability Coverage by TruRisk​™ Eliminate The share of your total vulnerabilities that TruRisk​™ Eliminate can patch or mitigate, with the remaining open vulnerabilities split across Windows, Linux, and Mac.
Zero-Touch Remediation Using AI-Powered Patch Reliability Low operational risk third-party applications detected in your environment, their associated vulnerabilities, the high-reliability patches available, and the share of vulnerabilities you can eliminate with no testing, breakage, or reboots.
Top Recommendations for Zero-Touch Patch Automation The products to target first for set-and-forget patch jobs, with the associated vulnerability count and the percentage that is risky.
Risk Elimination Options The split between vulnerabilities that have patches available, patchable vulnerabilities that have temporary mitigations you can apply until patching, and vulnerabilities with no patch available that Qualys-curated permanent fixes can close.
Deep Dive into Risk Sources A prioritized view of vulnerabilities from third-party applications, Microsoft vulnerabilities published over 30 days ago, Linux vulnerabilities, and vulnerabilities with no patch available. Each source lists the top associated threat actors, risky vulnerabilities split across servers and workstations, the recommended remediation approach, and an MTTR view measured against peer averages and regulatory patch compliance SLAs (PCI DSS, CISA, NIST, NCSC UK, IRS, and CIS).
Industry Trends in Permanent and Temporary Mitigations The top CVEs for which peer organizations are applying permanent and temporary mitigations created by the Qualys Threat Research team, along with the number of assets in your environment affected by those CVEs.
Uninstall EOS Software The top 10 EOL/EOS bloatware products driving risk, ranked by the unique CVEs attributable to the product on servers, that you can remove using the TruRisk™ Eliminate software uninstallation capability.
Appendix: Definitions The key terms and thresholds used in the report include critical assets, risky vulnerabilities, critical vulnerabilities, permanent fixes, and temporary mitigations.

Addressable Vulnerabilities Summary

You can view the total number of vulnerabilities that TruRisk​™ Eliminate can address, for example, 17.71K Vulnerabilities Addressable by TruRisk​™ Eliminate

This figure is the baseline for the three vulnerability category cards that follow. Each card expresses its own count as a percentage of this total. Large counts are abbreviated using K for thousands, M for millions, and B for billions. When your environment has no addressable vulnerabilities, this summary line does not appear.

Vulnerability Category Cards

Three cards divide your addressable vulnerabilities into the categories that call for different remediation approaches. Each card shows the category count, the percentage that count represents of your total addressable vulnerabilities, the remediation resources available, the MTTR for the category, and a summary of how much of the category you can close using the safest remediation option. The three categories are: 

  • Vulnerabilities in Third-Party Applications: This card displays the number of open vulnerabilities detected in third-party (non-Microsoft) applications such as browsers, media players, utilities and so on. 
  • Microsoft Vulnerabilities Published 30 Days Ago: This card displays the open Microsoft vulnerabilities that were published more than 30 days ago. The card reports the same metrics as the third-party card.
  • Vulnerabilities with No Patch Available: This card displays the number of open vulnerabilities for which no vendor patch exists. You cannot patch these vulnerabilities, but Qualys curates permanent fixes for many of them. A permanent fix is the mitigation with Qualys-authored remediation script that removes the vulnerable condition, for example, by changing a configuration or removing a vulnerable component.
    Because these vulnerabilities have no patches, this card
    reports Permanent Fixes in place of Total Patches and High-Reliability Patches. 

Metrics shown on Vulnerability Category Cards

Metric  Description
Percentage and count The number of open vulnerabilities in this category, and that number as a percentage of your total addressable vulnerabilities. The supporting text shows the category count and the total, for example, 5.27K / 17.71K.
Total Patches The number of distinct patches available for the vulnerabilities in this category. This metric does not appear on the Vulnerabilities with No Patch Available card.
High-Reliability Patches The number of patches in this category that carry a high AI-based patch reliability score. A high score indicates that the patch has deployed successfully across a large population of assets with few reported failures or rollbacks, so it carries a low operational risk.
Permanent Fixes The number of Qualys-curated permanent fixes available for vulnerabilities that have no vendor patch. This metric appears only on the Vulnerabilities with No Patch Available card.
MTTR Mean Time To Remediate. The average time taken to fix the vulnerabilities in this category that have already been remediated in your environment. Use this metric to compare remediation speed across categories and to track improvement over time.
Summary line The proportion of the category that you can close using the safest available option: high-reliability patches for the third-party and Microsoft cards, permanent fixes for the No Patch Available card.

 Select View Risk Elimination on any card to open the Eliminations page with the results already filtered to that category. You can create a patch job for exactly the vulnerabilities the card describes. For more information, see Creating Patch Job for Windows Assets.

MTTR is calculated only from vulnerabilities that have already been remediated. A category in which you have not yet fixed anything shows an MTTR of 0 days.

Recommendations by Agent Sara

Below the three category cards, the page displays a prompt to review the risk reduction recommendations produced by Agent Sara, the Qualys AI agent that builds wave-based remediation plans. 

This feature will be available in upcoming release. 

Non-Addressable Vulnerabilities Alert

When the three vulnerability categories together account for less than the total number of vulnerabilities detected in your environment, an alert reports the remaining percentage as non-addressable, for example, 7.3% of non-addressable vulnerabilities are due to products not covered by TruRisk Eliminate or assets that have not been scanned recently.

A vulnerability is non-addressable for one of the following reasons:

  • The affected product is not covered by the TruRisk​™ Eliminate patch catalog, so no Qualys patch, mitigation, or permanent fix exists for it.
  • The affected assets have not been scanned recently, so Qualys does not hold current detection data for them.

Scanning your assets on a regular schedule reduces the second category and moves those vulnerabilities into the addressable count. The alert does not appear when every detected vulnerability is addressable.

Risk Reduction Recommendations

This section contains four panels. 

Zero-Touch Remediation Using AI Powered Patch Reliability

Zero-touch remediation is patching that you can automate without a manual testing cycle, because the AI-based reliability score already establishes that the patch deploys safely. This panel indicates how much of your risk qualifies.

The panel reports two figures:

  • The percentage of your addressable risk that comes from third-party applications carrying a low operational risk, for example, 21% of 17.71K vulnerabilities. These are the applications where automated patching is safe to adopt.
  • The percentage of that low-operational-risk subset that you can eliminate using high-reliability patches, for example, 46.7% of 3.71K vulnerabilities.

The first number indicates how much of your environment is a applicable for automation, and the second number indicates how much risk can be addressed immediately.

Top Zero-Touch Patch Targets

This panel lists the third-party products that would deliver the greatest risk reduction if you automate their patching. The products are ranked by the number of vulnerabilities they contribute. 

Column Description
Product The name of the third-party product, for example, Chrome, Notepad++, or 7-zip.
Vulnerabilities The number of open vulnerabilities detected for this product across your assets.
Risk The percentage of this product's vulnerabilities that are classified as risky. A value of 90% or above is shown in red so that you can identify the most urgent products at a glance.

CISA BOD 26-04 Compliance

CISA Binding Operational Directive 26-04 requires organizations to remediate CISA Known Exploited Vulnerabilities (KEVs) within a defined service level agreement. CISA KEVs are vulnerabilities that CISA has confirmed to be exploited in real-world attacks, which makes them the highest-priority class of vulnerability in most environments.

This card displays your organization's position against that directive.

Metric Description
CISA KEVs The total number of CISA Known Exploited Vulnerabilities detected in your environment, shown with the applicable remediation SLA.
Total Patches The number of patches available to remediate these CISA KEVs.
High-Reliability Patches The number of those patches that carry a high reliability score and can be deployed with minimal testing.
Internet Facing Assets The number of internet-facing assets affected by these CISA KEVs. These assets are reachable by attackers and warrant remediation first.
Current MTTR Your average remediation time for CISA KEVs. Compare this value against the stated SLA to see whether you are meeting the directive.

Select View Risk Elimination to open the Eliminations page filtered to your CISA KEVs. For more information, see Creating Patch Job for Windows Assets.

Deploy These Top 10 Patches for Maximum Risk Reduction

This card identifies the smallest set of patches that closes the largest number of Critical and High severity vulnerabilities. It answers the question of what to patch first when you have limited maintenance capacity.

Metric Description
Patches The number of patches in the recommended set.
Unique Vulnerabilities The number of distinct vulnerabilities that this set of patches remediates.
Severity The severity levels considered when building the recommendation. The recommendation
is always based on Critical and High severity vulnerabilities.

Select View Risk Reduction Recommendation to see the individual patches in the recommended set and to create a deployment job from them. For more information, see Creating Patch Job for Windows Assets.

Viewing Feature Details and Activating a Trial

If your subscription does not include every TruRisk​™ Eliminate capability, you can review what you have and what an upgrade adds.

Viewing Your Current and Available Capabilities

  • On the Welcome to TruRisk​™ Eliminate card, select View Feature Details.
  • Review Your current active capabilities. This section lists the capabilities that are already available in your subscription, such as Patch with AI-based patch reliability scoring.
  • Review the capabilities that an upgrade adds. These are Permanent Fix, Mitigate, Custom Assessment & Remediation, Uninstall, and Isolate.
  • Select Maybe Later to close the window without making a change. If your subscription already includes every capability, select Close.

When your subscription does not include the full TruRisk​™ Eliminate license, this card also displays the following controls:

 

  •    
  • View Feature Details: Opens a window that lists the capabilities you use today and the capabilities you gain when you upgrade.
  •    
  • Enable Trial: Starts a trial of the remediation capabilities that your subscription does not currently include.
  •  

 

When your subscription already includes the full TruRisk​™ Eliminate license, these controls are hidden because every capability is already available to you.

Activating a Trial

  • On the Welcome to TruRisk​™ Eliminate card, select Enable Trial. Alternatively, select Activate Trial in the feature details window.
  • Wait while the trial is activated. The button is unavailable during activation to prevent duplicate requests.
  • The page reloads automatically when activation succeeds, and the trial capabilities become available.

To know more about a full upgrade instead of a trial, select Talk to my TAM in the feature details window. This opens a new message to Qualys Support in your default email application.

Related Topics

Creating Patch Job for Windows Assets

Creating Patch Job for Linux Assets

Creating Patch Job for Mac Assets