The Web Applications tab lets you define and manage your web applications once added to your subscription. The Web Application Scanning service provides you an ability to scan web applications in your subscription for vulnerabilities. Your subscription comprises the number of web applications you have added to your account. Qualys supports HTTP and HTTPS and assumes ports 80 and 443, respectively, but you can specify another port in your URL. To access your web applications, go to the Web applications section.
The tab displays the web application name, last scanned date, updated date, and tags. The tab displays the total number of links crawled for the web application and the vulnerability level of the web application with the number of open vulnerabilities and the TruRisk™ score calculated for the web applications, which indicates the level of vulnerability of the web application. For details on the TruRisk™ score, see Web Application TruRisk™ Calculation.
From the Web Applications tab, you can:
A) Add new web applications or import them from a CSV or TXT file. Select the New Web App drop-down to create and import web applications.
B) Enter QQL (Qualys Query Language) queries in the search box to search for web applications. Use either web application or detection tokens or both types of tokens in combination to search for web applications. To use both web application and detection tokens, click the plus icon in the search box. Enter the web application tokens to search for web applications by their name, severity, authentication record name, etc. If you want to search for web applications for specific detections, click the plus icon, and enter detection tokens. For example, you can find web applications that have certain QIDs. See the “Search Tokens for Web Applications Scanning” topic.
C) Use the left pane filters to search for web applications by using Quick or Classic Filters by multiple criteria severity, last scan status, authentication type, and tags.
- From Quick filters, you can search web applications using security risk, last scan status, authentication type and applied tags. For more information, see Web Applications - Quick Filters.
- From Classic filters, you can add or selet values for multiple criteria for web applications and associated detections to search the web applications. For more information, see Web Applications - Classic Filters.
D)Take one or more actions against individual applications using the Quick Actions .menu. Select or hover a web application and click the arrow to view the options in the Quick Actions menu. Use the Quick Actions menu to view, edit the details of web assets, add tags and remove tags from web assets, purge scan data of web assets. You can also remove web assets from the subscription and other associated modules and create a new web asset with the same configurations using the Save as option.
E) Take actions against multiple applications using the Bulk Actions menu. Use the Bulk Actions menu to edit the details of web assets, add or remove tags from web assets, purge scan data of web assets. You can also remove web assets from the subscription and other associated modules.
F) Use the Group By filter to filter the web applications by security risks: Low, Medium, High, and None. Use the Search Actions menu to view the recent searches, save search queries added in the search box and manage saved searches.
G) Use the Search Actions menu to view the recent searches, save search queries added in the search box and manage saved searches.
Related topics
Add Comment to Web Applications