Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Delivery Manager at a tech vendor with 1,001-5,000 employees
Vendor
We can do scanning and submit reports straight to customers when there are new vulnerabilities
Pros and Cons
  • "We can do scanning and submit reports straight to the customers when there are new vulnerabilities, then tell them whether they are affected or not."
  • "In terms of the Policy Compliance model which they currently have, not all the platforms are being covered. If they could improve on the Policy Compliance model, since there are policies which are benchmarked against it, this will be helpful for us."

What is our primary use case?

We use it for external connection testing whenever we have a customer who utilizes post scanning tools for their main message. From the scanner's perspective, we use the scanner results to do manual testing.

How has it helped my organization?

We are looking for automation in our scanning activities or projects, because manual won't work. So, automation is required for us. As a result, using the Qualys scanner result is helpful for us.

What is most valuable?

We are using scanners and the PCI model. We do PCI scanning because we are a PCI vendor. We are using the tool to do the scanning on whatever the latest vulnerabilities there are, and Qualys is always providing us updates. We can do scanning and submit reports straight to the customers when there are new vulnerabilities, then tell them whether they are affected or not.

What needs improvement?

In terms of the Policy Compliance model which they currently have, not all the platforms are being covered. If they could improve on the Policy Compliance model, since there are policies which are benchmarked against it, this will be helpful for us.

Buyer's Guide
Qualys Web Application Scanning
March 2025
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
851,823 professionals have used our research since 2012.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

It has been stable.

What do I think about the scalability of the solution?

It is good and scalable.

How are customer service and support?

Technical support is responsive.

Which solution did I use previously and why did I switch?

We were and still are using webMethods Professional. We use both in tandem to do manual testing. That is our process of doing things.

How was the initial setup?

We use the cloud instances for our setups. We have one setup, and it is on the cloud, so it is not complex. Actually, we don't have to do any set up. 

We have applications located in our different offices, and so far there set up has not been a challenge.

What's my experience with pricing, setup cost, and licensing?

Qualys has an IT-based licensing based on a yearly license, which is a good way of handling it. However, in some cases, when we do the PCI scanning, the host will not like the scanning and we lose the IT license. So, this could be improved.

What other advice do I have?

It is a very much stable. If you have a good amount of calender-based activities, it is good for defining frequency. You can define the calendar internally, then you can do your scanning. Though, it has some triaging features which should finally be fixed. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user494979 - PeerSpot reviewer
Module Lead with 1,001-5,000 employees
Vendor
It reports fewer false positives than other tools. The tool should have a live HTTP editor and more mature APIs.

What is most valuable?

There is nothing out of the box in the Qualys web application scanning module. One good thing is that it reports fewer false positives.

How has it helped my organization?

We use many other products along with Qualys. In a way, Qualys dashboards are good to keep track of vulnerabilities found asset-wise.

What needs improvement?

The tool should have a live HTTP editor and more configuration options for some situations, such as handling applications that have URL rewriting enabled.

The tool should have more mature APIs for integration and automation. They should provide more flexible APIs to download reports.

For how long have I used the solution?

I have been using it for almost four years now.

What do I think about the stability of the solution?

Qualys is good, stability-wise.

What do I think about the scalability of the solution?

Qualys is perfect, scalability-wise.

How are customer service and technical support?

On a scale of 1-5 with 5 being the highest, I would rate technical support at 3.

Which solution did I use previously and why did I switch?

I have used Nessus, Burp Suite, and IBM AppScan. Cost- and functionality-wise, I find Burp Suite the best of them all. AppScan is good, but very expensive and reports more false positives.

How was the initial setup?

Setup is straightforward.

What's my experience with pricing, setup cost, and licensing?

Licensing could be cheaper. It is expensive at present.

What other advice do I have?

Qualys is only a good product for in-house vulnerability management programs. It is not feasible to use Qualys for client-facing consulting engagements because of the cost.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys Web Application Scanning
March 2025
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
851,823 professionals have used our research since 2012.
CybSec9734 - PeerSpot reviewer
Cyber Security Consultant at a tech services company with 10,001+ employees
Consultant
The way results are presented makes remediation easy, but GUI is a little complex
Pros and Cons
  • "Key features include: Cloud-based, so the installation is not so tedious. Easily deployed. Highly scalable. Comprehensive reporting."
  • "You can integrate your Burp Suite results and create an integrated report. Also, the way it shows the results - threats and exploit details - makes remediation very easy."
  • "The GUI could be a little less complicated as it opens a lot of new windows for creating search lists, templates, reports, or for scanning purposes."

What is our primary use case?

We have a lot of applications in our environment that we need to scan frequently. We have a lot of tutorial sites, e-learning sites, and other related websites which we have to build, maintain, and scan continuously for security purposes.

How has it helped my organization?

It definitely helps us with the remediation process as we can create different reports, whatever is required at the time. 

What is most valuable?

  • It's cloud-based so the installation is not so tedious.
  • Easily deployed.
  • Highly scalable.
  • Comprehensive reporting.

Also, you can integrate your Burp Suite results and create an integrated report. 

The way it shows the results - threats and exploit details - makes remediation very easy.

We have seen very few false positives. We found the documentation very useful, particularly the roll-out guide. While the tool is not hard to use, by dividing the documentation into sections, the company provided specific guidance on use cases that are not necessarily limited to the tool itself.

What needs improvement?

The GUI could be a little less complicated as it opens a lot of new windows for creating search lists, templates, reports, or for scanning purposes. 

Also, occasionally it can't even authenticate to basic web forms.

For how long have I used the solution?

One to three years.

How is customer service and technical support?

Qualys offers one excellent support, which includes 24/7 phone and mail support, as well as access to its online user community.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user335103 - PeerSpot reviewer
Info-Security Consultant at a financial services firm with 1,001-5,000 employees
Vendor
It protects against zero-day vulnerabilities, like Heartbleed.

What is most valuable?

It protects against zero-day vulnerabilities, like Heartbleed.

What needs improvement?

It's missing some zero-day patches.

For how long have I used the solution?

I've used it for a few months.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

It's high.

Technical Support:

It's high.

Which solution did I use previously and why did I switch?

I used Rapid7 NeXpose in another shop.

How was the initial setup?

The product was already installed when I got there, I just added more scanning jobs and used the reports for remediation, etc.

Which other solutions did I evaluate?

I evaluated and selected Rapid7 NeXpose in a previous job (over QualysGuard) because the compliance department there vetoed using “an external service”. Also, we wanted to get Metasploit later.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user563475 - PeerSpot reviewer
Deputy Manager at a tech services company with 10,001+ employees
Real User
Network scanner has good reporting and coverage, but it needs manual pen testing

What is our primary use case?

Cloud hosted application, and was also accessible through mobile app.

How has it helped my organization?

Dynamic features for pen testing automation, with manual.

What is most valuable?

Network scanner has good reporting, coverage was also good. In Web scanner, dashboard was good but features were limited.

What needs improvement?

Please add manual penetration testing features. 

Also I didn't like the license terms and the features were limited compared to other tools used for web applications.

For how long have I used the solution?

Trial/evaluations only.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user255879 - PeerSpot reviewer
Security Analyst at a tech services company with 1,001-5,000 employees
Consultant
Automated tools cannot find all the vulnerabilities, but this is one of the best.

What is most valuable?

WAS and being able to integrate Selenium IDE to automate the login process was most helpful.

How has it helped my organization?

Scheduling feature allows to scan on the weekends and holidays in a planned way.

What needs improvement?

Enhancing the capability to find XSS.

For how long have I used the solution?

I've used it for six months.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

I've never had the chance to interact.

Technical Support:

I've never had the chance to interact.

Which solution did I use previously and why did I switch?

This would depend on the clients' requirements.

How was the initial setup?

It's straightforward. In fact, it's one of the easiest solutions to implement.

What about the implementation team?

We used a vendor team who had good expertise.

What other advice do I have?

I would recommend this tool. Simply, go for it. The video tutorials would give an insight on the simplicity and effectiveness of the product.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2025
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.