All templates

Automated Qualys Scan Coverage Checks

Every morning, WebRun signs in to Qualys, checks whether each scheduled scan ran and finished, lists assets that failed to report or have not been scanned within your policy window, drafts a Gmail note to each asset owner asking them to fix it, and sends you a WhatsApp summary of the coverage gap.

Runs on WebRun · Strict Lockdown policy
Every day at 7:00 AM WebRunorchestrates each step
1 Qualys verify scans ran and assets reported
2 Gmail draft the note to asset owners
3 WhatsApp send you the coverage gap
In short

How do I verify that all our Qualys scans ran and covered every asset?

WebRun signs in to Qualys every morning, confirms each scheduled scan ran and completed, and lists assets that failed to report or fell outside your scan policy window. It drafts a Gmail note to each asset owner and sends the security team a WhatsApp summary, so coverage gaps are proven rather than assumed.

  • A failed scan is caught the next morning instead of at audit time
  • Uncovered assets are chased with a named owner and a date
  • Coverage is evidenced daily, which is exactly what auditors ask for

Built for security teams · vulnerability managers · IT operations · compliance officers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.qualys.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Qualys - verify scans ran and assets reported
    qualys.com
    WebRun in Qualys: verify scans ran and assets reported
    WebRun opens Qualys to verify scans ran and assets reported.
    • Sign in to Qualys and open your scan schedules and recent scan results
    • Confirm each scheduled scan started, finished, and did not error
    • List assets in scope that returned no result or were unreachable
    • List assets whose last successful scan is older than your policy window
    • Group the gaps by owner, business unit, or asset tag

    Done when Every scheduled scan has a completion state and every uncovered asset is listed.

  3. 2
    Gmail - draft the note to asset owners
    gmail.com
    WebRun in Gmail: draft the note to asset owners
    WebRun opens Gmail to draft the note to asset owners.
    • Compose a short note to each owner whose assets were missed
    • List the specific hostnames or asset tags, the last successful scan date, and the policy window they breached
    • Keep the tone factual and include what you need them to check, such as connectivity or agent status
    • Leave every message in Drafts. Nothing is sent until a security team member reviews it

    Done when A draft note is ready for every owner with an uncovered asset.

  4. 3
    WhatsApp - send you the coverage gap
    whatsapp.com
    WebRun in WhatsApp: send you the coverage gap
    WebRun opens WhatsApp to send you the coverage gap.
    • Send a short WhatsApp summary to the security team chat
    • Report how many scheduled scans completed and how many failed or did not run
    • Give the count of assets outside the policy window and name the worst offending group
    • Note how many owner notes are waiting in Gmail Drafts
    • Stay quiet on days when every scan completed and coverage is whole

    Done when The security team knows this morning's coverage position.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.qualys.com
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Coverage gap summary · WhatsApp
OutputWhat each run produces - A daily coverage check: which scheduled scans completed, which assets failed to report, and which are outside your scan policy window.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it launch or cancel scans?

No. WebRun reads schedules and results only. Starting a scan, changing a schedule, or altering an asset group stays with your security team, because scans touch production systems.

Does it email asset owners on its own?

No. Every owner note is left in Gmail Drafts naming the assets and the dates. A security team member reads it and sends it, so nobody gets chased by an automation.

What counts as an uncovered asset?

Any asset in scope with no successful scan inside the policy window you set, plus any asset that was unreachable during a scheduled scan. Your own window defines the standard.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.