Automated Qualys Scan Coverage Checks
Every morning, WebRun signs in to Qualys, checks whether each scheduled scan ran and finished, lists assets that failed to report or have not been scanned within your policy window, drafts a Gmail note to each asset owner asking them to fix it, and sends you a WhatsApp summary of the coverage gap.
How do I verify that all our Qualys scans ran and covered every asset?
WebRun signs in to Qualys every morning, confirms each scheduled scan ran and completed, and lists assets that failed to report or fell outside your scan policy window. It drafts a Gmail note to each asset owner and sends the security team a WhatsApp summary, so coverage gaps are proven rather than assumed.
- A failed scan is caught the next morning instead of at audit time
- Uncovered assets are chased with a named owner and a date
- Coverage is evidenced daily, which is exactly what auditors ask for
Built for security teams · vulnerability managers · IT operations · compliance officers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.qualys.comin a real browser with your saved login - no setup, no API keys. -
1
Qualys - verify scans ran and assets reported
WebRun opens Qualys to verify scans ran and assets reported. - Sign in to Qualys and open your scan schedules and recent scan results
- Confirm each scheduled scan started, finished, and did not error
- List assets in scope that returned no result or were unreachable
- List assets whose last successful scan is older than your policy window
- Group the gaps by owner, business unit, or asset tag
Done when Every scheduled scan has a completion state and every uncovered asset is listed.
-
2
Gmail - draft the note to asset owners
WebRun opens Gmail to draft the note to asset owners. - Compose a short note to each owner whose assets were missed
- List the specific hostnames or asset tags, the last successful scan date, and the policy window they breached
- Keep the tone factual and include what you need them to check, such as connectivity or agent status
- Leave every message in Drafts. Nothing is sent until a security team member reviews it
Done when A draft note is ready for every owner with an uncovered asset.
-
3
WhatsApp - send you the coverage gap
WebRun opens WhatsApp to send you the coverage gap. - Send a short WhatsApp summary to the security team chat
- Report how many scheduled scans completed and how many failed or did not run
- Give the count of assets outside the policy window and name the worst offending group
- Note how many owner notes are waiting in Gmail Drafts
- Stay quiet on days when every scan completed and coverage is whole
Done when The security team knows this morning's coverage position.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it launch or cancel scans?
No. WebRun reads schedules and results only. Starting a scan, changing a schedule, or altering an asset group stays with your security team, because scans touch production systems.
Does it email asset owners on its own?
No. Every owner note is left in Gmail Drafts naming the assets and the dates. A security team member reads it and sends it, so nobody gets chased by an automation.
What counts as an uncovered asset?
Any asset in scope with no successful scan inside the policy window you set, plus any asset that was unreachable during a scheduled scan. Your own window defines the standard.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.