Feature Highlight: Qualys Importer

by | Jan 30, 2023 | New Features

Qualys is a popular vulnerability assessment tool, used by pentesters to find and quantify devices, systems, and vulnerabilities. It also automatically checks for OWASP Top 10 and other well-defined risks, can track vulnerabilities over time, and integrates into IT ticketing systems. For this reason, it’s increasingly popular with both pentesters and with organizations looking to monitor their cybersecurity environment. 

Every pentester relies on their toolkit, ranging from scanners and probing tools like NMap and Metasploit to network monitoring and security testing like Burp Suite and Nessus. Your toolkit supports the work that you do and it’s important that every tool you use continues to support that tooling. 

That’s why Cyver Core now offers an integrated Qualys importer, meaning you can directly import Qualys exports into your Cyver Core portal. 

You can now import files directly from: 

  • Burp
  • Nessus
  • NMap
  • Qualys 

Cyver Core is also working on developing integration for NexPose and Open VAS, which will soon be available in the platform. 

Importing Findings from Qualys 

Cyver Core’s Qualys importer allows you to directly import findings exported from your Qualys tooling. 

  1. Export your findings to an XML 
  2. Click “Pentests” from the Cyver Core portal and choose the relevant pentest 
  3. Select “Import/Export” and choose “Import from File” 
  4. Click the “Qualys XML” option 
  5. Import your file 
  6. Choose settings and turn Auto-Fill for CWE/CVSS/Compliance Norms/Vulnerability Types, and Merge with Library on or off
  7. Wait for your Findings to import

Your Qualys findings will be imported to your Cyver Core portal, under the selected pentest, and using data as selected. From there, you can review those findings and choose to publish them directly to the client. 

If you’d like to know more about the Qualys importer in our pentest management portal, contact us for a demo of Cyver Core.

Feature Highlight: Smarter Planning with the New Calendar Component

Feature Highlight: Smarter Planning with the New Calendar Component

Plan smarter. Move faster. Stay in control.We’re introducing a brand-new Calendar component designed to make planning, scheduling, and task management more intuitive than ever, fully integrated into your workflow. Whether you're managing pentests or coordinating...

How Inconsistent Risk Scoring Breaks Security Metrics Over Time

How Inconsistent Risk Scoring Breaks Security Metrics Over Time

CVSS scores are perhaps the most important part of a pentest report, giving teams a standardised way to understand the severity of vulnerabilities they uncover and prioritise remediation efforts.  But they need to be consistent. With so much change in applications,...

Why Two Pentests of the Same App Rarely Produce the Same Results

Why Two Pentests of the Same App Rarely Produce the Same Results

In 2026, more and more companies are pentesting their applications. This is a good thing, of course – it demonstrates increased awareness amongst brands of the cybersecurity risks they face, and just how much of a threat they can be for their data and systems. But...

The Ceiling of Automated Pentesting (And Where It Still Wins)

The Ceiling of Automated Pentesting (And Where It Still Wins)

Automation in the world of cybersecurity has become a core part of many modern strategies. From continuous vulnerability scanning to real-time network monitoring, automation has enabled organisations to identify and respond to threats at scale, but nowhere is this...