Home > Partners > Synack Partners with Qualys

Synack and Qualys Integration

Turn scan findings into validated, exploitable risk

Import findings from Qualys Vulnerability Management and Web Application Scanning into the Synack Platform, then use Sara agentic AI triage and Synack Red Team researchers to confirm which vulnerabilities an attacker could actually exploit.

Definition

What Is the Synack and Qualys Integration?

Short answer

The Synack and Qualys integration imports vulnerabilities found by Qualys into the Scanner Findings list in the Synack Platform. Once there, findings are connected to the assets they affect and can be submitted to Sara, Synack's Autonomous Red Agent, for exploitability triage. Synack researchers review what Sara marks exploitable, so the vulnerabilities that reach your team are confirmed rather than suspected.

Synack then provides exposure analysis, remediation recommendations and patch verification for those findings.

The Challenge

Scanning Finds a Lot. It Does Not Tell You What an Attacker Can Use

Scanning identifies potential vulnerabilities but may not confirm what is exploitable, and it can be noisy, which makes it hard to zero in on the vulnerabilities that matter most. Security testing confirms exploitability and provides detailed analysis, paths to remediation and patch verification. Each is vital, but the two sets of results are too often siloed, so it takes too long to isolate and fix exploitable vulnerabilities.

Volume without prioritization

A scan returns thousands of findings across hosts and web applications. Severity alone does not tell you which ones a real attacker could reach and use.

No confirmation of exploitability

Unconfirmed findings send teams chasing issues that existing controls already block, while genuinely exploitable weaknesses sit in the same queue.

Scanning and testing stay siloed

When scan output and security testing results live in separate tools, the handoff is manual and the time to isolate and fix exploitable risk stretches out.

How It Works

From Qualys Scan Result to Confirmed Exploitable Vulnerability

Qualys provides breadth across the attack surface. Synack applies AI-assisted and human-led testing to prove what is exploitable. The integration is the connection between the two.

Qualys Vulnerability Management and Web Application Scanning Scanning gives broad visibility into potential security risk across host and web resources, including CVEs and threat intelligence such as the Qualys Detection Score.
Qualys VM Qualys WAS CVE and QDS context
Synack Scanner Findings and Sara Triage Imported vulnerabilities are linked to their assets, triaged by Sara for exploitability, then reviewed by Synack researchers before they reach your team.
Sara Triage Synack Red Team Patch verification
  1. Step 1
    Connect
    A Synack admin adds Qualys credentials and the API URL under Integrations in the Synack Platform.
  2. Step 2
    Import
    Run a one-time import or enable daily import. Optional severity and asset tag filters limit what comes across.
  3. Step 3
    Triage
    Select findings in the Scanner Findings list and submit them to Sara for exploitability analysis.
  4. Step 4
    Validate
    Synack researchers review what Sara marks exploitable to remove false positives and duplicates.
  5. Step 5
    Fix and verify
    Confirmed findings carry remediation guidance, and Synack can verify the patch once the fix ships.
Sara Triage

Every Finding Gets a Verdict, Not Just a Severity

Sara analyses each submitted finding for exploitability and assigns it a status. That turns a long list of scanner output into a short list of proven risk, plus a clear record of why the rest were set aside.

Findings that Sara marks exploitable go to Synack's vulnerability operations team and the Synack Red Team for human review before they appear on your Exploitable Vulnerabilities page.

Sara triage statuses

  • Exploitable. Confirmed reachable and usable by an attacker. Goes to human review, then to your team.
  • Not exploitable. Present, but existing conditions or controls prevent exploitation.
  • Unreachable. The affected asset could not be reached during testing.
  • Out of scope. The asset sits outside the agreed testing scope.
  • Not applicable. The finding does not apply to the asset as deployed.
The Outcome

Broad Scanning Coverage, Confirmed Exploitable Risk

Joint customers get the reach of automated scanning and the certainty of AI-assisted and human-led testing, without maintaining a connection between the two themselves.

Less noise, clearer priorities

Isolate the vulnerabilities that are accessible to bad actors, so triage effort goes to the findings that matter most rather than the longest list.

Real-world validation

Combine automated scanning, AI triage and human-led analysis that mimics the behaviour of real attackers to find what scanning alone can miss.

End-to-end remediation workflow

Move from finding to fix to verified patch in one workflow, and hand the time-consuming exploit and patch verification work to Synack.

Import Controls

You Decide What Comes Across

The integration is configured under Integrations in the Synack Platform by a user with the Synack Admin role. These settings control the scope and cadence of the import.

You Decide What Comes Across
Setting What it does
Account details Qualys username, password and API server URL, supplied by your Qualys administrator. The API server URL is not the same as the Qualys platform URL.
Severity filter Optional. Limits the import to selected severities. Left blank, severity is ignored and everything in scope is imported.
Asset tags Optional. Limits the import to Qualys applications carrying the tags you enter. Left blank, tags are ignored.
Enable asset creation On by default. Publicly accessible web assets associated with a Qualys result are added to the Synack Asset List automatically. Turned off, only vulnerabilities on assets already in the list are imported.
Import cadence Run a one-time import, or enable daily import so new vulnerabilities arrive automatically. The first scheduled import runs within 24 hours.
Availability

Who Can Use the Integration

The integration is for organizations running both the Synack Platform and Qualys. It supports Qualys Vulnerability Management and Qualys Web Application Scanning, which are configured as two separate connectors with their own guides.

  • An active Synack PTaaS subscription
  • A valid Qualys Vulnerability Management or Web Application Scanning subscription
  • The Synack Admin role, which is required to see and configure Integrations
  • Qualys API credentials, with the User Role Manager role recommended
  • Qualys Cloud Platform, or a Private Platform allowlisted by Synack support
  • FedRAMP customers on the Qualys Government Platform, using the FedRAMP Synack Portal

The integration is available at no additional charge to Synack PTaaS customers with valid Qualys Vulnerability Management or Web Application Scanning subscriptions.

FAQ

Synack and Qualys Integration FAQ

What is the Synack and Qualys integration?

The integration imports vulnerabilities found by Qualys into the Scanner Findings list in the Synack Platform, where Sara agentic AI triage and Synack researchers determine which of them are actually exploitable, then provide remediation guidance and patch verification.

Which Qualys products does Synack integrate with?

Qualys Vulnerability Management and Qualys Web Application Scanning. Each is a separate connector in the Synack Platform with its own integration guide. The integration does not currently work with other Qualys scanning solutions such as Qualys Container Security.

Which direction does data move?

One way. Qualys findings are imported into Synack. Synack does not write findings back into Qualys.

Can the import run automatically?

Yes. You can run a one-time import, or enable daily import so new vulnerabilities are brought across automatically. When daily import is enabled, the first scheduled import runs within 24 hours.

Why do I see fewer vulnerabilities in Synack than in Qualys?

The integration only imports vulnerabilities associated with assets that already exist in the Synack Asset List, unless Enable asset creation is selected, in which case publicly accessible assets from Qualys web application scanning results are added automatically. Internal assets are not added this way. Assets can also be added through Synack Attack Surface Discovery, assessment creation, or manually.

Why do the vulnerability counts differ between the two platforms?

Qualys and Synack count differently. Depending on the view, Qualys may report the number of uniquely vulnerable assets impacted, each of which can be affected by multiple CVEs. Synack counts every vulnerability individually, even when several relate to the same asset, so the Synack count can exceed the Qualys figure for the same assets.

Can FedRAMP customers use the integration?

Yes, on the Qualys Government Platform. FedRAMP customers log in to the FedRAMP instance of the Synack Portal rather than the commercial one.

Does the integration cost extra?

No. It is available at no additional charge to Synack PTaaS customers who hold valid Qualys Vulnerability Management or Web Application Scanning subscriptions.

Get Started

Put Your Qualys Findings in Front of Testers Who Prove Exploitability

Bring Qualys scan results into Synack, and act on the vulnerabilities an attacker could actually use.