The same ground as VMDR, Patch Management and the Cloud Agent. Measured at the end, on one license.
If your servers run on Qualys today, you already know the routine: detection in one application, asset inventory in another, patching and configuration licensed on top. Infrastructure Defense covers Windows and Linux fleets with one agent and one per-host license, and it closes every patch cycle with a number: which vulnerabilities closed and how far the risk score dropped.
- 11 vulnerabilities closed, 2 listed in CISA KEV
- 9 of 9 security updates installed
- No restart pending, boot time confirmed
Where the difference shows up in daily work.
Both platforms inventory your servers, find vulnerabilities, rank them and deploy patches. The difference is in what you buy, what the score knows, and what a finished job proves.
One license, not a stack of subscriptions
Detection, asset inventory, patch execution, configuration hardening and network discovery come with the same per-host license. Nothing to add later when the team wants to act on what it found.
Every patch job ends with proof
The agent reassesses the host right after the job. The result names the vulnerabilities that closed, the score before and after, and any restart still pending. Installed is not the same as fixed, and the job says which one happened.
A score that sees the attack, not only the package
The Viking Exposure Score adds evidence a host agent cannot collect alone: internet exposure proven by our attack surface discovery, and attack traffic blocked at your edge against that server in the last seven days.
Configuration you can fix, not just grade
CIS-aligned controls show expected against actual on every host. For common hardening items, Apply fix runs the change through the agent and the next inventory confirms it. Accepted exceptions carry a reason, an approver and an expiry date.
Different packaging. The same infrastructure problem.
Products are not one-to-one clones, so compare the operational job each one does. On Qualys, server work is spread across applications on the same Cloud Agent, several of them licensed on their own. Infrastructure Defense covers the same ground from one inventory and one per-host license.
Host telemetry
Persistent endpoint visibility and data collection.
Host telemetry
Native service for Windows, Linux and macOS, outbound mutual TLS only.
Asset inventory
Asset visibility, classification, lifecycle and context.
CSAM licensedInventory and lifecycle
Hardware, software, services, listening ports, end of life and cloud metadata.
IncludedVulnerability management
Detection, threat context and prioritization.
Per assetVulnerability and exposure
CVEs weighted by EPSS, CISA KEV, internet exposure and business context.
IncludedPatch management
Patch deployment and remediation workflows.
Add-onRemediation
Approval, maintenance window, execution, restart state and reassessment.
IncludedPolicy compliance
Configuration assessment against benchmark policies.
Add-onConfiguration posture
CIS-aligned checks, exceptions, evidence and supported fixes.
IncludedGateway and cache
Proxy connectivity and caching of agent upgrades and patch content.
Controlled distribution
Secure relay for agents and local caching of patch content for restricted networks.
One loop from discovery to proof.
Six steps in one console, on the same host record. Nobody on the team has to learn which application covers which step.
-
Discover
Know what exists, including devices without an agent, found by the Sentinel Probe.
-
Inventory
One hardware and software record for every host.
-
Prioritize
Weigh each vulnerability against exploitation, exposure and business context.
-
Remediate
Approve, patch, harden and control restarts inside the maintenance window.
-
Verify
Reassess after the change instead of treating installed as fixed.
-
Prove
Keep audit evidence tied to the asset and to the change record.
Included in the per-host license: asset inventory, CVE detection, Viking Exposure Score, patch execution, rollback, configuration hardening and Sentinel Probe network discovery.
Same CVE, different urgency. The score knows why.
A risk score built from what the host reports ranks two servers with the same vulnerability almost the same. Infrastructure Defense also reads what the rest of the platform sees about each server, and every point on the score has a name.
Why acme-web-02 scores 99
Viking Exposure Score, points per factor
The edge factor appears when Edge Threat Radar is connected to your CDN or WAF.
acme-batch-07 waits its turn
Same vulnerability, same CVSS, internal only and quiet at the edge: it scores 91 and lands below acme-web-02 in the queue. Your team patches the server that is being attacked first, and can explain the order to anyone who asks.
The arithmetic is on the screen
Every factor shows its points, its source and its date. When the attack traffic stops, that factor decays on its own. When your team sets a host as not exposed, the manual decision wins over the automation.
Impact before approval
A pending update is shown as the vulnerabilities it closes and the score it is expected to deliver, so the approver sees the payoff of each change before anything runs.
Twelve weeks of a fleet that gets safer on the record.
Every point on this line comes from a reassessment, never from a patch count. Patch Tuesday pushes the score up, verified jobs bring it down, and leadership sees the trend without anyone building a spreadsheet.
ACME fleet, average Viking Exposure Score
Weekly, from reassessment only. Lower is better.
Internet-facing assets, by management state
48 public assets found by attack surface discovery
Each unmanaged asset comes with its next step: enroll an agent, point the Sentinel Probe at it, or link it to an existing host.
Illustrative data from the ACME demonstration tenant
The Command Center your team opens every morning.
Fleet risk, the trend, the projected score after the fixes available today, and the assets to fix first with the reason and the next step for each.
Audit evidence that builds itself while the team works.
Every inventory, approval, patch job and configuration check is recorded with who, what and when. When the auditor, the DPO or a customer asks for proof, it is already there, mapped to the controls they read.
Hardening measured on every host
Controls aligned with CIS benchmark sections run on every inventory, showing expected against actual. Each policy picks a baseline or CIS Level 1 profile, and common fixes run from the failing control.
Change control your QSA recognizes
Ranked vulnerabilities, hardening mapped to the requirement, a dated record of every patch from approval to verification, and internal scan evidence kept with the assets it covers.
Security measures you can demonstrate
Dated evidence that the servers processing personal data are inventoried, assessed, patched under control and hardened, collected by an agent built on data minimization.
ACME · Production servers · CIS Level 1
41 hosts · last inventory 12 min ago| Control | CIS | PCI DSS | Hosts | Status |
|---|---|---|---|---|
| SMBv1 protocol disabledExpected: disabled · Actual: enabled on 3 hosts | 2.2 / 18.4 | Req 2 | 38 / 41 | FAIL |
| WDigest credential caching offExpected: UseLogonCredential = 0 | 18.4 | Req 8 | 41 / 41 | PASS |
| Account lockoutExpected: 5 attempts or fewer, 15 min or longer | 1.2 | Req 8 | 41 / 41 | PASS |
| Mandatory access controlExpected: SELinux enforcing · Actual: permissive on 2 hosts | 1.3 / 1.6 | Req 2, 7 | 19 / 21 | FAIL |
| Audit daemon runningExpected: auditd active, audit=1 at boot | 6.2 | Req 10 | 21 / 21 | PASS |
| Time synchronizationException until Dec 31 · approved by M. Souza | 2.1 | Req 10 | 40 / 41 | ACCEPTED |
Illustrative data from the ACME demonstration tenant
ACME fleet, controls passing by area
Share of CIS-aligned checks passing, production servers
Highlighted: the area to work on next. Each failing control links to the hosts, the evidence and, for common items, Apply fix.
Requirement by requirement, the evidence is already collected.
The records your QSA asks for come out of the daily work: detection, approval, execution and verification. Nobody assembles screenshots the week before the assessment.
Secure configuration
CIS-aligned controls with expected against actual, and approved exceptions with expiry.
Vulnerabilities identified and ranked
CVEs with CVSS, EPSS and CISA KEV, ranked by the Viking Exposure Score.
Security patches installed
A dated record of each patch job, from approval to verified reassessment.
Change control
Reason, change reference, back-out plan and approval on every job, emergency access limited to named people.
Authentication settings
Password, lockout and credential protection controls checked on every host.
Audit logging
Host audit logging verified, plus the platform audit trail of every approval and change.
Internal vulnerability scans
Quarterly internal scans through the Sentinel Probe, credentialed as 11.3.1.2 asks, with evidence packages.
Inventory of system components
Live hardware and software inventory of every enrolled host and every discovered device.
Security measures under the LGPD, with the evidence attached.
The law asks controllers to adopt security measures and to be able to show them. Infrastructure Defense produces that record for the servers that process personal data, without collecting personal data itself.
Technical security measures
Inventory, vulnerability management, patching under approval and hardening of the servers that hold personal data, each step dated and verifiable.
Only the data security needs
The agent reads configuration, packages and services. It never opens user files, so assessing a server does not create a new flow of personal data.
A governance program you can show
Policies per host group, approvals, exceptions with expiry and an audit trail give the DPO a working security program to present, not a document in a drawer.
Module by module, what each platform delivers.
Rows follow the four Qualys applications a server fleet typically runs: Cloud Agent, Global AssetView, VMDR and Patch Management. Where both platforms do the job well, we say so.
| Capability | Qualys | WASViking® Infrastructure Defense |
|---|---|---|
| The agentCloud Agent · Sentinel Host | ||
| Lightweight agent as a native service | Cloud Agent for Windows, Linux and macOS | Sentinel Host for Windows, Linux and macOS, outbound mutual TLS only, signed MSI for GPO, Intune or SCCM On par |
| Protecting production workloads | CPU limit and throttle in the agent configuration profile | Performance profiles per policy, the enforcement actually applied on each host shown in the console, and heavy work deferred while the host is under load Goes further |
| Asset inventoryGlobal AssetView · Assets | ||
| Hardware, software, services and ports | Full inventory with software and hardware details | Hardware down to volumes and GPU, software with publisher and install date, services, listening ports with the owning process, local accounts, cloud metadata On par |
| End of life and end of support | Lifecycle data in CyberSecurity Asset Management | Operating system and software lifecycle from published vendor data, counted as a risk factor with the date on the label On par |
| Devices without an agent | Scanner appliances and passive sensors | Sentinel Probe network discovery, unauthenticated or credentialed over SSH and WinRM, with PCI DSS 11.3.1 scan evidence. Discovered devices do not consume licenses Goes further |
| Internet-facing assets against managed state | External attack surface in CyberSecurity Asset Management | Every public asset labeled fully managed, partially managed, unmanaged or unknown, with the next step and an alert for unprotected internet assets, in the same license Goes further |
| Vulnerability managementVMDR · Vulnerabilities and VES | ||
| Detection on Linux and Windows | Proprietary vulnerability knowledge base | Linux packages qualified by distribution release, Amazon Linux advisories, Windows by build against Microsoft security updates, third-party Windows applications through the package manager On par |
| Risk-based prioritization | TruRisk and the Qualys Detection Score, with threat intelligence | Viking Exposure Score: CVSS, EPSS, CISA KEV, end of life and business context, plus internet exposure proven by attack surface discovery and live attack traffic at your edge Goes further |
| Missing patches as impact | Patches mapped to the vulnerabilities they fix | Each update shown with the vulnerabilities it closes and the expected score after it, before approval On par |
| Configuration assessment | A subset of misconfigurations in VMDR; CIS benchmarks in Policy Compliance, licensed separately | CIS-aligned controls with expected against actual, baseline or CIS Level 1 per policy, exceptions with approval and expiry, included On par |
| Fixing a misconfiguration | Handled by separate remediation capabilities or scripts | Apply fix from the failing control for supported hardening items such as SMBv1, RDP without NLA, LLMNR and kernel parameters, confirmed on the next inventory Goes further |
| Patch managementPatch Management · Resolve | ||
| Operating system patching | Windows, Linux and macOS jobs with pre-actions and post-actions | Native update mechanism on each platform, pre-checks for disk, memory, host health and package database, maintenance windows per policy On par |
| Rollback | Rollback jobs for Windows and Linux | Rollback linked to the original job, with reason and back-out plan under the same approvals, reporting which vulnerabilities opened again On par |
| Proof that the patch worked | Deployment status per asset; closure shows on the next detection cycle | The job closes with a reassessment: vulnerabilities closed, score before and after, residual risk explained, restart still pending stated plainly Goes further |
| CommercialLicensing | ||
| What the license covers | VMDR per asset; full Patch Management, Policy Compliance and CSAM licensed on top | One per-host license with detection, prioritization, patch execution, rollback, configuration hardening and network discovery Goes further |
| What counts toward the license | Assets in scope of each application | Only hosts with an enrolled agent. Devices found by the Sentinel Probe are inventoried and assessed without counting Goes further |
Built by people who run patch windows.
What decides a platform is the Sunday at two in the morning when a job stalls. These are the details that keep the team out of the war room.
Approvals an auditor recognizes
Approval by environment, a quorum when you want one, and a tested-first rule that holds production until the same patch succeeds on a test group. Moving a host to a lower environment to skip approval does not work: the change itself needs approval, and emergency access is limited to named people.
A job that tells you where it is
Waiting for the window, held for a restart with the exact reason, running with live progress, or confirming the result. If the host goes offline, the job says since when and alerts the team instead of sitting approved forever.
Restarts handled with manners
Automatic reboot stays off by default. Users get a prompt with deferrals and a countdown, a pending restart holds the next job instead of failing it, and the boot time proves the restart really happened.
The real state of the package system
Running kernel against the newest installed one, packages left half configured and kernel modules that failed to build are facts on the asset. Repair package database is one quick action away, and the agent never runs arbitrary commands.
Enrollment that survives the real world
A local check command names TLS interception, proxy settings and the antivirus that blocked the install. Reinstalled hosts reattach to their history instead of showing up twice.
Alerts where the team already works
Job outcomes, approvals, restarts, new enrollments and unprotected internet assets go to Slack, Microsoft Teams, email or webhooks, and every action lands in the audit trail with who and when.
Evaluate on your own servers, next to what you run today.
No big-bang cutover. The proof of concept runs on your real fleet, so the comparison uses your hosts, your vulnerabilities and your patch windows.
Enroll a pilot group
Create an activation key and push the signed MSI through your existing deployment tool, or run one command on Linux. The first inventory and score arrive within minutes.
Compare the findings
Put both reports for the same hosts side by side. Look at what each one ranks first and whether the reason holds up.
Run the first patch window
Approve jobs for the pilot group inside a normal maintenance window and read the verified result of each job the next morning.
Extend and consolidate
Roll out by host group, point the Sentinel Probe at the segments without agents, and retire subscriptions as their scope moves over.
Frequently asked questions
Can Infrastructure Defense replace VMDR and Patch Management for our servers?
For Windows and Linux server fleets, yes: asset inventory, vulnerability detection, prioritization, patch execution, rollback and configuration assessment run in one product under one license. Container security, file integrity monitoring and endpoint detection are separate categories, and Infrastructure Defense works alongside the tools you use for them.
Which operating systems are supported?
Windows Server and Windows desktop, the major Linux distributions (Ubuntu, Debian, Red Hat Enterprise Linux and its rebuilds, Amazon Linux) and macOS. Devices without an agent are covered by the Sentinel Probe.
Can both agents run on the same host during the evaluation?
Yes. The Sentinel Host agent is independent of other agents on the machine, and performance profiles keep its footprint predictable, so you can compare both platforms on the same servers before deciding anything.
Where does the vulnerability data come from?
Installed packages are matched against OSV and the distribution advisories, qualified by release so a patched host is not flagged for another branch. Windows is assessed by build against Microsoft security updates. Every finding carries CVSS, EPSS and CISA KEV context.
How is it licensed?
Per monitored host, with patch execution, rollback, configuration hardening and network discovery included. Devices discovered without an agent do not count. Larger fleets are priced on a progressive table, so the cost per host goes down as the fleet grows.
Does the agent ever change anything on its own?
No. The agent collects, executes what a person approved, and verifies. Manual approval is on by default, automatic deployment and automatic reboot are off by default, and the agent never reads the content of user files.
Qualys, VMDR, Global AssetView, CyberSecurity Asset Management, Patch Management, Policy Compliance, Qualys Gateway Service, TruRisk and Cloud Agent are trademarks of Qualys, Inc. WASViking LLC is not affiliated with or endorsed by Qualys, Inc.
The Qualys column reflects publicly available product documentation reviewed in September 2026. Features, editions and licensing terms vary by contract and change over time, so validate each row in your own evaluation. ACME figures on this page are illustrative data from a demonstration tenant, not customer results.