WASViking® Infrastructure DefensevsQualys

The same ground as VMDR, Patch Management and the Cloud Agent. Measured at the end, on one license.

If your servers run on Qualys today, you already know the routine: detection in one application, asset inventory in another, patching and configuration licensed on top. Infrastructure Defense covers Windows and Linux fleets with one agent and one per-host license, and it closes every patch cycle with a number: which vulnerabilities closed and how far the risk score dropped.

Windows, Linux and macOS agents Patch execution included Verified by reassessment Proof of concept on your real fleet
acme-web-02
Ubuntu 24.04 · Production · Job #214
COMPLETED
82→54-28 pts
Viking Exposure Score
Before82
After54
  • 11 vulnerabilities closed, 2 listed in CISA KEV
  • 9 of 9 security updates installed
  • No restart pending, boot time confirmed
Verified by reassessment 12 min after the job · approved with change CHG-2291
Illustrative data from the ACME demonstration tenant
At a glance

Where the difference shows up in daily work.

Both platforms inventory your servers, find vulnerabilities, rank them and deploy patches. The difference is in what you buy, what the score knows, and what a finished job proves.

One license, not a stack of subscriptions

Detection, asset inventory, patch execution, configuration hardening and network discovery come with the same per-host license. Nothing to add later when the team wants to act on what it found.

Every patch job ends with proof

The agent reassesses the host right after the job. The result names the vulnerabilities that closed, the score before and after, and any restart still pending. Installed is not the same as fixed, and the job says which one happened.

A score that sees the attack, not only the package

The Viking Exposure Score adds evidence a host agent cannot collect alone: internet exposure proven by our attack surface discovery, and attack traffic blocked at your edge against that server in the last seven days.

Configuration you can fix, not just grade

CIS-aligned controls show expected against actual on every host. For common hardening items, Apply fix runs the change through the agent and the next inventory confirms it. Accepted exceptions carry a reason, an approver and an expiry date.

How it is packaged

Different packaging. The same infrastructure problem.

Products are not one-to-one clones, so compare the operational job each one does. On Qualys, server work is spread across applications on the same Cloud Agent, several of them licensed on their own. Infrastructure Defense covers the same ground from one inventory and one per-host license.

Qualys WASViking® Infrastructure Defense
Cloud Agent

Host telemetry

Persistent endpoint visibility and data collection.

Sentinel Host

Host telemetry

Native service for Windows, Linux and macOS, outbound mutual TLS only.

GAV / CSAM

Asset inventory

Asset visibility, classification, lifecycle and context.

CSAM licensed
Assets

Inventory and lifecycle

Hardware, software, services, listening ports, end of life and cloud metadata.

Included
VMDR

Vulnerability management

Detection, threat context and prioritization.

Per asset
VES

Vulnerability and exposure

CVEs weighted by EPSS, CISA KEV, internet exposure and business context.

Included
PM

Patch management

Patch deployment and remediation workflows.

Add-on
Resolve

Remediation

Approval, maintenance window, execution, restart state and reassessment.

Included
PC

Policy compliance

Configuration assessment against benchmark policies.

Add-on
Compliance

Configuration posture

CIS-aligned checks, exceptions, evidence and supported fixes.

Included
QGS

Gateway and cache

Proxy connectivity and caching of agent upgrades and patch content.

Sentinel Gateway

Controlled distribution

Secure relay for agents and local caching of patch content for restricted networks.

Daily operation

One loop from discovery to proof.

Six steps in one console, on the same host record. Nobody on the team has to learn which application covers which step.

  1. Discover

    Know what exists, including devices without an agent, found by the Sentinel Probe.

  2. Inventory

    One hardware and software record for every host.

  3. Prioritize

    Weigh each vulnerability against exploitation, exposure and business context.

  4. Remediate

    Approve, patch, harden and control restarts inside the maintenance window.

  5. Verify

    Reassess after the change instead of treating installed as fixed.

  6. Prove

    Keep audit evidence tied to the asset and to the change record.

Included in the per-host license: asset inventory, CVE detection, Viking Exposure Score, patch execution, rollback, configuration hardening and Sentinel Probe network discovery.

Prioritization

Same CVE, different urgency. The score knows why.

A risk score built from what the host reports ranks two servers with the same vulnerability almost the same. Infrastructure Defense also reads what the rest of the platform sees about each server, and every point on the score has a name.

Why acme-web-02 scores 99

Viking Exposure Score, points per factor

Worst open vulnerabilityCVSS 9.8
+80
Listed in CISA KEVKnown exploited vulnerability
+6
Exploitation likelyEPSS 0.89
+5
Internet exposure, provenshop.acme.example → 203.0.113.24
+4
Under attack at the edge1,420 blocked requests in 7 days
+3
Production, high criticalityBusiness context
+1
Viking Exposure Score99
Host and threat intelligence factors Evidence from the rest of the WASViking platform

The edge factor appears when Edge Threat Radar is connected to your CDN or WAF.

acme-batch-07 waits its turn

Same vulnerability, same CVSS, internal only and quiet at the edge: it scores 91 and lands below acme-web-02 in the queue. Your team patches the server that is being attacked first, and can explain the order to anyone who asks.

The arithmetic is on the screen

Every factor shows its points, its source and its date. When the attack traffic stops, that factor decays on its own. When your team sets a host as not exposed, the manual decision wins over the automation.

Impact before approval

A pending update is shown as the vulnerabilities it closes and the score it is expected to deliver, so the approver sees the payoff of each change before anything runs.

Measured, not estimated

Twelve weeks of a fleet that gets safer on the record.

Every point on this line comes from a reassessment, never from a patch count. Patch Tuesday pushes the score up, verified jobs bring it down, and leadership sees the trend without anyone building a spreadsheet.

Servers under management
146
Windows Server and Linux, one agent each
Vulnerabilities closed and verified
1,284
Confirmed by reassessment, last 12 weeks
Median time from approval to verified fix
2.6 days
Maintenance windows included

ACME fleet, average Viking Exposure Score

Weekly, from reassessment only. Lower is better.

Average Viking Exposure Score fell from 62 to 31 over twelve weeks, with a rise after each Patch Tuesday. 0 25 50 75 100 12 weeks ago This week Patch Tuesday 62 31
Average VES Patch Tuesday week

Internet-facing assets, by management state

48 public assets found by attack surface discovery

31Fully managedAgent on the host behind it
9Partially managedSome hosts still without agent
6UnmanagedExposed, nothing watching it
2UnknownNot yet tied to a host

Each unmanaged asset comes with its next step: enroll an agent, point the Sentinel Probe at it, or link it to an existing host.

Illustrative data from the ACME demonstration tenant

Product screen

The Command Center your team opens every morning.

Fleet risk, the trend, the projected score after the fixes available today, and the assets to fix first with the reason and the next step for each.

Infrastructure Defense Command Center
Compliance built in

Audit evidence that builds itself while the team works.

Every inventory, approval, patch job and configuration check is recorded with who, what and when. When the auditor, the DPO or a customer asks for proof, it is already there, mapped to the controls they read.

CIS Benchmarks
87%
of CIS-aligned controls passing across the ACME fleet, twelve weeks after rollout

Hardening measured on every host

Controls aligned with CIS benchmark sections run on every inventory, showing expected against actual. Each policy picks a baseline or CIS Level 1 profile, and common fixes run from the failing control.

WindowsLinuxmacOSCIS Level 1 profile
PCI DSS v4.0
100%
of ACME patch jobs in the cardholder data environment with approver, change reference and back-out plan on record

Change control your QSA recognizes

Ranked vulnerabilities, hardening mapped to the requirement, a dated record of every patch from approval to verification, and internal scan evidence kept with the assets it covers.

2.26.3.16.3.36.5.18.310.211.3.112.5.1
LGPD
0
bytes of user file content read by the agent. It collects posture, never personal data in files

Security measures you can demonstrate

Dated evidence that the servers processing personal data are inventoried, assessed, patched under control and hardened, collected by an agent built on data minimization.

Art. 46Art. 6, IIIArt. 50
Compliance · By control

ACME · Production servers · CIS Level 1

41 hosts · last inventory 12 min ago
ControlCISPCI DSSHostsStatus
SMBv1 protocol disabledExpected: disabled · Actual: enabled on 3 hosts2.2 / 18.4Req 238 / 41FAIL
WDigest credential caching offExpected: UseLogonCredential = 018.4Req 841 / 41PASS
Account lockoutExpected: 5 attempts or fewer, 15 min or longer1.2Req 841 / 41PASS
Mandatory access controlExpected: SELinux enforcing · Actual: permissive on 2 hosts1.3 / 1.6Req 2, 719 / 21FAIL
Audit daemon runningExpected: auditd active, audit=1 at boot6.2Req 1021 / 21PASS
Time synchronizationException until Dec 31 · approved by M. Souza2.1Req 1040 / 41ACCEPTED

Illustrative data from the ACME demonstration tenant

ACME fleet, controls passing by area

Share of CIS-aligned checks passing, production servers

Security software
96%
Credential protection
91%
Access control
88%
Audit and logging
84%
Network hardening
79%
System integrity
72%

Highlighted: the area to work on next. Each failing control links to the hosts, the evidence and, for common items, Apply fix.

PCI DSS v4.0

Requirement by requirement, the evidence is already collected.

The records your QSA asks for come out of the daily work: detection, approval, execution and verification. Nobody assembles screenshots the week before the assessment.

2.2

Secure configuration

CIS-aligned controls with expected against actual, and approved exceptions with expiry.

6.3.1

Vulnerabilities identified and ranked

CVEs with CVSS, EPSS and CISA KEV, ranked by the Viking Exposure Score.

6.3.3

Security patches installed

A dated record of each patch job, from approval to verified reassessment.

6.5.1

Change control

Reason, change reference, back-out plan and approval on every job, emergency access limited to named people.

8.3

Authentication settings

Password, lockout and credential protection controls checked on every host.

10.2

Audit logging

Host audit logging verified, plus the platform audit trail of every approval and change.

11.3.1

Internal vulnerability scans

Quarterly internal scans through the Sentinel Probe, credentialed as 11.3.1.2 asks, with evidence packages.

12.5.1

Inventory of system components

Live hardware and software inventory of every enrolled host and every discovered device.

Patch jobs with their approval records in the WASViking console
Every job keeps its approval record: who requested it, who signed off and why, the change reference and the expected score. The records export for the assessor in one click.
LGPD

Security measures under the LGPD, with the evidence attached.

The law asks controllers to adopt security measures and to be able to show them. Infrastructure Defense produces that record for the servers that process personal data, without collecting personal data itself.

Art. 46

Technical security measures

Inventory, vulnerability management, patching under approval and hardening of the servers that hold personal data, each step dated and verifiable.

Art. 6, III

Only the data security needs

The agent reads configuration, packages and services. It never opens user files, so assessing a server does not create a new flow of personal data.

Art. 50

A governance program you can show

Policies per host group, approvals, exceptions with expiry and an audit trail give the DPO a working security program to present, not a document in a drawer.

Also mapped:ISO 27001:2022NIST CSF 2.0BACEN CMN 4.893GDPR
Side-by-side

Module by module, what each platform delivers.

Rows follow the four Qualys applications a server fleet typically runs: Cloud Agent, Global AssetView, VMDR and Patch Management. Where both platforms do the job well, we say so.

Capability Qualys WASViking® Infrastructure Defense
The agentCloud Agent · Sentinel Host
Lightweight agent as a native service Cloud Agent for Windows, Linux and macOS Sentinel Host for Windows, Linux and macOS, outbound mutual TLS only, signed MSI for GPO, Intune or SCCM
On par
Protecting production workloads CPU limit and throttle in the agent configuration profile Performance profiles per policy, the enforcement actually applied on each host shown in the console, and heavy work deferred while the host is under load
Goes further
Asset inventoryGlobal AssetView · Assets
Hardware, software, services and ports Full inventory with software and hardware details Hardware down to volumes and GPU, software with publisher and install date, services, listening ports with the owning process, local accounts, cloud metadata
On par
End of life and end of support Lifecycle data in CyberSecurity Asset Management Operating system and software lifecycle from published vendor data, counted as a risk factor with the date on the label
On par
Devices without an agent Scanner appliances and passive sensors Sentinel Probe network discovery, unauthenticated or credentialed over SSH and WinRM, with PCI DSS 11.3.1 scan evidence. Discovered devices do not consume licenses
Goes further
Internet-facing assets against managed state External attack surface in CyberSecurity Asset Management Every public asset labeled fully managed, partially managed, unmanaged or unknown, with the next step and an alert for unprotected internet assets, in the same license
Goes further
Vulnerability managementVMDR · Vulnerabilities and VES
Detection on Linux and Windows Proprietary vulnerability knowledge base Linux packages qualified by distribution release, Amazon Linux advisories, Windows by build against Microsoft security updates, third-party Windows applications through the package manager
On par
Risk-based prioritization TruRisk and the Qualys Detection Score, with threat intelligence Viking Exposure Score: CVSS, EPSS, CISA KEV, end of life and business context, plus internet exposure proven by attack surface discovery and live attack traffic at your edge
Goes further
Missing patches as impact Patches mapped to the vulnerabilities they fix Each update shown with the vulnerabilities it closes and the expected score after it, before approval
On par
Configuration assessment A subset of misconfigurations in VMDR; CIS benchmarks in Policy Compliance, licensed separately CIS-aligned controls with expected against actual, baseline or CIS Level 1 per policy, exceptions with approval and expiry, included
On par
Fixing a misconfiguration Handled by separate remediation capabilities or scripts Apply fix from the failing control for supported hardening items such as SMBv1, RDP without NLA, LLMNR and kernel parameters, confirmed on the next inventory
Goes further
Patch managementPatch Management · Resolve
Operating system patching Windows, Linux and macOS jobs with pre-actions and post-actions Native update mechanism on each platform, pre-checks for disk, memory, host health and package database, maintenance windows per policy
On par
Rollback Rollback jobs for Windows and Linux Rollback linked to the original job, with reason and back-out plan under the same approvals, reporting which vulnerabilities opened again
On par
Proof that the patch worked Deployment status per asset; closure shows on the next detection cycle The job closes with a reassessment: vulnerabilities closed, score before and after, residual risk explained, restart still pending stated plainly
Goes further
CommercialLicensing
What the license covers VMDR per asset; full Patch Management, Policy Compliance and CSAM licensed on top One per-host license with detection, prioritization, patch execution, rollback, configuration hardening and network discovery
Goes further
What counts toward the license Assets in scope of each application Only hosts with an enrolled agent. Devices found by the Sentinel Probe are inventoried and assessed without counting
Goes further
Day two

Built by people who run patch windows.

What decides a platform is the Sunday at two in the morning when a job stalls. These are the details that keep the team out of the war room.

Approvals an auditor recognizes

Approval by environment, a quorum when you want one, and a tested-first rule that holds production until the same patch succeeds on a test group. Moving a host to a lower environment to skip approval does not work: the change itself needs approval, and emergency access is limited to named people.

A job that tells you where it is

Waiting for the window, held for a restart with the exact reason, running with live progress, or confirming the result. If the host goes offline, the job says since when and alerts the team instead of sitting approved forever.

Restarts handled with manners

Automatic reboot stays off by default. Users get a prompt with deferrals and a countdown, a pending restart holds the next job instead of failing it, and the boot time proves the restart really happened.

The real state of the package system

Running kernel against the newest installed one, packages left half configured and kernel modules that failed to build are facts on the asset. Repair package database is one quick action away, and the agent never runs arbitrary commands.

Enrollment that survives the real world

A local check command names TLS interception, proxy settings and the antivirus that blocked the install. Reinstalled hosts reattach to their history instead of showing up twice.

Alerts where the team already works

Job outcomes, approvals, restarts, new enrollments and unprotected internet assets go to Slack, Microsoft Teams, email or webhooks, and every action lands in the audit trail with who and when.

Switching

Evaluate on your own servers, next to what you run today.

No big-bang cutover. The proof of concept runs on your real fleet, so the comparison uses your hosts, your vulnerabilities and your patch windows.

Enroll a pilot group

Create an activation key and push the signed MSI through your existing deployment tool, or run one command on Linux. The first inventory and score arrive within minutes.

Compare the findings

Put both reports for the same hosts side by side. Look at what each one ranks first and whether the reason holds up.

Run the first patch window

Approve jobs for the pilot group inside a normal maintenance window and read the verified result of each job the next morning.

Extend and consolidate

Roll out by host group, point the Sentinel Probe at the segments without agents, and retire subscriptions as their scope moves over.

Questions buyers ask

Frequently asked questions

Can Infrastructure Defense replace VMDR and Patch Management for our servers?

For Windows and Linux server fleets, yes: asset inventory, vulnerability detection, prioritization, patch execution, rollback and configuration assessment run in one product under one license. Container security, file integrity monitoring and endpoint detection are separate categories, and Infrastructure Defense works alongside the tools you use for them.

Which operating systems are supported?

Windows Server and Windows desktop, the major Linux distributions (Ubuntu, Debian, Red Hat Enterprise Linux and its rebuilds, Amazon Linux) and macOS. Devices without an agent are covered by the Sentinel Probe.

Can both agents run on the same host during the evaluation?

Yes. The Sentinel Host agent is independent of other agents on the machine, and performance profiles keep its footprint predictable, so you can compare both platforms on the same servers before deciding anything.

Where does the vulnerability data come from?

Installed packages are matched against OSV and the distribution advisories, qualified by release so a patched host is not flagged for another branch. Windows is assessed by build against Microsoft security updates. Every finding carries CVSS, EPSS and CISA KEV context.

How is it licensed?

Per monitored host, with patch execution, rollback, configuration hardening and network discovery included. Devices discovered without an agent do not count. Larger fleets are priced on a progressive table, so the cost per host goes down as the fleet grows.

Does the agent ever change anything on its own?

No. The agent collects, executes what a person approved, and verifies. Manual approval is on by default, automatic deployment and automatic reboot are off by default, and the agent never reads the content of user files.

See WASViking on your own stack.

Tell us about your environment. Our team will reach out within one business day with next steps and a quote.