Keep your Qualys vulnerability scanner: Fix what it finds with Patch Manager Plus

Patch Manager Plus vulnerability scanner integration

Key takeaways  

  • Organizations that already run a vulnerability scanner should not have to replace it to get faster vulnerability remediation. They need their scanner connected to a patching tool that can act on what it finds.

  • Patch Manager Plus now integrates with Qualys, adding to the lineup of existing integrations with Tenable, Rapid7 InsightVM, and CrowdStrike Falcon Spotlight.

  • Each integration imports scanner findings and maps them to deployable patches. You remediate vulnerabilities from the same console where you see them.

  • The scanner you already trust for detection stays your detection layer. Patch Manager Plus becomes the remediation layer.


Most organizations that run a vulnerability scanner have already made a significant investment. They chose Qualys, Tenable, Rapid7, or CrowdStrike based on their detection needs, their compliance requirements, and the way their security team works. That scanner is embedded in their workflows, audit processes, and reporting chain.

Then they look at their vulnerability remediation times and realize the problem is not on the scanning side.

Vulnerability exploitation accounted for 20% of all breach events analyzed in Verizon's Data Breach Investigations Report, a 34% increase from the year before. Only 54% of edge device vulnerabilities were fully remediated within the year, with a median patch time of 32 days. That 32-day median is not the deployment time. Deployment takes hours. It is the coordination time, and most of it disappears when the scanner and the patching tool share a direct connection.

Why ripping out your scanner is the wrong answer  

When vulnerability remediation is slow, there is a temptation to consolidate: Find one platform that does both scanning and patching and replace the existing tools, eliminating the gap by eliminating the tools on either side of it. On paper, it sounds clean.

In practice, it creates a different problem. Your security team selected its scanner for specific reasons. Qualys has a particular strength in compliance-driven scanning for regulated environments. Tenable offers flexibility across cloud and on-premises deployments. Rapid7 InsightVM's Active Risk Score gives security teams a prioritization layer that goes beyond raw CVSS scores. CrowdStrike Falcon Spotlight adds vulnerability assessment to an existing endpoint detection agent without requiring the deployment of separate scanning infrastructure.

Replacing any of these means retraining the security team, rebuilding scan policies, migrating historical data, and reestablishing the audit trail. That migration project takes months, and during those months, remediation gets slower, not faster.

The better approach is to keep the scanner that works and connect it to a patch management tool that can act on what it finds. That is the design principle behind Patch Manager Plus' vulnerability scanner integrations. Your scanner handles detection and risk scoring. Patch Manager Plus handles patch identification, testing, deployment, and compliance reporting. The integration eliminates the manual translation layer between the two.

Qualys joins the integration lineup  

Patch Manager Plus already supported integrations with Tenable (One Vulnerability Management and Security Center), Rapid7 InsightVM (cloud and on-premises), and CrowdStrike Falcon Spotlight. Qualys is the newest addition to that list.

For organizations running Qualys VMDR, this means vulnerability data can now flow directly into the Patch Manager Plus console. Qualys scans your environment and assigns severity ratings. Patch Manager Plus imports that data, matches each vulnerability to its corresponding patch, and presents the results under Threats and Patches, specifically in the Qualys Threats view. You deploy the fixes from there.

Setup requires a Qualys Manager user account with read permissions for vulnerability and asset data, access to three Qualys APIs (the host listing, VM detection, and knowledge base), and the Qualys API server URL. You enter these credentials in the Patch Manager Plus console under Admin > Integrations > Threat scanner settings > Qualys, configure the sync frequency, and click Save. The first sync starts importing data immediately. The full setup steps are in the Qualys integration guide.

The intent is straightforward. If you already run Qualys, you should not need to leave it behind to get better vulnerability remediation. You connect it to Patch Manager Plus, and the gap between Qualys finding something and the patch being deployed shrinks from days to hours.

How the integration works across all 4 scanners  

The integration mechanism is the same regardless of which scanner you use. You configure API credentials in your scanner, enter them in Patch Manager Plus, and set how often the data should sync.

On each sync cycle, Patch Manager Plus pulls vulnerability and endpoint data from the scanner's API. It maps each reported vulnerability against its own patch database. The results appear in the Threats and Patches view with three pieces of information side by side: what the scanner found, which patch fixes it, and which endpoints are affected. Deployment happens from that same screen.

The integration does not override your scanner's analysis. If Qualys rates a vulnerability as critical, that rating carries into Patch Manager Plus. If Rapid7 InsightVM's Active Risk Score flags something as high priority, that context informs your patching order. The scanner remains the authority on risk. Patch Manager Plus is the execution layer.

All four scanner integrations support configurable sync schedules and on-demand syncs. After a Patch Tuesday deployment, you can trigger an immediate sync to confirm which vulnerabilities are resolved and which still need attention.

What your team gets after connecting  

The most immediate change is that the triage step disappears: no more exporting scanner reports, cross-referencing CVE IDs with patch catalogs, or building deployment tasks from scratch. The mapping between vulnerabilities and patches is already done when the data arrives in the console.

The second change is the speed increase. Remediation becomes measurable by the time between two sync cycles instead of the time it takes to schedule a meeting between the security team and the IT operations team. For organizations with automated patch approval policies, the entire chain from scanner detection to patch deployment can run without manual intervention on the triage side.

The third change is improved visibility. Both teams, security and IT operations, look at the same view. The security team sees that its scanner findings have matching patches, and it can confirm the deployment status. The IT team sees the risk context the scanner provides without having to open a separate tool. Scheduled reports covering scanner threat data and remediation statuses are supported for all four integrations, which simplifies compliance evidence collection.

None of this requires abandoning a tool your team already depends on. That is the point. The scanner stays. The remediation gets faster.

Which scanner integration fits your setup  ?

You should not have to choose a scanner based on which one integrates with your patching tool. Choose the scanner that fits your detection and compliance needs. Then connect it.

Qualys fits organizations with compliance-driven scanning requirements, particularly in healthcare, finance, and government organizations where Qualys VMDR is already standard. Tenable works well for enterprise environments that need both cloud and on-premises scanning from a single platform. Rapid7 InsightVM is a strong choice for teams that want continuous scanning with prioritization based on active risk scoring. CrowdStrike Falcon Spotlight makes sense if the CrowdStrike agent is already deployed for endpoint detection and response, since it adds vulnerability scanning without a separate agent footprint.

Patch Manager Plus integrates with all four. The experience in the Threats and Patches view is consistent regardless of which scanner feeds it data. The only difference is the initial credential setup, which takes minutes for each.

Start your free, 30-day trial and connect your scanner.