Cracken + Qualys
Cracken reads your Qualys host detections while an operation runs. It attacks the ones inside your approved scope. It launches a fresh Qualys scan when the last one is too old to act on.
Connecting Qualys
- Connect with
A Qualys username and password, plus your Qualys API server URL (defaults to qualysapi.qg3.apps.qualys.com)
- Cadence
Queried live during an operation
- Requires
Launching a scan needs target IPs or asset groups. Filtering findings by CVE, resource ID or resource type is not available on the connector — it reads Qualys Host List Detection, which filters by QID
What Cracken gets from Qualys
Host detections, one per QID per host, id-ed as {host id}_{QID} and named "QID <n>"
QID, detection type, severity (critical, high, medium, low, info) and state (New, Active, Re-Opened, Fixed)
scan_output — the raw RESULTS block Qualys returned for the detection
first_seen and last_seen (FIRST_FOUND_DATETIME, LAST_FOUND_DATETIME)
device with id, ipv4s and hostnames, taken from the HOST ID, IP and DNS elements
Trigger Scan returns scan_id, scan_reference and status for the launched scan
What Qualys does not do
Qualys findings cannot be filtered by CVE, resource ID or resource type through the connector — it reads Qualys Host List Detection, which filters by QID only, so Cracken filters the returned findings itself. A scan will not launch without either an IP list or asset groups, and Cracken never guesses an option profile or scanner appliance name.
How Cracken uses Qualys
- 01
Connect Qualys
- 02
Let Cracken query detections mid-operation
- 03
Attack, and rescan when needed
- 04
Confirm it connected
Frequently asked questions
Can Cracken launch a Qualys scan?
Yes — Qualys is the one connected scanner Cracken triggers directly, launching a vulnerability scan against the IPs or asset groups you scope. It uses an option profile or scanner appliance only when you name it exactly, never guessing or defaulting one.
Does Cracken change my Qualys configuration?
No — Cracken reads vulnerability findings and can launch a scan with settings you supply. It never creates, edits, or deletes option profiles, scanner appliances, asset groups, or users, nor closes or reclassifies findings.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Amazon Inspector
Cracken proves which Amazon Inspector findings an attacker can actually reach.

CrowdStrike Spotlight
Cracken proves which CrowdStrike Spotlight vulnerabilities are exploitable on those hosts.
Attack with real Qualys context.
See how Cracken works what Qualys already knows into attack paths it proves end to end.


