Qualys Expands TruConfirm to Validate Exploits on Both Network and Host Endpoints
What Happened — Qualys announced that its TruConfirm service now runs on the Qualys Cloud Agent, extending exploit‑validation from network‑only scans to the host level. The agent can prove exploitability for local, kernel, browser and post‑authentication CVEs that were previously invisible to network scanners.
Why It Matters for Compliance & Audit Readiness
- SOC 2’s Vulnerability Management (CC6.1) and Risk Management (CC7.1) controls require evidence that identified findings are truly exploitable, not just theoretical. Agent‑based TruConfirm supplies that proof across the full attack surface.
- Continuous, automated validation creates a defensible audit trail, reducing manual triage and showing auditors that remediation decisions are risk‑based.
- Mapping host‑level exploit validation to your control framework closes the evidence gap that many organizations face when proving “risk‑based remediation” to auditors.
Who Is Affected — Enterprises that rely on vulnerability‑management programs, especially SaaS, cloud‑infrastructure and technology service providers that must meet SOC 2 or similar audit regimes.
Recommended Actions
- Add Qualys Cloud Agent‑based TruConfirm to your vulnerability‑management workflow.
- Map the validation results to SOC 2 CC6.1 (Vulnerability Management) and CC7.1 (Risk Management) controls, retaining the proof‑of‑exploit reports as audit evidence.
- Periodically review coverage reports to ensure new CVE classes (kernel, client‑side, post‑auth) are included in your risk assessments.
Source: Qualys Blog – TruConfirm Cloud Agent Exploit Validation
Technical Notes
- The new engine runs on the Qualys Cloud Agent already deployed on hosts, leveraging the same payload library used by network‑based TruConfirm.
- Coverage now includes >1,800 CVEs, with more added as the Qualys Threat Research Unit releases new exploit payloads.
- Validation is performed safely without triggering the vulnerability, providing a “proof‑of‑exploit” result for each finding.
Source: same as above