Asset Management guide

Connect vulnerability data and review technical exposure

Configure the supported provider centrally through Admin → Integrations, review imported scanner findings, inspect evidence and connect selected technical vulnerabilities to Risk Management.

Asset Manager, Vulnerability Manager or Risk Manager Approximately 15–30 minutes for initial configuration; ongoing review thereafter Updated 3 October 2026

How the model works

PurpleWASP keeps scanner observations separate from business Risks. The integration imports Assets and technical findings into Asset Management. Risk Management references selected findings as technical evidence instead of turning every finding into a separate Risk.

Provider-neutral design: Qualys is the first implemented vulnerability provider, but the workspace groups and links findings through common PurpleWASP fields so future Tenable, Rapid7, Defender, Wiz or other providers can use the same Risk workflow.

1. Configure and run the provider integration

  1. Open Admin → Integrations.
  2. Select Qualys, save the provider connection details and run Test Connection.
  3. Activate the connection and run it manually or allow the configured schedule to queue work.
  4. Review run history and runtime health before relying on imported findings.

Provider credentials, jobs and scheduling are owned by the shared Integration Management service. The web request only queues the work; the background worker performs the provider API call. Asset Management owns the resulting vulnerability-domain records, matching and technical-exposure lifecycle.

Credentials are operational secrets. Keep integration credentials encrypted and keep production TLS verification enabled.

2. Review the Asset Vulnerabilities workspace

Open an Asset and select Vulnerabilities. PurpleWASP groups related observations by the provider/source vulnerability identity so one QID or plugin does not appear as dozens of unrelated Risk items simply because it was observed on several ports.

Use status, severity, search and Risk-link filters to focus the list. Summary cards show active findings, Critical/High exposure, vulnerability groups and groups already linked to Risks.

3. Open Finding Details before making a Risk decision

Select Details on a vulnerability group or finding. The detail view combines the provider vulnerability definition with the observation on this Asset where the data is available.

DefinitionProvider title, description, CVEs, category, consequence, remediation and scoring context.
ObservationAsset/host, IP, port, protocol, service, first/last seen, occurrence count and scanner evidence.
HistoryOpen, resolved, reopened or suppressed lifecycle evidence retained by the integration.

Scanner output is rendered as evidence text rather than executable HTML.

4. Link selected technical evidence to a Risk

  1. Select one or more vulnerability groups.
  2. Choose Link selected to risk.
  3. Select an active Risk for the same Asset. A completed assessment may still accept new live evidence for the next reassessment.
  4. If no suitable Risk exists, choose Create risk from selected and complete the normal Risk creation workflow.

The link does not alter or delete the underlying Asset finding. It creates traceability from the Risk back to the observed evidence.

5. Understand the finding lifecycle

Resolved findings remain evidence. If the provider later reports the same issue as reopened, PurpleWASP can show the current technical state while completed Risk assessments retain their historical snapshots. Resolving every linked finding does not automatically close the business Risk.

Common problems

The Asset has no findings

Confirm the integration is active, a successful run has completed, the imported integration Asset is mapped to the PurpleWASP Asset and the provider returned detections for that host.

A QID has no mapped CVE

This can be valid. Configuration, information-disclosure and product-specific findings do not always have a CVE. Use the provider definition and observation evidence rather than treating the absence of a CVE as an invalid finding.

The existing Risk does not appear in the link dialog

Archived, closed or pending-exception Risks may not be linkable. A completed but still-active Risk can accept evidence for the next reassessment.