cf-qualys-scanner
cf-qualys-scanner is a cloud-based web application security scanner that provides automated crawling and vulnerability testing to identify security flaws including XSS, SQL injection, and OWASP Top 10 vulnerabilities.
At a glance
- Operator: Qualys
- Type: Security
How Centinel checks it
- User agent: The request calls itself this crawler. Anyone can send the same string.
cf-qualys-scanner publishes nothing Centinel can check a source against, so a match reports the name and leaves the source unconfirmed. The match tokens, verification domains, and address feeds are not published here.
Allowing or blocking it
The crawler object in the /validate response sets access_allowed to true only for a verified source that your tenant allowlists. A policy rule can allow or block this crawler by its category, Security.