Qualys Vulnerability Scan Flags Default Credentials Findings

Flags Qualys vulnerability scan results that indicate potential default credential usage on scanned hosts.

FreeUnreviewedSigmamediumv1
title: Qualys Vulnerability Scan Flags Default Credentials Findings
id: c2d05bc8-975f-4555-a37a-955556e96d5d
status: experimental
description: This rule identifies Qualys vulnerability management scans that return specific vulnerability check IDs associated with default credential usage. Default credentials can enable rapid initial access if accounts were not changed from vendor or factory defaults. The detection relies on Qualys host scan telemetry for the matched vulnerability identifiers reported by vulnerability scans.
references:
  - https://www.cisecurity.org/controls/cis-controls-list/
  - https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf
  - https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
  - https://community.qualys.com/docs/DOC-6406-reporting-toolbox-focused-search-lists
  - https://github.com/SigmaHQ/sigma/blob/master/rules-compliance/product/qualys/qualys_default_credentials_usage.yml
author: Alexandr Yampolskyi, SOC Prime, Huntrule Team
date: 2019-03-26
modified: 2025-11-01
tags:
  - attack.initial-access
logsource:
  product: qualys
detection:
  selection:
    host.scan.vuln:
      - 10693
      - 11507
      - 11633
      - 11804
      - 11821
      - 11847
      - 11867
      - 11931
      - 11935
      - 11950
      - 12541
      - 12558
      - 12559
      - 12560
      - 12562
      - 12563
      - 12565
      - 12587
      - 12590
      - 12599
      - 12702
      - 12705
      - 12706
      - 12907
      - 12928
      - 12929
      - 13053
      - 13178
      - 13200
      - 13218
      - 13241
      - 13253
      - 13274
      - 13296
      - 13301
      - 13327
      - 13373
      - 13374
      - 13409
      - 13530
      - 13532
      - 20065
      - 20073
      - 20081
      - 27202
      - 27358
      - 38702
      - 38719
      - 42045
      - 42417
      - 43029
      - 43220
      - 43221
      - 43222
      - 43223
      - 43225
      - 43246
      - 43431
      - 43484
      - 86857
      - 87098
      - 87106
  condition: selection
falsepositives:
  - Unknown
level: medium
license: DRL-1.1
related:
  - id: 1a395cbc-a84a-463a-9086-ed8a70e573c7
    type: derived

What it detects

This rule identifies Qualys vulnerability management scans that return specific vulnerability check IDs associated with default credential usage. Default credentials can enable rapid initial access if accounts were not changed from vendor or factory defaults. The detection relies on Qualys host scan telemetry for the matched vulnerability identifiers reported by vulnerability scans.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.