Qualys Web Application Scanning (WAS) is a cloud-based web application security testing solution that automates the detection of vulnerabilities and misconfigurations in web applications and APIs. The solution performs dynamic application security testing (DAST) in CI/CD environments with shift-left testing capabilities, operating across perimeter networks, internal networks, remote devices, mobile endpoints, and public cloud instances. It detects runtime vulnerabilities, OWASP Top 10, OWASP API Top 10, misconfigurations, PII exposures, sensitive data exposures, web malware, compliance issues, and drift from OpenAPI (OAS v3) specifications through automated end-to-end crawling and testing. The solution supports modern development processes like DevOps, Agile, and Continuous Delivery by detecting security issues throughout development, QA, and production phases.