Web App Scanning (WAS) by Qualys is a cloud-based web application security scanning solution that provides automated end-to-end crawling and testing capabilities in CI/CD environments with shift-left DAST (Dynamic Application Security Testing) testing. The solution performs deep scans to identify vulnerabilities, misconfigurations, OWASP Top 10 risks, OWASP API Top 10 risks, CISA Known Exploited Vulnerabilities, SQL injection, Cross-Site Scripting (XSS), and runtime risks in APIs across cloud-native and on-premises infrastructure, including SOAP and REST-based APIs. It conducts continuous monitoring of internal and external-facing web applications deployed across on-premises, cloud, mobile, and IoT systems. The solution integrates with DevOps, Agile, and Continuous Delivery processes to identify security issues throughout development, QA, and production phases. It reduces attack surface and risk by identifying official, unofficial, and forgotten applications and APIs, and includes PII exposure detection and web malware detection for compliance with regulations like GDPR, HIPAA, and PCI DSS.