Web Application Scanning (WAS) by Qualys is a cloud-based security scanning solution that automates the discovery, scanning, and detection of web applications, APIs, and vulnerabilities across cloud-native and on-premises environments. The solution performs automated scanning in CI/CD environments with shift-left DAST (Dynamic Application Security Testing) capabilities to identify vulnerabilities, misconfigurations, PII exposures, and OWASP risks across web environments. It enables security testing during development, QA, and production phases across internal and external networks, including applications on open HTTP ports, cloud, mobile, and IoT environments. The solution reduces attack surface and risk for modern web applications and APIs through comprehensive discovery, vulnerability detection, and remediation capabilities, while detecting runtime vulnerabilities, OWASP Top 10, OWASP API Top 10, sensitive data exposures, web malware, compliance issues, and deviations from OpenAPI specifications through automated end-to-end crawling and testing.