why local account from Qualys scanner is trying to connect to ESXi host instead of connecting using domain accouny? As the authentication needs to happen using ‘Domain0\Qualys’ account and not the local accounts.
Please check what authentication is defined for the ESXi IP.
Qualys has a well defined VMware auth record to connect and scan ESX and ESXi.
Thanks for response.
We do have authentication type selected as VMware, so this is not the cause.
If you scanned the ESX/ESXi host interface and the Qualys service finds a http service, it will try to brute force it with some default creds to look for factory supplied default passwords etc. It is the nature of the scan engine but you can avoid it in many ways.
Retrieving data ...