Qualys Solutions¶
Cyderes supports the ingestion of alerts pulled from Qualys Search API within the Qualys Continuous Monitoring Solution as well as host vulnerability detections from the Qualys Vulnerability Management API within the Qualys Vulnerability Management Solution. Qualys is a provider of cloud-based security and compliance solutions. For more information about Qualys, visit the Qualys Continuous Monitoring website or Qualys Vulnerability Management website.
Chronicle Data Types¶
- QUALYS_CONTINUOUS_MONITORING
- QUALYS_VM
Caveats / Known Limitations¶
The username and password must be from a Qualys user with API access to the corresponding API that is expected to be pulled.
Requirements¶
A Qualys account is required to complete this integration. To determine how to create a Qualys account, click here.
Configuration¶
Continuous Monitoring Alerts¶
Create rules for alerts desired. Follow this Qualys Guide to create rules.
Vulnerability Management Detections¶
Hosts that either run the qualys agent or are scanned by scanners from within the cloud vulnerability management service. Follow this Qualys Guide to manage hosts.
Gather Information¶
Provide the following information to Cyderes to complete implementation:
- What Qualys solution to ingest data for
- Username & Password (see Caveats section)
- Qualys Domain where a tenant lives