Skip to main content
Skip table of contents

Qualys

Qualys is a cloud-based solution that detects vulnerabilities on all networked assets, including servers, network devices (e.g. routers, switches, firewalls, etc.), peripherals (such as IP-based printers or fax machines) and workstations.

Cloudaware CMDB and Breeze Agent support Qualys Vulnerability Scanning Service. The integration supports several distinct use cases:

  • Qualys as datasource

  • Qualys Breeze plugin

    • Deployment

    • Floating license management

    • Software asset management

  • Qualys as a vulnerability scanning provider

    • BYOL deployment

    • Cloudaware license

Qualys As Datasource

Cloudaware is a CMDB service that supports AWS, Azure and GCE cloud providers. Cloudaware enhances CMDB inventory data using Qualys API.

For example, for every EC2, Azure and GCE instance, Cloudaware will use Qualys API to ascertain Last Scan Date of the instance in question. Using this example, CMDB users can build a report of instances that are not getting scanned at all or have not been scanned in a long time.

Here is a complete list of fields and items that Cloudaware either extracts from Qualys or calculates based on the extracted data:

  • Last Scan Date

  • Last Scan Result

  • Critical Vulnerabilities Count

  • High Vulnerabilities Count

  • Medium Vulnerabilities Count

  • Low Vulnerabilities Count

Cloudaware enhances the following CMDB object types with data from Qualys:

  • AWS EC2 Instance

  • Azure VM

  • Azure Scale Set VM

  • GCE Instance

  • Physical Server

  • VMWare Virtual Machine

In addition, complete vulnerability scan results for every asset are also downloaded into CMDB. Vulnerabilities contain all standard fields from Qualys such as CVSS Base Score, Risk, Remediation Instructions, Impact, etc.

CMDB users can now build reports using report types such as AWS EC2 Instances With Cloudaware Vulnerabilities, for example.

Key Benefits

  • Measure Scan Coverage: identify unscanned instances or instances that have not been scanned in a long time.

  • Create vulnerability reports that combine data from Qualys, data from cloud provider and other CMDB data, e.g. group critical vulnerabilities, by AWS account owner or application or combine vulnerability data filtered by cloud provider tags.

  • Establish other key KPI such as MTTR and Scan Frequency.

  • Establish complete risk profile by identifying instances with critical vulnerabilities that are also in permissive/public security groups, subnets, VPCs.

Qualys Breeze Plugin

Cloudaware Breeze is an optional agent that customers can deploy to cloud compute, virtual and on-prem instances. Cloudaware uses Breeze agent data to enhance CMDB data with operating system level, data about installed packages, patches, services, users and performance metrics.

Breeze Agent has several capabilities in regards to Qualys:

  1. Discover and interrogate Qualys agent state and version. Qualys is a supported software in Breeze’s software asset management capability. Using Breeze agent data, CMDB users can create software asset inventory reports showing which versions of Qualys are installed. In addition, Breeze catalogs the state of the Qualys agent - whether it is running or not.

  2. Install/Uninstall/Configure Qualys agent. Breeze Agent, when deployed in DevOps mode, can not only interrogate state of pre-existing Qualys agent, but to install and configure as well. If Breeze detects that agent is corrupt or missing: not starting or otherwise malfunctioning, it will perform clean reinstall of the Qualys agent to enforce desired state. Breeze supports deployment of Qualys Agent on all Breeze supported operating systems.

License Management

Breeze agent working in coordination with CMDB will manage Qualys Agent registration and de-registration processes. During registration process CMDB will furnish Breeze Agent with Qualys registration keys based on the attributes of the instance where Breeze is running, such as cloud provider account ID, VPC or application name.

When CMDB notices instances that have been terminated or stopped for over 24 hours, it will issue an asset de-registration request directly to Qualys API endpoint. Once server is restarted, Breeze will re-register Qualys agent upon boot.

Vulnerability Scanning Provider

Cloudaware offers vulnerability scanning as a service (VSaaS). When subscribing for VSaaS, Cloudaware will ensure that all infrastructure gets scanned at least once on a weekly basis. Cloudaware VSaaS supports Qualys as vulnerability scanning provider. Breeze agent will automatically deploy and perform at least one scan every 7 days.

When subscribing to VSaaS, customers can bring their own license or leverage licenses provided by Cloudaware.

Permissions and Settings

If Qualys is acting as datasource only, Reader role is sufficient. However, if Cloudaware/Breeze is managing the agent deployment along with activation and de-activation, Cloudaware user needs to be given permissions to Install/Uninstall and Activate/Deactivate agents as shown here.

Cloudaware Setup

1. Log in to your Cloudaware account → Admin.

2. Find Qualys in the list of Security integrations. Click +Add.

3. Fill out the form:

4. The green light in 'Status' means that Qualys integration has been successfully added. If there is a red light, please contact support@cloudaware.com.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.