Skip to main content
Vulnerability Management (VM)

Qualys

Import Qualys hosts and vulnerability detections into Guard over the API or from a VMDR CSV export.

The Qualys integration imports hosts and vulnerabilities from Qualys VMDR into the Praetorian Guard Platform (PGP). The same connection also imports web application findings from Qualys WAS; see Qualys WAS Integration.

PGP offers two methods for importing Qualys data:

  1. API integration -- PGP connects to Qualys and syncs data on a schedule.
  2. CSV import -- You upload a vulnerability export from Qualys.

API Integration

Create a Qualys user

Ask a Qualys administrator to create a dedicated user for PGP from the Users page in Qualys. The new user receives an activation email; click Activate Your Account and enter the one-time password. You then have the API server URL, username, and password that PGP needs.

Connect Qualys to PGP

  1. In PGP, go to Integrations > Vulnerability Management > Qualys.
  2. Enter:
    • Qualys API Server URL -- for example https://qualysapi.qualys.com. Use the Identify your Qualys platform link in the dialog to find the URL for your platform.
    • Username
    • Password
  3. Choose what to import:
    • Import Assets (on by default)
    • Import Vulnerabilities (on by default)
    • Import Cloud Agent Assets (off by default) -- also imports hosts tracked by the Qualys Cloud Agent.
  4. Click Connect. PGP checks the credentials by listing scheduled scans (or, if that fails, WAS web applications) before saving.

What the API integration imports

  • Scope -- PGP builds its scope from the targets of your active scheduled scans in Qualys. With Import Assets on, it adds the targets of finished scans launched recently. Hosts outside that scope are skipped, except Cloud Agent hosts when Import Cloud Agent Assets is on.
  • Hosts -- PGP imports in-scope hosts that Qualys has scanned within the sync window: the past 90 days on the first sync, and since the previous sync (at least 24 hours) after that. Each host becomes an asset named by its FQDN, or by its IP address when there is no FQDN.
  • Ports -- A detection with a port creates a TCP port on the asset.
  • Vulnerabilities -- Each detection becomes a risk in triage. The Qualys knowledge base supplies the title, description, impact, and recommendation. Proof includes the QID, port, CVSS vector and scores, CVE references, and the Qualys detection results.

Severity mapping

When a vulnerability has a CVSS vector, PGP sets severity from the CVSS temporal score, or the base score when there is no temporal score. Otherwise it maps the Qualys severity level: 1 is Info, 2 is Low, 3 is Medium, 4 is High, and 5 is Critical.

CSV Import

  1. In Qualys, go to VMDR > Vulnerabilities and click the download icon. Download the export with the default settings.
  2. In PGP, go to Vulnerabilities and click Import.
  3. Select Qualys and upload the .csv file.

The CSV must include a CVE column. For each row, PGP:

  • Creates an asset from the Asset Name column and the Asset IPv4 column (or Asset IPv6 when there is no IPv4 address).
  • Creates a port when the row has Protocol and Port values.
  • Creates a risk in triage named by the CVE value, or by Title when the CVE is empty. Severity comes from the first letter of CVSS Rating Labels (for example, High becomes High), and is Info when that column is empty.
  • Attaches the Results value as proof.

If you need help with this integration, contact support@praetorian.com.

Still need help? Ask the team