With the Qualys Vulnerability Assessment Connector, you can ingest data from both Qualys VMDR and Qualys CSAM.
Qualys Vulnerability Management, Detection & Response (VMDR) is a comprehensive cloud-based vulnerability management solution that continuously discovers, assesses, and prioritizes vulnerabilities across hybrid IT environments. The Balbix integration with Qualys VMDR ingests asset inventories and associated vulnerability data discovered by Qualys VMDR, including risk-based prioritization through TruRisk scoring and threat intelligence feeds.
Qualys CyberSecurity Asset Management (CSAM) is an advanced cloud-based asset discovery and inventory solution that continuously identifies, catalogs, and assesses all IT assets across internal and external attack surfaces. The Balbix integration with Qualys CSAM ingests comprehensive asset inventories and associated risk factors discovered by Qualys CSAM, including hardware, software, IoT/OT devices, and external-facing assets with their security posture and business context.
VMDR Prerequisites
To configure the Balbix connector, you must have a Qualys VMDR user account with the appropriate roles and permissions. These credentials are required for completing the configuration process.
Required Role Name(s)/Permissions
Manager role with full scope
Reader role with full scope
Non-manager role with the following permissions:
Access Permission: API Access
Access Permission: GUI Access (for initial setup)
Asset Management Permission: Read Asset
Requested assets within scope
Note: The user account must have access to the "All" asset group or specific asset groups that contain the assets you want to import into Balbix.
CSAM Prerequisites
To configure the Balbix connector, you must have a Qualys CSAM user account with the appropriate roles and permissions. These credentials are required for completing the configuration process.
Required Role Name(s)/Permissions
Manager role with full scope
Custom role with the following minimum permissions:
• Access Permission: API Access
• CSAM Module Access: Read Access
• Asset Management Permission: Read Asset
• Dashboard Permission: View Dashboard (optional)
• Tagging Permission: Read Tags (if tag-based filtering is required)
Note: Users must be granted access to the CSAM application in the subscription. A Manager or user with Edit User permission can grant this access using the Administration utility.
Follow this procedure to add a Qualys Vulnerability Assessment Connector:
Module Selection
You may enable one or both of the following:
Enable VMDR: Enables vulnerability data ingestion.
Enable AM: Enables asset metadata ingestion.
Common Troubleshooting
Role Access: Double-check the user’s role permissions, as limited-access accounts are common. If the test connection is run, it will indicate that the user does not have access.
Credential Access: Verify that credentials are correct, as misconfigured values are frequent. A test connection will return “Invalid Credentials” if this is the case.
URLs: Confirm that all URLs are correct, since misconfigured URLs are common. If incorrect, a test connection will fail to retrieve any asset data.