Qualys Vulnerability Management, Detection & Response (VMDR) enables vulnerability assessment and management for hybrid technology environments across IT, OT, and IoT. Qualys also offers Security Configuration Assessment (SCA), an optional add-on, that remediates security-related configuration issues based on the Center for Internet Security (CIS) Benchmarks. The Balbix integration with Qualys VMDR ingests on-premises and cloud infrastructure assets, associated vulnerabilities, software entities, configured operational and business information, and controls assessment information (when configured).
Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.
Integration Summary
The table below provides information about the integration type, asset types, and data types that are fetched by the Balbix connector for Qualys VMDR.
Integration Type | Fetch: An inbound API integration used to fetch assets, vulnerabilities, control assessment information, and related metadata such as tags. |
Types of Assets Fetched | Infrastructure devices such as servers, virtual machines, desktops, laptops, networking, IoT. |
Types of Data Fetched | Asset names, hardware information, processor information, open port information, location information, interface information (MAC address, IP address), OS information, BIOS information, tags (flat and hierarchical), software information, system status, vulnerability information, relevant timestamps (e.g., first observed, last observed), control assessment findings. |
Note: Availability of specific fields, such as OS details, may depend on the Qualys VMDR implementation and whether a Qualys host-based agent has been deployed.
Prerequisites
To configure the Balbix connector, you must first create Qualys VMDR API credentials with the appropriate permissions. These credentials are required for completing the configuration process.
Required Role Name(s)/Permissions
Manager role with full scope
Reader role with full scope
Non-manager role with the following permissions:
Access Permission: API Access
Asset Management Permission: Read Asset
Requested assets within scope
Auth Permissions and Roles
To provide permissions and access to all objects in the subscription:
From the Qualys administration utility, select Users > User Management.
Click the user account, then Actions > Edit.
Go to Roles and Scopes and select the Allow user full permissions and scope option.
Enable User Access
To enable user access to the API:
From the Qualys administration utility, click User > User Profile. The Edit User page will display.
From the left navigation sidebar, click User Role, and select the API option.
Click Save.
Create and Configure the Connector
After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Qualys VMDR.
Step 1: Select the Connector
Start by selecting a connector using the steps outlined below:
Go to Data Sources from the left navigation bar.
In the Connectors table, click + Add Connector.
Click Select a Connector to Configure to expand the window and view the list of available connectors.
Click the + icon on the Qualys VMDR tile.
Choose API as the Integration Option, then click Next to configure the connector.
Step 2: Configure the Connector
Configure the connector using the steps outlined below.
Fill in the required configuration fields.
.png)
.png)
Instance Name
.png)
Qualys VMDR Inventory Base URL
Enter the base API URL of the server where asset information will be fetched (e.g., https://qualysapi.qualys.com). Make sure the authorized user for this account has the necessary privileges to access the API.
.png)
Qualys VMDR Vulnerability Base URL
Enter the base API URL of the server where vulnerability information will be fetched. Make sure the authorized user for this account has the necessary privileges to access the API.
.png)
Qualys Username
Enter the username for the user account with the necessary permissions to fetch assets and vulnerabilities.
.png)
Qualys Password
Enter the password for the user account with the necessary permissions to fetch assets and vulnerabilities.
.png)
Qualys API Filter
.png)
Asset Last Seen Days Filter
.png)
Enable Hierarchical Tags
Select this option to fetch Qualys tags via the hierarchical structure.
Click Test Connection.
Step 3: Schedule the Connector
Step 4: Review Connector Details
API Reference Documentation
To learn more about the Qualys VMDR API, see the references listed below: