Qualys Web Application Scanning (WAS) is a robust cloud-based application security product that continuously discovers, detects, and catalogs web applications and APIs. The Balbix integration with Qualys WAS ingests web applications and associated vulnerabilities discovered by Qualys WAS.
Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.
Integration Summary
The table below provides information about the integration type, asset types, and data types that are fetched by the Balbix connector for Qualys WAS.
Integration Type | Fetch: An inbound API integration used to fetch web applications and their associated vulnerabilities. |
Types of Assets Fetched | Web applications. |
Types of Data Fetched | Application name, application URL application ID, application owner, vulnerabilities information, relevant timestamps (e.g., first observed, last observed), applications tags. |
Prerequisites
To configure the Balbix connector, you must first create Qualys WAS API credentials with the appropriate permissions. These credentials are required for completing the configuration process.
Required Role Name and Permissions
Manager role with full scope
Reader role with full scope
Non-manager role with the following permissions:
Access Permission: API Access
Asset Management Permission: Read Asset
Requested assets within scope
Note: The Qualys Username provided during connector configuration must be associated with one of the user roles and permissions listed above.
Permissions and Roles
To provide permissions and access to all objects in the subscription:
From the Qualys administration utility, select Users > User Management.
Click the user account, then Actions > Edit.
Go to Roles and Scopes and select the Allow user full permissions and scope option.
Enable User Access
To enable user access to the API:
From the Qualys administration utility, click User next to the logout > User Profile. The Edit User page is displayed.
From the left sidebar, click User Role, and select the API option to enable API access.
Click Save.
Create and Configure the Connector
After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Qualys WAS.
API Reference Documentation
To learn more about the Qualys WAS API, see the references listed below: