Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Qualys Web Application Scanning Connector Guide

Prev Next

Qualys Web Application Scanning (WAS) is a robust cloud-based application security product that continuously discovers, detects, and catalogs web applications and APIs. The Balbix integration with Qualys WAS ingests web applications and associated vulnerabilities discovered by Qualys WAS.

Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.

Integration Summary

The table below provides information about the integration type, asset types, and data types that are fetched by the Balbix connector for Qualys WAS.

Integration Type

Fetch: An inbound API integration used to fetch web applications and their associated vulnerabilities.

Types of Assets Fetched

Web applications.

Types of Data Fetched

Application name, application URL application ID, application owner, vulnerabilities information, relevant timestamps (e.g., first observed, last observed), applications tags.

Prerequisites

To configure the Balbix connector, you must first create Qualys WAS API credentials with the appropriate permissions. These credentials are required for completing the configuration process.

Required Role Name and Permissions

  • Manager role with full scope

  • Reader role with full scope

  • Non-manager role with the following permissions:

    • Access Permission: API Access

    • Asset Management Permission: Read Asset

    • Requested assets within scope

Note: The Qualys Username provided during connector configuration must be associated with one of the user roles and permissions listed above.

Permissions and Roles

To provide permissions and access to all objects in the subscription:

  1. From the Qualys administration utility, select Users > User Management.

  2. Click the user account, then Actions > Edit.

  3. Go to Roles and Scopes and select the Allow user full permissions and scope option.

Enable User Access

To enable user access to the API:

  1. From the Qualys administration utility, click User next to the logout > User Profile. The Edit User page is displayed.

  2. From the left sidebar, click User Role, and select the API option to enable API access.

  3. Click Save.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Qualys WAS.

API Reference Documentation

To learn more about the Qualys WAS API, see the references listed below: