본문으로 건너뛰기

Qualys VMDR Integration

Overview

Qualys Vulnerability Management, Detection, and Response provides continuous vulnerability assessment. KYRA MDR collects Qualys findings via the API for vulnerability management and risk-based alerting.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Qualys subscription with VMDR module
  • API credentials
  • Qualys API URL for your platform

Configuration

Configure Qualys API integration:

  1. Obtain API access credentials from your Qualys administrator
  2. Identify your Qualys API URL (e.g., https://qualysapi.qualys.com)
  3. Configure the KYRA MDR collector:
collector-config.yaml
sources:
- type: qualys
api_url: https://qualysapi.qualys.com
username: <api-username>
password: <api-password>
poll_interval: 3600s
  1. Restart the collector service

Collected Log Types

Log TypeDescriptionSecurity Use
Host DetectionsVulnerability detections per hostRisk assessment
QIDsQualys vulnerability identifiersVulnerability tracking
CompliancePolicy compliance statusCompliance monitoring
Asset InventoryDiscovered assets and attributesAsset management
Patch AvailabilityAvailable patches for findingsRemediation planning
Threat IndicatorsActive exploit and malware flagsThreat prioritization

Troubleshooting

API authentication failed: Use the correct platform URL for your region (qualysapi.qualys.com, qualysapi.qg2.apps.qualys.com, qualysapi.qualys.eu).

No detection data: Ensure vulnerability scans have been completed.

Rate limiting: Qualys enforces concurrent session limits. Set poll interval to at least 3600 seconds.

Contact kyra@seekerslab.com for support.