qualys-consulting-edition-user-guide
qualys-consulting-edition-user-guide
Verity Confidential
Copyright 2018-2019 by Qualys, Inc. All Rights Reserved.
Qualys and the Qualys logo are registered trademarks of Qualys, Inc. All other trademarks
are the property of their respective owners.
Qualys, Inc.
919 E Hillsdale Blvd
4th Floor
Foster City, CA 94404
1 (650) 801 6100
Table of Contents
Welcome to the Qualys Consulting Edition .............................................. 4
About Qualys ........................................................................................................................... 4
Contact Qualys Support.......................................................................................................... 4
3
Qualys Consulting Edition
Welcome to the Qualys Consulting Edition
About Qualys
Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of cloud-based security and
compliance solutions. The Qualys Cloud Platform and its integrated apps help businesses
simplify security operations and lower the cost of compliance by delivering critical
security intelligence on demand and automating the full spectrum of auditing,
compliance and protection for IT systems and web applications.
Founded in 1999, Qualys has established strategic partnerships with leading managed
service providers and consulting organizations including Accenture, BT, Cognizant
Technology Solutions, Deutsche Telekom, Fujitsu, HCL, HP Enterprise, IBM, Infosys, NTT,
Optiv, SecureWorks, Tata Communications, Verizon and Wipro. The company is also a
founding member of the Cloud Security Alliance (CSA). For more information, please visit
www.qualys.com.
4
Qualys Consulting Edition
Get Started
Get Started
The main addition to the Qualys Consulting Edition is the Networks feature, which is the
cornerstone of multi-tenancy within the platform. Because of this, the first step when
starting with Consulting Edition is to add a network for your clients. This feature silos
network space for your individual clients and prevents the overlapping of data for assets
which share the same IP address. Generally, this is only necessary for client engagements
in which you are performing an ongoing assessment.
The Clients Tab associates individual scan instances with the applicable client. This will
aid in keeping data organized between all your clients and is especially useful for clients
who require ad hoc or periodic scans.
Define networks
Consultants can manage overlapping IP ranges within a single Qualys subscription. Define
discrete private networks for each client to keep overlapping blocks isolated from each
other. This allows you to easily manage ongoing engagements with clients and track
trending information without confusion between environments.
Go to Assets > Networks > New > Network (Manager only), and give your network a
friendly name. Save the network. We’ll add appliances to it later.
The Global Default
Network is used to scan
assets that do not
belong to custom
networks. Want to scan
your network
perimeter? You’ll need
to choose the Global
Default Network.
5
Qualys Consulting Edition
Get Started
Add assets
You’ll need to tell us the IPs/ranges you want to scan and report on. Go to Assets > Host
Assets. From the New menu, select IP Tracked Hosts, DNS Tracked Hosts or NetBIOS
Tracked Hosts. The tracking method you choose will be assigned to the hosts being added.
Jump to the Host IPs tab. Enter the IPs you’re adding, and click Add. That’s it! The new IPs
will appear on your Host Assets list and they’ll be available for scanning.
6
Qualys Consulting Edition
Get Started
7
Qualys Consulting Edition
Get Started
Click Start Wizard and we’ll walk you through the steps.
Give your scanner a name, choose a virtualization platform, get your personalization code.
Complete the
configuration using the
virtual scanner console or
cloud platform (this is
when you’ll need the
personalization code).
8
Qualys Consulting Edition
Get Started
1- tells you the virtual scanner is ready. Now you can start internal scans! Next to this
you’ll see the busy icon is grayed out until you launch a scan using this scanner.
2 - This shows you it’s a virtual appliance.
3 - Latest software versions - these are installed as part of the activation.
4 - The available capacity will be 100% until you launch a scan.
Good to Know
- The scanner appliances you assign to the network will be used to scan the IP addresses in
the network.
9
Qualys Consulting Edition
Get Started
- Each scanner appliance can be included in only one network. That means when you add
a scanner appliance to a network, it will be removed from its previous network and any
asset groups that it belonged to, if applicable.
- Be sure the scanner appliances you add to the network will be able to phone home to the
Qualys Cloud Platform and can access the IP addresses that you will be scanning.
10
Qualys Consulting Edition
Get Started
Run/Schedule scans
Go to Scans > Scans > New Scan. (Want to schedule your scan?)
11
Qualys Consulting Edition
Get Started
(1) Client - Choose the client you want to scan. Click Create to add a client at this time.
You’ll provide client information like name, email and company address.
(2) Option Profile - You can select one of the default profiles provided or a custom profile
that you previously saved.
(3) Network - Choose the network you want to scan. You can scan one network at a time. If
you didn’t set up networks then you won’t see this option.
(4) Scanner Appliance - If you added a virtual scanner then you can choose the scanner for
an internal scan. If you don’t have a scanner, we’ll use external scanners for a perimeter
scan.
(5) Scan Target - Click Assets to select a combination of asset groups and IP addresses to
scan. Or Click Tags to select one or more asset tags to scan.
That’s it - just click Launch and you’re done.
You’ll see your scan in the scans list where you can track its progress.
12
Qualys Consulting Edition
Get Started
means the scan is finished but the results are not processed. Go to Filters > Processing
Tasks to see the status.
Go to the Notifications tab if you want to be notified by email before the scan starts or
when it’s finished. You can even customize the message included in the email body.
Note - You are the task
owner. Notifications will
be sent to the email
address saved in your
account.
13
Qualys Consulting Edition
Get Started
Hit Save to save your scheduled scan. It will appear on the Schedules list. When the scan
starts running (at its next scheduled launch time) you’ll see it on the Scans list where you
can track the status and view results when it’s finished.
14
Qualys Consulting Edition
Get Started
PCAP Scans
With a PCAP Scan you’ll get vulnerability scan results plus a PCAP (Packet Capture) file
that contains all TCP network traffic captured between the scanner and the target host.
Good to Know
- The PCAP Scanning feature must be enabled for your account. Please contact your
Technical Account Manager or Support to get it.
- A scanner appliance (physical or virtual) is required.
- You can scan one IP address at a time.
- The PCAP file will be available for 7 days. You’ll need a PCAP Viewer to read file contents.
Give your scan a name, select a client, select an option profile, and choose a scanner
appliance. Then tell us the host you want to scan (a single IP) and click Launch.
15
Qualys Consulting Edition
Get Started
Enter one or more domains and netblocks (see the help for proper formatting). Click Add.
Qualys provides a demo domain called “qualys-test.com” for network mapping. This
domain may already be in your account. If not you can add it yourself. Note that the
devices in the demo domain reside in Qualys Security Operations Centers, so the Qualys
Internet scanners can be used for mapping this domain.
16
Qualys Consulting Edition
Get Started
Option Profile - Choose an option profile with the map settings you want to use. Tip - For
mapping IPs/ranges without a domain, be sure to enable the map option “Perform live
host sweep” in the option profile applied to the task.
Target Domains - Specify any combination of asset groups, domains and IPs/ranges for
your map target. Enter asset groups in the Asset Groups field, and enter domains and IPs
in the Domains/Netblocks field.
We’ll create a separate map report for each target. That means we’ll create a separate
map for each domain plus a map for any IPs entered. These maps will run sequentially -
one at a time - and each map will use a single scanner appliance.
When the map status is Finished, choose View Report from the Quick Actions menu.
17
Qualys Consulting Edition
Get Started
In the Results section you’ll see a list of the hosts detected on the mapped domain. For
each host, you’ll see the IP address, DNS and NetBIOS hostnames, the router being used by
the host and the operating system.
18
Qualys Consulting Edition
Get Started
Your map results will appear in a graphical view like shown below. Use the Summary on
the left to drill-down into results or enter a search query at the top of the page.
19
Qualys Consulting Edition
Deploy Cloud Agents
Overview
With Qualys Cloud Agent you’ll get continuous network security updates through the
cloud. As soon as changes are discovered on your hosts they’ll be assessed and you’ll
know about new security threats right away. All you have to do is install lightweight
agents on your hosts - we’ll help you do this quickly!
Install lightweight agents in minutes on your IT assets. These can be installed on your
on-premise systems, dynamic cloud environments and mobile endpoints. Agents are
centrally managed by the cloud agent platform and are self-updating (no reboot needed).
Scanning in the Cloud We’ll start syncing asset data to the cloud agent platform once
agents are installed. Agents continuously collect metadata, beam it to the cloud agent
platform where full assessments occur right away. Since the heavy lifting is done in the
cloud the agent needs minimal footprint and processing on target systems.
Stay updated with network security Scanning in the cloud uses the same signatures
(vulnerabilities, compliance datapoints) as traditional scanning with Qualys scanners.
You’ll get informed right away about new security threats using your Qualys Cloud
Platform applications - Vulnerability Management (VM), Policy Compliance (PC),
Continuous Monitoring (CM), AssetView (AV) and more!
20
Qualys Consulting Edition
Deploy Cloud Agents
- To install Windows Agent you must have local administrator privileges on your hosts.
Proxy configuration is supported
- To install Linux Agent, Unix Agent, Mac Agent you must have root privileges, non-root
with Sudo root delegation, or non-root with sufficient privileges (VM scan only). Proxy
configuration is supported.
Get Started
Select the Cloud Agent app from the app picker.
Check out the Quick Start Guide (you can go to user name menu and select this option
anytime). You’ll see step by step instructions with links to the right places to take actions.
21
Qualys Consulting Edition
Deploy Cloud Agents
We recommend you create different keys for different clients. Give your key a name (e.g.
Client A) and assign the key an asset tag (e.g. Client A). We’ll automatically add the same
tag to the agents installed using that key.
Did you know? We’ve defined certain tags for you. You’ll have one asset tag for each asset
group in your account. That means if you created asset groups for your clients (Client A,
Client B, etc.) then you already have asset tags for your clients.
Next, provision the key for the VM application. If you have additional apps like PC, FIM and
IOC then you’ll see them listed as well. Click Generate.
22
Qualys Consulting Edition
Deploy Cloud Agents
Review requirements and click Install Instructions for the target agent host.
You’ll download the agent installer and run it on your hosts. To run the installer you just
copy and paste the command shown - it’s that simple.
Run the installer on each
host from an elevated
command prompt, or use
group policy or a systems
management tool.
Our installation guides will
help you with additional
options like setting up proxy
support, and more.
Installation Guides:
Windows Agent
Linux Agent
Unix Agent
Mac Agent
23
Qualys Consulting Edition
Deploy Cloud Agents
In the Tag Creation wizard, enter the settings for your tag. You’ll give the tag a name and
configure a tag rule. The rule is used to evaluate asset data returned by scans. When asset
data matches a tag rule we’ll automatically add the tag to the asset.
24
Qualys Consulting Edition
Analyze, Query & Report
Go to the Assets tab. This is where you’ll see an inventory of all your scanned assets.
Start typing in the search field and you’ll see a list of asset properties (tokens) you can use
to search. Hover over the token name to see syntax help to the right.
25
Qualys Consulting Edition
Analyze, Query & Report
Save Query
Easily save your searches for reuse and share them with others.
26
Qualys Consulting Edition
Analyze, Query & Report
Create widget
You can create a widget based on your query and add it to your dashboard. First search for
assets and then choose Create widget. Add a title, you’ll see your query is populated for
you, just one click to add to your dashboard.
27
Qualys Consulting Edition
Analyze, Query & Report
Create Reports
There are several reporting options available. Different reports provide different views of
client data.
Consultant Reports
Create reports specific to your clients’ needs. You can add a custom cover page to your
report to include client and consultant contact information plus a summary.
To get started, you’ll need to create a consultant report template. Go to Reports >
Templates > New > Consultant Template. See the help for help with template settings.
28
Qualys Consulting Edition
Analyze, Query & Report
Choose the report template you created, a report format, and the client.
Tip - By running the report
in DOCX format you can
edit the report to focus on
the details most important
to each of your clients.
Click Next. You’ll be prompted to choose client scan results to include in the report, then
click Run. Your report will run in a new window.
29
Qualys Consulting Edition
Analyze, Query & Report
Choose a report template and pick a report format. If you configured client networks then
choose the network you want to report on and your report target. Then click Run.
30
Qualys Consulting Edition
Analyze, Query & Report
When the SSL Labs Grade feature is enabled for your subscription, you’ll see a grade (A+,
A, A-, B, C, D, E, F, T, M, NA) for each certificate on your certificates list. Grades are updated
automatically each time new vulnerability scan results are processed for your hosts.
31
Qualys Consulting Edition
PCI Compliance
PCI Compliance
32
Qualys Consulting Edition
PCI Compliance
In your report you’ll see the PCI compliance status (PASS or FAIL) for the overall report, for
each host and each vulnerability detected. Vulnerabilities with the FAIL status must be
fixed to pass the PCI compliance requirements. (Vulnerabilities with no PCI status are not
required for compliance, however we do recommend you fix them in severity order.) See
the online help to better understand the Qualys KnowledgeBase and severity levels.
After fixing vulnerabilities, be sure to re-scan to verify that all PCI vulnerabilities are fixed
and the overall status is PASS.
33
Qualys Consulting Edition
Wait, there’s more!
Policy Compliance
Use Qualys Policy Compliance (PC) to reduce the risk of internal and external threats
while providing proof of compliance demanded by auditors and government regulations.
Qualys Policy Compliance Getting Started Guide
Qualys API
You’ll get the Qualys API with your Consultant subscription. Run up to 25 API calls per day
(additional packages available).
Check out these API user guides
Qualys API (VM, SCA, PC) User Guide
Qualys API (VM, SCA, PC) XML/DTD Reference
34