Cloud Detection and Response

Qualys Cloud Detection and Response (CDR) protects your multi-cloud environment against active exploitation. Qualys CDR uses Deep Learning AI to provide detailed visibility into your workloads and secure them against advanced threats. When an attacker tries to compromise your network, Qualys CDR can detect in real-time:

  • scans run by the attacker
  • malicious payload transfers
  • communications to known or unknown attacker-controlled domains

Use Cases

You can use CDR to 

  • detect network activities and malicious activities on my appliances using 'Traffic Mirroring'
  • detect additional network activities using 'Flow Logs'
  • detect any malicious activities in a cloud operation using the 'CloudTrail' events

What do you want to do?

Resources

I want to detect my network and malicious activities using 'Traffic Mirroring'.

Pre-requisites

Create Deployments in TotalCloud

Deploy Qualys CDR in AWS

Deploy Traffic Mirroring on Workloads

I want to monitor my network activities using Flow Logs.

Pre-requisites

Configure Flow Logs for AWS 

Configure Flow Logs for Azure

I want to detect malicious activities in my cloud account using CloudTrail (Activity Log).

Pre-requisites

Configure GuardDuty

 

Related Topics

Prioritize Threats using TruRisk