Integrate Cloud Detection and Response (CDR)
By integrating CDR with AWS S3, you can gain near-real-time, up-to-date visibility into your threat posture and suspicious network activity in the AWS S3 console. These findings, gained by correlating Qualys information with other data in AWS S3, allow you to take rapid, remedial actions.
Prerequisites
The following are the prerequisites to integrate the Qualys Cloud Detection and Response application with AWS S3:
- You must have a storage account with the necessary permissions.
- The CIPS service must be enabled for your subscription. Qualys Support enables it for your account. Contact the Qualys Support team for the integration process.
- Qualys applications: You must have enabled Cloud Detection and Response (CDR) and Cloud Agent (CA) for your subscription.
- Permissions: The API Access permission must be enabled for your account.
- Role: You must have the Manager or Unit Manager role.
- Platform version: You must be on Enterprise TruRisk Platform Version QWEB-10.21.1.0 or later.
Onboarding APIs
The Qualys Support helps you integrate AWS S3 with the Qualys Could Platform.
If you do not have a CDR product created for your subscription, you can start by calling the product APIs. If you already have a CDR product running, you can start with CDR Integration APIs below.
CDR Product APIs
The following APIs are used for creating and managing the CDR product:
|
API |
URL |
Operator |
Description |
|---|---|---|---|
|
/partner- integration/product |
POST |
Creates a new CDR product. |
|
|
/partner- integration/product/CDR |
GET |
Gets the details of the created CDR product. |
|
|
/partner- integration/product/CDR |
DELETE |
Delete the CDR product. |
CDR Integration APIs
The following APIs are used for integration the CDR product with AWS S3:
| API | URL | Operator | Description |
|---|---|---|---|
| Create Integration | /partner-integration/product-id/integration | POST | Creates a new integration with AWS S3 |
| /partner-integration/product-id/integration | PUT | Update the integration with AWS S3 | |
| /partner-integration/product-id/integration | GET | Get details of the integration with AWS S3 | |
| /partner-integration/product-id/integration | PATCH | Validate the integration with AWS S3 | |
| /partner-integration/product-id/integration | DELETE | Delete the integration with AWS S3 |