Get Started with CDR Webhook
Qualys Cloud Detection and Response (CDR) now supports Webhook-based integration to deliver runtime security events directly to customer-managed SIEM and SOC platforms.
A webhook is an automated, event-driven HTTP push mechanism that sends real-time data from one application to another when a specific event occurs.
Qualys Cloud Detection and Response (CDR) is a key feature belonging to the Qualys TotalCloud application. CDR helps you to monitor your network traffic in real-time to identify key security threats and suspicious activity.
Using the Webhook integration, customers can stream malicious file and network runtime events generated by TC CDR to external security analytics platforms in near real time. This enables centralized monitoring, correlation with other security signals, and faster incident response across hybrid and multi-cloud environments.
By integrating TC CDR runtime events with SIEM and SOC tools through Webhooks, security teams gain continuous visibility into threat activity and can take timely remedial actions using their existing security operations workflows.
Prerequisites
The following prerequisites must be met for integrating Qualys CDR:
-
Ensure that you accept all the Qualys Terms and Conditions and contact the Qualys Support team for the integration process.
You can access integration API only after accepting Terms and Conditions provided by Qualys.
- Qualys Applications: Cloud Detection and Response (CDR)
- Ensure API Access permission is enabled for the user account.
- Manager or Unit Manager role.
Get Started
Quick Steps: Integrating CDR with Qualys
The following is the user flow for integrating Qualys CDR.
Additional Resources
You might already be familiar with Qualys Cloud Suite, its features, and user interface. If you are new to Qualys, we recommend below given overview tutorials.
From the Community
Qualys Training | Free self paced classes, video series, online classes
Qualys Documentation | Getting started guides, quick references, API docs