TotalCloud Release 2.28 API
August 21, 2026
Before understanding the API release highlights, learn more about the API server URL to be used in your API requests by referring to the Know Your Qualys API Server URL section. In these API Release Notes, <qualys_base_url> is used in the sample API requests.
Get Flagged TruRisk Insights (List API)
Applicable for:
| New or Updated API | New |
| API Endpoint | /rest/v1/insights |
| Method | GET |
| DTD or XSD changes | Not Applicable |
Qualys TotalCloud offers hundreds of insights into your cloud environment, with visualization via Attack Path. With this release, you can use this new API to fetch the list of TruRisk Insights that TotalCloud has flagged, that is, insights with one or more affected resources. The response for each insight includes its title, applicable cloud platform, attack path availability, description, contributing factors, control ID (cid), and the count of impacted resources.
Input ParameterInput Parameter
| Parameter Name | Mandatory/Optional | Data Type | Description | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| filter | Optional | String | Filter the insight list using QQL. Supported filter aliases:
|
||||||||||
| pageNo | Optional | Integer | The page number to retrieve, starting at 0. Default: 0. | ||||||||||
| size | Optional | Integer | The number of insights to return per page. Default: 20. | ||||||||||
| updated | Optional | String | Restrict results to insights updated within a date range in the format ['startAt'..'endAt']. For Example, ['2026-08-10T13:37:01.076Z'..'2026-09-09T23:59:59.999Z'] |
Sample: Get flagged TruRisk InsightsSample: Get flagged TruRisk Insights
API request
curl -X 'GET' \ '<qualys_base_url>/cloudview-api/rest/v1/insights?size=20&pageNo=0' \ --header 'Authorization: Basic xxxxxxxxxxx'
Response (JSON)
{
"content": [
{
"insightTitle": "Publicly exposed VM with no encryption on attached EBS volumes",
"cloudType": [
"AWS"
],
"isAttackPathEnabled": true,
"insightDetail": "The identification of a critical exploitable vulnerability on a public VM signifies a pressing security risk, potentially leading to unauthorized access, data breaches, or system compromise. Urgent action is essential to address this threat effectively.",
"contributingFactors": [
{
"key": "EBS Encryption",
"value": "False"
},
{
"key": "Public Exposure",
"value": "True"
}
],
"Cid": 5014,
"ImpactedResources": 22
}
],
"pageable": {
"pageNumber": 0,
"pageSize": 1,
"sort": {
"sorted": false,
"empty": true,
"unsorted": true
},
"offset": 0,
"paged": true,
"unpaged": false
},
"totalPages": 21,
"totalElements": 21,
"last": false,
"number": 0,
"size": 1,
"numberOfElements": 1,
"sort": {
"sorted": false,
"empty": true,
"unsorted": true
},
"first": true,
"empty": false
}
Get Resources for a Flagged TruRisk Insight (Resource API)
Applicable for:
| New or Updated API | New |
| API Endpoint | /rest/v1/insights/{cid}/resources |
| Method | GET |
| DTD or XSD changes | Not Applicable |
Use this new public REST API to fetch the resources affected by a specific flagged TruRisk Insight, across all your supported cloud platforms. The response for each resource includes the provider, account ID, region, resource ID/UUID/name/type, service type, status, and the first and last evaluated timestamps.
Input ParameterInput Parameter
| Parameter Name | Mandatory/Optional | Data Type | Description | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cid (path parameter) | Mandatory | Integer | The cid of the flagged insight, as returned by the List API, for which to fetch affected resources. Example: /rest/v1/insights/5087/resources. |
||||||||||
| filter | Optional | String | Filter the resource list using QQL. Supports the same aliases as the List API:
|
||||||||||
| size | Optional | Integer | The number of resources to return per page. Default: 20. | ||||||||||
| marker | Optional | String | Pagination cursor. Pass the marker value from the previous response to fetch the next page of results. |
||||||||||
| updated | Optional | String | Restrict results to resources last evaluated within a date range, in the format ['startAt'..'endAt']. For Example, ['2026-08-10T13:37:01.076Z'..'2026-09-09T23:59:59.999Z']. |
API request
curl -X 'GET' \ '<qualys_base_url>/cloudview-api/rest/v1/insights/5087/resources?size=20' \ --header 'Authorization: Basic xxxxxxxxxxx'
Response (JSON)
{
"currentPageSize": 1,
"content": [
{
"provider": "AWS",
"accountId": "xxxxxxxxxxx",
"region": "ca-central-1",
"resourceId": "i-xxxxxxxxxxxxxxxxx",
"resourceUuid": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"resourceName": "ec2-instance-01",
"resourceType": "EC2_INSTANCE",
"serviceType": "EC2",
"status": "ACTIVE",
"firstEvaluated": "2025-11-21T15:45:01.000+00:00",
"lastEvaluated": "2026-08-18T17:35:02.000+00:00"
}
],
"hasNext": true,
"totalHits": 22,
"hasContent": true,
"marker": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=="
}