TotalCloud Release 2.28 API

August 21, 2026

Before understanding the API release highlights, learn more about the API server URL to be used in your API requests by referring to the Know Your Qualys API Server URL section. In these API Release Notes, <qualys_base_url> is used in the sample API requests.

Get Flagged TruRisk Insights (List API)

Applicable for:  aws azure oci gcp

New or Updated API New
API Endpoint /rest/v1/insights
Method GET
DTD or XSD changes Not Applicable

Qualys TotalCloud offers hundreds of insights into your cloud environment, with visualization via Attack Path. With this release, you can use this new API to fetch the list of TruRisk Insights that TotalCloud has flagged, that is, insights with one or more affected resources. The response for each insight includes its title, applicable cloud platform, attack path availability, description, contributing factors, control ID (cid), and the count of impacted resources.

Input ParameterInput Parameter

Parameter Name Mandatory/Optional Data Type Description
filter Optional String Filter the insight list using QQL. Supported filter aliases:
Alias Internal QQL Field
provider cloud.provider
accountId cloud.id
resourceId cloud.resource.id
qualysTag connector.tag.name
All tokens currently supported in the TotalCloud UI are also supported as filters in this API. Cloud tags are not currently supported as a filter.
pageNo Optional Integer The page number to retrieve, starting at 0. Default: 0.
size Optional Integer The number of insights to return per page. Default: 20.
updated Optional String Restrict results to insights updated within a date range in the format ['startAt'..'endAt']. For Example, ['2026-08-10T13:37:01.076Z'..'2026-09-09T23:59:59.999Z']

Sample: Get flagged TruRisk InsightsSample: Get flagged TruRisk Insights

API request

curl -X 'GET' \
  '<qualys_base_url>/cloudview-api/rest/v1/insights?size=20&pageNo=0' \
  --header 'Authorization: Basic xxxxxxxxxxx'

Response (JSON)

{
    "content": [
        {
            "insightTitle": "Publicly exposed VM with no encryption on attached EBS volumes",
            "cloudType": [
                "AWS"
            ],
            "isAttackPathEnabled": true,
            "insightDetail": "The identification of a critical exploitable vulnerability on a public VM signifies a pressing security risk, potentially leading to unauthorized access, data breaches, or system compromise. Urgent action is essential to address this threat effectively.",
            "contributingFactors": [
                {
                    "key": "EBS Encryption",
                    "value": "False"
                },
                {
                    "key": "Public Exposure",
                    "value": "True"
                }
            ],
            "Cid": 5014,
            "ImpactedResources": 22
        }
    ],
    "pageable": {
        "pageNumber": 0,
        "pageSize": 1,
        "sort": {
            "sorted": false,
            "empty": true,
            "unsorted": true
        },
        "offset": 0,
        "paged": true,
        "unpaged": false
    },
    "totalPages": 21,
    "totalElements": 21,
    "last": false,
    "number": 0,
    "size": 1,
    "numberOfElements": 1,
    "sort": {
        "sorted": false,
        "empty": true,
        "unsorted": true
    },
    "first": true,
    "empty": false
}

Get Resources for a Flagged TruRisk Insight (Resource API)

Applicable for:  aws azure oci gcp

New or Updated API New
API Endpoint /rest/v1/insights/{cid}/resources
Method GET
DTD or XSD changes Not Applicable

Use this new public REST API to fetch the resources affected by a specific flagged TruRisk Insight, across all your supported cloud platforms. The response for each resource includes the provider, account ID, region, resource ID/UUID/name/type, service type, status, and the first and last evaluated timestamps.

Input ParameterInput Parameter

Parameter Name Mandatory/Optional Data Type Description
cid (path parameter) Mandatory Integer The cid of the flagged insight, as returned by the List API, for which to fetch affected resources. Example: /rest/v1/insights/5087/resources.
filter Optional String Filter the resource list using QQL. Supports the same aliases as the List API:
Alias Internal QQL Field
provider cloud.provider
accountId cloud.id
resourceId cloud.resource.id
qualysTag connector.tag.name
All tokens currently supported in the TotalCloud UI are also supported as filters in this API. Cloud tags are not currently supported as a filter.
size Optional Integer The number of resources to return per page. Default: 20.
marker Optional String Pagination cursor. Pass the marker value from the previous response to fetch the next page of results.
updated Optional String Restrict results to resources last evaluated within a date range, in the format ['startAt'..'endAt']. For Example, ['2026-08-10T13:37:01.076Z'..'2026-09-09T23:59:59.999Z'].

Sample: Get resources for a flagged TruRisk InsightSample: Get resources for a flagged TruRisk Insight

API request

curl -X 'GET' \
  '<qualys_base_url>/cloudview-api/rest/v1/insights/5087/resources?size=20' \
  --header 'Authorization: Basic xxxxxxxxxxx'

Response (JSON)

{
    "currentPageSize": 1,
    "content": [
        {
            "provider": "AWS",
            "accountId": "xxxxxxxxxxx",
            "region": "ca-central-1",
            "resourceId": "i-xxxxxxxxxxxxxxxxx",
            "resourceUuid": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
            "resourceName": "ec2-instance-01",
            "resourceType": "EC2_INSTANCE",
            "serviceType": "EC2",
            "status": "ACTIVE",
            "firstEvaluated": "2025-11-21T15:45:01.000+00:00",
            "lastEvaluated": "2026-08-18T17:35:02.000+00:00"
        }
    ],
    "hasNext": true,
    "totalHits": 22,
    "hasContent": true,
    "marker": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=="
}