Qualys VMDR® - All-in-One Vulnerability Management, Detection, and Response

Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

Qualys VMDR® — All-in-One

Vulnerability Management, Detection,


and Response
Bringing the #1 Vulnerability Management solution
to the next level

Discover, assess, prioritize, and patch critical vulnerabilities


in real time and across your global hybrid-IT landscape
— all from a single solution.

Identify all known and unknown


assets on your global hybrid-IT
Knowing what’s active in a global hybrid-IT
environment is fundamental to security.
Automatically detect all known and unknown IT
assets everywhere for a complete, categorized
inventory enriched with details such as vendor
lifecycle information and much more.

Analyze vulnerabilities and


misconfigurations with six sigma
accuracy
Automatically detect vulnerabilities and critical
misconfigurations per CIS benchmarks, by asset.

Quickly focus on what's most


urgent
Using advanced correlation and machine learning,
automatically prioritize the riskiest vulnerabilities
on the most critical assets, reducing thousands of
VMDR with Built-in vulnerabilities to the few hundred that matter.

Orchestration Inoculate your assets from the


most critical threats
With the push of a button, deploy the most
relevant, superseding patch to quickly
remediate vulnerabilities and threats across any
size environment.
Today's processes involve different teams, using
multiple point solutions — significantly adding
complexity and time to the critical patching process.
Traditional endpoint solutions don't interface well with each other, creating integration headaches, false positives,
and delays. Ultimately, devices are left unidentified, critical assets are misclassified, vulnerabilities are poorly
prioritized, and patches don't get fully applied.

A single app for discovery, assessment,


detection and response.
The Qualys Cloud Platform, combined with its powerful vulnerabilities and applies the latest threat intel analysis
lightweight Cloud Agents, Virtual Scanners, and Network to prioritize actively exploitable vulnerabilities. Finally,
Analysis (passive scanning) capabilities bring together all VMDR automatically detects the latest superseding patch
four key elements of an effective vulnerability for the vulnerable asset and easily deploys it for
management program into a single app unified by remediation.
powerful out-of-the-box orchestration workflows. Qualys
VMDR® enables organizations to automatically discover Built-in Orchestration
every asset in their environment, including unmanaged By delivering all this in a single app workflow, VMDR
assets appearing on the network, inventory all hardware automates the entire process and significantly accelerates
and software, and classify and tag critical assets. VMDR an organization’s ability to respond to threats, thus
continuously asseses these assets for the latest preventing possible exploitation.

Key Benefits
1 2 3 4
It's all in the cloud ASSET MANAGEMENT VULNERABILITY MANAGEMENT THREAT PRIORITIZATON PATCH MANAGEMENT

No need for bulky appliances. Everything is Automated asset Real-time vulnerability Automated remediation Patching and remediation Confirm and repeat
in the cloud and ready to run. identification and and misconfiguration prioritization at your fingertips VMDR closes the loop and completes
the vulnerability management lifecycle
categorization detection VMDR uses real-time threat After prioritizing vulnerabilities by risk,
Easy to deploy intelligence and machine learning VMDR rapidly remediates targeted
from a single pane of glass that offers
Knowing what’s active in a global VMDR enables customers to
Deployment is incredibly simple. With real-time customizable dashboards and
hybrid-IT environment is fundamental automatically detect vulnerabilities and models to automatically prioritize the vulnerabilities, across any size
unlimited virtual scanners, you can spin a widgets with built-in trending. Priced on
to security. VMDR enables customers to critical misconfigurations per CIS riskiest vulnerabilities on the most environment, by deploying the most
scanner up and be ready to go in no time. a per-asset basis and with no software
automatically discover and categorize benchmarks, broken out by asset. critical assets. Indicators such as relevant superseding patch.
to update, VMDR drastically reduces
known and unknown assets, Misconfigurations lead to breaches and Exploitable, Actively Attacked, and High Additionally, policy-based, automated
your total cost of ownership.
Includes VM continuously identify unmanaged compliance failures, creating Lateral Movement bubble up current recurring jobs keep systems up to date,
VM assets, and create automated workflows vulnerabilities on assets without vulnerabilities that are at risk while providing proactive patch management
VMDR has the same vulnerability management
to manage them effectively. common vulnerabilities and exposures machine learning models highlight for security and non-security patches.
solution that you have come to know and trust,
(CVEs). VMDR continuously identifies vulnerabilities most likely to become This significantly reduces the
as well as many other great apps.
After the data is collected, customers critical vulnerabilities and severe threats, providing multiple levels vulnerabilities the operations team has
can instantly query assets and any misconfigurations on the industry's of prioritization. to chase down as part of a remediation
Drastically reduce time attributes to get deep visibility into widest range of devices, operating cycle.
and money hardware, system configuration, systems and applications.
Using a single cloud platform organizations applications, services, network
save significant resources and the time information, and more.
required to otherwise install multiple agents,
multiple consoles and integrations.
Qualys VMDR® — All-in-One Solution

ed

n
do
lud
Inc

Ad
ASSET MANAGEMENT
Asset Discovery Detect and inventory all known and unknown assets that connect to your global hybrid-IT
environment – including, on-premises devices and applications, mobile, endpoints, clouds, containers,
OT and IoT. Includes Qualys Passive Scanning Sensors.
Asset Inventory • On-premises Device Inventory – Detect all devices and applications connected to the network
Get up-to-date real-time including servers, databases, workstations, routers, printers, IoT devices, and more.
inventory for all IT assets. • Certificate Inventory – Detect and catalog all TLS/SSL digital certificates (internal and external
facing) from any Certificate Authority.
• Cloud Inventory – Monitor users, instances, networks, storage, databases and their relationships for
a continuous inventory of resources and assets across all public cloud platforms.
• Container Inventory – Discover and track container hosts and their information – from build to runtime.
• Mobile Device Inventory – Detect and catalog Android, iOS/iPadOS devices across the enterprise,
with extensive information about the device, its configurations, and installed apps.
Asset Categorization Gather detailed information, such as an asset’s details, running services, installed software, and more.
and Normalization Eliminate the variations in product and vendor names and categorize them by product families on all assets.
Enriched Asset Get advanced, in-depth details including, hardware/software lifecycles (EOL/EOS), software license
Information auditing, commercial and open source licenses, and more.
CMDB Synchronization Bi-directionally synchronize asset information between Qualys and the ServiceNow CMDB.

VULNERABILITY MANAGEMENT
Vulnerability Continuously detect software vulnerabilities with the most comprehensive signature database, across
Management the widest range of asset categories. Qualys is the market leader in VM.
Configuration Assess, report and monitor security-related misconfiguration issues based on the Center for Internet
Assessment Security (CIS) benchmarks.
Certificate Assessment Assess your digital certificates (internal and external) and TLS configurations for certificate issues and
vulnerabilities.
Additional Assessment • Mobile Device Vulnerability & Misconfiguration Assessment – Continuously detect device, OS,
Add Ons apps, and network vulnerabilities and monitor critical mobile device configurations.
• Cloud Security Assessment – Continuously monitor and assess your PaaS/IaaS resources for
misconfigurations and non-standard deployments.
• Container Security Assessment – Scan container images and running containers in your
environment for high-severity vulnerabilities, unapproved packages and drive remediation efforts.
Includes the ability to scan in the build phase with plug-ins for CI/CD tools and registries.

THREAT DETECTION & PRIORITIZATION


Continuous Monitoring Alerts you in real time about network irregularities. Identifies threats and monitors unexpected
network changes before they turn into breaches.
Threat Protection Pinpoint your most critical threats and prioritize patching. Using real-time threat intelligence and
machine learning, take control of evolving threats, and identify what to remediate first.

RESPONSE
Patch Detection Automatically correlate vulnerabilities and patches for specific hosts, decreasing your remediation
response time. Search for CVEs and identify the latest superseding patches.
Patch Management via Speed up patch deployment by eliminating dependence on third-party patch deployment solutions
Qualys Cloud Agents using Qualys Cloud Agents.
Patch Management for Uninstall or update vulnerable apps, alert users, reset or lock devices, change passcodes, and more.
Mobile Devices
Container Runtime Secure, protect and monitor running containers in traditional host-based container and
Security Container-As-A-Service environments with granular behavioral policy enforcement.
Certificate Renewal Renew expiring certificates directly through Qualys.

VMDR also includes, UNLIMITED: Qualys Virtual Passive Scanning Sensors (for discovery), Qualys Virtual Scanners, Qualys Cloud
Agents, Qualys Container Sensors, and Qualys Virtual Cloud Agent Gateway Sensors for bandwidth optimization.

© 2021 Qualys, Inc. All rights reserved. 5/21

You might also like