category: Vulnerability Management provider: Qualys sectionorder: - Connect - Collect commonfields: id: QualysV2 version: -1 configuration: - defaultvalue: https://qualysguard.qg2.apps.qualys.com display: Server URL name: url required: true type: 0 additionalinfo: "When using asset-tag commands, the official documentation recommends that the SERVER URL parameter should be in the following format: `https://qualysapi..apps.qualys.com/`. For more details see the integration documentation." section: Connect - display: Username name: credentials required: true type: 9 section: Connect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect advanced: true - display: Use system proxy settings name: proxy type: 8 required: false section: Connect advanced: true - display: Fetch Vulnerabilities Behavior defaultvalue: Fetch by last modified date name: fetch_vulnerabilities_behavior options: - Fetch by last modified date - Fetch by unique QIDs of assets section: Collect advanced: true required: false type: 15 hidden: - xsoar - xpanse supportedModules: - xsiam - display: Fetch events name: isFetchEvents type: 8 section: Collect required: false hidden: - xsoar - xpanse supportedModules: - xsiam - defaultvalue: 3 days section: Collect display: Event first fetch time name: first_fetch additionalinfo: If "First event fetch time" is set for a long time ago, it may cause performance issues. required: false advanced: true type: 0 hidden: - xsoar - xpanse supportedModules: - xsiam - defaultvalue: 10000 section: Collect display: Event Fetch Limit name: max_fetch_activity_logs additionalinfo: Maximum number of events to fetch per fetch iteration. advanced: true required: false type: 0 hidden: - xsoar - xpanse supportedModules: - xsiam - defaultvalue: 1 display: Events Fetch Interval name: eventFetchInterval type: 19 section: Collect advanced: true required: false hidden: - xsoar - xpanse supportedModules: - xsiam - display: Fetch assets and vulnerabilities name: isFetchAssets type: 8 section: Collect required: false hidden: - xsoar - xpanse supportedModules: - xsiam - exposure_management - additionalinfo: The fetch interval for assets and vulnerabilities. It is recommended to set it to 24 hours. Interval lower then 1 hour is not supported. defaultvalue: 1440 display: Assets and Vulnerabilities Fetch Interval name: assetsFetchInterval type: 19 section: Collect advanced: true required: false hidden: - xsoar - xpanse supportedModules: - xsiam - exposure_management description: Qualys Vulnerability Management lets you create, run, manage reports and to fetch Activity Logs, Assets and Vulnerabilities, launch and manage vulnerability and compliance scans, and manage the host assets you want to scan for vulnerabilities and compliance. display: Qualys VMDR name: QualysV2 script: commands: - arguments: - description: Show only certain IP addresses/ranges. name: ips - description: Restrict the request to a certain custom network ID. name: network_id - auto: PREDEFINED description: Show only IP addresses/ranges which have a certain tracking method. name: tracking_method predefined: - IP - DNS - NETBIOS - auto: PREDEFINED description: Specify 1 to list compliance IP addresses in the user’s account. These hosts are assigned to the policy compliance module. Specify 0 to get host that are not assigned to the policy compliance module. name: compliance_enabled predefined: - '0' - '1' - auto: PREDEFINED description: (Optional) Specify 1 to list IP addresses in the user’s account assigned to the Certificate View module. Specify 0 to list IP addresses that are not assigned to the Certificate View module. Note - This option will be supported when Certificate View GA is released and is enabled for your account. name: certview_enabled predefined: - '0' - '1' - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: View a list of IP addresses in the user account. name: qualys-ip-list outputs: - contextPath: Qualys.IP.Address description: IP addresses. - contextPath: Qualys.IP.Range description: IP range. - arguments: - description: Specify a report ID of a report that is saved in the Report Share storage space. name: id - auto: PREDEFINED description: Specify reports with a certain state. name: state predefined: - Running - Finished - Canceled - Errors - description: Specify a user login ID to get reports launched by the specified user login ID. name: user_login - description: Specify the date and time to get only reports that expire before it. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: expires_before_datetime - description: (Optional) Id assigned to the client (Consultant type subscriptions). name: client_id - description: (Optional) Name of the client (Consultant type subscriptions). Note, The client_id and client_name parameters are mutually exclusive and cannot be specified together in the same request. name: client_name - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: Get a list of generated reports in the system. name: qualys-report-list outputs: - contextPath: Qualys.Report.ID description: Report ID. type: String - contextPath: Qualys.Report.TITLE description: Report title. - contextPath: Qualys.Report.TYPE description: Report type. - contextPath: Qualys.Report.LAUNCH_DATETIME description: Date and time the report launched. - contextPath: Qualys.Report.OUTPUT_FORMAT description: Report output format. - contextPath: Qualys.Report.SIZE description: Report size. - contextPath: Qualys.Report.STATUS.STATE description: Report state status. - contextPath: Qualys.Report.STATUS.MESSAGE description: Report status message. - contextPath: Qualys.Report.STATUS.PERCENT description: Report status percent. - contextPath: Qualys.Report.EXPIRATION_DATETIME description: Report expiration datetime. - arguments: - description: Show only a scan with a certain scan reference code. name: scan_ref - description: Show only one or more scan states. name: state - auto: PREDEFINED description: Specify 0 to show only scans that are not processed. Specify 1 to show only scans that have been processed. name: processed predefined: - '0' - '1' - auto: PREDEFINED description: Show only a certain scan type. name: type predefined: - On-Demand - Scheduled - API - description: Show only one or more target IP addresses. name: target - description: Show only a certain user login. name: user_login - description: Show only scans launched after a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week.' name: launched_after_datetime - description: Show only scans launched before a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week.' name: launched_before_datetime - auto: PREDEFINED description: Specify 1 to show asset group information for each scan in the output. name: show_ags predefined: - '1' - auto: PREDEFINED description: Specify 1 to show option profile information for each scan in the output. name: show_op predefined: - '1' - auto: PREDEFINED description: Specify 0 to not show scan status for each scan in the output. name: show_status predefined: - '0' - auto: PREDEFINED description: Specify 1 to show only the most recent scan (which meets all other search filters in the request) in the output. name: show_last predefined: - '1' - description: (Optional) Show only a scan with a certain compliance scan ID. name: scan_id - description: (Optional) Id assigned to the client (Consultant type subscription only). Parameter client_id or client_name may be specified for the same request. name: client_id - description: (Optional) Name of the client (Consultant type subscription only). Parameter client_id or client_name may be specified for the same request. name: client_name - auto: PREDEFINED description: (Optional) Specify 1 to show only external PCI scans in the XML output. External PCI scans are vulnerability scans run with the option profile "Payment Card Industry (PCI) Options". When pci_only=1 is specified, the XML output will not include other types of scans run with other option profiles. name: pci_only predefined: - '1' - auto: PREDEFINED description: (Optional) Specify 1 to hide target information from the scan list. Specify 0 to display the target information. name: ignore_target predefined: - '1' - '0' - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: Lists vulnerability scans in the user’s account. name: qualys-vm-scan-list outputs: - contextPath: Qualys.Scan.REF description: Scan REF. - contextPath: Qualys.Scan.TYPE description: Scan type. - contextPath: Qualys.Scan.TITLE description: Scan title. - contextPath: Qualys.Scan.LAUNCH_DATETIME description: Date and time the scan launched. - contextPath: Qualys.Scan.DURATION description: Scan Duration. - contextPath: Qualys.Scan.PROCESSING_PRIORITY description: Scan Processing Priority. - contextPath: Qualys.Scan.PROCESSED description: Scan Processed. - contextPath: Qualys.Scan.STATUS.STATE description: Scan status state. - contextPath: Qualys.Scan.STATUS.SUB_STATE description: Scan status sub state. - contextPath: Qualys.Scan.SCHEDULE description: Scan Schedule. - contextPath: Qualys.Scan.TARGET description: Scan Target. - contextPath: Qualys.Scan.ASSET_GROUP_TITLE description: Target Asset Group Title. - contextPath: Qualys.Scan.DEFAULT_FLAG description: Scan Default Flag. - contextPath: Qualys.Scan.USER_LOGIN description: The user that created the scan. - arguments: - description: Show only a scan with a certain scan reference code. name: scan_ref - description: Show only one or more scan states. name: state - auto: PREDEFINED description: Specify 0 to show only scans that are not processed. Specify 1 to show only scans that have been processed. name: processed predefined: - '0' - '1' - auto: PREDEFINED description: Show only a certain scan type. name: type predefined: - On-Demand - Scheduled - API - description: Show only one or more target IP addresses. name: target - description: Show only a certain user login. name: user_login - description: Show only scans launched after a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week.' name: launched_after_datetime - description: Show only scans launched before a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week.' name: launched_before_datetime - auto: PREDEFINED description: Specify 1 to show asset group information for each scan in the output. name: show_ags predefined: - '1' - auto: PREDEFINED description: Specify 1 to show option profile information for each scan in the output. name: show_op predefined: - '1' - auto: PREDEFINED description: Specify 0 to not show scan status for each scan in the output. name: show_status predefined: - '0' - auto: PREDEFINED description: Specify 1 to show only the most recent scan (which meets all other search filters in the request) in the output. name: show_last predefined: - '1' - description: (Optional) Show only a scan with a certain compliance scan ID. name: scan_id - description: (Optional) Id assigned to the client (Consultant type subscription only). Parameter client_id or client_name may be specified for the same request. name: client_id - description: (Optional) Name of the client (Consultant type subscription only). Parameter client_id or client_name may be specified for the same request. name: client_name - auto: PREDEFINED description: (Optional) Specify 1 to show only external PCI scans in the XML output. External PCI scans are vulnerability scans run with the option profile "Payment Card Industry (PCI) Options". When pci_only=1 is specified, the XML output will not include other types of scans run with other option profiles. name: pci_only predefined: - '1' - auto: PREDEFINED description: (Optional) Specify 1 to hide target information from the scan list. Specify 0 to display the target information. name: ignore_target predefined: - '1' - '0' - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: Gives you a list of SCAP scans in your account. name: qualys-scap-scan-list outputs: - contextPath: Qualys.SCAP.Scan.ID description: Scan ID. - contextPath: Qualys.SCAP.Scan.Reference description: Scan ref. - contextPath: Qualys.SCAP.Scan.REF description: Scan REF. - contextPath: Qualys.SCAP.Scan.Type description: Scan type. - contextPath: Qualys.SCAP.Scan.Title description: Scan title. - contextPath: Qualys.SCAP.Scan.LaunchDatetime description: Date and time the scan launched. - contextPath: Qualys.SCAP.Scan.Duration description: Scan Duration. - contextPath: Qualys.SCAP.Scan.ProcessingPriority description: Scan Processing Priority. - contextPath: Qualys.SCAP.Scan.Processed description: Scan Processed. - contextPath: Qualys.SCAP.Scan.Status.State description: Scan status state. - contextPath: Qualys.SCAP.Scan.Status.SubState description: Scan status sub state. - contextPath: Qualys.SCAP.Scan.Schedule description: Scan Schedule. - contextPath: Qualys.SCAP.Scan.Target description: Scan Target. - contextPath: Qualys.SCAP.Scan.AssetGroupTitle description: Target Asset Group Title. - contextPath: Qualys.SCAP.Scan.DeafualtFlag description: Scan Default Flag. - contextPath: Qualys.SCAP.Scan.UserLogin description: The user that created the scan. - arguments: - description: Scan id. name: scan_id - description: Scan reference. name: scan_ref - description: Show only one or more scan states. name: state - auto: PREDEFINED description: Specify 0 to show only scans that are not processed. Specify 1 to show only scans that have been processed. name: processed predefined: - '0' - '1' - description: Show only a certain scan type. name: type - description: Show only one or more target IP addresses. name: target - description: Show only a certain user login. name: user_login - description: Show only scans launched after a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week.' name: launched_after_datetime - description: Show only scans launched before a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week.' name: launched_before_datetime - auto: PREDEFINED description: Specify 1 to show asset group information for each scan in the output. name: show_ags predefined: - '1' - auto: PREDEFINED description: Specify 1 to show option profile information for each scan in the output. name: show_op predefined: - '1' - auto: PREDEFINED description: Specify 0 to not show scan status for each scan in the output. name: show_status predefined: - '0' - auto: PREDEFINED description: Specify 1 to show only the most recent scan (which meets all other search filters in the request) in the output. name: show_last predefined: - '1' - auto: PREDEFINED description: Specify 1 to show only external PCI scans in the XML output. External PCI scans are vulnerability scans run with the option profile "Payment Card Industry (PCI) Options". When pci_only=1 is specified, the XML output will not include other types of scans run with other option profiles. name: pci_only predefined: - '1' - '0' - auto: PREDEFINED description: Specify 1 to hide target information from the scan list. Specify 0 to display the target information. name: ignore_target predefined: - '1' - '0' - description: (Optional) Id assigned to the client (Consultant type subscriptions). name: client_id - description: (Optional) Name of the client (Consultant type subscriptions). Note, The client_id and client_name parameters are mutually exclusive and cannot be specified together in the same request. name: client_name - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: Get a list of compliance scans in your account. name: qualys-pc-scan-list outputs: - contextPath: Qualys.Scan.REF description: Scan REF. - contextPath: Qualys.Scan.TYPE description: Scan type. - contextPath: Qualys.Scan.TITLE description: Scan title. - contextPath: Qualys.Scan.LAUNCH_DATETIME description: Date and time the scan launched. - contextPath: Qualys.Scan.DURATION description: Scan Duration. - contextPath: Qualys.Scan.PROCESSING_PRIORITY description: Scan Processing Priority. - contextPath: Qualys.Scan.PROCESSED description: Scan Processed. - contextPath: Qualys.Scan.STATUS.STATE description: Scan status state. - contextPath: Qualys.Scan.STATUS.SUB_STATE description: Scan status sub state. - contextPath: Qualys.Scan.SCHEDULE description: Scan Schedule. - contextPath: Qualys.Scan.TARGET description: Scan Target. - contextPath: Qualys.Scan.ASSET_GROUP_TITLE description: Target Asset Group Title. - contextPath: Qualys.Scan.DEFAULT_FLAG description: Scan Default Flag. - contextPath: Qualys.Scan.USER_LOGIN description: The user that created the scan. - arguments: - description: The ID of the scan schedule you want to display. name: id - auto: PREDEFINED description: Specify 1 for active schedules only, or 0 for deactivated schedules only. name: active predefined: - '0' - '1' - description: (Optional) Specify 1 to include the notification settings for each schedule in the XML output. name: show_notifications - auto: PREDEFINED description: (Optional) Launch a scan with a certain type. name: scan_type predefined: - certview - perimeter - description: (Optional) The target FQDN for a vulnerability scan. You must specify at least one target i.e. IPs, asset groups or FQDNs. Multiple values are comma separated. name: fqdn - description: (Optional) Set to 1 to display the cloud details (Provider, Connector, Scan Type and Cloud Target) in the XML output. Otherwise the details are not displayed in the output. The cloud details will show scan type "Cloud Perimeter" for cloud perimeter scans. name: show_cloud_details - description: (Optional) Id assigned to the client (Consultant type subscription only). Parameter client_id or client_name may be specified for the same request. name: client_id - description: (Optional) Name of the client (Consultant type subscription only). Parameter client_id or client_name may be specified for the same request. name: client_name - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: Shows schedule scans. name: qualys-schedule-scan-list outputs: - contextPath: Qualys.Scan.ID description: Scan ID. - contextPath: Qualys.Scan.REF description: Scan REF. - contextPath: Qualys.Scan.TYPE description: Scan type. - contextPath: Qualys.Scan.TITLE description: Scan title. - contextPath: Qualys.Scan.LAUNCH_DATETIME description: Date and time the scan launched. - contextPath: Qualys.Scan.DURATION description: Scan Duration. - contextPath: Qualys.Scan.PROCESSING_PRIORITY description: Scan Processing Priority. - contextPath: Qualys.Scan.PROCESSED description: Scan Processed. - contextPath: Qualys.Scan.STATUS.STATE description: Scan status state. - contextPath: Qualys.Scan.STATUS.SUB_STATE description: Scan status sub state. - contextPath: Qualys.Scan.TARGET description: Scan Target. - contextPath: Qualys.Scan.ASSET_GROUP_TITLE description: Target Asset Group Title. - contextPath: Qualys.Scan.DEFAULT_FLAG description: Scan Deafualt Flag. - contextPath: Qualys.Scan.USER_LOGIN description: The user that created the scan. - contextPath: Qualys.Scan.ACTIVE description: Scheduled scan active. - contextPath: Qualys.Scan.USER_ENTERED_IPS.RANGE.START description: IP range requested start. - contextPath: Qualys.Scan.USER_ENTERED_IPS.RANGE.END description: IP range requested end. - contextPath: Qualys.Scan.ISCANNER_NAME description: Iscanner name used in the scan. - contextPath: Qualys.Scan.SCHEDULE.DAILY.@frequency_days description: Frequency of usage of the scan. - contextPath: Qualys.Scan.SCHEDULE.START_DATE_UTC description: Start date of the scheduled scan in UTC format. - contextPath: Qualys.Scan.SCHEDULE.START_HOUR description: Start hour of the scheduled scan. - contextPath: Qualys.Scan.SCHEDULE.START_MINUTE description: Start minute of the scheduled scan. - contextPath: Qualys.Scan.SCHEDULE.TIME_ZONE.TIME_ZONE_CODE description: Time zone code of the time for the scheduled scan. - contextPath: Qualys.Scan.SCHEDULE.TIME_ZONE.TIME_ZONE_DETAILS description: Time zone details of the time for the scheduled scan. - contextPath: Qualys.Scan.OPTION_PROFILE.DEFAULT_FLAG description: Default flag of the option profile. - contextPath: Qualys.Scan.OPTION_PROFILE.TITLE description: Title of the option profile. - contextPath: Qualys.Scan.EC2_INSTANCE.CONNECTOR_UUID description: Connector UUID of EC2 instance. - contextPath: Qualys.Scan.EC2_INSTANCE.EC2_ENDPOINT description: Endpoint of EC2 instance. - contextPath: Qualys.Scan.EC2_INSTANCE.EC2_ONLY_CLASSIC description: EC2 only classic. - arguments: - description: Show only hosts which have an operating system matching a certain regular expression. An empty value cannot be specified. Use “%5E%24” to match empty string. name: os_pattern - description: Specify the maximum number of host records processed per request. When not specified, the truncation limit is set to 1000 host records. You may specify a value less than the default (1-999) or greater than the default (1001-1000000). name: truncation_limit - description: Show only certain IP addresses/ranges. One or more IPs/ranges may be specified. Multiple entries are comma separated. An IP range is specified with a hyphen (for example, 10.10.10.1-10.10.10.100). name: ips - description: Show only hosts belonging to asset groups with certain strings in the asset group title. One or more asset group titles may be specified. Multiple entries are comma separated (for example, My+First+Asset+Group,Another+Asset+Group). name: ag_titles - description: Show only certain host IDs/ranges. One or more host IDs/ranges may be specified. Multiple entries are comma separated. A host ID range is specified with a hyphen (for example, 190-400).Valid host IDs are required. name: ids - description: (Optional, and valid only when the Network Support feature is enabled for the user’s account) Restrict the request to certain custom network IDs. Multiple network IDs are comma separated. name: network_ids - description: 'Show hosts not scanned since a certain date and time (optional). use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. Permissions: An Auditor cannot specify this parameter.' name: no_vm_scan_since - description: 'Show hosts that were last scanned for vulnerabilities since a certain date and time (optional). Hosts that were the target of a vulnerability scan since the date/time will be shown. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. Permissions: An Auditor cannot specify this parameter.' name: vm_scan_since - description: (Optional) Show compliance hosts not scanned since a certain date and time (optional). This parameter is invalid for an Express Lite user. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: no_compliance_scan_since - auto: PREDEFINED description: Specify 0 (the default) if you want to select hosts based on IP addresses/ranges and/or asset groups. Specify 1 if you want to select hosts based on asset tags. name: use_tags predefined: - '0' - '1' - auto: PREDEFINED description: (Optional when use_tags=1) Specify “id” (the default) to select a tag set by providing tag IDs. Specify “name” to select a tag set by providing tag names. name: tag_set_by predefined: - id - name - auto: PREDEFINED description: (Optional when use_tags=1) Select “any” (the default) to include hosts that match at least one of the selected tags. Select “all” to include hosts that match all of the selected tags. name: tag_include_selector predefined: - any - all - auto: PREDEFINED description: (Optional when use_tags=1) Select “any” (the default) to exclude hosts that match at least one of the selected tags. Select “all” to exclude hosts that match all of the selected tags. name: tag_exclude_selector predefined: - any - all - description: (Optional when use_tags=1) Specify a tag set to include. Hosts that match these tags will be included. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_include - description: (Optional when use_tags=1) Specify a tag set to exclude. Hosts that match these tags will be excluded. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_exclude - auto: PREDEFINED description: (Optional) Specify 1 to display asset tags associated with each host in the XML output. name: show_tags predefined: - '0' - '1' - description: 'Specify the name of the cloud provider to show the assets managed by the cloud provider. Valid values: ec2, google, azure.' name: host_metadata - description: (Optional when host_metadata is specified) Specify metadata fields to only return data for certain attributes. name: host_metadata_fields - auto: PREDEFINED description: (Optional) Specify 1 to display cloud provider tags for each scanned host asset in the output. The default value of the parameter is set to 0. When set to 0, we will not show the cloud provider tags for the scanned assets. name: show_cloud_tags predefined: - '0' - '1' - description: (Optional when show_cloud_tags is specified) Specify cloud tags or cloud tag and name combinations to only return information for specified cloud tags. A cloud tag name and value combination is specified with a colon (for example:SomeTag6:AY_ec2). For each cloud tag, we show the cloud tag’s name, its value, and last success date (the tag last success date/time, fetched from instance). If this parameter is not specified and "show_cloud_tags" is set to 1, we will show all the cloud provider tags for the assets. name: cloud_tag_fields - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit auto: PREDEFINED - auto: PREDEFINED defaultValue: Basic description: '(Optional) Show the requested amount of host information for each host. A valid value is: Basic, Basic/AGs, All, All/AGs, or None. AGs is equal to Asset Groups.' name: details predefined: - Basic - Basic/AGs - All - All/AGs - None description: View a list of scanned hosts in the user account. name: qualys-host-list outputs: - contextPath: Qualys.Endpoint.ID description: Endpoint ID. - contextPath: Qualys.Endpoint.IP description: IP. - contextPath: Qualys.Endpoint.CLOUD_PROVIDER description: Host's cloud provider. - contextPath: Qualys.Endpoint.DNS description: DNS. - contextPath: Qualys.Endpoint.EC2_INSTANCE_ID description: EC2 instance ID. - contextPath: Qualys.Endpoint.QG_HOSTID description: QG host ID. - contextPath: Qualys.Endpoint.CLOUD_SERVICE description: Cloud service of the endpoint. - contextPath: Qualys.Endpoint.TRACKING_METHOD description: Tracking method of the endpoint. - contextPath: Qualys.Endpoint.CLOUD_RESOURCE_ID description: Cloud resource ID of the endpoint. - contextPath: Qualys.Endpoint.DNS_DATA.DOMAIN description: Domain of the endpoint. - contextPath: Qualys.Endpoint.DNS_DATA.HOSTNAME description: Host name of the endpoint. - contextPath: Qualys.Endpoint.NETBIOS description: NETBIOS. - contextPath: Qualys.Endpoint.OS description: Endpoint operating system. - arguments: - description: Show only virtual hosts that have a certain IP address. name: ip - description: Show only virtual hosts that have a certain port. name: port - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: View a list of virtual hosts in the user account. name: qualys-virtual-host-list outputs: - contextPath: Qualys.VirtualEndpoint.IP description: IP. - contextPath: Qualys.VirtualEndpoint.PORT description: Port. - contextPath: Qualys.VirtualEndpoint.FQDN description: Fully qualified domain name. - arguments: - auto: PREDEFINED description: Virtual host action to perform. name: action predefined: - create - update - delete - add_fqdn - delete_fqdn required: true - description: An IP address for the virtual host configuration. name: ip required: true - description: A port number for the virtual host configuration. name: port required: true - description: Network support must be enabled to specify the network_id. If network support is enabled and you do not provide a network_id, then the Default Global Network is considered. You can specify only one network_id. name: network_id - description: (Required for all actions except “delete”. Invalid for “delete”.) One or more fully-qualified domain names (FQDNs) for the virtual host configuration. Multiple entries are comma separated. name: fqdn description: View a list of virtual hosts in the user account. name: qualys-virtual-host-manage outputs: - contextPath: Qualys.VirtualEndpoint.DATETIME description: Date and time of the executed manage action. - contextPath: Qualys.VirtualEndpoint.TEXT description: Result message of the executed action. - arguments: - description: Get list of excluded hosts or addresses range. name: ips - description: (Optional, and valid only when the Network Support feature is enabled for the user’s account) Restrict the request to a certain custom network ID. name: network_id - description: (Optional) Show excluded hosts belonging to asset groups with certain IDs. One or more asset group IDs and/or ranges may be specified. Multiple entries are comma separated. A range is specified with a dash (for example, 386941-386945). Valid asset group IDs are required. name: ag_ids - description: (Optional) Show excluded hosts belonging to asset groups with certain strings in the asset group title. One or more asset group titles may be specified. Multiple entries are comma separated (for example, My+First+Asset+Group,Another+Asset+Group). name: ag_titles - auto: PREDEFINED description: (Optional) Specify 0 (the default) if you want to select hosts based on IP addresses/ranges and/or asset groups. Specify 1 if you want to select hosts based on asset tags. name: use_tags predefined: - '0' - '1' - auto: PREDEFINED description: (Optional when use_tags=1) Specify "any" (the default) to include excluded hosts that match at least one of the selected tags. Specify "all" to include excluded hosts that match all of the selected tags. name: tag_include_selector predefined: - any - all - auto: PREDEFINED description: (Optional when use_tags=1) Specify "any" (the default) to ignore excluded hosts that match at least one of the selected tags. Specify "all" to ignore excluded hosts that match all of the selected tags. name: tag_exclude_selector predefined: - any - all - auto: PREDEFINED description: (Optional when use_tags=1) Specify "id" (the default) to select a tag set by providing tag IDs. Specify "name" to select a tag set by providing tag names. name: tag_set_by predefined: - id - name - description: (Optional when use_tags=1) Specify a tag set to include. Excluded hosts that match these tags will be included. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_include - description: (Optional when use_tags=1) Specify a tag set to exclude. Excluded hosts that match these tags will be ignored. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_exclude - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: Show the excluded host list for the user's account. Hosts in your excluded host list will not be scanned. name: qualys-host-excluded-list outputs: - contextPath: Qualys.Excluded.Host.Address description: IP Address. - contextPath: Qualys.Excluded.Host.Address.#text description: IP of excluded host with expiration date. - contextPath: Qualys.Excluded.Host.Address.@expiration_date description: Expiration date of excluded host address. - contextPath: Qualys.Excluded.Host.Range.#text description: Range of excluded hosts with expiration date. - contextPath: Qualys.Excluded.Host.Range.@expiration_date description: Expiration date of excluded hosts ranges. - contextPath: Qualys.Excluded.Host.Range description: Range of IP addresses. - arguments: - description: Scheduled report ID. name: id - auto: PREDEFINED description: Select is_active=1 for active or is_active=0 for inactive scheduled reports to view. name: is_active predefined: - '1' - '0' - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: Get list of scheduled reports. name: qualys-scheduled-report-list outputs: - contextPath: Qualys.Report.ID description: Report ID. type: String - contextPath: Qualys.Report.TITLE description: Report title. - contextPath: Qualys.Report.TYPE description: Report type. - contextPath: Qualys.Report.LAUNCH_DATETIME description: Date and time the report launched. - contextPath: Qualys.Report.OUTPUT_FORMAT description: Report output format. - contextPath: Qualys.Report.SIZE description: Report size. - contextPath: Qualys.Report.STATUS.STATE description: Report state status. - contextPath: Qualys.Report.STATUS.MESSAGE description: Report status message. - contextPath: Qualys.Report.STATUS.PERCENT description: Report status percent. - contextPath: Qualys.Report.EXPIRATION_DATETIME description: Report expiration datetime. - contextPath: Qualys.Report.ACTIVE description: Report active. - contextPath: Qualys.Report.TEMPLATE_TITLE description: Title of the template. - contextPath: Qualys.Report.SCHEDULE.START_DATE_UTC description: Start date of the scheduled report in UTC format. - contextPath: Qualys.Report.SCHEDULE.START_HOUR description: Start hour of the scheduled report. - contextPath: Qualys.Report.SCHEDULE.START_MINUTE description: Start minute of the scheduled report. - contextPath: Qualys.Report.SCHEDULE.DAILY.@frequency_days description: Frequency of the scheduled report. - contextPath: Qualys.Report.SCHEDULE.TIME_ZONE.TIME_ZONE_CODE description: Timezone of the scheduled report. - contextPath: Qualys.Report.SCHEDULE.TIME_ZONE.TIME_ZONE_DETAILS description: Timezone details of the scheduled report. - arguments: - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: get list of report template for user. name: qualys-report-template-list outputs: - contextPath: Qualys.ReportTemplate.ID description: Report template ID. - contextPath: Qualys.ReportTemplate.TYPE description: Report type. - contextPath: Qualys.ReportTemplate.TITLE description: Report template title. - contextPath: Qualys.ReportTemplate.LAST_UPDATE description: Last update time. - contextPath: Qualys.ReportTemplate.GLOBAL description: Report template global. - contextPath: Qualys.ReportTemplate.DEFAULT description: Report template default. - contextPath: Qualys.ReportTemplate.USER.LOGIN description: Last updated user login. - contextPath: Qualys.ReportTemplate.USER.FIRSTNAME description: Last updated user login first name. - contextPath: Qualys.ReportTemplate.USER.LASTNAME description: Last updated user login last name. - contextPath: Qualys.ReportTemplate.TEMPLATE_TYPE description: Type of report template. - arguments: - auto: PREDEFINED description: 'Show the requested amount of information for each vulnerability in the XML output. A valid value is: Basic (default), All, or None. Basic includes basic elements plus CVSS Base and Temporal scores. All includes all vulnerability details, including the Basic details.' name: details predefined: - Basic - All - None - description: Used to filter the XML output to include only vulnerabilities that have QID numbers matching the QID numbers you specify. name: ids - description: Used to filter the XML output to show only vulnerabilities that have a QID number greater than or equal to a QID number you specify. name: id_min - description: Used to filter the XML output to show only vulnerabilities that have a QID number less than or equal to a QID number you specify. name: id_max - auto: PREDEFINED description: Used to filter the XML output to show only vulnerabilities that are patchable or not patchable. A vulnerability is considered patchable when a patch exists for it. When 1 is specified, only vulnerabilities that are patchable will be included in the output. When 0 is specified, only vulnerabilities that are not patchable will be included in the output. When unspecified, patchable and unpatchable vulnerabilities will be included in the output. name: is_patchable predefined: - '0' - '1' - description: Used to filter the XML output to show only vulnerabilities last modified after a certain date and time. When specified vulnerabilities last modified by a user or by the service will be shown. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: last_modified_after - description: Used to filter the XML output to show only vulnerabilities last modified before a certain date and time. When specified vulnerabilities last modified by a user or by the service will be shown. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: last_modified_before - description: Used to filter the XML output to show only vulnerabilities last modified by a user after a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: last_modified_by_user_after - description: Used to filter the XML output to show only vulnerabilities last modified by a user before a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: last_modified_by_user_before - description: Used to filter the XML output to show only vulnerabilities last modified by the service after a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: last_modified_by_service_after - description: Used to filter the XML output to show only vulnerabilities last modified by the service before a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: last_modified_by_service_before - description: Used to filter the XML output to show only vulnerabilities published after a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: published_after - description: Used to filter the XML output to show only vulnerabilities published before a certain date and time. use YYYY-MM-DD[THH:MM:SSZ] like “2007-07-01” or “2007-01-25T23:12:00Z” or today, yesterday, 24hr ago, 3 days ago, last week. name: published_before - auto: PREDEFINED description: ' (Optional) Used to filter the XML output to show only vulnerabilities assigned a certain discovery method. A valid value is: Remote, Authenticated, RemoteOnly, AuthenticatedOnly, or RemoteAndAuthenticated.' name: discovery_method predefined: - Remote - Authenticated - RemoteOnly - AuthenticatedOnly - RemoteAndAuthenticated - description: 'Used to filter the XML output to show only vulnerabilities having one or more authentication types. A valid value is: Windows, Oracle, Unix or SNMP. Multiple values are entered as a comma-separated list.' name: discovery_auth_types - auto: PREDEFINED description: Used to filter the XML output to show reasons for passing or failing PCI compliance (when the CVSS Scoring feature is turned on in the user’s subscription). Specify 1 to view the reasons in the XML output. When unspecified, the reasons are not included in the XML output. name: show_pci_reasons predefined: - '0' - '1' - auto: PREDEFINED description: Used to filter the XML output to show Qualys modules that can be used to detect each vulnerability. Specify 1 to view supported modules in the XML output. When unspecified, supported modules are not included in the XML output. name: show_supported_modules_info predefined: - '0' - '1' - auto: PREDEFINED description: Specify 1 to include the disabled flag for each vulnerability in the XML output. name: show_disabled_flag predefined: - '0' - '1' - auto: PREDEFINED description: Specify 1 to include QID changes for each vulnerability in the XML output. name: show_qid_change_log predefined: - '0' - '1' - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit - description: The cloud agent scan type to filter vulnerabilities by. When applied, only Deep Scan QIDs are returned. Possible value - "Deep Scan - Windows". name: cloud_agent_scan_type description: Downloads a list of vulnerabilities from Qualys' KnowledgeBase. name: qualys-vulnerability-list outputs: - contextPath: Qualys.Vulnerability.List.QID description: Vulnerability QID. - contextPath: Qualys.Vulnerability.List.PATCHABLE description: Is Vulnerability patchable. - contextPath: Qualys.Vulnerability.List.SEVERITY_LEVEL description: Severity level of the Vulnerability. - contextPath: Qualys.Vulnerability.List.CONSEQUENCE description: Consequence of the Vulnerability. - contextPath: Qualys.Vulnerability.List.VENDOR_REFERENCE_LIST.VENDOR_REFERENCE.ID description: ID of the vendor. - contextPath: Qualys.Vulnerability.List.VENDOR_REFERENCE_LIST.VENDOR_REFERENCE.URL description: URL of the vendor. - contextPath: Qualys.Vulnerability.List.LAST_SERVICE_MODIFICATION_DATETIME description: Date of the last service modification. - contextPath: Qualys.Vulnerability.List.CVE_LIST.CVE.ID description: CVE ID. - contextPath: Qualys.Vulnerability.List.CVE_LIST.CVE.URL description: CVE URL. - contextPath: Qualys.Vulnerability.List.PUBLISHED_DATETIME description: Published date. - contextPath: Qualys.Vulnerability.List.DISCOVERY.ADDITIONAL_INFO description: Additional info. - contextPath: Qualys.Vulnerability.List.DISCOVERY.AUTH_TYPE_LIST.AUTH_TYPE description: Discovery Authentication type. - contextPath: Qualys.Vulnerability.List.DISCOVERY.REMOTE description: Is discovery remote. - contextPath: Qualys.Vulnerability.List.DIAGNOSIS description: Diagnosis of vulnerability. - contextPath: Qualys.Vulnerability.List.PCI_FLAG description: PCI flag. - contextPath: Qualys.Vulnerability.List.SOFTWARE_LIST.SOFTWARE.PRODUCT description: Product name. - contextPath: Qualys.Vulnerability.List.SOFTWARE_LIST.SOFTWARE.VENDOR description: Vendor of the product. - contextPath: Qualys.Vulnerability.List.VULN_TYPE description: Type of the vulnerability. - contextPath: Qualys.Vulnerability.List.TITLE description: Title of the vulnerability. - contextPath: Qualys.Vulnerability.List.SOLUTION description: Solution for the vulnerability. - contextPath: Qualys.Vulnerability.List.CATEGORY description: Category of the vulnerability. - arguments: - description: Show only asset groups with certain IDs. Multiple IDs are comma separated. name: ids - description: Show only asset groups with certain IDs. Multiple IDs are comma separated. name: id_min - description: Show only asset groups that have an ID less than or equal to the specified ID. name: id_max - description: Specify the maximum number of asset group records to output. By default this is set to 1000 records. If you specify truncation_limit=0, the output is not paginated and all records are returned in a single output. name: truncation_limit - description: Optional and valid only when the Networks feature is enabled in your account) Restrict the request to certain network IDs. Multiple IDs are comma separated. name: network_ids - description: Show only asset groups that have a business unit ID equal to the specified ID. name: unit_id - description: Show only asset groups that have a user ID equal to the specified ID. name: user_id - description: ' Show only the asset group that has a title equal to the specified string - this must be an exact match.' name: title - description: 'Show attributes for each asset group along with the ID. Your options are: None, All or a comma-separated list of attribute names: ID, TITLE, OWNER_USER_NAME, OWNER_USER_ID, OWNER_UNIT_ID, NETWORK_IDS, LAST_UPDATE, IP_SET, APPLIANCE_LIST, DOMAIN_LIST, DNS_LIST, NETBIOS_LIST, EC2_ID_LIST, HOST_IDS, ASSIGNED_USER_IDS, ASSIGNED_UNIT_IDS, BUSINESS_IMPACT, CVSS, COMMENTS.' name: show_attributes - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: Get account asset groups. name: qualys-group-list outputs: - contextPath: Qualys.AssetGroup.ID description: Asset Group ID. - contextPath: Qualys.AssetGroup.TITLE description: Asset Group title. - contextPath: Qualys.AssetGroup.OWNER_ID description: Asset Group owner ID. - contextPath: Qualys.AssetGroup.UNIT_ID description: Asset Group unit ID. - contextPath: Qualys.AssetGroup.NETWORK_ID description: Asset Group network ID. - contextPath: Qualys.AssetGroup.IP_SET.IP description: IP in the asset group. - contextPath: Qualys.AssetGroup.IP_SET.IP_RANGE description: Asset Group IP range. - contextPath: Qualys.AssetGroup.APPLIANCE_IDS description: Appliance IDs of the asset group. - contextPath: Qualys.AssetGroup.DEFAULT_APPLIANCE_ID description: Default appliance IDs of the asset group. - arguments: - description: Report ID of a saved report that you want to download. name: id required: true - auto: PREDEFINED description: Type of the file of the report. Can be checked by calling the qualys-report-list command. name: file_format predefined: - pdf - html - mht - xml - csv - docx - online required: true description: Download report. name: qualys-report-fetch outputs: - contextPath: InfoFile.Name description: The file name. - contextPath: InfoFile.EntryID description: The ID for locating the file in the War Room. - contextPath: InfoFile.Size description: The size of the file (in bytes). - contextPath: InfoFile.Type description: The file type, as determined by libmagic (same as displayed in file entries). - contextPath: InfoFile.Extension description: The file extension. - contextPath: InfoFile.Info description: Basic information about the file. - arguments: - description: 'The scan reference for a vulnerability scan. This will have the format: scan/nnnnnnnnnn.nnnnn' name: scan_ref required: true - description: 'Show only certain IP addresses/ranges in the scan results. One or more IPs/ranges may be specified. A range entry is specified using a hyphen (for example, 10.10.10.1-10.10.10.20). Multiple entries are comma separated. ' name: ips - auto: PREDEFINED description: 'The verbosity of the scan results details. One verbosity mode may be specified: brief (the default) or extended. The brief output includes this information: IP address, DNS hostname, NetBIOS hostname, QID and scan test results if applicable. The extended output includes the brief output plus this extended information: protocol, port, an SSL flag (“yes” is returned when SSL was used for the detection, “no” is returned when SSL was not used), and FQDN if applicable.' name: mode predefined: - brief - extended - description: Id assigned to the client (Consultant type subscription only). Parameter client_id or client_name may be specified for the same request. name: client_id - description: Name of the client (Consultant type subscription only). Parameter client_id or client_name may be specified for the same request. name: client_name description: Download scan results when scan has status Finished, Canceled, Paused or Error. name: qualys-vm-scan-fetch outputs: - contextPath: Qualys.VM.Dns description: Scanned device DNS. - contextPath: Qualys.VM.Instance description: Scanned device instance. - contextPath: Qualys.VM.IP description: Scanned device IP address. - contextPath: Qualys.VM.Netbios description: Scanned device Netbios. - contextPath: Qualys.VM.QID description: Qualys ID for vulnerabilities. - contextPath: Qualys.VM.Result description: Scan result. - arguments: - description: 'The scan reference for a compliance scan. This will have the format: compliance/nnnnnnnnnn.nnnnn' name: scan_ref required: true description: fetch scan results for a scan. name: qualys-pc-scan-fetch outputs: - contextPath: Qualys.PC.USERNAME description: The user who executed the scan. - contextPath: Qualys.PC.COMPANY description: The company of the user who executed the scan. - contextPath: Qualys.PC.USERNAME description: The user who executed the scan. - contextPath: Qualys.PC.DATE description: The date of the scan. - contextPath: Qualys.PC.TITLE description: The scan title. - contextPath: Qualys.PC.TARGET description: IP’s which were scanned. - contextPath: Qualys.PC.EXCLUDED_TARGET description: IP’s which were excluded from the scan. - contextPath: Qualys.PC.DURATION description: The duration of the scan. - contextPath: Qualys.PC.NBHOST_ALIVE description: Number of hosts that are available during the scan. - contextPath: Qualys.PC.NBHOST_TOTAL description: Total number of hosts that were submitted to scan. - contextPath: Qualys.PC.REPORT_TYPE description: Type of the report. - contextPath: Qualys.PC.OPTIONS description: Scan option profile. - contextPath: Qualys.PC.STATUS description: Status of the scan. - arguments: - description: Report ID. name: id required: true description: Cancel the running report. execution: true name: qualys-report-cancel outputs: - contextPath: Qualys.Report.ID description: ID of the canceled report. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for report cancellation. type: String - arguments: - description: (Required) The report ID you want to take action on. name: id required: true description: Delete a saved report in the user’s Report Share. execution: true name: qualys-report-delete outputs: - contextPath: Qualys.Report.ID description: Deleted report ID. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the report deletion. type: String - arguments: - description: Scorecard name for the vulnerability scorecard report. name: name required: true - description: User-defined report title. name: report_title - auto: PREDEFINED defaultValue: xml description: Output format of the report. One output format may be specified. name: output_format predefined: - pdf - html - mht - xml - csv required: true - description: The source asset groups for the report. name: source required: true - auto: PREDEFINED description: (Valid for CSV format report only). Specify hide_header=1 to omit the header information from the report. name: hide_header predefined: - '1' - '0' - description: The password to be used for encryption. name: pdf_password - description: The report recipients in the form of one or more distribution groups. name: recipient_group - description: Specify users who will receive the email notification when the report is complete. name: recipient_group_id - description: The titles of asset groups to be used as source asset groups for the scorecard report. name: asset_groups - auto: PREDEFINED description: et to 1 to select all asset groups available in your account as the source asset groups for the scorecard report. name: all_asset_groups predefined: - '1' - description: The title of a business unit containing the source asset groups. name: business_unit - description: A business info tag identifying a division that asset group(s) belong to. name: division - description: A business info tag identifying a business function for asset group(s). name: function - description: A business info tag identifying a location where asset group(s) are located. name: location - description: Up to 10 QIDs for vulnerabilities or potential vulnerabilities with available patches. Multiple QIDs are comma separated. name: patch_qids - description: One or two QIDs for missing software. Two QIDs are comma separated. name: missing_qids description: Launch a vulnerability scorecard report. execution: true name: qualys-scorecard-launch outputs: - contextPath: Qualys.Report.ID description: Report ID. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the scorecard launch. type: String - arguments: - description: The scan title. This can be a maximum of 2000 characters (ascii). name: scan_title - auto: PREDEFINED defaultValue: assets description: Specify “assets” (the default) when your scan target will include IP addresses/ranges and/or asset groups. Specify “tags” when your scan target will include asset tags. name: target_from predefined: - assets - tags - description: 'The IP addresses to be scanned. You may enter individual IP addresses and/or ranges. Multiple entries are comma separated. One of these parameters is required: ip, asset_groups or asset_group_ids.' name: ip - description: 'The titles of asset groups containing the hosts to be scanned. Multiple titles are comma separated. One of these parameters is required: ip, asset_groups or asset_group_ids.' name: asset_groups - description: 'The IDs of asset groups containing the hosts to be scanned. Multiple IDs are comma separated. One of these parameters is required: ip, asset_groups or asset_group_ids.' name: asset_group_ids - description: The IP addresses to be excluded from the scan when the scan target is specified as IP addresses (not asset tags). You may enter individual IP addresses and/or ranges. Multiple entries are comma separated. name: exclude_ip_per_scan - auto: PREDEFINED description: ' Select “any” (the default) to include hosts that match at least one of the selected tags. Select “all” to include hosts that match all of the selected tags.' name: tag_include_selector predefined: - all - any - auto: PREDEFINED description: Select “any” (the default) to exclude hosts that match at least one of the selected tags. Select “all” to exclude hosts that match all of the selected tags. name: tag_exclude_selector predefined: - all - any - auto: PREDEFINED description: Specify “id” (the default) to select a tag set by providing tag IDs. Specify “name” to select a tag set by providing tag names. name: tag_set_by predefined: - id - name - description: Specify a tag set to include. Hosts that match these tags will be included. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_include - description: Specify a tag set to exclude. Hosts that match these tags will be excluded. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_exclude - auto: PREDEFINED description: Specify “0” (the default) to select from all tags (tags with any tag rule). Specify “1” to scan all IP addresses defined in the tag selection. When this is specified, only tags with the dynamic IP address rule called “IP address in Network Range(s)” can be selected. valid only when target_from=tags is specified. name: use_ip_nt_range_tags_include predefined: - '0' - '1' - auto: PREDEFINED description: Specify “0” (the default) to select from all tags (tags with any tag rule). Specify “1” to exclude all IP addresses defined in the tag selection. When this is specified, only tags with the dynamic IP address rule called “IP address in Network Range(s)” can be selected. valid only when target_from=tags is specified. name: use_ip_nt_range_tags_exclude predefined: - '0' - '1' - auto: PREDEFINED description: Specify “0” (the default) to select from all tags (tags with any tag rule). Specify “1” to scan all IP addresses defined in tags. When this is specified, only tags with the dynamic IP address rule called “IP address in Network Range(s)” can be selected. name: use_ip_nt_range_tags predefined: - '0' - '1' - description: "The IDs of the scanner appliances to be used. Multiple entries are comma separated. For an Express Lite user, Internal Scanning must be enabled in the user's account. One of these parameters must also be specified in a request: iscanner_name, iscanner_id, default_scanner, scanners_in_ag, scanners_in_tagset. When none of these are specified, External scanners are used. These parameters are mutually exclusive and cannot be specified in the same request: iscanner_id and iscanner_name." name: iscanner_id - description: Specifies the name of the Scanner Appliance for the map, when the map target has private use internal IPs. Using Express Lite, Internal Scanning must be enabled in your account. name: iscanner_name - auto: PREDEFINED description: Specify 1 to use the default scanner in each target asset group. For an Express Lite user, Internal Scanning must be enabled in the user’s account. name: default_scanner predefined: - '0' - '1' - auto: PREDEFINED description: Specify 1 to distribute the scan to the target asset groups’ scanner appliances. Appliances in each asset group are tasked with scanning the IPs in the group. By default up to 5 appliances per group will be used and this can be configured for your account (please contact your Account Manager or Support). For an Express Lite user, Internal Scanning must be enabled in the user’s account. name: scanners_in_ag predefined: - '0' - '1' - auto: PREDEFINED description: 'Specify 1 to distribute the scan to scanner appliances that match the asset tags specified for the scan target. One of these parameters must be specified in a request for an internal scan: iscanner_name, iscanner_id, default_scanner, scanners_in_ag, scanners_in_tagset. When none of these are specified, external scanners are used. Only valid when the target_from=tags is specified.' name: scanners_in_tagset predefined: - '0' - '1' - description: Specify 1 to distribute the scan to all scanner appliances in the network. name: scanners_in_network - description: 'The title of the compliance option profile to be used. One of these parameters must be specified in a request: option_title or option_id. These are mutually exclusive and cannot be specified in the same request.' name: option_title - description: 'The ID of the compliance option profile to be used. One of these parameters must be specified in a request: option_title or option_id. These are mutually exclusive and cannot be specified in the same request.' name: option_id - auto: PREDEFINED description: Specify a value of 0 - 9 to set a processing priority level for the scan. When not specified, a value of 0 (no priority) is used. 0 = No Priority (the default), 1 = Emergency, 2 = Ultimate, 3 = Critical, 4 = Major, 5 = High, 6 = Standard, 7 = Medium, 8 = Minor, 9 = Low. name: priority predefined: - '0' - '1' - '2' - '3' - '4' - '5' - '6' - '7' - '8' - '9' - description: (Required for EC2 scan) The name of the EC2 connector for the AWS integration you want to run the scan on. name: connector_name - description: (Required for EC2 scan) The EC2 region code or the ID of the Virtual Private Cloud (VPC) zone. name: ec2_endpoint - description: The ID of the EC2 instance on which you want to launch the VM or compliance scan. Multiple ec2 instance ids are comma separated. You can add up to maximum 10 instance Ids. name: ec2_instance_ids - description: The ID of a network used to filter the IPs/ranges specified in the“ip” parameter. Set to a custom network ID (note this does not filter IPs/ranges specified in “asset_groups” or “asset_group_ids”). Or set to “0” (the default) for the Global Default Network - this is used to scan hosts outside of your custom networks. name: ip_network_id - description: Set a custom value in order to drop defenses (such as logging, IPs, etc) when an authorized scan is being run. The value you enter will be used in the “Qualys-Scan:” header that will be set for many CGI and web application fingerprinting checks. Some discovery and web server fingerprinting checks will not use this header. name: runtime_http_header - auto: PREDEFINED description: Launch a CertView type scan. This option will be supported when CertView GA is released and enabled for your account. name: scan_type predefined: - certview - description: The target FQDN for a vulnerability scan. You must specify at least one target i.e. IPs, asset groups or FQDNs. Multiple values are comma separated. name: fqdn - description: Id assigned to the client (Consultant type subscription only). Parameter client_id or client_name may be specified for the same request. name: client_id - description: Name of the client (Consultant type subscriptions only). Parameter client_id or client_name may be specified for the same request. name: client_name - auto: PREDEFINED description: Specify 1 when your scan target includes agent hosts. This lets you scan private IPs where agents are installed when these IPs are not in your VM/PC license. name: include_agent_targets predefined: - '0' - '1' description: ' launch vulnerability scans in the user’s account.' name: qualys-vm-scan-launch outputs: - contextPath: Qualys.Report.VM.Launched.KEY description: Key name of launched VM scan, either ID or a REFERENCE. - contextPath: Qualys.Report.VM.Launched.VALUE description: Value of the key. - arguments: - auto: PREDEFINED description: One action required for the request. name: action predefined: - cancel - pause - resume - delete required: true - description: 'The scan reference for a vulnerability scan. This will have the format: scan/nnnnnnnnnn.nnnnn' name: scan_ref required: true description: allows users to take actions on vulnerability scans in their account, like cancel, pause, resume, delete and fetch completed scan results. execution: true name: qualys-vm-scan-action - arguments: - auto: PREDEFINED description: One action required for the request. name: action predefined: - cancel - pause - resume - delete required: true - description: ' The scan reference for a compliance scan. This will have the format: compliance/nnnnnnnnnn.nnnnn' name: scan_ref required: true description: Allows users to take actions on compliance scans in their account, like cancel, pause, resume, delete and fetch completed scan results. name: qualys-pc-scan-manage outputs: - contextPath: Qualys.Scan.KEY description: Key name, either ID or REFERENCE. - contextPath: Qualys.Scan.VALUE description: Value of either ID or REFERENCE. - arguments: - description: The scan title. This can be a maximum of 2000 characters (ascii). name: scan_title - description: ' The ID of the compliance option profile to be used. One of these parameters must be specified in a request: option_title or option_id. These are mutually exclusive and cannot be specified in the same request.' name: option_id - description: 'The title of the compliance option profile to be used. One of these parameters must be specified in a request: option_title or option_id. These are mutually exclusive and cannot be specified in the same request.' name: option_title - description: ' The IP addresses to be scanned. You may enter individual IP addresses and/or ranges. Multiple entries are comma separated. One of these parameters is required: ip, asset_groups or asset_group_ids.' name: ip - description: 'The IDs of asset groups containing the hosts to be scanned. Multiple IDs are comma separated. One of these parameters is required: ip, asset_groups or asset_group_ids.' name: asset_group_ids - description: 'The titles of asset groups containing the hosts to be scanned. Multiple titles are comma separated. One of these parameters is required: ip, asset_groups or asset_group_ids.' name: asset_groups - description: The IP addresses to be excluded from the scan when the scan target is specified as IP addresses (not asset tags). You may enter individual IP addresses and/or ranges. Multiple entries are comma separated. name: exclude_ip_per_scan - auto: PREDEFINED description: Specify 1 to use the default scanner in each target asset group. For an Express Lite user, Internal Scanning must be enabled in the user’s account. name: default_scanner predefined: - '0' - '1' - auto: PREDEFINED description: Specify 1 to distribute the scan to the target asset groups’ scanner appliances. Appliances in each asset group are tasked with scanning the IPs in the group. By default up to 5 appliances per group will be used and this can be configured for your account (please contact your Account Manager or Support). For an Express Lite user, Internal Scanning must be enabled in the user’s account. name: scanners_in_ag predefined: - '0' - '1' - auto: PREDEFINED defaultValue: assets description: Specify “assets” (the default) when your scan target will include IP addresses/ranges and/or asset groups. Specify “tags” when your scan target will include asset tags. name: target_from predefined: - assets - tags - auto: PREDEFINED description: ' Select “any” (the default) to include hosts that match at least one of the selected tags. Select “all” to include hosts that match all of the selected tags.' name: tag_include_selector predefined: - all - any - auto: PREDEFINED description: Select “any” (the default) to exclude hosts that match at least one of the selected tags. Select “all” to exclude hosts that match all of the selected tags. name: tag_exclude_selector predefined: - all - any - auto: PREDEFINED description: Specify “id” (the default) to select a tag set by providing tag IDs. Specify “name” to select a tag set by providing tag names. name: tag_set_by predefined: - id - name - description: Specify a tag set to include. Hosts that match these tags will be included. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_include - description: Specify a tag set to exclude. Hosts that match these tags will be excluded. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_exclude - auto: PREDEFINED description: Specify “0” (the default) to select from all tags (tags with any tag rule). Specify “1” to scan all IP addresses defined in tags. When this is specified, only tags with the dynamic IP address rule called “IP address in Network Range(s)” can be selected. name: use_ip_nt_range_tags predefined: - '0' - '1' - description: The ID of a network used to filter the IPs/ranges specified in the“ip” parameter. Set to a custom network ID (note this does not filter IPs/ranges specified in “asset_groups” or “asset_group_ids”). Or set to “0” (the default) for the Global Default Network - this is used to scan hosts outside of your custom networks. name: ip_network_id - description: Set a custom value in order to drop defenses (such as logging, IPs, etc) when an authorized scan is being run. The value you enter will be used in the “Qualys-Scan:” header that will be set for many CGI and web application fingerprinting checks. Some discovery and web server fingerprinting checks will not use this header. name: runtime_http_header - description: Specifies the name of the Scanner Appliance for the map, when the map target has private use internal IPs. Using Express Lite, Internal Scanning must be enabled in your account. name: iscanner_name description: launch compliance scans. execution: true name: qualys-pc-scan-launch outputs: - contextPath: Qualys.Scan.KEY description: Scan key, either ID or Reference. - contextPath: Qualys.Scan.VALUE description: Scan value, either value of ID or Reference. - arguments: - description: 'The hosts you want to add to the subscription. ' name: ips required: true - auto: PREDEFINED description: The tracking method is set to IP for IP address by default. To use another tracking method specify DNS or NETBIOS. name: tracking_method predefined: - IP - DNS - NETBIOS - auto: PREDEFINED defaultValue: '0' description: You must enable the hosts for the VM application (enable_vm=1) or the PC application (enable_pc=1) or both VM and PC. name: enable_vm predefined: - '0' - '1' required: true - auto: PREDEFINED defaultValue: '0' description: You must enable the hosts for the VM application (enable_vm=1) or the PC application (enable_pc=1) or both VM and PC. name: enable_pc predefined: - '0' - '1' required: true - description: The owner of the host asset(s). The owner must be a Manager or a Unit Manager. name: owner - description: Values for user-defined fields 1, 2 and 3. You can specify a maximum of 128 characters. name: ud1 - description: Values for user-defined fields 1, 2 and 3. You can specify a maximum of 128 characters. name: ud2 - description: Values for user-defined fields 1, 2 and 3. You can specify a maximum of 128 characters. name: ud3 - description: User-defined comments. name: comment - description: (Required if the request is being made by a Unit Manager; otherwise invalid) The title of an asset group in the Unit Manager’s business unit that the host(s) will be added to. name: ag_title - auto: PREDEFINED description: Set to 1 to add IPs to your CertView license. By default IPs are not added to your CertView license. This option will be supported when CertView GA is released and is enabled for your account. name: enable_certview predefined: - '0' - '1' description: Add IP addresses to the subscription. execution: true name: qualys-ip-add outputs: - contextPath: Qualys.IP.Add.TEXT description: Action result message. type: String - contextPath: Qualys.IP.Add.DATETIME description: Date & time of the action. type: Date - arguments: - description: ' The hosts within the subscription that you want to update.' name: ips required: true - description: (valid only when the Network Support feature is enabled for the user's account) Restrict the request to a certain custom network by specifying the network ID. When unspecified, we default to "0" for Global Default Network. name: network_id - description: (Optional) The DNS hostname for the IP you want to update. A single IP must be specified in the same request and the IP will only be updated if it matches the hostname specified. name: host_dns - description: (Optional) The NetBIOS hostname for the IP you want to update. A single IP must be specified in the same request and the IP will only be updated if it matches the hostname specified. name: host_netbios - auto: PREDEFINED description: The tracking method is set to IP for IP address by default. To use another tracking method specify DNS or NETBIOS. name: tracking_method predefined: - IP - DNS - NETBIOS - description: The owner of the host asset(s). The owner must be a Manager or a Unit Manager. name: owner - description: Values for user-defined fields 1, 2 and 3. You can specify a maximum of 128 characters. name: ud1 - description: Values for user-defined fields 1, 2 and 3. You can specify a maximum of 128 characters. name: ud2 - description: Values for user-defined fields 1, 2 and 3. You can specify a maximum of 128 characters. name: ud3 - description: User-defined comments. name: comment description: gives you the ability to update IP addresses within the subscription. execution: true name: qualys-ip-update outputs: - contextPath: Qualys.IP.Update.TEXT description: Action result message. - contextPath: Qualys.IP.Update.DATETIME description: Date & time of the action. - arguments: - auto: PREDEFINED description: Select add/remove/remove_all ips. name: action predefined: - add - remove - remove_all required: true - description: User-defined notes (up to 1024 characters). name: comment required: true - description: 'The IP addresses to be added to the excluded IPs list. Enter a comma-separated list of IPv4 singletons or ranges. For example: 10.10.10.13,10.10.10.25-10.10.10.29.' name: ips - description: (Optional when action=add) The number of days the IPs being added to the excluded IPs list will be considered valid for exclusion. When the expiration is reached, the IPs are removed from the list and made available again for scanning. When unspecified, the IPs being added have no expiration and will remain on the list until removed by a user. name: expiry_days - description: (Optional when action=add) Specify users who will be notified 7 days before hosts are removed from the excluded hosts list (i.e. supply distribution group names as defined in the Qualys UI). name: dg_names - description: Assign a network ID to the IPs being added to the excluded IPs list. By default, the user’s default network ID is assigned. name: network_id description: Manage your excluded IPs list using the Excluded IP. The IPs in your excluded IPs list will not be scanned. execution: true name: qualys-host-excluded-manage outputs: - contextPath: Qualys.Endpoint.KEY description: Result of action requested. - contextPath: Qualys.Endpoint description: IPs action was made on. - arguments: - description: Scheduled report ID. Can be found by running the command qualys-scheduled-report-list. name: id required: true description: Launch a scheduled report now. execution: true name: qualys-scheduled-report-launch outputs: - contextPath: Qualys.Report.ID description: Launched report ID. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the scheduled report launch. type: String - arguments: - description: The template ID of the report you want to launch. Can be found by running the command qualys-report-template-list. name: template_id required: true - description: Specifies the map references (1 or 2) to include. A map reference starts with the string "map/" followed by a reference ID number. When two map references are given, the report compares map results. Two map references are comma separated. name: report_refs required: true - auto: PREDEFINED description: One output format may be specified. name: output_format predefined: - pdf - html - mht - xml - csv required: true - description: Specifies the target domain for the map report. Include the domain name only; do not enter "www." at the start of the domain name. When the special “none” domain is specified as a parameter value, the ip_restriction parameter is required. name: domain required: true - description: A user-defined report title. The title may have a maximum of 128 characters. For a PCI compliance report, the report title is provided by Qualys and cannot be changed. name: report_title - auto: PREDEFINED description: (Valid for CSV format report only). Specify hide_header=1 to omit the header information from the report. By default this information is included. name: hide_header predefined: - '0' - '1' - description: (Required for secure PDF distribution, Manager or Unit Manager only) Used for secure PDF report distribution when this feature is enabled in the user's account (under Reports > Setup > Report Share). The password to be used for encryption. - the password must have a minimum of 8 characters (ascii), and a maximum of 32 characters - the password must contain alpha and numeric characters - the password cannot match the password for the user’s Qualys account. - the password must follow the password security guidelines defined for your subscription (under Users > Setup > Security). name: pdf_password - description: Used for secure PDF distribution. The report recipients in the form of one or more distribution group names, as defined using the Qualys UI. Multiple distribution groups are comma separated. A maximum of 50 distribution groups may be entered. name: recipient_group - description: The report recipients in the form of one or more distribution group IDs. Multiple distribution group IDs are comma separated. Where do I find this ID? Log in to your Qualys account, go to Users > Distribution Groups and select Info for a group in the list. name: recipient_group_id - description: For a map report, specifies certain IPs/ranges to include in the report. Multiple IPs and/or ranges are comma separated. name: ip_restriction description: Launches a map report. execution: true name: qualys-report-launch-map outputs: - contextPath: Qualys.Report.ID description: Launched map report ID. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the report launch map. type: String - arguments: - description: The template ID of the report you want to launch. Can be found by running the command qualys-report-template-list. name: template_id required: true - auto: PREDEFINED description: output format may be specified. When output_format=pdf is specified, the Secure PDF Distribution may be used. name: output_format predefined: - pdf - html - mht - xml - csv required: true - description: A user-defined report title. The title may have a maximum of 128 characters. For a PCI compliance report, the report title is provided by Qualys and cannot be changed. name: report_title - description: (Valid for CSV format report only). Specify hide_header=1 to omit the header information from the report. By default this information is included. name: hide_header - description: Specify users who will receive the email notification when the report is complete (i.e. supply a distribution group ID). Where do I find this ID? Log in to your Qualys account, go to Users > Distribution Groups and select Info for a group in the list. name: recipient_group_id - description: '(Optional; Required for secure PDF distribution) The password to be used for encryption. Requirements: - the password must have a minimum of 8 characters (ascii), and a maximum of 32 characters - the password must contain alpha and numeric characters - the password cannot match the password for the user’s Qualys account. - the password must follow the password security guidelines defined for your subscription (log in and go to Subscription Setup—>Security Options).' name: pdf_password - description: Optional; Optional for secure PDF distribution) The report recipients in the form of one or more distribution groups, as defined using the Qualys UI. Multiple distribution groups are comma separated. A maximum of 50 distribution groups may be entered. Chapter 4 — Report API Launch Report recipient_group={value}. name: recipient_group - description: Specify IPs/ranges to change (override) the report target, as defined in the scan report template. Multiple IPs/ranges are comma separated. When specified, hosts defined in the report template are not included in the report. See also “Using Asset Tags.”. name: ips - description: Specify asset group IDs to change (override) the report target, as defined in the scan report template. When specified, hosts defined in the report template are not included in the report. Looking for asset group IDs? Use the asset_group_list.php function (see the API v1 User Guide). name: asset_group_ids - description: Optional, and valid only when the Network Support feature is enabled for the user’s account) The ID of a network that is used to restrict the report’s target to the IPs/ranges specified in the“ips” parameter. Set to a custom network ID (note this does not filter IPs/ranges specified in “asset_group_ids”). Or set to “0” (the default) for the Global Default Network - this is used to report on hosts outside of your custom networks. name: ips_network_id description: Run host based findings report. execution: true name: qualys-report-launch-host-based-findings outputs: - contextPath: Qualys.Report.ID description: Report ID. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the scan based findings. type: String - arguments: - description: The template ID of the report you want to launch. Can be found by running qualys-report-template-list. name: template_id required: true - auto: PREDEFINED description: One output format may be specified. When output_format=pdf is specified, the Secure PDF Distribution may be used. name: output_format predefined: - pdf - html - mht - xml - csv - docx required: true - description: (Required) This parameter specifies the scan references to include. A scan reference starts with the string "scan/" followed by a reference ID number. Multiple scan references are comma separated. Reference can be found by running the command qualys-vm-scan-list. name: report_refs required: true - description: A user-defined report title. The title may have a maximum of 128 characters. For a PCI compliance report, the report title is provided by Qualys and cannot be changed. name: report_title - description: (Valid for CSV format report only). Specify hide_header=1 to omit the header information from the report. By default this information is included. name: hide_header - description: Specify users who will receive the email notification when the report is complete (i.e. supply a distribution group ID). Where do I find this ID? Log in to your Qualys account, go to Users > Distribution Groups and select Info for a group in the list. name: recipient_group_id - description: '(Optional; Required for secure PDF distribution) The password to be used for encryption. Requirements: - the password must have a minimum of 8 characters (ascii), and a maximum of 32 characters - the password must contain alpha and numeric characters - the password cannot match the password for the user’s Qualys account. - the password must follow the password security guidelines defined for your subscription (log in and go to Subscription Setup—>Security Options).' name: pdf_password - description: Optional; Optional for secure PDF distribution) The report recipients in the form of one or more distribution groups, as defined using the Qualys UI. Multiple distribution groups are comma separated. A maximum of 50 distribution groups may be entered. Chapter 4 — Report API Launch Report recipient_group={value}. name: recipient_group - description: (Optional) For a scan report, the report content will be restricted to the specified IPs/ranges. Multiple IPs and/or ranges are comma separated. name: ip_restriction description: launches a scan report including scan based findings. name: qualys-report-launch-scan-based-findings outputs: - contextPath: Qualys.Report.ID description: Report ID. type: String - arguments: - description: The template ID of the report you want to launch. Can be found by running the command qualys-report-template-list. name: template_id required: true - auto: PREDEFINED description: One output format may be specified. When output_format=pdf is specified, the Secure PDF Distribution may be used. name: output_format predefined: - pdf - online - xml - csv required: true - description: A user-defined report title. The title may have a maximum of 128 characters. For a PCI compliance report, the report title is provided by Qualys and cannot be changed. name: report_title - description: (Valid for CSV format report only). Specify hide_header=1 to omit the header information from the report. By default this information is included. name: hide_header - description: Specify users who will receive the email notification when the report is complete (i.e. supply a distribution group ID). Where do I find this ID? Log in to your Qualys account, go to Users > Distribution Groups and select Info for a group in the list. name: recipient_group_id - description: '(Optional; Required for secure PDF distribution) The password to be used for encryption. Requirements: - the password must have a minimum of 8 characters (ascii), and a maximum of 32 characters - the password must contain alpha and numeric characters - the password cannot match the password for the user’s Qualys account. - the password must follow the password security guidelines defined for your subscription (log in and go to Subscription Setup—>Security Options).' name: pdf_password - description: Optional; Optional for secure PDF distribution) The report recipients in the form of one or more distribution groups, as defined using the Qualys UI. Multiple distribution groups are comma separated. A maximum of 50 distribution groups may be entered. Chapter 4 — Report API Launch Report recipient_group={value}. name: recipient_group - description: Specify IPs/ranges to change (override) the report target, as defined in the patch report template. Multiple IPs/ranges are comma separated. When specified, hosts defined in the report template are not included in the report. See also “Using Asset Tags.”. name: ips - description: Specify IPs/ranges to change (override) the report target, as defined in the patch report template. Multiple asset group IDs are comma separated. When specified, hosts defined in the report template are not included in the report. Looking for asset group IDs? Use the asset_group_list.php function (see the API v1 User Guide). name: asset_group_ids description: Run patch report. execution: true name: qualys-report-launch-patch outputs: - contextPath: Qualys.Report.ID description: Report ID. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the launch patch. type: String - arguments: - description: The template ID of the report you want to launch. Can be found by running qualys-report-template-list. name: template_id required: true - auto: PREDEFINED description: One output format may be specified. When output_format=pdf is specified, the Secure PDF Distribution may be used. name: output_format predefined: - pdf - html - mht - csv required: true - description: A user-defined report title. The title may have a maximum of 128 characters. For a PCI compliance report, the report title is provided by Qualys and cannot be changed. name: report_title - description: (Valid for CSV format report only). Specify hide_header=1 to omit the header information from the report. By default this information is included. name: hide_header - description: Specify users who will receive the email notification when the report is complete (i.e. supply a distribution group ID). Where do I find this ID? Log in to your Qualys account, go to Users > Distribution Groups and select Info for a group in the list. name: recipient_group_id - description: '(Optional; Required for secure PDF distribution) The password to be used for encryption. Requirements: - the password must have a minimum of 8 characters (ascii), and a maximum of 32 characters - the password must contain alpha and numeric characters - the password cannot match the password for the user’s Qualys account. - the password must follow the password security guidelines defined for your subscription (log in and go to Subscription Setup—>Security Options).' name: pdf_password - description: Optional; Optional for secure PDF distribution) The report recipients in the form of one or more distribution groups, as defined using the Qualys UI. Multiple distribution groups are comma separated. A maximum of 50 distribution groups may be entered. Chapter 4 — Report API Launch Report recipient_group={value}. name: recipient_group - description: (Optional for remediation report) Specify IPs/ranges you want to include in the report. Multiple IPs and/or ranges are comma separated. name: ips - description: Specify asset group IDs that identify hosts you want to include in the report. Multiple asset group IDs are comma separated. Looking for asset group IDs? Use the asset_group_list.php function (in the API v1 User Guide). name: asset_group_ids - auto: PREDEFINED description: ' Specifies whether the report will include tickets assigned to the current user, or all tickets in the user account. By default tickets assigned to the current user are included. Valid values are: User (default) or All.' name: assignee_type predefined: - User - All description: Run remediation report. execution: true name: qualys-report-launch-remediation outputs: - contextPath: Qualys.Report.ID description: Remediation report ID. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the launch remediation. type: String - arguments: - description: The template ID of the report you want to launch. Can be found by running the command qualys-report-template-list. name: template_id required: true - description: A user-defined report title. The title may have a maximum of 128 characters. For a PCI compliance report, the report title is provided by Qualys and cannot be changed. name: report_title - description: (Valid for CSV format report only). Specify hide_header=1 to omit the header information from the report. By default this information is included. name: hide_header - description: Specify users who will receive the email notification when the report is complete (i.e. supply a distribution group ID). Where do I find this ID? Log in to your Qualys account, go to Users > Distribution Groups and select Info for a group in the list. name: recipient_group_id - description: '(Optional; Required for secure PDF distribution) The password to be used for encryption. Requirements: - the password must have a minimum of 8 characters (ascii), and a maximum of 32 characters - the password must contain alpha and numeric characters - the password cannot match the password for the user’s Qualys account. - the password must follow the password security guidelines defined for your subscription (log in and go to Subscription Setup—>Security Options).' name: pdf_password - description: Optional; Optional for secure PDF distribution) The report recipients in the form of one or more distribution groups, as defined using the Qualys UI. Multiple distribution groups are comma separated. A maximum of 50 distribution groups may be entered. Chapter 4 — Report API Launch Report recipient_group={value}. name: recipient_group - auto: PREDEFINED description: 'One output format may be specified. When output_format=pdf is specified, the Secure PDF Distribution may be used. ' name: output_format predefined: - pdf - html - mht required: true - description: (Optional for compliance report) For a compliance report (except a PCI report), specify the IPs/ranges you want to include in the report. Multiple IPs and/or ranges are comma separated. name: ips - description: (Optional for compliance report) For a compliance report (except a PCI report), specify asset groups IDs which identify hosts to include in the report. Multiple asset group IDs are comma separated. Looking for asset group IDs? Use the asset_group_list.php function (in the API v1 User Guide). name: asset_group_ids - description: For a PCI compliance report, either the technical or executive report, this parameter specifies the scan reference to include. A scan reference starts with the string “scan/” followed by a reference ID number. The scan reference must be for a scan that was run using the PCI Options profile. Only one scan reference may be specified. Reference can be found by running the command qualys-pc-scan-list. name: report_refs description: Run compliance report. execution: true name: qualys-report-launch-compliance outputs: - contextPath: Qualys.Report.ID description: Compliance report ID. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the launch compliance. type: String - arguments: - description: The template ID of the report you want to launch. Can be found by running the command qualys-report-template-list. name: template_id required: true - description: A user-defined report title. The title may have a maximum of 128 characters. For a PCI compliance report, the report title is provided by Qualys and cannot be changed. name: report_title - description: (Valid for CSV format report only). Specify hide_header=1 to omit the header information from the report. By default this information is included. name: hide_header - description: Specify users who will receive the email notification when the report is complete (i.e. supply a distribution group ID). Where do I find this ID? Log in to your Qualys account, go to Users > Distribution Groups and select Info for a group in the list. name: recipient_group_id - description: '(Optional; Required for secure PDF distribution) The password to be used for encryption. Requirements: - the password must have a minimum of 8 characters (ascii), and a maximum of 32 characters - the password must contain alpha and numeric characters - the password cannot match the password for the user’s Qualys account. - the password must follow the password security guidelines defined for your subscription (log in and go to Subscription Setup—>Security Options).' name: pdf_password - description: Optional; Optional for secure PDF distribution) The report recipients in the form of one or more distribution groups, as defined using the Qualys UI. Multiple distribution groups are comma separated. A maximum of 50 distribution groups may be entered. Chapter 4 — Report API Launch Report recipient_group={value}. name: recipient_group - auto: PREDEFINED description: 'One output format may be specified. When output_format=pdf is specified, the Secure PDF Distribution may be used. ' name: output_format predefined: - pdf - html - mht - xml - csv required: true - description: Specifies the policy to run the report on. A valid policy ID must be entered. name: policy_id required: true - description: Specify asset group IDS if you want to include only certain asset groups in your report. These asset groups must be assigned to the policy you are reporting on. Multiple asset group IDs are comma separated. Looking for asset group IDs? Use the asset_group_list.php function (in the API v1 User Guide). name: asset_group_ids - description: Specify IPs/ranges if you want to include only certain IP addresses in your report. These IPs must be assigned to the policy you’re reporting on. Multiple entries are comma separated. name: ips - description: ' In the policy report output, show only results for a single host instance. Specify the ID for the host to include in the report. A valid host ID must be entered.' name: host_id - description: Specifies a single instance on the selected host. The instance string may be “os” or a string like “oracle10:1:1521:ora10204u”. name: instance_string description: Run compliance policy report. execution: true name: qualys-report-launch-compliance-policy outputs: - contextPath: Qualys.Report.ID description: Policy report ID. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the launch compliance policy. type: String - arguments: - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: Get the list of restricted IPs within the user's subscription. execution: true name: qualys-ip-restricted-list outputs: - contextPath: Qualys.Restricted.Address description: List of the restricted IPs. - contextPath: Qualys.Restricted.Range description: List of the restricted IPs. - arguments: - auto: PREDEFINED description: activate - enable or disable the restricted IPs feature. clear - clear all restricted IPs and de-active this feature. add - add restricted IPs. delete - delete restricted IPs. replace - replace restricted IPs. name: action predefined: - activate - clear - add - delete - replace required: true - auto: PREDEFINED description: Enable or disable the restricted IPs list. set enable=1 to enable the list; set enable=0 to clear any IPs in the list and disable the feature. name: enable predefined: - '0' - '1' - description: The hosts you want to add to, remove from or replace in the restricted IPs list. How to specify IP addresses. One or more IPs/ranges may be specified. Multiple IPs/ranges are comma separated. An IP range is specified with a hyphen (for example, 10.10.30.1-10.10.30.50). name: ips description: Get the list of restricted IPs within the user's subscription. execution: true name: qualys-ip-restricted-manage outputs: - contextPath: Qualys.Restricted.Manage.TEXT description: Action result message. - contextPath: Qualys.Restricted.Manage.DATETIME description: Date & time of the action. - contextPath: Qualys.Restricted.Manage.ITEM_LIST.ITEM.VALUE description: Status of the restricted ips feature. - arguments: - description: A comma-separated list of host IDs/ranges. A host ID range is specified with a hyphen (for example, 190-400). Valid host IDs are required. isArray: true name: ids - description: A comma-separated list of host IP addresses/ranges. An IP address range is specified with a hyphen (for example, 10.10.30.1-10.10.30.50). isArray: true name: ips - description: A comma-separated list of valid detection record QIDs. A range is specified with a dash (for example, 68518-68522). isArray: true name: qids - description: A comma-separated list of severity levels. A range is specified with a dash (for example, 1-5 where 1 is low and 5 is high).. isArray: true name: severities - auto: PREDEFINED description: Specify 0 (the default) to select hosts based on IP addresses/ranges and/or asset groups. Specify 1 to select hosts based on asset tags. name: use_tags predefined: - '0' - '1' - auto: PREDEFINED description: (Optional when use_tags=1) Specify “id” (the default) to select a tag set by providing tag IDs. Specify “name” to select a tag set by providing tag names. name: tag_set_by predefined: - id - name - auto: PREDEFINED description: (Optional when use_tags=1) Specify “any” (the default) to include hosts that match at least one of the selected tags. Specify “all” to include hosts that match all of the selected tags. name: tag_include_selector predefined: - any - all - auto: PREDEFINED description: (Optional when use_tags=1) Specify “any” (the default) to exclude hosts that match at least one of the selected tags. Specify “all” to exclude hosts that match all of the selected tags. name: tag_exclude_selector predefined: - any - all - description: (Optional when use_tags=1) Specify a comma-separated list of tag names or IDs to include hosts that match these tags. isArray: true name: tag_set_include - description: (Optional when use_tags=1) Specify a comma-separated list of tag names or IDs for which to exclude hosts that match the tags. isArray: true name: tag_set_exclude - description: Specify the date before which to retrieve detections vulnerability scan results that were processed. Specify the date in YYYY-MMDD[THH:MM:SSZ] format (UTC/GMT), for example, “2016-09-12” or “2016-09-12T23:15:00Z”. name: detection_processed_before - description: Specify the date after which to retrieve detections vulnerability scan results that were processed. Specify the date in YYYY-MMDD[THH:MM:SSZ] format (UTC/GMT), for example, “2016-09-12” or “2016-09-12T23:15:00Z”. name: detection_processed_after - description: 'Show hosts that were last scanned for vulnerabilities since the specified date and time (optional). Hosts that were the target of a vulnerability scan since the date/time will be shown. Date/time is specified in the following format: YYYY-MM-DD[THH:MM:SSZ] (UTC/GMT). Permissions: An Auditor cannot specify this parameter.' name: vm_scan_since - description: 'Show hosts not scanned since the specified date and time (optional). The date/time is specified in the following format: YYYY-MMDD[THH:MM:SSZ] format (UTC/GMT), for example, “2007-07-01” or “2007-01-25T23:12:00Z”. Permissions - An Auditor cannot specify this parameter.' name: no_vm_scan_since - description: Specify the maximum number of host records processed per request. When not specified, the truncation limit is set to 1000 host records. You may specify a value less than the default (1-999) or greater than the default (1001-1000000). name: truncation_limit description: Get a list of hosts with the hosts latest vulnerability data. The list is based on the host based scan data available in the user’s account. execution: true name: qualys-host-list-detection outputs: - contextPath: Qualys.HostDetections.ID description: Host detection ID. type: String - contextPath: Qualys.HostDetections.IP description: Host detection IP address. type: String - contextPath: Qualys.HostDetections.TRACKING_METHOD description: Tracking method. type: String - contextPath: Qualys.HostDetections.OS description: Host operating system. type: String - contextPath: Qualys.HostDetections.DNS description: Host DNS. type: String - contextPath: Qualys.HostDetections.DNS_DATA.HOSTNAME description: DNS data host name. type: String - contextPath: Qualys.HostDetections.DNS_DATA.DOMAIN description: DNS data domain. type: Unknown - contextPath: Qualys.HostDetections.DNS_DATA.FQDN description: DNS data FQDN. type: Unknown - contextPath: Qualys.HostDetections.NETBIOS description: Netbios. type: String - contextPath: Qualys.HostDetections.QG_HOSTID description: QG host ID. type: String - contextPath: Qualys.HostDetections.LAST_SCAN_DATETIME description: Last scan date. type: Date - contextPath: Qualys.HostDetections.LAST_VM_SCANNED_DATE description: Last VM scan date. type: Date - contextPath: Qualys.HostDetections.LAST_VM_SCANNED_DURATION description: Last VM scan duration. type: String - contextPath: Qualys.HostDetections.LAST_PC_SCANNED_DATE description: Last PC scan date. type: Date - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.QID description: Detection QID. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.TYPE description: Detection type. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.SEVERITY description: Detection severity. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.SSL description: Detection SSL. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.RESULTS description: Detection results. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.STATUS description: Detection status. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.FIRST_FOUND_DATETIME description: Date detection was first found. type: Date - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.LAST_FOUND_DATETIME description: Date detection was last found. type: Date - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.TIMES_FOUND description: Number of times detection was found. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.LAST_TEST_DATETIME description: Date detection was last tested. type: Date - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.LAST_UPDATE_DATETIME description: Date detection was last updated. type: Date - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.IS_IGNORED description: Whether detection is ignored. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.IS_DISABLED description: Whether detection is disabled. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.LAST_PROCESSED_DATETIME description: Date detection was last processed. type: Date - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.PORT description: Detection port. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.PROTOCOL description: Detection protocol. type: String - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.QDS description: Detection score. type: Object - contextPath: Qualys.HostDetections.DETECTION_LIST.DETECTION.QDS_FACTORS description: Factors affecting detection score. type: Object - arguments: - description: A comma-separated list of host IDs/ranges to update. A host ID range is specified with a hyphen (for example, 190-400). Valid host IDs are required. Either the `ips` or `ids` parameter must be supplied. IDs or IPs can be retrieved via running the `qualys-host-list-detection` command, using the ID field or IPs field. isArray: true name: ids - description: A comma-separated list of host IP addresses/ranges to add to, remove from or replace in the restricted IPs list. An IP range is specified with a hyphen (for example, 10.10.30.1-10.10.30.50). Either the `ips` or `ids` parameter must be supplied. isArray: true name: ips - description: (Valid only when the Network Support feature is enabled for the user’s account.) The network ID of the custom network for which to restrict the request. When unspecified, defaults to Global Default Network. name: network_id - description: The DNS hostname for the IP you want to update. A single IP must be specified in the same request and the IP will only be updated if it matches the hostname specified. name: host_dns - description: The NetBIOS hostname for the IP you want to update. A single IP must be specified in the same request and the IP will only be updated if it matches the hostname specified. name: host_netbios - auto: PREDEFINED description: Show only IP addresses/ranges which have a certain tracking method. name: tracking_method predefined: - IP - DNS - NETBIOS - auto: PREDEFINED description: The new tracking method. Note - You cannot change the tracking method to EC2 or AGENT. If an IP is already tracked by EC2 or AGENT, you cannot change the tracking method to something else. name: new_tracking_method predefined: - IP - DNS - NETBIOS - description: The new owner of the host asset(s). The owner must be a Manager. Another user (Unit Manager, Scanner, Reader) can be the owner if the IP address is in the user’s account. isArray: true name: new_owner - description: The user-defined comments. Specify new comments for the host asset(s). name: new_comment - description: Change value for user-defined field 1. You can specify a maximum of 128 characters (ASCII) for each field value. name: new_ud1 - description: Change value for user-defined field 2. You can specify a maximum of 128 characters (ASCII) for each field value. name: new_ud2 - description: Change value for user-defined field 3. You can specify a maximum of 128 characters (ASCII) for each field value. name: new_ud3 description: Update host attributes using new update parameters. execution: true name: qualys-host-update outputs: - contextPath: Qualys.Endpoint.Update.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.Endpoint.Update.TEXT description: Qualys response for the host update. type: String - arguments: - description: Specify 1 for active schedules only, or 0 for deactivated schedules only. name: active - description: Specify 1 to distribute the scan to all scanner appliances in the network. name: scanners_in_network - description: A comma-separated list of Fully Qualified Domain Names to be scanned. name: fqdn - description: The number of times the scan will be run before it is deactivated. name: recurrence - description: Specify 1 to distribute the scan to all scanner appliances in the network. name: end_after_mins - description: Specifies the name of the Scanner Appliance for the map, when the map target has private use internal IPs. When using Express Lite, Internal Scanning must be enabled in your account. name: iscanner_id - description: The scan title. name: scan_title required: true - description: 'A comma-separated list of IP addresses/ranges to be scanned. At most, one of these parameters can be supplied: ip, asset_groups or asset_group_ids.' isArray: true name: ip - description: 'A comma-separated list of IDs of asset groups containing the hosts to be scanned. At most, one of these parameters can be supplied: ip, asset_groups or asset_group_ids.' isArray: true name: asset_group_ids - description: 'A comma-separated list of titles of asset groups containing the hosts to be scanned. At most, one of these parameters can be supplied: ip, asset_groups or asset_group_ids.' isArray: true name: asset_groups - description: The title of the compliance option profile to be used. name: option_title - description: "Filter IPs/ranges in “ip” parameter (valid when the networks feature is enabled)." name: ip_network_id - description: "The ID of the option profile to be used." name: option_id - description: "End a scan after some number of hours. A valid value is from 0 to 119." name: end_after - description: "The frequency (days) in which the scan occurs. The value is between 1-365. For example: '1' indicates that the schedule will occur every day. '2' indicates that the schedule will occur every 2 days. At most, one of these parameters can be supplied: 'frequency_days', 'frequency_weeks', 'frequency_months'." name: frequency_days - description: "The frequency (weeks) in which the scan occurs. The value is between 1-52. For example: '1' indicates that the schedule will occur every week. '2' indicates that the schedule will occur every 2 weeks. The argument 'weekdays' is required when frequency_weeks is given. Scan will occur only on specified days given in the 'weekdays' argument. At most, one of these parameters can be supplied: 'frequency_days', 'frequency_weeks', 'frequency_months'." name: frequency_weeks - description: "The frequency (months) in which the scan occurs. The value is between 1-12. For example: '1' indicates that the schedule will occur every month. '2' indicates that the schedule will occur every 2 months. Either the argument 'day_of_month' or the arguments 'day_of_week' and 'week_of_month' are required when frequency_months is given. The scan will occur only on specified days given in those arguments At most, one of these parameters can be supplied: 'frequency_days', 'frequency_weeks', 'frequency_months'." name: frequency_months - auto: PREDEFINED description: "A comma-separated list of the days when the scan will occur each week. Required when 'frequency_weeks' is given. For example: weekdays='sunday,tuesday' along with 'frequency_weeks=2' means the scan will occur on Sunday and Tuesday every two weeks." isArray: true name: weekdays predefined: - sunday - monday - tuesday - wednesday - thursday - friday - saturday - description: "Day of the month the monthly schedule will run on. The value is between 1-31 depending on the month. Only relevant when 'frequency_months' value was given. For example: day_of_month=15 along with frequency_months=2 will result in the scan running every 2 months on the 15th of the month." name: day_of_month - description: "Day of week that the schedule will run on. The value is between 0-6, where 0 is Sunday, and 6 is Saturday depending on the month. Only relevant when 'frequency_months' value was given. Must be used with 'week_of_month' as well. For example: day_of_week=2, week_of_month=second along with frequency_months=2 will result in the scan running every 2 months on Tuesday in the second week of the month." name: day_of_week auto: PREDEFINED predefined: - '0' - '1' - '2' - '3' - '4' - '5' - '6' - description: "Comma-separated list of the days of the week that the schedule will run on. The value is between 0-6, where 0 is Sunday, and 6 is Saturday depending on the month. Only relevant when 'frequency_months' value was given. Must be used with 'week_of_month' as well. For example: day_of_week=2, week_of_month=second along with frequency_months=2 will result in the scan running every 2 months on Tuesday in the second week of the month." name: week_of_month auto: PREDEFINED isArray: true predefined: - first - second - third - fourth - last - description: 'The start date of the schedule in the format of mm/dd/yyyy. For example: 12/15/2020.' name: start_date required: true - description: The start hour of the scheduled scan. Required when 'start_date' is given. The value is between 0-23. name: start_hour required: true - description: "The start minute of the scheduled scan. Required when 'start_date' is given. The value is between 0-59." name: start_minute required: true - description: "Time zone code of the given scheduled scan. For example: US-CA for California time zone in the US. Required when 'start_date' is given." name: time_zone_code required: true - auto: PREDEFINED description: "Whether to observe Daylight Saving Time (DST). Required when start_date is given. This parameter is valid when the time zone code specified in time_zone_code supports DST. To get the list of time zones and their DST support, use the `qualys-time-zone-code` command." name: observe_dst predefined: - 'yes' - 'no' - description: "A comma-separated list of IP addresses/ranges to be excluded from the scan when the scan target is specified as IP addresses (not asset tags). One of the following parameters must be set: 'scanners_in_ag', 'default_scanner'." isArray: true name: exclude_ip_per_scan - auto: PREDEFINED description: "Specify 1 to use the default scanner in each target asset group. For an Express Lite user, Internal Scanning must be enabled in the user’s account. At most, one of these parameters can be supplied: 'scanners_in_ag', 'default_scanner'." name: default_scanner predefined: - '0' - '1' - auto: PREDEFINED description: "Specify 1 to distribute the scan to the target asset groups’ scanner appliances. Appliances in each asset group are tasked with scanning the IPs in the group. By default, up to 5 appliances per group will be used and this can be configured for your account (contact your Account Manager or Support). For an Express Lite user, Internal Scanning must be enabled in the user’s account. At most, one of these parameters can be supplied: 'scanners_in_ag', 'default_scanner'." name: scanners_in_ag predefined: - '0' - '1' - auto: PREDEFINED description: (Optional) Specify "assets" (the default) when your scan target will include IP addresses/ranges and/or asset groups. Specify "tags" when your scan target will include asset tags. name: target_from predefined: - assets - tags - auto: PREDEFINED description: (Optional) Select "any" (the default) to include hosts that match at least one of the selected tags. Select "all" to include hosts that match all of the selected tags. name: tag_include_selector predefined: - all - any - auto: PREDEFINED description: (Optional) Select "any" (the default) to exclude hosts that match at least one of the selected tags. Select "all" to exclude hosts that match all of the selected tags. name: tag_exclude_selector predefined: - all - any - auto: PREDEFINED description: (Optional) Specify "id" (the default) to select a tag set by providing tag IDs. Specify "name" to select a tag set by providing tag names. name: tag_set_by predefined: - id - name - description: (Optional) Specify a tag set to include. Hosts that match these tags will be included. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_include - description: (Optional) Specify a tag set to exclude. Hosts that match these tags will be excluded. You identify the tag set by providing a tag names or IDs. Multiple entries are comma separated. name: tag_set_exclude - auto: PREDEFINED description: (Optional) Specify “0” (the default) to select from all tags (tags with any tag rule). Specify “1” to scan all IP addresses defined in the tag selection. When this is specified, only tags with the dynamic IP address rule called “IP address in Network Range(s)” can be selected. name: use_ip_nt_range_tags_include predefined: - "0" - "1" - auto: PREDEFINED description: (Optional) Specify “0” (the default) to select from all tags (tags with any tag rule). Specify “1” to exclude all IP addresses defined in the tag selection. When this is specified, only tags with the dynamic IP address rule called “IP address in Network Range(s)” can be selected. name: use_ip_nt_range_tags_exclude predefined: - "0" - "1" description: Create a scan schedule in the user’s account. execution: true name: qualys-schedule-scan-create outputs: - contextPath: Qualys.ScheduleScan.ID description: ID of the new scheduled scan. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the scheduled scan creation. type: String - arguments: - description: The scan ID to update. The ID can be retrieved by running the 'qualys-schedule-scan-list' command, and using the ID field. name: id required: true - description: The scan title. name: scan_title - description: 'A comma-separated list of IP addresses/ranges to be scanned. At most, one of these parameters can be supplied: ip, asset_groups or asset_group_ids.' isArray: true name: ip - description: 'A comma-separated list of IDs of asset groups containing the hosts to be scanned. At most, one of these parameters can be supplied: ip, asset_groups or asset_group_ids.' isArray: true name: asset_group_ids - description: 'A comma-separated list of titles of asset groups containing the hosts to be scanned. At most, one of these parameters can be supplied: ip, asset_groups or asset_group_ids.' isArray: true name: asset_groups - description: "The frequency (days) in which the scan occurs. The value is between 1-365. For example: '1' indicates that the schedule will occur every day. '2' indicates that the schedule will occur every 2 days. At most, one of these parameters can be supplied: 'frequency_days', 'frequency_weeks', 'frequency_months'." name: frequency_days - description: "The frequency (weeks) in which the scan occurs. The value is between 1-52. For example: '1' indicates that the schedule will occur every week. '2' indicates that the schedule will occur every 2 weeks. The argument 'weekdays' is required when frequency_weeks is given. Scan will occur only on specified days given in the 'weekdays' argument. At most, one of these parameters can be supplied: 'frequency_days', 'frequency_weeks', 'frequency_months'." name: frequency_weeks - description: "The frequency (months) in which the scan occurs. The value is between 1-12. For example: '1' indicates that the schedule will occur every month. '2' indicates that the schedule will occur every 2 months. Either the argument 'day_of_month' or the arguments 'day_of_week' and 'week_of_month' are required when frequency_months is given. The scan will occur only on specified days given in those arguments At most, one of these parameters can be supplied: 'frequency_days', 'frequency_weeks', 'frequency_months'." name: frequency_months - auto: PREDEFINED description: "A comma-separated list of the days when the scan will occur each week. Required when 'frequency_weeks' is given. For example: weekdays='sunday,tuesday' along with 'frequency_weeks=2' means the scan will occur on Sunday and Tuesday every two weeks." isArray: true name: weekdays predefined: - sunday - monday - tuesday - wednesday - thursday - friday - saturday - description: "Day of the month the monthly schedule will run on. The value is between 1-31 depending on the month. Only relevant when 'frequency_months' value was given. For example: day_of_month=15 along with frequency_months=2 will result in the scan running every 2 months on the 15th of the month." name: day_of_month - auto: PREDEFINED description: "Day of week that the schedule will run on. The value is between 0-6, where 0 is Sunday, and 6 is Saturday depending on the month. Only relevant when 'frequency_months' value was given. Must be used with 'week_of_month' as well. For example: day_of_week=2, week_of_month=second along with frequency_months=2 will result in the scan running every 2 months on Tuesday in the second week of the month." name: day_of_week predefined: - '0' - '1' - '2' - '3' - '4' - '5' - '6' - auto: PREDEFINED description: "Comma-separated list of the days of the week that the schedule will run on. The value is between 0-6, where 0 is Sunday, and 6 is Saturday depending on the month. Only relevant when 'frequency_months' value was given. Must be used with 'week_of_month' as well. For example: day_of_week=2, week_of_month=second along with frequency_months=2 will result in the scan running every 2 months on Tuesday in the second week of the month." isArray: true name: week_of_month predefined: - first - second - third - fourth - last - description: 'The start date of the schedule in the format of mm/dd/yyyy. For example: 12/15/2020.' name: start_date - description: The start hour of the scheduled scan. Required when 'start_date' is given. The value is between 0-23. name: start_hour - description: The start minute of the scheduled scan. Required when 'start_date' is given. The value is between 0-59. name: start_minute - description: "Time zone code of the given scheduled scan. For example: US-CA for California time zone in the US. Required when 'start_date' is given." name: time_zone_code - auto: PREDEFINED description: Whether to observe Daylight Saving Time (DST). Required when start_date is given. This parameter is valid when the time zone code specified in time_zone_code supports DST. To get the list of time zones and their DST support, use the `qualys-time-zone-code` command. name: observe_dst predefined: - yes - no - description: "A comma-separated list of IP addresses/ranges to be excluded from the scan when the scan target is specified as IP addresses (not asset tags). One of the following parameters must be set: 'scanners_in_ag', 'default_scanner'." isArray: true name: exclude_ip_per_scan - auto: PREDEFINED description: "Specify 1 to use the default scanner in each target asset group. For an Express Lite user, Internal Scanning must be enabled in the user’s account. At most, one of these parameters can be supplied: 'scanners_in_ag', 'default_scanner'." name: default_scanner predefined: - '0' - '1' - auto: PREDEFINED description: "Specify 1 to distribute the scan to the target asset groups’ scanner appliances. Appliances in each asset group are tasked with scanning the IPs in the group. By default, up to 5 appliances per group will be used and this can be configured for your account (contact your Account Manager or Support). For an Express Lite user, Internal Scanning must be enabled in the user’s account. At most, one of these parameters can be supplied: 'scanners_in_ag', 'default_scanner'." name: scanners_in_ag predefined: - '0' - '1' - auto: PREDEFINED description: Whether the scheduled scan is activated. name: active predefined: - '0' - '1' - description: Specifies the name of the Scanner Appliance for the map, when the map target has private use internal IPs. Using Express Lite, Internal Scanning must be enabled in your account. name: iscanner_name - description: Filter IPs/ranges in “ip” parameter (valid when the networks feature is enabled). name: ip_network_id - description: The ID of the option profile to be used. name: option_id - description: End a scan after some number of hours. A valid value is from 0 to 119. name: end_after - description: (Optional) Specify "assets" (the default) when your scan target will include IP addresses/ranges and/or asset groups. Specify "tags" when your scan target will include asset tags. name: target_from auto: PREDEFINED predefined: - assets - tags - auto: PREDEFINED description: (Optional) Select "any" (the default) to include hosts that match at least one of the selected tags. Select "all" to include hosts that match all of the selected tags. name: tag_include_selector predefined: - all - any - auto: PREDEFINED description: (Optional) Select "any" (the default) to exclude hosts that match at least one of the selected tags. Select "all" to exclude hosts that match all of the selected tags. name: tag_exclude_selector predefined: - all - any - auto: PREDEFINED description: (Optional) Specify "id" (the default) to select a tag set by providing tag IDs. Specify "name" to select a tag set by providing tag names. name: tag_set_by predefined: - id - name - description: (Optional) Specify a tag set to include. Hosts that match these tags will be included. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_include - description: (Optional) Specify a tag set to exclude. Hosts that match these tags will be excluded. You identify the tag set by providing tag names or IDs. Multiple entries are comma separated. name: tag_set_exclude - auto: PREDEFINED description: (Optional) Specify “0” (the default) to select from all tags (tags with any tag rule). Specify “1” to scan all IP addresses defined in the tag selection. When this is specified, only tags with the dynamic IP address rule called “IP address in Network Range(s)” can be selected. name: use_ip_nt_range_tags_include predefined: - "0" - "1" - auto: PREDEFINED description: (Optional) Specify “0” (the default) to select from all tags (tags with any tag rule). Specify “1” to exclude all IP addresses defined in the tag selection. When this is specified, only tags with the dynamic IP address rule called “IP address in Network Range(s)” can be selected. name: use_ip_nt_range_tags_exclude predefined: - "0" - "1" description: Updates a scan schedule in the user’s account. execution: true name: qualys-schedule-scan-update outputs: - contextPath: Qualys.ScheduleScan.ID description: ID of the scheduled scan to be updated. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the scheduled scan update. type: String - arguments: - description: The asset group title to add. name: title required: true - description: Restrict the request to a certain custom network ID. name: network_id - description: A comma-separated list of IP address/ranges to add to an asset group. An IP range is specified with a hyphen (for example, 10.10.10.1-10.10.10.100). isArray: true name: ips - description: A comma-separated list of domains to add to an asset group. Do not enter "www." at the start of the domain name. isArray: true name: domains - description: A comma-separated list of DNS names to add to an asset group. isArray: true name: dns_names - description: A comma-separated list of NETBIOS names to add to an asset group. isArray: true name: netbios_names - auto: PREDEFINED description: The CVSS environment target distribution to add. name: cvss_enviro_td predefined: - high - medium - low - none - auto: PREDEFINED description: The CVSS environment confidentiality requirement to add. name: cvss_enviro_cr predefined: - high - medium - low - auto: PREDEFINED description: The CVSS environment integrity requirement to add. name: cvss_enviro_ir predefined: - high - medium - low - auto: PREDEFINED description: The CVSS environment availability requirement to add. name: cvss_enviro_ar predefined: - high - medium - low - description: A comma-separated list of appliance IDs to add to an asset group. isArray: true name: appliance_ids description: Create a new asset group. execution: true name: qualys-asset-group-add outputs: - contextPath: Qualys.AssetGroup.ID description: Asset group ID. type: String - contextPath: Qualys.AssetGroup.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.AssetGroup.TEXT description: Qualys response for the asset group creation. type: String - arguments: - description: The new asset group title. name: set_title - description: The ID of the asset group to edit. The ID of asset groups can be retrieved via running the `qualys-group-list` command and using its ID field. name: id required: true - description: A comma-separated list of IP address/ranges to add to an asset group. An IP range is specified with a hyphen (for example, 10.10.10.1-10.10.10.100). isArray: true name: add_ips - description: A comma-separated list of IP address/ranges of an asset group to set. An IP range is specified with a hyphen (for example, 10.10.10.1-10.10.10.100). isArray: true name: set_ips - description: A comma-separated list of IP addresses/ranges to remove from an asset group. An IP range is specified with a hyphen (for example, 10.10.10.1-10.10.10.100). isArray: true name: remove_ips - description: A comma-separated list of domains to add to an asset group. Do not enter "www." at the start of the domain name. isArray: true name: add_domains - description: A comma-separated list of domains of an asset group to set. Do not enter "www." at the start of the domain name. isArray: true name: set_domains - description: A comma-separated list of domains to remove from an asset group. Do not enter "www." at the start of the domain name. isArray: true name: remove_domains - description: A comma-separated list of DNS names to add to an asset group. isArray: true name: add_dns_names - description: A comma-separated list of DNS names of asset group to set. isArray: true name: set_dns_names - description: A comma-separated list of DNS names to remove from an asset group. isArray: true name: remove_dns_names - description: A comma-separated list of NETBIOS names to add to an asset group. isArray: true name: add_netbios_names - description: A comma-separated list of NETBIOS names of an asset group to set. isArray: true name: set_netbios_names - description: A comma-separated list of NETBIOS names to delete from an asset group. isArray: true name: remove_netbios_names - auto: PREDEFINED description: The CVSS environment target distribution to set. name: set_cvss_enviro_td predefined: - high - medium - low - none - auto: PREDEFINED description: The CVSS environment confidentiality requirement to set. name: set_cvss_enviro_cr predefined: - high - medium - low - auto: PREDEFINED description: The CVSS environment integrity requirement to set. name: set_cvss_enviro_ir predefined: - high - medium - low - auto: PREDEFINED description: The CVSS environment availability requirement to set. name: set_cvss_enviro_ar predefined: - high - medium - low - description: A comma-separated list of appliance IDs to add to an asset group. isArray: true name: add_appliance_ids - description: A comma-separated list of appliance IDs of an asset group to set. isArray: true name: set_appliance_ids - description: A comma-separated list of appliance IDs to remove from an asset group. isArray: true name: remove_appliance_ids description: Update an asset group. execution: true name: qualys-asset-group-edit outputs: - contextPath: Qualys.AssetGroup.ID description: Asset group ID. type: String - contextPath: Qualys.AssetGroup.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.AssetGroup.TEXT description: Qualys response for the asset group update. type: String - arguments: - description: Asset group ID to delete. ID of asset groups can be retrieved via running the `qualys-group-list` command and using its ID field. name: id required: true description: Delete an asset group. execution: true name: qualys-asset-group-delete outputs: - contextPath: Qualys.AssetGroup.ID description: Asset group ID. type: String - contextPath: Qualys.AssetGroup.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.AssetGroup.TEXT description: Qualys response for the asset group deletion. type: String - arguments: - description: Scheduled Scan ID to delete. The ID can be retrieved via running the `qualys-schedule-scan-list` command, and using the ID field. name: id required: true description: Delete a scheduled scan. execution: true name: qualys-schedule-scan-delete outputs: - contextPath: Qualys.ScheduleScan.ID description: ID of the scheduled scan to be deleted. type: String - contextPath: Qualys.ScheduleScan.DATETIME description: Date the command was executed. type: Date - contextPath: Qualys.ScheduleScan.TEXT description: Qualys response for the scheduled scan deletion. type: String - arguments: [] description: Gets a list of the supported time zone codes. execution: true name: qualys-time-zone-code outputs: - contextPath: Qualys.TimeZone.DST_SUPPORTED description: Whether Daylight Saving Time (DST) is supported. type: String - contextPath: Qualys.TimeZone.TIME_ZONE_CODE description: Time zone code. type: String - contextPath: Qualys.TimeZone.TIME_ZONE_DETAILS description: Timezone code details. type: String - arguments: - description: Record IDs to update. name: ids required: true - description: IPs specified will overwrite existing IPs in the record, and existing IPs will be removed. name: add_ips required: true name: qualys-update-unix-record description: Update Unix records for authenticated scans of hosts running on Unix. - arguments: - description: Criteria field to search by predefined types. name: criteria required: true auto: PREDEFINED predefined: - parent - provider - ruleType - name - id - criticalityScore - description: "Operator assigned to the search criteria.\nAcceptable values are:\nparent - EQUALS, NOT EQUALS, IN\nprovider - EQUALS, NOT EQUALS, IN\nruleType - EQUALS, NOT EQUALS, IN\nname - CONTAINS, EQUALS, NOT EQUALS\nid - EQUALS, NOT EQUALS, IN, GREATER, LESSER\ncriticalityScore - EQUALS, NOT EQUALS, GREATER, LESSER." name: operator required: true - description: Content to search. name: search_data required: true - description: The total number of items to return (Automatic Pagination). The default is 100. name: limit description: List asset tags based on a search criteria. name: qualys-asset-tag-list outputs: - contextPath: Qualys.AssetTags.id description: Parent asset tag ID. type: Number - contextPath: Qualys.AssetTags.name description: Parent asset tag name. type: String - contextPath: Qualys.AssetTags.criticality_score description: Criticality score assigned to the asset tag. type: Number - contextPath: Qualys.AssetTags.chlid_id description: Child asset tags ID. type: Number - contextPath: Qualys.AssetTags.chlid_id.child_name description: Child asset tags name. type: String - contextPath: Qualys.AssetTags.tag_name.rule_type description: Created tag rule type. type: String - contextPath: Qualys.AssetTags.tag_name.rule_text description: Created tag rule text. type: String - arguments: - description: Name of the created tag. name: name required: true - description: Names of the created child tags. name: child_name isArray: true - description: "Type of rule to dynamically tagging host.\nThe Rule Type argument determines the type of the Rule Text argument that is acceptable." name: rule_type required: true auto: PREDEFINED predefined: - INSTALLED_SOFTWARE - NETWORK_RANGE - NAME_CONTAINS - OPEN_PORTS - VULN_EXIST - STATIC - description: "Criteria for the rule. \nOptional for STATIC rule type, required for the rest of the rule types. \nAcceptable formats for each Rule Type argument: \nNETWORK_RANGE - formats: 10.10.10.1-10.10.10.6 OR 10.10.10.0/24\nVULN_EXIST(QID) - format: 12345(int)\nOPEN_PORTS - format: 443,888,12034(int)\nNAME_CONTAINS - format: REGEX\nINSTALLED_SOFTWARE - format: REGEX\nSTATIC - *RULE TEXT OPTIONAL*." name: rule_text - description: Criticality score of the asset tag. Values between 1 (lowest) and 5 (highest). name: criticality_score description: "Create a new asset tag. \nThe changes caused by this procedure do not take effect immediately. The procedure could take several hours, depending (among other things) on the the amount of assets in the system." name: qualys-asset-tag-create outputs: - contextPath: Qualys.AssetTags.id description: Parent asset tag ID. type: String - contextPath: Qualys.AssetTags.name description: Parent asset tag name. type: String - contextPath: Qualys.AssetTags.criticality_score description: Criticality score assigned to the asset tag. type: Number - contextPath: Qualys.AssetTags.chlid_id description: Child asset tags ID. type: Number - contextPath: Qualys.AssetTags.chlid_id.child_name description: Child asset tags name. type: String - contextPath: Qualys.AssetTags.tag_name.rule_type description: Created tag rule type. type: String - contextPath: Qualys.AssetTags.tag_name.rule_text description: Created tag rule text. type: String - arguments: - description: ID of the tag to update. name: id required: true - description: Name of the created tag. name: name required: true - description: "Type of rule to dynamically tagging host.\nThe Rule Type argument determines the type of the Rule Text argument that is acceptable." name: rule_type required: true auto: PREDEFINED predefined: - INSTALLED_SOFTWARE - NETWORK_RANGE - NAME_CONTAINS - OPEN_PORTS - VULN_EXIST - STATIC - description: "Criteria for the rule. \nOptional for STATIC rule type, required for the rest of the rule types. \nAcceptable formats for each Rule Type argument: \nNETWORK_RANGE - formats: 10.10.10.1-10.10.10.6 OR 10.10.10.0/24\nVULN_EXIST(QID) - format: 12345(int)\nOPEN_PORTS - format: 443,888,12034(int)\nNAME_CONTAINS - format: REGEX\nINSTALLED_SOFTWARE - format: REGEX\nSTATIC - *RULE TEXT OPTIONAL*." name: rule_text - description: Comma-separated list of child tag ID's to remove. name: child_to_remove - description: Criticality score of the asset tag. Values between 1 (lowest) and 5 (highest). name: criticality_score description: "Update an existing asset tag. \nThe changes caused by this procedure do not take effect immediately. The procedure could take several hours, depending (among other things) on the the amount of assets in the system." name: qualys-asset-tag-update - arguments: - description: ID of the tag to delete. name: id required: true description: Delete an existing asset tag. name: qualys-asset-tag-delete - arguments: - description: Specify 1 to view input parameters in the XML output. name: echo_request auto: PREDEFINED predefined: - "0" - "1" defaultValue: "0" - description: Purge host information for the defined host IDs/ranges. name: ids - description: Purge host information for the defined IP addresses/ranges. name: ips - description: Purge hosts belonging to asset groups with the defined IDs,. name: ag_ids - description: Purge hosts belonging to asset groups with the defined strings in the asset group title. name: ag_titles - description: Restrict the request to the defined custom network IDs. name: network_ids - description: Purge hosts not scanned since the defined date and time. name: no_vm_scan_since - description: Purge compliance hosts not scanned since the defined date and time. name: no_compliance_scan_since - description: The type of data to purge. Specify “vm” to purge vulnerability data, specify “pc” to purge compliance data, or specify both as a comma-separated list to purge both types of data. name: data_scope - description: This parameter is valid only when the policy compliance module is enabled for the user account. Specify 1 to purge compliance hosts in the user's account. Specify 0 to purge hosts which are not assigned to the PC module. name: compliance_enabled auto: PREDEFINED predefined: - "0" - "1" - description: Purge only hosts that have an operating system matching the defined regular expression. Use “%5E%24” to match an empty string. name: os_pattern name: qualys-purge-scan-host-data outputs: - contextPath: Qualys.Purge.ID description: IDs of the hosts queued for purging. description: Purge hosts in your account to remove the assessment data associated with them. - name: qualys-update-vmware-record arguments: - name: ids required: true description: A comma-separated list of record IDs to update. Specify record IDs and/or ID ranges. - name: add_ips required: true description: A comma-separated list of IPs and/or ranges to add to the IPs list for this record. description: Update Vmware records for authenticated scans of hosts running on Vmware. - name: qualys-update-vcenter-record arguments: - name: ids required: true description: A comma-separated list of record IDs to update. Specify record IDs and/or ID ranges. - name: add_ips required: true description: A comma-separated list of IPs and/or ranges to add to the IPs list for this record. description: Update vCenter records for authenticated scans of hosts running on vCenter. - name: qualys-vcenter-esxi-mapped-record-list arguments: - description: Specify a positive numeric value to limit the amount of results in the requested list. name: limit description: List VCenter ESXi mapping records. outputs: - contextPath: Qualys.VcenterToEsxi.ESXI_IP description: The IP address of the ESXi server. - contextPath: Qualys.VcenterToEsxi.MAPPING_DATA_SOURCE description: The source of this mapping record. - contextPath: Qualys.VcenterToEsxi.VCENTER_IP description: The IP address of the vCenter. - name: qualys-vcenter-esxi-mapped-record-import description: Import vCenter - ESXi mapping records. arguments: - name: csv_data description: The CSV data file containing the vCenter - ESXi mapping records that you want to import. required: true - name: qualys-vcenter-esxi-mapped-record-purge description: Purge vCenter - ESXi mapping records. arguments: - name: csv_data description: The CSV data file containing the vCenter - ESXi mapping records that you want to purge. required: true - arguments: - auto: PREDEFINED defaultValue: 'false' description: If true, the command will create events, otherwise it will only display them. name: should_push_events predefined: - 'true' - 'false' required: true - description: Maximum number of results to return. name: limit - description: Date to return results from. name: since_datetime - description: Offset which events to return. name: offset description: Gets activity logs from Qualys. name: qualys-get-events - arguments: - auto: PREDEFINED defaultValue: 'false' description: If true, the command will create assets, otherwise it will only display the amount of available assets. name: should_push_assets predefined: - 'true' - 'false' required: true - description: The Qualys ID (QID) used to identify and retrieve assets affected by the specified vulnerability. name: qid description: Retrieves a list of assets (hosts) affected by a specified Qualys QID. If no QID is provided, all assets with detections will be returned. name: qualys-get-assets outputs: - contextPath: Qualys.Assets description: All Qualys assets associated with the specified QID (Qualys ID). type: unknown - arguments: - description: The CVE identifier (e.g., CVE-2023-12345) used to look up the corresponding Qualys QID. name: cve required: true - description: The cloud agent scan type to filter vulnerabilities by. When applied, only Deep Scan QIDs are returned. Possible value - "Deep Scan - Windows". name: cloud_agent_scan_type description: Retrieves one or more Qualys QIDs (Qualys IDs) associated with a specified CVE. name: qualys-get-quid-by-cve outputs: - contextPath: Qualys.QID description: All the Qualys QID (Qualys ID) associated with a specified CVE. type: unknown dockerimage: demisto/python3:3.12.13.10116658 isfetchevents: true isfetchassets: true runonce: false script: '' subtype: python3 type: python fromversion: 5.5.0 tests: - QualysVulnerabilityManagement-Test supportedModules: - agentix - xsiam - exposure_management