Qualys VMDR (beta)

Connect Nebulock Helix to Qualys VMDR for just-in-time vulnerability enrichment.

The Qualys VMDR integration enables Nebulock Helix to query vulnerability data from Qualys Vulnerability Management on demand, during hunts and investigations.

Create a dedicated Qualys service user

Log in to Qualys as an administrator (a user with the Manager or Unit Manager role), navigate to the Vulnerability Management product, and click Users in the top menu.

Click New > User to open the New User modal, then:

  • Under General Information, provide the required details (name, title, phone, email address, address, country). Use an email account that remains active even if an employee leaves.
  • Under User Role, select either Scanner or Reader, and check both the GUI and API boxes.
  • Under Asset Groups, click the "Add asset groups" dropdown and select All or the specific asset group(s) Nebulock should be able to query.

Click Save. Note the randomly generated username shown for the new account, then log out.

📘

API access inherits the permissions of the user it belongs to. Use a dedicated service account with only the minimum role required (Reader is sufficient for enrichment).

Complete the account registration

Open the registration email sent to the account's address and copy the OTP code — you'll need it on the next screen.

Follow the prompts to complete registration. You'll receive a password for the account, and the same screen displays the base URL for UI and API access. Save the username, password, and URL to a safe location.

🚧

If you lose the password, use the Forgot Password flow to reset it.

Enable the integration in Nebulock

In Nebulock, go to Settings > Integrations.

In the search bar, type "Qualys" and click Add New Connection.

Enter the connection details:

  • Name: a description of your choice, e.g. "Nebulock Qualys"
  • URL: the base URL from the registration screen
  • Username: the generated username from the user creation step
  • Password: the password from the registration step

Click Test, then Create Configuration.

Test the integration

Within Nebulock, navigate to Investigate. A simple "List the vulnerabilities from Qualys" will pull data from your Qualys VMDR instance.


What’s Next

Did this page help you?