Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
41 commits
Select commit Hold shift + click to select a range
e401ebe
feat: upgrade to Qualys v5 API endpoints with CVE, domain, and scan s…
sarus Jun 4, 2026
fb5a024
fix: set request.network in doLookup and onMessage, update deps
sarus Jun 4, 2026
8b5d507
chore: bump version to 4.1.0
sarus Jun 4, 2026
283cca5
Bump deps
sarus Jun 18, 2026
dc3d5ee
fix: use correct key 'id' for CVE data so pi-external-link renders pr…
sarus Jun 18, 2026
d204d78
feat: render CVE KB records as individual pi-cards per QID
sarus Jun 18, 2026
97cc9fa
feat: use pi-section-header for Diagnosis, Consequence, and Solution …
sarus Jun 18, 2026
005083e
fix: add margin-bottom spacing below CVE IDs (list-of-links)
sarus Jun 18, 2026
e68a52b
fix: move pi-copy-button out of absolute positioning into flex row
sarus Jun 18, 2026
e5909fc
fix: restore absolute positioning on copy button container
sarus Jun 18, 2026
c6ede5c
feat: render scans tab as bordered items with count limit
sarus Jun 18, 2026
51ce403
fix: scans tab — correct group count, remove indent-0 class, remove h…
sarus Jun 18, 2026
f50c20c
feat: wrap scans list in pi-show-more with maxLines=600
sarus Jun 18, 2026
b0b3cd2
fix: use max-lines attribute on pi-show-more (10 lines)
sarus Jun 18, 2026
1e59386
chore: set pi-show-more max-lines to 50
sarus Jun 18, 2026
5a34aef
fix: show correct record count on all pi-tab badges
sarus Jun 18, 2026
2690311
feat: render each host detection in a pi-card
sarus Jun 18, 2026
4653d5e
fix: set pi-card background to application-3 for visual contrast
sarus Jun 18, 2026
a158c0e
feat: render QDS Factors as pi-key-value list
sarus Jun 18, 2026
e215f60
fix: handle isKeyValueObject in _renderListItemField
sarus Jun 18, 2026
0ddb72c
fix: render label heading in _renderKeyValueObject
sarus Jun 18, 2026
bf55ab2
fix: use h2 and indent key-value pairs in kv-object-section
sarus Jun 18, 2026
4967814
feat: wrap detection list in pi-show-more max-lines=20
sarus Jun 18, 2026
2bd82ac
fix: extract friendly error message from Qualys 400 XML response on s…
sarus Jun 18, 2026
2ba3757
fix: migrate scan launch endpoint from api/2.0 to api/3.0
sarus Jun 18, 2026
52dfcb3
fix: parse scan REFERENCE value correctly when xml2js charkey conflic…
sarus Jun 19, 2026
9cb67a8
Bump deps
sarus Jun 19, 2026
8abc3c0
fix: sanitize scanRef input in checkScanStatus using regex extraction
sarus Jun 19, 2026
d4b0da7
fix: sanitize scanRef in web component on launch response
sarus Jun 19, 2026
9c3e277
Use loading prop on scan buttons during async operations
sarus Jun 19, 2026
b473957
feat(INT-2037): Port relaxed QID regex and custom type support to v2
sarus Jun 19, 2026
dd6d4bd
Use data types
sarus Jun 19, 2026
35c2e7f
docs: rewrite README with all options, QID formats, and Custom QID type
sarus Jun 19, 2026
f2c9bf1
docs: add missing QID separator formats (-, _, no separator) to README
sarus Jun 19, 2026
9137c35
Remove old screenshots
sarus Jun 22, 2026
16ce395
Improve QID regex
sarus Jun 22, 2026
31f63f7
REname options to better reflect usage
sarus Jun 22, 2026
a3fcee4
Update extractQidValue regex to support hyphen, underscore, and no-se…
sarus Jun 22, 2026
47610ab
Fix QID regex: place hyphen at end of character class
sarus Jun 22, 2026
bd7caea
Fix tests: use correct option key and function name
sarus Jun 22, 2026
f84583f
Merge pull request #20 from polarityio/v5-api-update
sarus Jun 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
113 changes: 84 additions & 29 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,45 +1,100 @@
# Polarity Qualys Integration
The Polarity Qualys Integration queries the Qualys Cloud Platform's Host Detection List for IP Addresses and QIDs. The Host Detections list will only get queried when searching for IP Addresses and QIDs, the host detection API does not enable other searching at this time. T

> *NOTE:* QIDs can be searched onDemand by prefixing the QID with `QID: <your_qid>`

### How to Review Polarity - Qualys Integration
***Host Detections***
* **Summary View** -> Number of Host Dections associated with QID or IP Address
* **Detail View**
* *Host Information*
* Asset ID -> Asset ID from Qualys
* Operating System -> Host OS
* DNS -> Host DNS/Domain
* Last Scan Information
* *Detections List*
* List of all detections associated with Host

<div style="display:flex; align-items: flex-start;">
<img width="370" style="margin-right: 7px" title="Host List Detections" alt="Host List Detections" src="./docs/Host List Detections.png">
</div>

## About Qualys
The Qualys Cloud Platform helps businesses simplify security operations and lower the cost of compliance by delivering critical security intelligence on demand and automating the full spectrum of auditing, compliance and protection for IT systems and web applications.

The Polarity Qualys Integration queries the Qualys Cloud Platform for IP addresses, domains, CVEs, and QIDs. Host detection results are returned for IP addresses and QIDs. CVE lookups query the Qualys KnowledgeBase and return matching vulnerability records along with any associated host detections.

## About Qualys

The Qualys Cloud Platform helps businesses simplify security operations and lower the cost of compliance by delivering critical security intelligence on demand and automating the full spectrum of auditing, compliance, and protection for IT systems and web applications.

To learn more about Qualys, visit the [official website](https://www.qualys.com/).

## Supported Entity Types

| Entity Type | Description |
|---|---|
| IPv4 | Returns host detection list and scan history for the IP address |
| IPv6 | Returns host detection list for the IPv6 address |
| Domain | Returns host detection list for hosts matching the domain name |
| CVE | Returns KnowledgeBase vulnerability records matching the CVE and associated host detections |
| Qualys ID (QID) | Returns KnowledgeBase records and host detections for the matched QID |
| Custom QID Value | User-configured type for matching arbitrary strings and extracting a QID value |

## QID Entity Type

The built-in **Qualys ID (QID)** data type automatically recognizes QID strings in the following formats (case-insensitive):

| Format | Example |
|---|---|
| `QID<number>` (no separator) | `QID12345` |
| `QID:<number>` | `QID:12345` |
| `QID: <number>` | `QID: 12345` |
| `QID : <number>` | `QID : 12345` |
| `QID-<number>` | `QID-12345` |
| `QID_<number>` | `QID_12345` |
| `QID <number>` | `QID 12345` |
| `qid:<number>` (lowercase) | `qid:38623` |

The numeric QID value is extracted automatically and used for the API lookup.

## Custom QID Value Data Type

The **Custom QID Value** data type is disabled by default. It is designed for environments where QID values appear embedded in custom string formats not covered by the built-in QID pattern (e.g., internal ticket references, asset tags, or CMDB identifiers).

When enabled, Polarity will match text against the regex you configure in the **Custom QID Value Regex** option. The integration then extracts a numeric QID from the matched string and looks it up in Qualys.

**To enable it:**
1. Go to **Integration Options → Qualys → Data Types**
2. Enable the **Custom QID Value** type and enter a regex pattern that matches your custom format
3. Optionally set the **Custom QID Value Regex** option to extract the QID number (see below)

## Integration Limitations

### Host Detection List Lookup Limits
Qualys' Host Detection List API only allows lookups on IP Addresses and QIDs, so only IP Addresses and QIDs will show Host Detection List results.
Qualys' Host Detection List API filters results by the query parameter. When searching by QID, only the detection entry for that specific QID is returned per host — not the host's full detection list. Searching by IP address returns all detections for that host.

## Integration Options

All options are admin-only and cannot be edited by regular users.

## Qualys Integration User Options
### Qualys URL
The URL of the Qualys you would like to connect to (including http:// or https://)
*(Required)* The base URL of your Qualys subscription, including the protocol (e.g., `https://qualysapi.qualys.com`). Do not include a trailing slash.

### Qualys Username
The Username for your Qualys Account
*(Required)* The username for your Qualys account.

### Qualys Password
The Password associated with the Qualys Account
*(Required)* The password associated with your Qualys account.

### Enable Scan Launch
*(Default: disabled)* When enabled, a **Launch Scan** button appears in the Scans tab for IP address entities, allowing analysts to initiate a Qualys VM scan directly from Polarity. Requires the **Scan Option Profile** to be configured.

### Scan Option Profile
The Qualys option profile title or numeric ID to use when launching scans (e.g., `Initial Options` or `43165`). Required when **Enable Scan Launch** is enabled. You can find the Scan Option Profile by navigating to the "Scans" page and then click on the "Option Profiles" tab. The "Title" column is the name of the scan option profile. Do not include the word `(default)` if selecting the default Scan Option Profile.

### Scanner Appliance Name
The name of the scanner appliance to target when launching scans (e.g., `scanner1`). Leave blank to use the account's default scanner for the target IP.

### Custom QID Value Regex
When the **Custom QID Value** data type is enabled, this regex is used to extract the numeric QID from the matched entity string.

- If the regex contains a **capture group**, the first capture group's value is used as the QID (e.g., `TICKET-(\d+)` would extract `42` from `TICKET-42`).
- If the regex has **no capture group**, the full match is used as the QID.
- If left **blank**, the integration falls back to extracting the last contiguous sequence of digits found in the matched string (e.g., `ASSET-00038623` → `38623`).

**Examples:**

| Custom type regex (Data Types) | Custom QID Value Regex (option) | Matched string | Extracted QID |
|---|---|---|---|
| `TICKET-\d+` | `TICKET-(\d+)` | `TICKET-38623` | `38623` |
| `VULN#\d{4,8}` | *(blank)* | `VULN#12345` | `12345` |
| `asset-tag-\d+` | `(\d+)$` | `asset-tag-00091` | `00091` |

## Installation Instructions

Installation instructions for integrations are provided on the [PolarityIO GitHub Page](https://polarityio.github.io/).

## Polarity
Polarity is a memory-augmentation platform that improves and accelerates analyst decision making. For more information about the Polarity platform please see:
https://polarity.io/

Polarity is a memory-augmentation platform that improves and accelerates analyst decision making. For more information about the Polarity platform please see:

https://polarity.io/
66 changes: 58 additions & 8 deletions config/config.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,13 +2,33 @@
"polarityIntegrationUuid": "fbe4d7e0-cce1-11ed-aeee-075d3490155d",
"name": "Qualys",
"acronym": "QLS",
"description": "The Polarity Qualys Integration queries the Qualys Cloud Platform's Host Detection List and KnowledgeBase for IP Addresses, Domains, CVEs and QIDs.",
"description": "The Polarity Qualys Integration queries the Qualys Cloud Platform's Host Detection List and KnowledgeBase for IP Addresses, IPv6 Addresses, Domains, CVEs, and QIDs.",
"runtimeVersion": 2,
"defaultColor": "light-purple",
"onDemandOnly": true,
"dataTypes": [
"IPv4",
"IPv6"
"IPv6",
"domain",
"cve",
{
"type": "custom",
"name": "Qualys ID (QID)",
"description": "Matches QID values prefixed with QID followed by a 1 to 8 digit number (e.g., QID1234, QID-1234, QID:1234, QID 1234)",
"key": "qid",
"regex": "(?:QID|qid)(?:\\s*[:_-]\\s*|\\s*)\\d{1,8}",
"editable": false,
"enabled": true
},
{
"type": "custom",
"name": "Custom QID Value",
"description": "Match custom QID values and extract the numeric QID via the \"Custom QID Value Regex\" integration option",
"key": "customQid",
"regex": "(?:QID|qid)(?:\\s*[:_-]\\s*|\\s*)\\d{1,8}",
"editable": true,
"enabled": false
}
],
"logging": {
"level": "info"
Expand All @@ -19,7 +39,7 @@
"components": [
{
"type": "details",
"element": "px-int-4szfuj42ymklnvnabm9q4yt1l-qls-details-v4-0-0"
"element": "px-int-4szfuj42ymklnvnabm9q4yt1l-qls-details-v4-1-0"
}
]
},
Expand Down Expand Up @@ -55,12 +75,42 @@
"type": "password",
"userCanEdit": false,
"adminOnly": true
}
],
"customTypes": [
},
{
"key": "qid",
"regex": "(?:QID|qid):\\s*\\d{1,8}"
"key": "enableScanLaunch",
"name": "Enable Scan Launch",
"description": "When enabled, a 'Launch Scan' button appears in the Scans tab for IP address entities. Requires the Scan Option Profile to be configured.",
"default": false,
"type": "boolean",
"userCanEdit": false,
"adminOnly": true
},
{
"key": "scanOptionProfile",
"name": "Scan Option Profile",
"description": "The Qualys option profile title or numeric ID to use when launching scans from Polarity (e.g., 'Initial Options' or '43165'). Required when Enable Scan Launch is enabled.",
"default": "",
"type": "text",
"userCanEdit": false,
"adminOnly": true
},
{
"key": "scannerName",
"name": "Scanner Appliance Name",
"description": "The scanner appliance name to target when launching scans (e.g., 'scanner1'). Leave blank to use the default scanner for the target IP.",
"default": "",
"type": "text",
"userCanEdit": false,
"adminOnly": true
},
{
"key": "customQidValueRegex",
"name": "Custom QID Value Regex",
"description": "When the Custom QID Value data type is enabled, this regex is used to extract the QID numeric value from the matched entity string. Leave blank to extract the last sequence of digits found in the match.",
"default": "",
"type": "text",
"userCanEdit": false,
"adminOnly": true
}
]
}
Binary file removed docs/Host List Detections.png
Binary file not shown.
Binary file removed docs/KnowledgeBase Record.png
Binary file not shown.
Binary file removed docs/hostDetectionsFullExample.png
Binary file not shown.
Binary file removed docs/knowledgeBaseFullExample.png
Binary file not shown.
Loading
Loading