Qualys previews TotalCloud FlexScan for multicloud security management

Vulnerability administration vendor Qualys this 7 days declared the demo availability of its TotalCloud with FlexScan featuring, an agentless, cloud-indigenous vulnerability detection and response system developed for use in multicloud and hybrid environments.

The program is intended to present a holistic overview of an organization’s cloud-primarily based workloads and detect known vulnerabilities. The system also scans workloads to check out regardless of whether they’ve opened network ports, and displays a host of other things to offer a comprehensive photograph of a business’ in general vulnerability standing, tracking publicly exposed VMs (virtual machines), databases, consumer accounts and exploitable vulnerabilities in general public-experiencing assets.

The business stated that quite a few of TotalCloud’s abilities are created to be no-code, enabling consumers to use a GUI (graphical consumer interface) to accomplish complicated operational duties such as quarantining belongings and placing alert parameters, which would ordinarily involve coding and be a great deal extra time-consuming.

TotalCloud, Qualys extra, is also developed as a devsecops instrument for developers, letting them to discover and correct safety flaws at each and every step of the growth procedure.

TotalCloud capabilities agentless design and style

Just one of TotalCloud’s major promoting factors is its agentless design, which means that no computer software has to operate on the monitored belongings, with the notion staying that the computer software won’t have an effect on the workloads it is monitoring, in accordance to IDC team vice president for safety and have faith in Frank Dickson.

“Agentless security is a great innovation to deal with imperfective techniques to software security in just businesses,” he stated. “Essentially, agentless safety mitigates cross corporation conflict ensuing from developer objections as cloud functions is primarily examining the surroundings powering a virtual sealed pane of glass.”

What that also usually means, nevertheless, is that the agentless solution to security is essentially based on unique snapshots of the programs it’s protecting, not on continual, moment-to-moment monitoring. In accordance to Dickson, this usually means that the technique are not able to safeguard workloads that spin up momentarily and then shut back again down once again in between those people snapshots.

“Additionally, agentless solutions are unable to extract exercise telemetry like process info, L3/L4 connections action, memory investigation or other authentic time information,” he observed. “Finally, you are extremely constrained in taking motion with out an agent so response and remediation actions are confined. A protection skilled will be constrained in the means to isolate a workload or redeploy a golden picture without having an agent.”

Qualys mentioned TotalCloud will be manufactured typically readily available by the finish of 2022.

Copyright © 2022 IDG Communications, Inc.

Leave a Reply