The innovative App Built on the native cloud platform, it provides context beyond endpoints, reduces false positives and simplifies threat hunting
Qualys, Inc. (NASDAQ: QLYS), a pioneer and leading provider of highly innovative cloud-based IT security and compliance solutions, announced the new Qualys EDR Multi-Vector App. By adopting a new multi-vector approach to Endpoint Detection and Response (EDR), Qualys today puts the power of its highly scalable cloud platform at the service of EDR.
Unlike traditional EDR solutions that focus on malicious endpoint activity to research and analyze cyber attacks, Qualys' multi-vector approach provides critical context and visibility across the entire attack chain, ensuring a complete, automated and rapid response to protect against cyber risks. With this approach, which combines a powerful backend capable of analyzing threat intelligence data, Multi-Vector EDR enables you to unify multiple context vectors such as asset and software inventory items, end-of-life device data, vulnerabilities and exploits, misconfigurations, network traffic summary data, MITER ATT&CK framework tactics and techniques, malware, endpoint telemetry and network reachability data, Security managers can leverage accurate detection, analysis and intervention capabilities ALL integrated into a single cloud-based application with a single lightweight agent.
"Qualys EDR Multi-Vector offers visibility that goes beyond endpoints to eliminate false positives and more effectively prevent lateral movement. This is possible because Qualys EDR Multi-Vector is a cloud-born platform that collects enormous amounts of telemetry data from a series of sensors that acquire information from the network. The Qualys Cloud Agent, integrated into the highly scalable Qualys Cloud Platform and the upcoming Incident Response capabilities, offer a unique opportunity to MSSPs (Managed Security Service Providers) who will be able to consolidate their operations and orchestrate the most appropriate response for faster and more effective protection,” he said Vishal Salvi, CISO of Infosys.
“Qualys EDR Multi-Vector represents a substantial expansion of both the Qualys Cloud platform and our agent-based technology,” he emphasized Philippe Courtot, President and CEO of Qualys. “Adding contextual data and correlating billions of global events with threat intelligence, analytics and machine learning results in a completely revolutionary strategy for EDR management, capable of not only blocking sophisticated multi-vector attacks, but also automatically processing the appropriate response from a single solution, thus significantly reducing response times and dramatically reducing costs.”
Acquisition of Spell Security Assets
Qualys also announced that it has acquired the software assets of startup Spell Security. This acquisition further strengthens Qualys' capabilities in Qualys' security and threat hunting businesses, extending detection capabilities across endpoint monitoring and adding rich telemetry to the Qualys Cloud Platform. For Multi-Vector EDR, Spell Security's knowledge of threat hunting and hacker techniques provides additional functionality to the application and additional analysis into the specific threats customers see in their enterprise. For further details on the press release, please consult the website www.qualys.com/spellsecurity_pr.
Overview di Qualys EDR Multi-Vector
Qualys EDR Multi-Vector helps security teams stay in command throughout the entire attack lifecycle, from preventative protection, pre- and post-breach detection, automated investigations and multi-layered response capabilities across the environment through a powerful cloud-based platform.
Cloud Agent Telemetry Collection – Qualys' widely deployed Cloud Agents have been enhanced to collect large amounts of telemetry data that is sent to the Qualys Cloud Platform in real time, enabling in-depth analysis in the shortest time possible. This approach helps customers eliminate an additional EDR agent on their endpoints.
Multi-Vector detection – By leveraging the highly scalable data stream as part of the Qualys Cloud Platform, security analysts can quickly correlate additional vectors such as software inventory, patch levels, vulnerability threat intelligence and misconfigurations with endpoint telemetry data such as file, process, log, network and related data. This approach eliminates the need for threat researchers to access multiple security solutions in every context.
Identification and prioritization – Internal detection capabilities based on the MITER ATT&CK framework combined with other context vectors and enriched by external threat data, allow security managers to receive real-time alerts, analyze and classify security incidents by severity, and discover threats using intuitive workflows that take into account the criticality of assets and attack paths on the network.
Response and prevention – Qualys EDR Multi-Vector uses multi-layered incident response strategies to neutralize threats and mitigate risks in real time. Unlike traditional EDR solutions, Qualys EDR Multi-Vector implements an attack prevention strategy by orchestrating workflows to remediate exploitable vulnerabilities and misconfigurations across the entire environment. To enhance Multi-Vector EDR, Qualys plans to add new endpoint protection capabilities such as anti-malware/anti-virus to the Agent in the fourth quarter of 2020.
Availability
Qualys EDR Multi-Vector is available by September 2020. To participate in the beta program, you need to sign up on http://www.qualys.com/beta-signup/. Linux support is expected by Q1 2021.
Additional Resources
- Learn more about EDR Multi-Vector Multi-Vector EDR
- Learn more about Qualys Cloud Platform
- Follow Qualys on LinkedIn e Twitter






