Qualys TotalCloud 2.25.0 Release Updates
Table of Contents
- CIEM: Inventory of Azure Entra ID and Entitlement Classification
- CSPM: Security Posture Cloud AI Configurations
- CSPM: Real-Time Inventory with AWS EventBridge (Delta Sync)
- CWPP: Agentless Snapshot-Based Scan for GCP Cloud
- CDR: Cloud Threat Detection using AWS CloudTrail Events
- Cloud Connector Enhancements
- CSPM Enhancements
- CSPM Control Enhancements
- Resources
The Qualys TotalCloud 2.25.0 version introduces new capabilities, features, and updates. The release is expected to be available by mid-July 2026.
CIEM: Inventory of Azure Entra ID and Entitlement Classification
Expanding entitlement visibility to Microsoft Azure, TotalCloud now delivers a comprehensive inventory of Azure Cloud Infrastructure Entitlement Management (CIEM) resources, giving organizations a complete, unified view of all identity and access assets across their Azure environment. Complementing this inventory, Qualys experts have classified Azure IAM entitlements, providing out-of-the-box context on permission risk levels, helping security teams immediately distinguish overprivileged identities from appropriately scoped ones without manual analysis.
Key Benefits:
- Complete Azure entitlement visibility: Discover and inventory all Azure identity resources, role assignments, and access configurations in one unified view, eliminating blind spots in your cloud identity landscape.
- Expert-backed entitlement classification: Leverage Qualys-curated IAM classifications to instantly identify overprivileged and high-risk entitlements, accelerating remediation without requiring manual triage.
- Entitlement governance: Build an authoritative inventory of who has access to what across Azure, enabling security teams to baseline permissions, track changes, and drive future identity governance strategies.

CSPM: Security Posture Cloud AI Configurations
Qualys TotalCloud now extends security posture management to AI and machine learning workloads with purpose-built controls that assess and enforce secure configurations for generative AI and ML infrastructure across AWS, Azure, and GCP. As AI services become a critical and rapidly expanding part of cloud estates, TotalCloud ensures they are held to the same rigorous security and compliance standards as traditional cloud resources — closing a growing blind spot for security teams.
The following AI and ML services are now covered:
- AWS: Bedrock, SageMaker, Comprehend, Lex, Kendra, Translate, Bedrock AgentCore, Personalize
- Azure: Cognitive Search (Azure AI Search), Cognitive Services (Azure OpenAI Service)
- GCP: Gemini Enterprise, Agent Platform, Workbench, Colab, Endpoints
Key Benefits:
- AI-specific governance: Evaluate AI/ML service configurations against security best practices to ensure proper access controls and compliance across all your AI workloads.
- No blind spots in AI infrastructure: Extend CSPM coverage to the full spectrum of AI services, eliminating visibility gaps as AI becomes a critical part of your cloud estate.
CSPM: Real-Time Inventory with AWS EventBridge (Delta Sync)
Qualys TotalCloud now delivers real-time inventory updates for AWS cloud resources through native AWS EventBridge integration. Rather than waiting for scheduled sync cycles, TotalCloud instantly responds to infrastructure changes, triggering inventory updates the moment resources are created, modified, or deleted. A full sync continues on the recommended 48-hour cycle, with full backward compatibility for existing connector sync processes.
Key Benefits:
- Immediate cleanup for deleted resources: Assets removed from AWS are instantly marked as deletedFromCloud upon delete events, before the next regular sync cycle.
- Always-current posture: Compliance status updates automatically the moment a resource is remediated, no waiting for the next scheduled evaluation.

CWPP: Agentless Snapshot-Based Scan for GCP Cloud
Qualys TotalCloud now supports snapshot-based FlexScan for Google Cloud Compute Engine instances, enabling agentless vulnerability scanning across both online and offline GCP VMs with no manual intervention required. Qualys TotalCloud now delivers agentless vulnerability scanning across all three major cloud providers, AWS, Azure, and GCP, complementing Qualys’ powerful agent-based scanning for a complete, layered security strategy.
Key Benefits:
- Agentless and non-intrusive: No agents to deploy. Snapshot-based scanning eliminates operational overhead and avoids any impact on live system performance, even scans shutdown workloads.
- Complementary coverage with Qualys Agent: Combine snapshot scans for broad GCP coverage with Qualys Agent for deep per-workload insights, delivering a complete, layered security strategy.

CDR: Cloud Threat Detection using AWS CloudTrail Events
Qualys TotalCloud now ingests AWS CloudTrail logs in real-time directly into the Cloud Detection and Response (CDR) module, generating alerts only for events that match predefined detection rules, covering suspicious API activity, unauthorized access attempts, and anomalous user behavior. This significantly reduces noise while strengthening threat detection and incident investigation at the API and account level.
With this addition, Qualys CDR now offers four complementary detection methods, giving security teams comprehensive, multi-layered visibility across their cloud environment. Those include
- CDR Appliance-based scanning with eBPF Runtime Threat Detection
- Network Flow Log analysis
- GuardDuty Event Integration, and
- AWS CloudTrail event ingestion
Key Benefits:
- Signal over noise: Alerts are generated only when CloudTrail events match predefined rules, ensuring security teams focus on critical, high-confidence findings rather than sifting through raw log volume.
- Deeper cloud threat visibility: Correlate API-level audit activity with CDR detections to accelerate investigation and response across your AWS environment.
Cloud Connector Enhancements
Activity Logs for Cloud Connector Operations
Qualys TotalCloud now captures detailed audit logs for all Cloud Connector operations — including creation, configuration changes, deletion, enable/disable actions, and tag updates, along with user identity, timestamp, and change details. You now know exactly who made what changes and when, giving security and compliance teams complete visibility into the connector lifecycle and stronger governance over your cloud connector configurations.
Unified Cloud Onboarding Template
Qualys TotalCloud now consolidates all connector onboarding requirements into a single Unified CloudFormation Template (CFT), replacing the multiple separate templates previously required for onboarding capabilities such as CSPM role creation, remediation, and API-based vulnerability scanning. This eliminates deployment complexity and reduces the risk of missed or misconfigured components across your cloud connectors.
CSPM Enhancements
This release brings a series of focused usability and access control improvements to Qualys TotalCloud’s Cloud Security Posture Management capabilities.
| Capability | What is introduced? |
| Column Selection | Qualys TotalCloud now extends column selection across the Connector, Posture, Insights, Controls, and Response pages, letting you display only the data fields most relevant to your workflow. Hide irrelevant columns, reduce visual clutter, and create personalized views for different teams, all in just a few clicks. |
| Default Time Filter Updated to 7 Days | The default time filter across TotalCloud has been updated from 24 hours to 7 days and now applies uniformly to Inventory, Posture, Reports, Insights, and Dashboard views. This gives teams broader historical context and trend visibility out of the box, without manual filter adjustments on every session. |
| Connector Tag-Based User Scoping | Qualys TotalCloud now uses Qualys Connector tags to scope posture and inventory data for sub-users, delivering accurate and predictable access control for organizations with distributed teams and complex permission structures. Tag-based filtering is now consistently applied across all evaluation-based inventory and posture data. |
| Improvements to Policy Edit | We now offer an additional edit capability on the view policy details. Users can now edit Policy Information, Controls, and Tags/Connectors directly from the Policy Details page, reducing clicks, accelerating policy updates, and streamlining workflows for security teams managing multiple policies and connectors. |
Strengthen Inventory Coverage
Qualys TotalCloud continues to expand inventory coverage across cloud, network, and AI resources, giving security teams a more complete and accurate foundation for posture assessment and risk analysis.
| Inventory | What is added/updated? |
| AWS Organization Tags Visibility | Qualys TotalCloud now displays AWS Organization-level and account-level tags directly within resource tag information, giving teams complete visibility into organizational tagging standards and whether resources comply with enterprise tag governance policies. |
| Lambda Runtime Details on CSV Inventory Exports | Users can now export a comprehensive Lambda function inventory, including runtime versions, enabling bulk analysis, reporting, and auditing of function configurations outside the TotalCloud UI, supporting compliance documentation and infrastructure-as-code workflows. |
| Expanded Inventory Coverage for All Azure Resources | TotalCloud now delivers comprehensive metadata for the Azure inventory previously available only via evaluations, with information organized into dedicated tabs: Summary, Tags, Evaluated Controls, and more. All resource details are also accessible via API for programmatic usage. |
| GCP Gemini Enterprise, Agent Platform (Vertex AI) | TotalCloud now extends inventory support for Google Cloud Vertex AI, enabling discovery and tracking of all model registry resources, including model deployments and resource labels, providing complete visibility into your AI/ML infrastructure on GCP. |
| Improved GCP Firewall Rules Inventory | Source Ranges are now surfaced directly in the Firewall Rules section on the Inventory Details page, providing immediate access to source IPs and ranges alongside firewall configurations and eliminating tab switching during security assessments. |
TruRisk Insights: Insights Count on the Instance Listing Page
Qualys TotalCloud now displays the TruRisk Insights count directly on the Instances Listing page, letting users instantly see which instances have active attack paths and navigate directly to filtered Insights results for that resource. Use the hasAttackPath: true/false token to query programmatically, enabling faster prioritization and remediation of high-risk attack paths.
CSPM Control Enhancements
New Controls and Title Updates
Qualys continuously monitors new security controls across cloud platforms. In this release, the following new controls have been added:
- AWS:
- Approximately 25 new security controls under AWS build-time checks
- 2 new controls for CIS Amazon Web Services Foundations Benchmark
- Azure: 18 new controls for CIS Microsoft Azure Compute Services Benchmark
- GCP, OCI: Several controls are added
Control titles for a selection of AWS and OCI controls have also been refreshed to align with the latest security checks.
| For ongoing updates on control changes, refer to the TotalCloud Release Notes for version 2.25, which will be published soon on the Qualys Product Release Notes page. |
Deprecated Controls
When cloud providers deprecate specific services or features, the corresponding Qualys CSPM controls are also deprecated to maintain alignment.
For more information on impacted controls, refer to the control metadata for: AWS | Azure | GCP | OCI
| Cloud | Deprecated Controls | Reason for Deprecation |
| Azure | 5006 – Ensure that Vulnerabilities in security configuration on your machines should be remediated is set to On. | These are no longer applicable as Control parameters have been deprecated by Azure. |
| 5008 – Ensure that Disk encryption should be applied on virtual machines is set to On. |
Resources
- TotalCloud™ – The Risk-minded CNAPP. Learn more about TotalCloud CNAPP.
- Online Help for TotalCloud, Connectors, TotalCloud API User Guide
- How-to Training Videos
- If you have questions, please contact your TAM or Qualys Technical Support.