Qualys: Alert When Firewall Product Is Not Detected on a Host

Alerts when Qualys reports a host missing a detectable firewall product during vulnerability management scanning.

FreeReviewedSigma · Low · v5
Product
qualys
Author
Alexandr Yampolskyi, SOC Prime (SigmaHQ), DRL 1.1
Published
2019-03-19
Updated
2026-07-31

What it detects

This rule flags Qualys vulnerability management scan results where the host reports that no firewall product was detected. Attackers rely on weakened network controls, and missing or unrecognized firewall protections can increase exposure to later exploitation and lateral movement. The detection relies on Qualys event telemetry indicating a security policy category finding with the text substring "Firewall Product Not Detected" in the reported vulnerability name.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.