Security Automation Qualys TheHive n8n

Automate Qualys Reports to TheHive

Streamline vulnerability management by automatically saving Qualys scan reports to TheHive for immediate security team access. Eliminate manual report transfers and accelerate incident response.

Download Template JSON · n8n compatible · Free
Qualys to TheHive workflow diagram showing automated report transfer process

What This Workflow Does

This automation bridges the gap between Qualys vulnerability scanning and TheHive security incident management. It automatically transfers completed scan reports from Qualys into TheHive cases, ensuring security teams have immediate access to the latest vulnerability data without manual intervention.

The workflow handles report formatting, metadata preservation, and proper case assignment within TheHive. It transforms raw scan data into actionable security tickets complete with severity ratings, affected systems, and remediation recommendations.

n8n workflow interface showing Qualys to TheHive integration
The n8n workflow interface showing the Qualys to TheHive integration nodes

How It Works

1. Qualys Report Trigger

The workflow initiates when a new Qualys scan report is generated, either on a schedule or manually triggered. It authenticates with Qualys API using your credentials and retrieves the completed report.

2. Data Processing

The raw report data is parsed and transformed into TheHive's required format. Critical fields like vulnerability severity, CVSS scores, and affected assets are extracted and mapped.

3. TheHive Case Creation

The workflow creates a new case in TheHive with all relevant vulnerability data. It sets appropriate tags, severity levels, and assigns the case to the correct security team based on predefined rules.

Pro tip: Configure the workflow to tag cases by vulnerability type (e.g., "SQLi", "XSS") for easier filtering and reporting in TheHive.

Who This Is For

This automation is ideal for security operations centers (SOCs), IT security teams, and compliance officers who need to streamline vulnerability management. It's particularly valuable for organizations that:

  • Run regular Qualys vulnerability scans
  • Use TheHive for security case management
  • Need to accelerate mean time to remediation (MTTR)
  • Require audit trails for compliance reporting

What You'll Need

  1. An active Qualys subscription with API access
  2. TheHive instance (self-hosted or cloud) with API credentials
  3. n8n instance (self-hosted or cloud)
  4. Network connectivity between n8n and both Qualys/TheHive

Quick Setup Guide

  1. Download the JSON template file
  2. Import into your n8n instance
  3. Configure Qualys API credentials in the HTTP Request node
  4. Set up TheHive connection details in the corresponding nodes
  5. Test with a sample Qualys report
  6. Schedule the workflow or trigger it manually

Key Benefits

Reduced manual work: Eliminates hours spent downloading, formatting, and uploading reports between systems.

Faster response times: Security teams get vulnerability data in their workflow system immediately after scans complete.

Improved accuracy: Automated transfers prevent human errors in report handling and data entry.

Enhanced visibility: All vulnerability data resides in TheHive's searchable, trackable case management system.

Audit compliance: Creates a documented chain of custody for vulnerability findings from detection to remediation.

Frequently Asked Questions

Common questions about Qualys and TheHive integration

Automating Qualys report delivery to TheHive ensures vulnerabilities are immediately visible to security teams. This eliminates manual report transfers that often cause delays in remediation.

Security analysts can begin investigating critical vulnerabilities within minutes rather than hours. The automation also reduces the risk of reports being overlooked or delayed in email inboxes.

  • Reduces vulnerability exposure window by 60-80%
  • Ensures consistent handling of all scan results
  • Integrates with existing security workflows

Vulnerability assessment reports and compliance scan results integrate most effectively with TheHive. These reports contain actionable security findings that benefit from TheHive's case management features.

The automation works particularly well for scheduled scan reports and on-demand assessment exports. PCI DSS compliance scans and web application vulnerability reports translate especially well into TheHive cases.

  • Prioritize vulnerability reports over asset inventory
  • Focus on reports with CVSS scoring
  • Include remediation recommendations

Yes, the workflow includes chunking logic to process large reports efficiently. It splits massive vulnerability exports into manageable segments while maintaining data integrity.

The automation preserves all critical metadata during transfer to TheHive's case management system. For enterprise-scale scans, the workflow can process reports with thousands of vulnerabilities without timing out.

  • Handles reports up to 50MB in size
  • Processes 1000+ vulnerabilities per run
  • Includes error handling for API limits

The automation creates an auditable trail of vulnerability findings in TheHive. This supports compliance requirements by documenting when issues were identified and how they were addressed.

Teams can generate compliance evidence directly from TheHive's case history. The workflow timestamps all actions, creating a clear chain of custody for auditors reviewing vulnerability management processes.

  • Supports PCI DSS Requirement 11.2
  • Documents remediation timelines
  • Provides searchable case history

TheHive provides collaborative investigation tools that Qualys lacks. Security teams can assign vulnerabilities, track remediation progress, and link related incidents.

The platform's timeline view helps visualize vulnerability trends across multiple scans. Analysts can correlate Qualys findings with other security events in TheHive's unified workspace.

  • Enables team collaboration on remediation
  • Provides workflow for vulnerability lifecycle
  • Integrates with other security tools

Most organizations configure daily or weekly transfers for ongoing scans. Critical systems may require real-time reporting.

The workflow supports both scheduled and trigger-based execution to match your security operations tempo. High-value assets might use immediate reporting, while less critical systems can use batch processing.

  • External systems: daily scans
  • Critical servers: real-time alerts
  • Compliance scans: after each assessment

Yes, GrowwStacks specializes in tailored security automation solutions. We can customize this workflow for your specific Qualys configuration, TheHive instance, and security team workflows.

Our engineers will ensure seamless integration with your existing tools and processes. We'll adapt the automation to your unique security policies, report formats, and case management requirements.

  • Custom severity mappings
  • Team-specific case assignments
  • Integration with other security tools

Need a Custom Qualys-TheHive Integration?

This free template is a starting point. Our team builds fully tailored automation systems for your specific needs.