Vigilance vs Qualys FIM

Qualys FIM. Watches files on your servers and reports every change to the cloud. Vigilance finds the update that gained a hidden power, before you install it.

Updated 5 Oct 2026

Start Free See Pricing

The Catch Qualys FIM Cannot Make

Qualys FIM reports file changes with details of who and what made them. It does not say what the change can do. Vigilance reads the change itself. It compares the version you trust with the version you install. It reports any file that can suddenly do more.

A real one: xz Utils, 2024

xz is a compression library on almost every Linux server. In release 5.6.1, a hidden backdoor shipped inside liblzma. It can intercept a remote login. The release was signed by its own maintainer. Qualys FIM flags the file as changed. It cannot say what the file can now do. One command sees it:

vigi diff --old ./xz-5.4.6 --new ./xz-5.6.1

HEADS UP. 1 file changed. liblzma can now run hidden code during a remote login.

Run both. Qualys FIM reports that a file changed. Vigilance sends word of what the file can now do. See them side by side below.

What Qualys FIM Does Well

Qualys FIM is a cloud app for file integrity monitoring. It uses the Qualys Cloud Agent and watches Windows and Linux systems for file changes across cloud, on-premises and hybrid assets. Source: the Qualys blog.

Qualys records the detail an auditor wants. It reports kernel-level change detection with the time, the user, the process and the owner of the process. A reviewer can answer who changed a file, when and with which program.

Qualys ships ready-made monitoring profiles for mandates such as PCI DSS, so a security team does not start from a blank policy. It also describes a curated library of file paths chosen to reduce noise. Qualys claims a noise cancellation feature that uses threat intelligence to cut false alerts by more than 90 percent. That figure is Qualys' own claim. Qualys also describes automated incident management for suspicious change events.

The product sits on the same agent as the rest of the Qualys platform. A company that already uses Qualys for vulnerability work adds FIM without a new rollout.

Where It Falls Short

Qualys FIM answers who changed a file and when. It does not describe a check of what the file can now do. A file that changed because of a normal update and a file that changed because of an attack look alike in a change log.

It needs the Cloud Agent on each machine and reports to the Qualys cloud. A shop that cannot send change data to a cloud service, or that has no agent policy for some machines, has a gap.

Software that is about to land is outside its view. Qualys FIM watches a live machine. It does not read a package or an installer before you install it. The Qualys pages Vigilance read list no price.

Feature Comparison

Qualys FIM watches live machines and records who changed a file, and Vigilance compares versions and reports new capabilities. The table shows how they differ.

Question Qualys FIM Vigilance
Watches files on a server for change Yes Yes
Records the user and process behind a change Yes No
Has ready-made profiles for PCI DSS Yes No
Tells you a file gained a new capability, not just a change Not described Yes
Needs a policy or a path list to start Profiles supply it No
Looks inside a package or installer before it lands No Yes
Sends changes to a cloud service Yes Pro: No. Free sends a signed report of hashes and capabilities only. A name, an email or a file is sent only if you opt in, and each one needs its own yes.
Works with no internet No Pro

When Qualys FIM Is the Better Fit

Choose Qualys FIM if an auditor must see a change record with the user and the process. This is the central use of the product.

Choose it if you work toward PCI DSS file integrity requirements and want ready-made profiles. Read the file integrity monitoring guide for what that standard asks.

Choose it if you already run the Qualys Cloud Agent. FIM then adds to a platform you know.

Choose it if you need continuous watching of live servers on Windows and Linux.

File Integrity for Audit Versus for Updates

Auditors ask a set of questions about files. Who changed this? When? Was the change approved? Qualys FIM is built to answer these. Vigilance does not record the user or the process, and it is not an audit log.

Security teams ask another question. Did the update I just installed add a power that the old one did not have? Vigilance is built for that. It compares the version you trust with the new one and shows the file that gained a capability.

The xz example above shows the difference. A change record flags a changed library file. Vigilance says that the file can now run hidden code during a remote login.

Running Both on a Server Fleet

Use Qualys FIM for the standing watch. It records changes on live servers and gives your auditor evidence.

Use Vigilance when new software arrives. Check the new version against the one you trust before you roll it out to the fleet. This is a cheap step, and it catches the change that a log of changed files cannot explain.

Vigilance enrols a machine with one line from Intune, Jamf, a GPO or an image. Each machine signs its own receipt into a folder you already back up, so no cloud password sits on a watched machine.

The two tools do not conflict. One watches the machine and the other checks the update.

What to Ask Before You Choose

Ask what your auditor needs to see. If the answer is a record with the user and the process, a tool built for audit is the right choice. Vigilance does not keep such a record.

Ask whether you can send change data to a cloud service. Qualys FIM reports to the Qualys cloud app. Some regulated sites cannot do that for every machine.

Ask how you will decide whether a change was an attack. A change record shows a changed file. A capability compare shows whether the file can now do more.

Ask which systems you must cover. Qualys describes Windows and Linux. Check your own list of operating systems before you buy.

Pricing

The Qualys pages Vigilance read list no price for Qualys FIM. Qualys describes FIM as a cloud app that runs on its Cloud Agent, so expect a quote from a sales team. Vigilance has a Free plan at $0 with the full scanner for up to 50 machines. Free needs a network and sends a signed report of hashes and capabilities only. A name, an email or a file is sent only if you opt in, and each one needs its own yes. Pro works with no network at all. It is flat for the whole company, starts at $999 CAD a month, and the price steps with company size, not with the machine count.

Which One Do You Need?

Qualys FIM records who changed a file, for an auditor. Vigilance tells you what the change lets the file do. They answer different questions.

Read how the two sit among other options in software supply chain security tools, or see real attacks that Vigilance replays.

Known Risk versus New Risk

Known risk

A bug or a bad package someone already reported, with a name and a number. Most tools work here.

New risk

A file that gained a capability it never had, that no report covers yet. Vigilance works here.

Common Questions

Is Vigilance a Qualys FIM alternative?

Yes, for one job. Vigilance shows the file that gained a new capability, on your own machine. It does not record who changed a file, so it does not replace the audit record from Qualys FIM.

What does Vigilance do that Qualys FIM does not?

Vigilance reads what a change lets a file do and checks a package or installer before it lands. It needs no policy and no cloud agent.

What does Qualys FIM do that Vigilance does not?

Qualys FIM watches live Windows and Linux systems and records the user and process behind each change. It has ready-made profiles for compliance such as PCI DSS.

How does Qualys FIM work?

Qualys FIM runs on the Qualys Cloud Agent. It detects file changes at the kernel level and reports the time, user and process to the Qualys cloud app.

Does Vigilance need the internet or a cloud account?

The Free plan runs online. Pro runs fully offline, with no cloud account.

Try It on Your Own Software.

Show it the version you run today and the one you are about to install.

Download Vigilance Talk to Us

Talk to Us

A question, a pilot, or a bigger fleet? Send a note. It reaches a person.