Skip to main content
Tools Reference

RoboShadow Tools

Written By Christopher Scaminaci

Last updated 7 days ago

RoboShadow Tools

roboshadow_ · 40 tools · Free 40 Vulnerability management and endpoint security reporting for MSPs. Every tool is a read: CVE and CPE reporting, antivirus and Microsoft Defender posture, ransomware protection, firewall configuration, missing Windows updates, remediation history, external vulnerability scans, a Microsoft 365 MFA report, and a full Windows device, hardware, disk and services inventory. One RoboShadow credential reaches several client organizations, so every tool takes an organization id — get it from roboshadow_list_organizations. Paged reports return up to 100 rows per page; the Microsoft 365 MFA report is the exception and pages in fixed blocks with a skip-pages number.

All connector tools · RoboShadow setup guide

RoboShadow tool groups

Vulnerabilities

ToolPlanAccessSummary
roboshadow_get_cpe_vulnerabilities_reportFreeRead-onlyList vulnerabilities grouped by CPE — the Common Platform Enumeration identifier for an affected product and version, rather than by CVE.
roboshadow_get_cve_vulnerabilities_reportFreeRead-onlyList the CVEs detected across an organization's Windows devices, with severity and affected-device counts.
roboshadow_get_device_vulnerability_summaryFreeRead-onlyGet one device's vulnerability totals — the per-machine counterpart of roboshadow_get_vulnerabilities_summary.
roboshadow_get_vulnerabilities_summaryFreeRead-onlyGet the organization-wide vulnerability totals — the headline numbers for a security review or a client report.
roboshadow_get_vulnerable_applications_reportFreeRead-onlyList the installed applications that carry known vulnerabilities across an organization, with the exposure each one contributes.
roboshadow_get_vulnerable_devices_reportFreeRead-onlyList the devices that carry known vulnerabilities across an organization, ranked by exposure.
roboshadow_list_cve_fixesFreeRead-onlyList the fixes that remediate one specific CVE in an organization — the step that closes the loop from finding to remedy.

[RoboShadow] List vulnerabilities grouped by CPE — the Common Platform Enumeration identifier for an affected product and version, rather than by CVE. Use this when the question is "which products and versions are causing our exposure"; use roboshadow_get_cve_vulnerabilities_report when the question is about a specific vulnerability. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] List the CVEs detected across an organization's Windows devices, with severity and affected-device counts. This is the primary answer to "which clients are exposed to CVE-X". Take a cveId from here to roboshadow_list_cve_fixes to find what remediates it. Paged: results come back in a totalItems + pagedData envelope. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
daysintegernonullOptional: restrict the report to the last N days.
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] Get one device's vulnerability totals — the per-machine counterpart of roboshadow_get_vulnerabilities_summary. Get the deviceId from roboshadow_list_devices or roboshadow_get_vulnerable_devices_report. Note that a RoboShadow deviceId is a plain string (for example device-67890), not a UUID. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] Get the organization-wide vulnerability totals — the headline numbers for a security review or a client report. Start here, then drill in with roboshadow_get_cve_vulnerabilities_report or roboshadow_get_vulnerable_devices_report. organizationId comes from roboshadow_list_organizations; one RoboShadow credential usually reaches several organizations, so pass the one you want rather than assuming a default. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
daysintegernonullOptional: restrict the report to the last N days. Omit for the full history.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List the installed applications that carry known vulnerabilities across an organization, with the exposure each one contributes. This is usually the fastest route to a remediation plan, because one application upgrade can clear many CVEs. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
daysintegernonullOptional: restrict the report to the last N days.
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] List the devices that carry known vulnerabilities across an organization, ranked by exposure. Use the deviceId from a row with roboshadow_get_device_vulnerability_summary for that machine's detail, or with roboshadow_get_device for its inventory record. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
daysintegernonullOptional: restrict the report to the last N days.
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] List the fixes that remediate one specific CVE in an organization — the step that closes the loop from finding to remedy. Get the cveId from roboshadow_get_cve_vulnerabilities_report. To check whether a fix was actually applied afterwards, use roboshadow_get_remediation_report. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
cveIdstringyesThe CVE identifier, for example CVE-2024-21412 (from roboshadow_get_cve_vulnerabilities_report).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

Antivirus & Ransomware

ToolPlanAccessSummary
roboshadow_get_antivirus_report_by_deviceFreeRead-onlyList every device in an organization with its antivirus product and protection state — the per-machine breakdown behind roboshadow_get_antivirus_summary_report.
roboshadow_get_antivirus_summary_reportFreeRead-onlyGet the organization-wide antivirus posture totals — how many devices are protected, unprotected, or out of date.
roboshadow_get_device_antivirusFreeRead-onlyGet one device's antivirus product and protection state.
roboshadow_get_ransomware_protection_reportFreeRead-onlyList each device's ransomware-protection state across an organization — for example whether controlled folder access is on.
roboshadow_get_threats_reportFreeRead-onlyList the threats antivirus detected across an organization's devices — what was caught, on which machine, and what happened to it.
roboshadow_get_windows_defender_reportFreeRead-onlyList each device's Microsoft Defender configuration across an organization — engine and signature state, and which protection features are enabled.

[RoboShadow] List every device in an organization with its antivirus product and protection state — the per-machine breakdown behind roboshadow_get_antivirus_summary_report. Use roboshadow_get_device_antivirus for one machine's detail. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] Get the organization-wide antivirus posture totals — how many devices are protected, unprotected, or out of date. Start here for "is every endpoint protected", then use roboshadow_get_antivirus_report_by_device to see which machines are the exceptions. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] Get one device's antivirus product and protection state. Get the deviceId from roboshadow_list_devices or roboshadow_get_antivirus_report_by_device. Note that a RoboShadow deviceId is a plain string (for example device-67890), not a UUID. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List each device's ransomware-protection state across an organization — for example whether controlled folder access is on. Pairs with roboshadow_get_windows_defender_report for the wider Defender configuration picture. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] List the threats antivirus detected across an organization's devices — what was caught, on which machine, and what happened to it. This is the "what got caught this week" report for a client review. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] List each device's Microsoft Defender configuration across an organization — engine and signature state, and which protection features are enabled. Use this to find machines where Defender is installed but partly disabled, which roboshadow_get_antivirus_summary_report can still count as protected. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

Updates & Remediation

ToolPlanAccessSummary
roboshadow_get_missing_updates_report_by_deviceFreeRead-onlyList the Windows updates each device is missing, with the richest filter set in this connector.
roboshadow_get_remediation_reportFreeRead-onlyList the remediation attempts RoboShadow recorded for an organization — the evidence trail that patching actually happened, and the report to reach for when a client asks what was done.
roboshadow_get_updates_summary_reportFreeRead-onlyGet the organization-wide missing-update totals — the headline patch-posture numbers.
roboshadow_list_device_updatesFreeRead-onlyList the Windows updates one device is missing, filterable by classification (critical, security, driver, rollup, other).
roboshadow_list_remediation_attempt_cvesFreeRead-onlyList the CVEs a single remediation attempt addressed.

[RoboShadow] List the Windows updates each device is missing, with the richest filter set in this connector. Filter by update classification (critical, security, driver, rollup, other), by device role (workstations, servers), and by whether the machine is waiting on a reboot. The classification filters combine, so passing critical=true and security=true returns both kinds. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
criticalbooleannonullOptional: include critical updates.
daysintegernonullOptional: restrict the report to the last N days.
driverbooleannonullOptional: include driver updates.
isRebootRequiredbooleannonullOptional: restrict to devices that are waiting on a reboot.
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
otherbooleannonullOptional: include updates in the 'other' classification.
pageintegerno11-based page number (default 1).
rollupbooleannonullOptional: include rollup updates.
searchstringnonullOptional free-text search over the results.
securitybooleannonullOptional: include security updates.
serversbooleannonullOptional: include server devices.
sortBystringnonullOptional field name to sort by.
sortDescbooleannonullOptional: sort descending instead of ascending.
workstationsbooleannonullOptional: include workstation devices.

[RoboShadow] List the remediation attempts RoboShadow recorded for an organization — the evidence trail that patching actually happened, and the report to reach for when a client asks what was done. Take an attempt id from a row to roboshadow_list_remediation_attempt_cves to see exactly which CVEs that attempt addressed. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
daysintegernonullOptional: restrict the report to the last N days.
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).
searchstringnonullOptional free-text search over the results.

[RoboShadow] Get the organization-wide missing-update totals — the headline patch-posture numbers. Start here, then use roboshadow_get_missing_updates_report_by_device to see which machines are behind and why. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
daysintegernonullOptional: restrict the report to the last N days.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List the Windows updates one device is missing, filterable by classification (critical, security, driver, rollup, other). Get the deviceId from roboshadow_list_devices or roboshadow_get_missing_updates_report_by_device. Note that a RoboShadow deviceId is a plain string (for example device-67890), not a UUID. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
criticalbooleannonullOptional: include critical updates.
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
driverbooleannonullOptional: include driver updates.
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
otherbooleannonullOptional: include updates in the 'other' classification.
pageintegerno11-based page number (default 1).
rollupbooleannonullOptional: include rollup updates.
securitybooleannonullOptional: include security updates.

[RoboShadow] List the CVEs a single remediation attempt addressed. Get the attemptId from roboshadow_get_remediation_report. This is how you prove a specific vulnerability was actually closed rather than merely reported. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
attemptIdstringyesThe remediation attempt id from roboshadow_get_remediation_report.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

Devices & Inventory

ToolPlanAccessSummary
roboshadow_get_application_groupFreeRead-onlyGet one application group's detail — the versions in the estate and where they are installed.
roboshadow_get_deviceFreeRead-onlyGet one device's full inventory record — operating system, agent state and hardware identity.
roboshadow_get_disk_report_by_deviceFreeRead-onlyList each device's disks across an organization, with capacity, free space and encryption state — the unencrypted-device signal for a compliance review.
roboshadow_get_disk_summary_reportFreeRead-onlyGet the organization-wide disk totals — overall capacity, free space and encryption coverage.
roboshadow_get_disk_usage_reportFreeRead-onlyList disk usage across an organization, disk by disk — the low-disk-space signal.
roboshadow_get_firewall_reportFreeRead-onlyList each device's Windows firewall configuration across an organization — which profiles are enabled and how inbound traffic is handled.
roboshadow_get_hardware_report_by_deviceFreeRead-onlyList each device's hardware specification across an organization — model, processor, memory and firmware.
roboshadow_get_hardware_summary_reportFreeRead-onlyGet the organization-wide hardware totals — the fleet view of models, memory and processor generations.
roboshadow_list_application_groupsFreeRead-onlyList the application groups RoboShadow tracks for an organization — installed software rolled up by product rather than per install.
roboshadow_list_device_applicationsFreeRead-onlyList the applications installed on one device, with versions.
roboshadow_list_device_disk_sharesFreeRead-onlyList the network shares published from one disk on one device — useful for finding unexpected or overly broad file shares.
roboshadow_list_device_disksFreeRead-onlyList one device's disks, with capacity, free space and encryption state.
roboshadow_list_device_servicesFreeRead-onlyList the Windows services installed on one device, with their state and start type.
roboshadow_list_device_user_profilesFreeRead-onlyList the Windows user profiles present on one device — who has actually signed in on that machine, and how much disk each profile holds.
roboshadow_list_device_usersFreeRead-onlyList the local user accounts on one device, including whether each is enabled and whether it holds administrator rights.
roboshadow_list_devicesFreeRead-onlyList the Windows devices RoboShadow monitors for an organization.

[RoboShadow] Get one application group's detail — the versions in the estate and where they are installed. Get the groupId from roboshadow_list_application_groups. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
groupIdstringyesThe application group id from roboshadow_list_application_groups.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] Get one device's full inventory record — operating system, agent state and hardware identity. Get the deviceId from roboshadow_list_devices. For that machine's security posture use roboshadow_get_device_antivirus or roboshadow_get_device_vulnerability_summary. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List each device's disks across an organization, with capacity, free space and encryption state — the unencrypted-device signal for a compliance review. Use roboshadow_list_device_disks for one machine's detail. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] Get the organization-wide disk totals — overall capacity, free space and encryption coverage. Use roboshadow_get_disk_report_by_device or roboshadow_get_disk_usage_report for the machines behind the numbers. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List disk usage across an organization, disk by disk — the low-disk-space signal. Use roboshadow_get_disk_report_by_device when you want the rows grouped by machine instead. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] List each device's Windows firewall configuration across an organization — which profiles are enabled and how inbound traffic is handled. Use this to find machines where the firewall is off on the domain or private profile. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] List each device's hardware specification across an organization — model, processor, memory and firmware. This is the report to reach for when planning a refresh cycle or checking hardware eligibility for an operating-system upgrade. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).

[RoboShadow] Get the organization-wide hardware totals — the fleet view of models, memory and processor generations. Use roboshadow_get_hardware_report_by_device for the per-machine breakdown behind these numbers. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List the application groups RoboShadow tracks for an organization — installed software rolled up by product rather than per install. Take a group id from a row to roboshadow_get_application_group for its detail. When the question is about risk rather than inventory, roboshadow_get_vulnerable_applications_report is usually the better tool. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).
searchstringnonullOptional free-text search, for example part of a product name.
sortBystringnonullOptional field name to sort by.
sortDescbooleannonullOptional: sort descending instead of ascending.

[RoboShadow] List the applications installed on one device, with versions. Get the deviceId from roboshadow_list_devices. Use the search parameter to check for a specific product on that machine. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).
searchstringnonullOptional free-text search, for example part of an application name.

[RoboShadow] List the network shares published from one disk on one device — useful for finding unexpected or overly broad file shares. Get the deviceId from roboshadow_list_devices and the diskId from roboshadow_list_device_disks. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
diskIdstringyesThe disk id from roboshadow_list_device_disks.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List one device's disks, with capacity, free space and encryption state. Take a diskId from a row to roboshadow_list_device_disk_shares to see what that disk publishes on the network. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List the Windows services installed on one device, with their state and start type. Use the search parameter to narrow to a service name. This tool only reports service state; RoboShadow's API has no endpoint that starts, stops or reconfigures a service. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).
searchstringnonullOptional free-text search, for example part of a service name.

[RoboShadow] List the Windows user profiles present on one device — who has actually signed in on that machine, and how much disk each profile holds. Use roboshadow_list_device_users for the account list rather than the profile list. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List the local user accounts on one device, including whether each is enabled and whether it holds administrator rights. Use this to find stale or unexpected local admin accounts. For the organization's RoboShadow portal users instead, use roboshadow_list_organization_users. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
deviceIdstringyesThe device id (a plain string, not a UUID) from roboshadow_list_devices.
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List the Windows devices RoboShadow monitors for an organization. This is the entry point for every per-device tool in this connector — take a deviceId from a row and use it with roboshadow_get_device, roboshadow_get_device_antivirus, roboshadow_list_device_updates and the rest. A RoboShadow deviceId is a plain string (for example device-67890), not a UUID. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).
searchstringnonullOptional free-text search, for example a hostname fragment.
sortBystringnonullOptional field name to sort by.
sortDescbooleannonullOptional: sort descending instead of ascending.

Platform

ToolPlanAccessSummary
roboshadow_get_mfa_reportFreeRead-onlyGet the Microsoft 365 multi-factor authentication report for an organization: each user's registered authentication methods, their MFA status, and whether they hold the Global Administrator role.
roboshadow_get_scan_ips_overviewFreeRead-onlyGet the per-address overview for one external vulnerability scan — which IP addresses were scanned and what was seen on each.
roboshadow_get_scan_summaryFreeRead-onlyGet the result summary for one external vulnerability scan — what the perimeter scan found.
roboshadow_list_organization_usersFreeRead-onlyList the RoboShadow portal users attached to one organization, with their roles.
roboshadow_list_organizationsFreeRead-onlyList the organizations this RoboShadow credential can reach.
roboshadow_list_scan_statusFreeRead-onlyList the external vulnerability scans for an organization and the status of each.

[RoboShadow] Get the Microsoft 365 multi-factor authentication report for an organization: each user's registered authentication methods, their MFA status, and whether they hold the Global Administrator role. This report pages differently from every other tool here — results arrive in fixed pages of 5000 users, and you advance with skipPages (0 is the first page) rather than page and itemsPerPage. Keep increasing skipPages while the response reports hasMoreData as true. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id from roboshadow_list_organizations. RoboShadow calls this one the organization's external identifier and, unlike every other tool here, does not document it as a UUID.
skipPagesintegerno0Zero-based page to skip to; pages hold 5000 users each. Default 0 (the first page).

[RoboShadow] Get the per-address overview for one external vulnerability scan — which IP addresses were scanned and what was seen on each. Get the scanId from roboshadow_list_scan_status; pair it with roboshadow_get_scan_summary for the scan's overall findings. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
scanIdstringyesThe scan id from roboshadow_list_scan_status.

[RoboShadow] Get the result summary for one external vulnerability scan — what the perimeter scan found. Get the scanId from roboshadow_list_scan_status. For the addresses the scan covered, use roboshadow_get_scan_ips_overview. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
scanIdstringyesThe scan id from roboshadow_list_scan_status.

[RoboShadow] List the RoboShadow portal users attached to one organization, with their roles. Get the organizationId from roboshadow_list_organizations. For the local Windows accounts on a specific machine, use roboshadow_list_device_users instead. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.

[RoboShadow] List the organizations this RoboShadow credential can reach. CALL THIS FIRST: one RoboShadow credential typically covers several client organizations, and every other tool in this connector takes an organizationId that comes from here. It is also the call StackJack's Test Connection uses to validate RoboShadow credentials. RoboShadow's own API path spells it /organisation.

[RoboShadow] List the external vulnerability scans for an organization and the status of each. Filter to scheduled scans with isScheduled, or to one overall status with the status parameter. Take a scan id from a row to roboshadow_get_scan_summary or roboshadow_get_scan_ips_overview. RoboShadow's API has no endpoint that launches a scan, so this surface is status reporting only. Paged. RoboShadow's own API path spells it /organisation.

ParamTypeRequiredDefaultDescription
isScheduledbooleannonullOptional: restrict to scans that were (true) or were not (false) started by a schedule.
itemsPerPageintegerno50Records per page (default 50, maximum 100).
organizationIdstringyesThe organization id (a UUID) from roboshadow_list_organizations.
pageintegerno11-based page number (default 1).
sortBystringnonullOptional field name to sort by.
sortDescbooleannonullOptional: sort descending instead of ascending.
statusstringnonullOptional: filter scans by their overall status.