RoboShadow Tools
Written By Christopher Scaminaci
Last updated 7 days ago
RoboShadow Tools
roboshadow_ · 40 tools · Free 40
Vulnerability management and endpoint security reporting for MSPs. Every tool is a read: CVE and CPE reporting, antivirus and Microsoft Defender posture, ransomware protection, firewall configuration, missing Windows updates, remediation history, external vulnerability scans, a Microsoft 365 MFA report, and a full Windows device, hardware, disk and services inventory. One RoboShadow credential reaches several client organizations, so every tool takes an organization id — get it from roboshadow_list_organizations. Paged reports return up to 100 rows per page; the Microsoft 365 MFA report is the exception and pages in fixed blocks with a skip-pages number.
All connector tools · RoboShadow setup guide
RoboShadow tool groups
- Vulnerabilities — 7 tools
- Antivirus & Ransomware — 6 tools
- Updates & Remediation — 5 tools
- Devices & Inventory — 16 tools
- Platform — 6 tools
Vulnerabilities
roboshadow_get_cpe_vulnerabilities_report details
roboshadow_get_cpe_vulnerabilities_report details
[RoboShadow] List vulnerabilities grouped by CPE — the Common Platform Enumeration identifier for an affected product and version, rather than by CVE. Use this when the question is "which products and versions are causing our exposure"; use roboshadow_get_cve_vulnerabilities_report when the question is about a specific vulnerability. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_cve_vulnerabilities_report details
roboshadow_get_cve_vulnerabilities_report details
[RoboShadow] List the CVEs detected across an organization's Windows devices, with severity and affected-device counts. This is the primary answer to "which clients are exposed to CVE-X". Take a cveId from here to roboshadow_list_cve_fixes to find what remediates it. Paged: results come back in a totalItems + pagedData envelope. RoboShadow's own API path spells it /organisation.
roboshadow_get_device_vulnerability_summary details
roboshadow_get_device_vulnerability_summary details
[RoboShadow] Get one device's vulnerability totals — the per-machine counterpart of roboshadow_get_vulnerabilities_summary. Get the deviceId from roboshadow_list_devices or roboshadow_get_vulnerable_devices_report. Note that a RoboShadow deviceId is a plain string (for example device-67890), not a UUID. RoboShadow's own API path spells it /organisation.
roboshadow_get_vulnerabilities_summary details
roboshadow_get_vulnerabilities_summary details
[RoboShadow] Get the organization-wide vulnerability totals — the headline numbers for a security review or a client report. Start here, then drill in with roboshadow_get_cve_vulnerabilities_report or roboshadow_get_vulnerable_devices_report. organizationId comes from roboshadow_list_organizations; one RoboShadow credential usually reaches several organizations, so pass the one you want rather than assuming a default. RoboShadow's own API path spells it /organisation.
roboshadow_get_vulnerable_applications_report details
roboshadow_get_vulnerable_applications_report details
[RoboShadow] List the installed applications that carry known vulnerabilities across an organization, with the exposure each one contributes. This is usually the fastest route to a remediation plan, because one application upgrade can clear many CVEs. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_vulnerable_devices_report details
roboshadow_get_vulnerable_devices_report details
[RoboShadow] List the devices that carry known vulnerabilities across an organization, ranked by exposure. Use the deviceId from a row with roboshadow_get_device_vulnerability_summary for that machine's detail, or with roboshadow_get_device for its inventory record. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_list_cve_fixes details
roboshadow_list_cve_fixes details
[RoboShadow] List the fixes that remediate one specific CVE in an organization — the step that closes the loop from finding to remedy. Get the cveId from roboshadow_get_cve_vulnerabilities_report. To check whether a fix was actually applied afterwards, use roboshadow_get_remediation_report. RoboShadow's own API path spells it /organisation.
Antivirus & Ransomware
roboshadow_get_antivirus_report_by_device details
roboshadow_get_antivirus_report_by_device details
[RoboShadow] List every device in an organization with its antivirus product and protection state — the per-machine breakdown behind roboshadow_get_antivirus_summary_report. Use roboshadow_get_device_antivirus for one machine's detail. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_antivirus_summary_report details
roboshadow_get_antivirus_summary_report details
[RoboShadow] Get the organization-wide antivirus posture totals — how many devices are protected, unprotected, or out of date. Start here for "is every endpoint protected", then use roboshadow_get_antivirus_report_by_device to see which machines are the exceptions. RoboShadow's own API path spells it /organisation.
roboshadow_get_device_antivirus details
roboshadow_get_device_antivirus details
[RoboShadow] Get one device's antivirus product and protection state. Get the deviceId from roboshadow_list_devices or roboshadow_get_antivirus_report_by_device. Note that a RoboShadow deviceId is a plain string (for example device-67890), not a UUID. RoboShadow's own API path spells it /organisation.
roboshadow_get_ransomware_protection_report details
roboshadow_get_ransomware_protection_report details
[RoboShadow] List each device's ransomware-protection state across an organization — for example whether controlled folder access is on. Pairs with roboshadow_get_windows_defender_report for the wider Defender configuration picture. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_threats_report details
roboshadow_get_threats_report details
[RoboShadow] List the threats antivirus detected across an organization's devices — what was caught, on which machine, and what happened to it. This is the "what got caught this week" report for a client review. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_windows_defender_report details
roboshadow_get_windows_defender_report details
[RoboShadow] List each device's Microsoft Defender configuration across an organization — engine and signature state, and which protection features are enabled. Use this to find machines where Defender is installed but partly disabled, which roboshadow_get_antivirus_summary_report can still count as protected. Paged. RoboShadow's own API path spells it /organisation.
Updates & Remediation
roboshadow_get_missing_updates_report_by_device details
roboshadow_get_missing_updates_report_by_device details
[RoboShadow] List the Windows updates each device is missing, with the richest filter set in this connector. Filter by update classification (critical, security, driver, rollup, other), by device role (workstations, servers), and by whether the machine is waiting on a reboot. The classification filters combine, so passing critical=true and security=true returns both kinds. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_remediation_report details
roboshadow_get_remediation_report details
[RoboShadow] List the remediation attempts RoboShadow recorded for an organization — the evidence trail that patching actually happened, and the report to reach for when a client asks what was done. Take an attempt id from a row to roboshadow_list_remediation_attempt_cves to see exactly which CVEs that attempt addressed. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_updates_summary_report details
roboshadow_get_updates_summary_report details
[RoboShadow] Get the organization-wide missing-update totals — the headline patch-posture numbers. Start here, then use roboshadow_get_missing_updates_report_by_device to see which machines are behind and why. RoboShadow's own API path spells it /organisation.
roboshadow_list_device_updates details
roboshadow_list_device_updates details
[RoboShadow] List the Windows updates one device is missing, filterable by classification (critical, security, driver, rollup, other). Get the deviceId from roboshadow_list_devices or roboshadow_get_missing_updates_report_by_device. Note that a RoboShadow deviceId is a plain string (for example device-67890), not a UUID. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_list_remediation_attempt_cves details
roboshadow_list_remediation_attempt_cves details
[RoboShadow] List the CVEs a single remediation attempt addressed. Get the attemptId from roboshadow_get_remediation_report. This is how you prove a specific vulnerability was actually closed rather than merely reported. RoboShadow's own API path spells it /organisation.
Devices & Inventory
roboshadow_get_application_group details
roboshadow_get_application_group details
[RoboShadow] Get one application group's detail — the versions in the estate and where they are installed. Get the groupId from roboshadow_list_application_groups. RoboShadow's own API path spells it /organisation.
roboshadow_get_device details
roboshadow_get_device details
[RoboShadow] Get one device's full inventory record — operating system, agent state and hardware identity. Get the deviceId from roboshadow_list_devices. For that machine's security posture use roboshadow_get_device_antivirus or roboshadow_get_device_vulnerability_summary. RoboShadow's own API path spells it /organisation.
roboshadow_get_disk_report_by_device details
roboshadow_get_disk_report_by_device details
[RoboShadow] List each device's disks across an organization, with capacity, free space and encryption state — the unencrypted-device signal for a compliance review. Use roboshadow_list_device_disks for one machine's detail. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_disk_summary_report details
roboshadow_get_disk_summary_report details
[RoboShadow] Get the organization-wide disk totals — overall capacity, free space and encryption coverage. Use roboshadow_get_disk_report_by_device or roboshadow_get_disk_usage_report for the machines behind the numbers. RoboShadow's own API path spells it /organisation.
roboshadow_get_disk_usage_report details
roboshadow_get_disk_usage_report details
[RoboShadow] List disk usage across an organization, disk by disk — the low-disk-space signal. Use roboshadow_get_disk_report_by_device when you want the rows grouped by machine instead. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_firewall_report details
roboshadow_get_firewall_report details
[RoboShadow] List each device's Windows firewall configuration across an organization — which profiles are enabled and how inbound traffic is handled. Use this to find machines where the firewall is off on the domain or private profile. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_hardware_report_by_device details
roboshadow_get_hardware_report_by_device details
[RoboShadow] List each device's hardware specification across an organization — model, processor, memory and firmware. This is the report to reach for when planning a refresh cycle or checking hardware eligibility for an operating-system upgrade. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_get_hardware_summary_report details
roboshadow_get_hardware_summary_report details
[RoboShadow] Get the organization-wide hardware totals — the fleet view of models, memory and processor generations. Use roboshadow_get_hardware_report_by_device for the per-machine breakdown behind these numbers. RoboShadow's own API path spells it /organisation.
roboshadow_list_application_groups details
roboshadow_list_application_groups details
[RoboShadow] List the application groups RoboShadow tracks for an organization — installed software rolled up by product rather than per install. Take a group id from a row to roboshadow_get_application_group for its detail. When the question is about risk rather than inventory, roboshadow_get_vulnerable_applications_report is usually the better tool. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_list_device_applications details
roboshadow_list_device_applications details
[RoboShadow] List the applications installed on one device, with versions. Get the deviceId from roboshadow_list_devices. Use the search parameter to check for a specific product on that machine. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_list_device_disk_shares details
roboshadow_list_device_disk_shares details
roboshadow_list_device_disks details
roboshadow_list_device_disks details
[RoboShadow] List one device's disks, with capacity, free space and encryption state. Take a diskId from a row to roboshadow_list_device_disk_shares to see what that disk publishes on the network. RoboShadow's own API path spells it /organisation.
roboshadow_list_device_services details
roboshadow_list_device_services details
[RoboShadow] List the Windows services installed on one device, with their state and start type. Use the search parameter to narrow to a service name. This tool only reports service state; RoboShadow's API has no endpoint that starts, stops or reconfigures a service. Paged. RoboShadow's own API path spells it /organisation.
roboshadow_list_device_user_profiles details
roboshadow_list_device_user_profiles details
[RoboShadow] List the Windows user profiles present on one device — who has actually signed in on that machine, and how much disk each profile holds. Use roboshadow_list_device_users for the account list rather than the profile list. RoboShadow's own API path spells it /organisation.
roboshadow_list_device_users details
roboshadow_list_device_users details
[RoboShadow] List the local user accounts on one device, including whether each is enabled and whether it holds administrator rights. Use this to find stale or unexpected local admin accounts. For the organization's RoboShadow portal users instead, use roboshadow_list_organization_users. RoboShadow's own API path spells it /organisation.
roboshadow_list_devices details
roboshadow_list_devices details
[RoboShadow] List the Windows devices RoboShadow monitors for an organization. This is the entry point for every per-device tool in this connector — take a deviceId from a row and use it with roboshadow_get_device, roboshadow_get_device_antivirus, roboshadow_list_device_updates and the rest. A RoboShadow deviceId is a plain string (for example device-67890), not a UUID. Paged. RoboShadow's own API path spells it /organisation.
Platform
roboshadow_get_mfa_report details
roboshadow_get_mfa_report details
[RoboShadow] Get the Microsoft 365 multi-factor authentication report for an organization: each user's registered authentication methods, their MFA status, and whether they hold the Global Administrator role. This report pages differently from every other tool here — results arrive in fixed pages of 5000 users, and you advance with skipPages (0 is the first page) rather than page and itemsPerPage. Keep increasing skipPages while the response reports hasMoreData as true. RoboShadow's own API path spells it /organisation.
roboshadow_get_scan_ips_overview details
roboshadow_get_scan_ips_overview details
[RoboShadow] Get the per-address overview for one external vulnerability scan — which IP addresses were scanned and what was seen on each. Get the scanId from roboshadow_list_scan_status; pair it with roboshadow_get_scan_summary for the scan's overall findings. RoboShadow's own API path spells it /organisation.
roboshadow_get_scan_summary details
roboshadow_get_scan_summary details
[RoboShadow] Get the result summary for one external vulnerability scan — what the perimeter scan found. Get the scanId from roboshadow_list_scan_status. For the addresses the scan covered, use roboshadow_get_scan_ips_overview. RoboShadow's own API path spells it /organisation.
roboshadow_list_organization_users details
roboshadow_list_organization_users details
[RoboShadow] List the RoboShadow portal users attached to one organization, with their roles. Get the organizationId from roboshadow_list_organizations. For the local Windows accounts on a specific machine, use roboshadow_list_device_users instead. RoboShadow's own API path spells it /organisation.
roboshadow_list_organizations details
roboshadow_list_organizations details
[RoboShadow] List the organizations this RoboShadow credential can reach. CALL THIS FIRST: one RoboShadow credential typically covers several client organizations, and every other tool in this connector takes an organizationId that comes from here. It is also the call StackJack's Test Connection uses to validate RoboShadow credentials. RoboShadow's own API path spells it /organisation.
roboshadow_list_scan_status details
roboshadow_list_scan_status details
[RoboShadow] List the external vulnerability scans for an organization and the status of each. Filter to scheduled scans with isScheduled, or to one overall status with the status parameter. Take a scan id from a row to roboshadow_get_scan_summary or roboshadow_get_scan_ips_overview. RoboShadow's API has no endpoint that launches a scan, so this surface is status reporting only. Paged. RoboShadow's own API path spells it /organisation.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team