Skip to main content
Tools Reference

CyberCNS (ConnectSecure) Tools

Written By Christopher Scaminaci

Last updated 7 days ago

CyberCNS (ConnectSecure) Tools

cns_ · 295 tools · Free 243 · Pro 52 Vulnerability management and compliance assessment. Credentials are a tenant name, client id and client secret exchanged for a session token; there is no refresh token, so recovery is a fresh exchange. The base address is your own pod host or on-premises server. Every path carries its own verb prefix, so read, write, delete and report paths differ by more than the HTTP method. Paging is skip and limit, with a per-endpoint condition filter language and a sort parameter. Rate limits are 300 a minute, 2,000 an hour and 30,000 a day.

All connector tools · CyberCNS (ConnectSecure) setup guide

CyberCNS (ConnectSecure) tool groups

Companies

ToolPlanAccessSummary
cns_delete_companiesProDestructivePermanently delete a managed company by id (from cns_list_companies).
cns_delete_custom_ticketing_templateProDestructivePermanently delete a custom ticketing template by id (from cns_list_custom_ticketing_template).
cns_get_app_baseline_plan_globalFreeRead-onlyGet a single global application-baseline plan entry by id (from cns_list_app_baseline_plan_global).
cns_get_companiesFreeRead-onlyGet a single managed company by its id (discover ids with cns_list_companies).
cns_get_company_statsFreeRead-onlyGet the rolled-up statistics for a single company by id.
cns_get_custom_ticketing_templateFreeRead-onlyGet a single custom ticketing template by id (from cns_list_custom_ticketing_template).
cns_list_app_baseline_plan_globalFreeRead-onlyList the global application-baseline plan entries — the tenant-wide baseline of approved/expected applications used to flag baseline deviations.
cns_list_asset_windows_compatibilityFreeRead-onlyList Windows OS patch/upgrade compatibility status across assets (e.g. which assets can move to a newer Windows build).
cns_list_companiesFreeRead-onlyList the managed companies (clients) in your ConnectSecure tenant.
cns_list_company_statsFreeRead-onlyList rolled-up statistics per company (asset counts, external/internal totals, risk figures).
cns_list_custom_ticketing_templateFreeRead-onlyList the custom ticketing templates configured for the tenant (used to shape tickets pushed to integrated PSA/ticketing systems).
cns_save_companiesProWriteCreate or update a managed company.
cns_save_custom_ticketing_templateProWriteCreate or update a custom ticketing template.

[CyberCNS (ConnectSecure)] Permanently delete a managed company by id (from cns_list_companies). This removes the company and its associated data in ConnectSecure and cannot be undone. A 403 means the API key's user lacks delete access.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the company to delete (from cns_list_companies).

[CyberCNS (ConnectSecure)] Permanently delete a custom ticketing template by id (from cns_list_custom_ticketing_template). Cannot be undone.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the custom ticketing template to delete.
ParamTypeRequiredDefaultDescription
idstringyesThe global app-baseline-plan entry id.

[CyberCNS (ConnectSecure)] Get a single managed company by its id (discover ids with cns_list_companies). Returns the company's full record.

ParamTypeRequiredDefaultDescription
idstringyesThe company id (from cns_list_companies).

[CyberCNS (ConnectSecure)] Get the rolled-up statistics for a single company by id. Discover ids with cns_list_company_stats or cns_list_companies.

ParamTypeRequiredDefaultDescription
idstringyesThe company id whose stats to fetch.
ParamTypeRequiredDefaultDescription
idstringyesThe custom ticketing template id.

[CyberCNS (ConnectSecure)] List the global application-baseline plan entries — the tenant-wide baseline of approved/expected applications used to flag baseline deviations. Filter with condition and sort with order_by. Paginated with skip + limit. Use cns_get_app_baseline_plan_global for one entry; see the company/asset baseline reads for scoped variants.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created:desc.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List Windows OS patch/upgrade compatibility status across assets (e.g. which assets can move to a newer Windows build). Filter with condition (e.g. condition=status=true) and sort with order_by (e.g. order_by=created). Paginated with skip + limit.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. status=true.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List the managed companies (clients) in your ConnectSecure tenant. Returns each company's id, name, and configuration. Filter with the ConnectSecure condition language (e.g. condition=name:startswith:abc) and sort with order_by (e.g. order_by=created or order_by=created:desc). Paginated with skip + limit. Use the returned company id with cns_get_companies, and as company_id inside condition on asset/report tools.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. name:startswith:abc.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created or created:desc.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List rolled-up statistics per company (asset counts, external/internal totals, risk figures). Filter with condition (e.g. condition=total_assets_external>1000) and sort with order_by. Paginated with skip + limit. Use cns_get_company_stats for one company's stats.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. total_assets_external>1000.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. total_assets_external.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List the custom ticketing templates configured for the tenant (used to shape tickets pushed to integrated PSA/ticketing systems). Filter with condition (e.g. condition=template_name:like:custom) and sort with order_by (e.g. order_by=created:desc). Paginated with skip + limit. Use cns_get_custom_ticketing_template for one template.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. template_name:like:custom.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created:desc.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] Create or update a managed company. Provide a JSON object body with the company fields (e.g. name and any tenant-specific configuration); include the record id to update an existing company, omit it to create a new one. A 403 means the API key's user lacks write access — re-issue the key from a user with company management rights.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body of company fields. Include id to update, omit to create.

[CyberCNS (ConnectSecure)] Create or update a custom ticketing template. Provide a JSON object body with the template fields (e.g. template_name and the template body/mapping); include the id to update an existing template, omit it to create a new one.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body of template fields. Include id to update, omit to create.

Agents & Credentials

ToolPlanAccessSummary
cns_delete_agent_discoverysettings_mappingProDestructivePermanently delete an agent-to-discovery-settings mapping by id (from cns_list_agent_discoverysettings_mapping).
cns_delete_credentialsProDestructivePermanently delete a scan credential by id (from cns_list_credentials).
cns_delete_discovery_settingsProDestructivePermanently delete a discovery-settings record by id (from cns_list_discovery_settings).
cns_get_agent_credentials_mappingFreeRead-onlyGet a single agent-to-credentials mapping by id (from cns_list_agent_credentials_mapping).
cns_get_agent_discoverysettings_mappingFreeRead-onlyGet a single agent-to-discovery-settings mapping by id (from cns_list_agent_discoverysettings_mapping).
cns_get_agentsFreeRead-onlyGet a single scanning agent by its id (from cns_list_agents).
cns_get_credentialsFreeRead-onlyGet a single scan credential record by id (from cns_list_credentials).
cns_get_discovery_settingsFreeRead-onlyGet a single discovery-settings record by id (from cns_list_discovery_settings).
cns_list_agent_credentials_mappingFreeRead-onlyList the mappings that bind scanning agents to the credentials they use.
cns_list_agent_discoverysettings_mappingFreeRead-onlyList the mappings that bind scanning agents to discovery settings.
cns_list_agentsFreeRead-onlyList the scanning agents associated with your companies.
cns_list_credentialsFreeRead-onlyList the scan credentials configured for a company (used by agents to authenticate to targets).
cns_list_discovery_settingsFreeRead-onlyList the discovery settings for a company (the address ranges/targets, exclusions, tags, and profiles that steer network discovery).
cns_save_agent_credentials_mappingProWriteCreate or update a mapping binding a scanning agent to a set of credentials.
cns_save_agent_discoverysettings_mappingProWriteCreate or update a mapping binding a scanning agent to a set of discovery settings.
cns_save_credentialsProWriteCreate or update a scan credential.
cns_save_discovery_settingsProWriteCreate or update a discovery-settings record.

[CyberCNS (ConnectSecure)] Permanently delete an agent-to-discovery-settings mapping by id (from cns_list_agent_discoverysettings_mapping). This unbinds the agent from those discovery settings and cannot be undone.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the agent-discovery-settings mapping to delete.

[CyberCNS (ConnectSecure)] Permanently delete a scan credential by id (from cns_list_credentials). Agents mapped to it will no longer be able to use it. Cannot be undone.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the credential to delete.

[CyberCNS (ConnectSecure)] Permanently delete a discovery-settings record by id (from cns_list_discovery_settings). Cannot be undone.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the discovery-settings record to delete.
ParamTypeRequiredDefaultDescription
idstringyesThe agent-credentials mapping id.
ParamTypeRequiredDefaultDescription
idstringyesThe agent-discovery-settings mapping id.

[CyberCNS (ConnectSecure)] Get a single scanning agent by its id (from cns_list_agents). Returns the agent's full detail. To reset/re-register agents, use cns_reset_agents.

ParamTypeRequiredDefaultDescription
idstringyesThe agent id (from cns_list_agents).

[CyberCNS (ConnectSecure)] Get a single scan credential record by id (from cns_list_credentials). Returns credential metadata only — never the raw secret.

ParamTypeRequiredDefaultDescription
idstringyesThe credential id (from cns_list_credentials).
ParamTypeRequiredDefaultDescription
idstringyesThe discovery-settings id (from cns_list_discovery_settings).

[CyberCNS (ConnectSecure)] List the mappings that bind scanning agents to the credentials they use. Filter with condition (e.g. condition=agent_id=123 or condition=credentials_id=789) and sort with order_by (e.g. order_by=created_at). Paginated with skip + limit. Discover agent ids with cns_list_agents and credential ids with cns_list_credentials.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. agent_id=123.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created_at.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List the mappings that bind scanning agents to discovery settings. Filter with condition (e.g. condition=agent_id=123) and sort with order_by (e.g. order_by=created). Paginated with skip + limit. Discover agent ids with cns_list_agents and discovery-settings ids with cns_list_discovery_settings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. agent_id=123.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List the scanning agents associated with your companies. Returns each agent's id, type, OS, and last-reported time. Filter with the condition language (e.g. condition=os_type:windows, condition=agent_type:desktop, condition=last_reported:<2023-04-01, or condition=company_id:123) and sort with order_by (e.g. order_by=name). Paginated with skip + limit. Use cns_get_agents for one agent.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. os_type:windows or company_id:123.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. name.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List the scan credentials configured for a company (used by agents to authenticate to targets). Returns credential metadata only — never raw secrets. Filter with condition (e.g. condition=credential_type=ssh, condition=address_type=internal, or condition=is_excluded=true) and sort with order_by (e.g. order_by=created). Paginated with skip + limit. Use cns_get_credentials for one credential.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. credential_type=ssh.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List the discovery settings for a company (the address ranges/targets, exclusions, tags, and profiles that steer network discovery). Filter with condition (e.g. condition=name="example") and sort with order_by (e.g. order_by=created). Paginated with skip + limit. Use cns_get_discovery_settings for one setting.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. name="example".
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] Create or update a mapping binding a scanning agent to a set of credentials. Provide a JSON object body with at least agent_id and credentials_id; include the record id to update, omit it to create. Discover the ids with cns_list_agents and cns_list_credentials.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body (e.g. { "agent_id": "...", "credentials_id": "..." }). Include id to update, omit to create.

[CyberCNS (ConnectSecure)] Create or update a mapping binding a scanning agent to a set of discovery settings. Provide a JSON object body with at least agent_id and discovery_settings_id; include the record id to update, omit it to create.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body (e.g. { "agent_id": "...", "discovery_settings_id": "..." }). Include id to update, omit to create.

[CyberCNS (ConnectSecure)] Create or update a scan credential. Provide a JSON object body with the credential fields (e.g. credential_type, username, secret, address_type); include the id to update, omit it to create. The body contains a secret — handle it as sensitive material.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body of credential fields (contains a secret). Include id to update, omit to create.

[CyberCNS (ConnectSecure)] Create or update a discovery-settings record. Provide a JSON object body with the settings fields (e.g. name, address_type, address, ignore_ports, is_excluded, manual_tags, target_ip, custom_profile_id); include the id to update, omit it to create.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body of discovery-settings fields. Include id to update, omit to create.

Scheduling & Events

ToolPlanAccessSummary
cns_delete_event_setProDestructivePermanently delete an event set by id (from cns_list_event_set).
cns_delete_schedulerProDestructivePermanently delete a scan scheduler by id (from cns_list_scheduler).
cns_external_scanProDestructiveTrigger an external (attack-surface) scan.
cns_get_event_setFreeRead-onlyGet a single event set by id (from cns_list_event_set).
cns_get_jobs_viewFreeRead-onlyGet a single scan/processing job by id (from cns_list_jobs_view).
cns_get_report_jobs_viewFreeRead-onlyGet a single report-generation job by id (from cns_list_report_jobs_view).
cns_get_schedulerFreeRead-onlyGet a single scan scheduler by id (from cns_list_scheduler).
cns_list_event_setFreeRead-onlyList the event sets (notification/alert rule groups) configured for the tenant.
cns_list_jobs_viewFreeRead-onlyList scan/processing jobs for your companies (status, timing, and outcome of scans and background work).
cns_list_report_jobs_viewFreeRead-onlyList report-generation jobs (status and outcome of report builds).
cns_list_schedulerFreeRead-onlyList the scan schedulers configured for your companies (the recurring scan/report schedules).
cns_remove_scheduleProDestructiveRemove a scan schedule.
cns_reset_agentsProDestructiveReset one or more scanning agents.
cns_save_event_setProWriteCreate or update an event set (notification/alert rule group).
cns_save_schedulerProWriteCreate or update a scan scheduler.
cns_update_scheduleProWriteUpdate an existing scan schedule.

[CyberCNS (ConnectSecure)] Permanently delete an event set by id (from cns_list_event_set). Cannot be undone.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the event set to delete.

[CyberCNS (ConnectSecure)] Permanently delete a scan scheduler by id (from cns_list_scheduler). Cannot be undone.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the scheduler to delete.

[CyberCNS (ConnectSecure)] Trigger an external (attack-surface) scan. Provide a JSON object body specifying the scan target/scope (e.g. company_id and the domains/hosts to scan). This starts scan work; poll cns_list_jobs_view or cns_list_scheduler for progress.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body specifying the external scan target/scope (e.g. company_id, domains).
ParamTypeRequiredDefaultDescription
idstringyesThe event set id (from cns_list_event_set).

[CyberCNS (ConnectSecure)] Get a single scan/processing job by id (from cns_list_jobs_view). Returns the job's full detail.

ParamTypeRequiredDefaultDescription
idstringyesThe job id (from cns_list_jobs_view).
ParamTypeRequiredDefaultDescription
idstringyesThe report job id (from cns_list_report_jobs_view).
ParamTypeRequiredDefaultDescription
idstringyesThe scheduler id (from cns_list_scheduler).

[CyberCNS (ConnectSecure)] List the event sets (notification/alert rule groups) configured for the tenant. Filter with condition (e.g. condition=name:event-set-1) and sort with order_by (e.g. order_by=created). Paginated with skip + limit. Use cns_get_event_set for one event set.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. name:event-set-1.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List scan/processing jobs for your companies (status, timing, and outcome of scans and background work). Filter with the condition language (jobs are commonly filtered by company_id and status) and sort with order_by (e.g. order_by=created_at). Paginated with skip + limit. Use cns_get_jobs_view for one job.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter, e.g. company_id=123 or status=active.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created_at.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List report-generation jobs (status and outcome of report builds). Filter with the condition language and sort with order_by. Paginated with skip + limit. Use cns_get_report_jobs_view for one report job; see the report_builder tools to create report jobs and fetch download links.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created_at.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List the scan schedulers configured for your companies (the recurring scan/report schedules). Filter with the condition language and sort with order_by (e.g. order_by=created:desc). Paginated with skip + limit. Use cns_get_scheduler for one scheduler; cns_save_scheduler to create/update; cns_update_schedule / cns_remove_schedule for schedule actions.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional ConnectSecure filter.
limitintegerno100Max records to return (default 100). Capped at the ConnectSecure limit.
orderBystringnonullOptional sort, e.g. created:desc.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] Remove a scan schedule. Provide a JSON object body identifying the schedule to remove (e.g. its id). This stops the recurring scan and cannot be undone. Discover schedules with cns_list_scheduler.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body identifying the schedule to remove (e.g. its id).

[CyberCNS (ConnectSecure)] Reset one or more scanning agents. Provide a JSON object body identifying the agents to reset (e.g. their ids or a company_id). Resetting forces the agents to re-register/re-initialize and can interrupt in-progress scans — treat as a disruptive action. Discover agents with cns_list_agents.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body identifying the agents to reset (e.g. agent ids or company_id).

[CyberCNS (ConnectSecure)] Create or update an event set (notification/alert rule group). Provide a JSON object body with the event-set fields (e.g. name and the rules/thresholds); include the id to update, omit it to create.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body of event-set fields. Include id to update, omit to create.

[CyberCNS (ConnectSecure)] Create or update a scan scheduler. Provide a JSON object body with the scheduler fields (e.g. name, schedule/recurrence, company_id, scan type); include the id to update, omit it to create.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body of scheduler fields. Include id to update, omit to create.

[CyberCNS (ConnectSecure)] Update an existing scan schedule. Provide a JSON object body identifying the schedule (e.g. its id) and the fields to change (e.g. recurrence, next run). Use cns_list_scheduler to discover schedules; use cns_remove_schedule to remove one.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body identifying the schedule and the fields to change.

Baselines

ToolPlanAccessSummary
cns_delete_application_baseline_rulesProDestructivePermanently delete an application-baseline rule by id.
cns_delete_backup_softwareProDestructivePermanently delete a backup-software record by id.
cns_get_app_baseline_plan_assetsFreeRead-onlyGet a single asset-level application-baseline-plan record by its id (from cns_list_app_baseline_plan_assets).
cns_get_app_baseline_plan_companyFreeRead-onlyGet a single company-level application-baseline-plan record by its id (from cns_list_app_baseline_plan_company).
cns_get_application_baseline_rulesFreeRead-onlyGet a single application-baseline rule by its id (from cns_list_application_baseline_rules).
cns_get_backup_softwareFreeRead-onlyGet a single backup-software record by its id (from cns_list_backup_software).
cns_list_app_baseline_plan_assetsFreeRead-onlyList the application-baseline plan evaluated at the asset level — which baseline applications each asset has, is missing, or has extra.
cns_list_app_baseline_plan_companyFreeRead-onlyList the application-baseline plan rolled up at the company level.
cns_list_application_baseline_rulesFreeRead-onlyList the application-baseline rules — the policy of approved / unapproved applications used to grade assets.
cns_list_backup_softwareFreeRead-onlyList detected backup-software inventory across the company (e.g. Veeam, Acronis) used for backup-coverage posture.
cns_save_application_baseline_rulesProWriteCreate or update an application-baseline rule.
cns_save_backup_softwareProWriteCreate or update a backup-software definition.

[CyberCNS (ConnectSecure)] Permanently delete an application-baseline rule by id. Assets are re-graded against the remaining rules — this cannot be undone. id comes from cns_list_application_baseline_rules.

ParamTypeRequiredDefaultDescription
idstringyesRule id to delete (from cns_list_application_baseline_rules).

[CyberCNS (ConnectSecure)] Permanently delete a backup-software record by id. This cannot be undone. id comes from cns_list_backup_software.

ParamTypeRequiredDefaultDescription
idstringyesRecord id to delete (from cns_list_backup_software).
ParamTypeRequiredDefaultDescription
idstringyesRecord id (from cns_list_app_baseline_plan_assets).
ParamTypeRequiredDefaultDescription
idstringyesRecord id (from cns_list_app_baseline_plan_company).
ParamTypeRequiredDefaultDescription
idstringyesRule id (from cns_list_application_baseline_rules).
ParamTypeRequiredDefaultDescription
idstringyesRecord id (from cns_list_backup_software).

[CyberCNS (ConnectSecure)] List the application-baseline plan evaluated at the asset level — which baseline applications each asset has, is missing, or has extra. Offset paginated (skip/limit, max 5000). Optional condition filter (e.g. "company_id=123") and order_by. Pair with cns_get_app_baseline_plan_assets for a single record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "company_id=123" or "name:contains:acme".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List the application-baseline plan rolled up at the company level. Offset paginated (skip/limit, max 5000), optional condition filter and order_by. Pair with cns_get_app_baseline_plan_company for a single record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "company_id=123".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List the application-baseline rules — the policy of approved / unapproved applications used to grade assets. Offset paginated (skip/limit, max 5000), optional condition (e.g. "os_type=windows") and order_by. Create/update via cns_save_application_baseline_rules; delete via cns_delete_application_baseline_rules.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "os_type=windows".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List detected backup-software inventory across the company (e.g. Veeam, Acronis) used for backup-coverage posture. Offset paginated (skip/limit, max 5000), optional condition (e.g. "name:Veeam") and order_by. Create/update via cns_save_backup_software; delete via cns_delete_backup_software.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "name:Veeam".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] Create or update an application-baseline rule. Pass the full rule object as JSON (include the record id to update an existing rule; omit it to create). A 401/403 means the CyberCNS API key lacks write access — re-issue it.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the application-baseline rule. Include the id to update; omit to create.

[CyberCNS (ConnectSecure)] Create or update a backup-software definition. Pass the full object as JSON (include the id to update; omit to create).

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the backup-software record. Include the id to update; omit to create.

Security Posture

ToolPlanAccessSummary
cns_delete_compliance_assessmentProDestructivePermanently delete a compliance assessment by id, discarding its recorded progress and answers.
cns_delete_custom_profileProDestructivePermanently delete a custom compliance/scan profile by id.
cns_delete_edrProDestructivePermanently delete an EDR coverage definition by id.
cns_delete_pii_scan_settingsProDestructivePermanently delete a PII-scan-settings record by id.
cns_get_attack_surface_resultsFreeRead-onlyGet a single external attack-surface result by its id (from cns_list_attack_surface_results), including the full detail (target_ips, subdomains, breach creds/hashes, email spoof checks, raw headers).
cns_get_compliance_assessmentFreeRead-onlyGet a single compliance assessment by its id (from cns_list_compliance_assessment).
cns_get_custom_profileFreeRead-onlyGet a single custom compliance/scan profile by its id (from cns_list_custom_profile).
cns_get_edrFreeRead-onlyGet a single EDR coverage definition by its id (from cns_list_edr).
cns_get_pii_scan_settingsFreeRead-onlyGet a single PII-scan-settings record by its id (from cns_list_pii_scan_settings).
cns_list_attack_surface_resultsFreeRead-onlyList external attack-surface scan results (subdomains, emails, leaked creds/hashes, DNS/SPF/DMARC/MX findings, S3 buckets, exposed employees) discovered for the company's monitored domains.
cns_list_compliance_assessmentFreeRead-onlyList compliance assessments for the company (template name/status, completed sections, type, completion time).
cns_list_custom_profileFreeRead-onlyList custom compliance/scan profiles defined for the company (tailored check sets layered on top of the built-in compliance templates).
cns_list_edrFreeRead-onlyList EDR (endpoint detection & response) coverage definitions for the company — which EDR products are recognized/expected on assets.
cns_list_pii_scan_settingsFreeRead-onlyList PII-scan settings for the company (which sensitive-data patterns/paths the scanner looks for).
cns_save_compliance_assessmentProWriteCreate or update a compliance assessment.
cns_save_custom_profileProWriteCreate or update a custom compliance/scan profile.
cns_save_edrProWriteCreate or update an EDR coverage definition.
cns_save_pii_scan_settingsProWriteCreate or update a PII-scan-settings record.

[CyberCNS (ConnectSecure)] Permanently delete a compliance assessment by id, discarding its recorded progress and answers. This cannot be undone. id comes from cns_list_compliance_assessment.

ParamTypeRequiredDefaultDescription
idstringyesAssessment id to delete (from cns_list_compliance_assessment).

[CyberCNS (ConnectSecure)] Permanently delete a custom compliance/scan profile by id. Scans/assessments referencing it revert to the built-in defaults — this cannot be undone. id comes from cns_list_custom_profile.

ParamTypeRequiredDefaultDescription
idstringyesProfile id to delete (from cns_list_custom_profile).

[CyberCNS (ConnectSecure)] Permanently delete an EDR coverage definition by id. This cannot be undone. id comes from cns_list_edr.

ParamTypeRequiredDefaultDescription
idstringyesEDR record id to delete (from cns_list_edr).

[CyberCNS (ConnectSecure)] Permanently delete a PII-scan-settings record by id. This cannot be undone. id comes from cns_list_pii_scan_settings.

ParamTypeRequiredDefaultDescription
idstringyesSettings id to delete (from cns_list_pii_scan_settings).
ParamTypeRequiredDefaultDescription
idstringyesResult id (from cns_list_attack_surface_results).
ParamTypeRequiredDefaultDescription
idstringyesAssessment id (from cns_list_compliance_assessment).
ParamTypeRequiredDefaultDescription
idstringyesProfile id (from cns_list_custom_profile).
ParamTypeRequiredDefaultDescription
idstringyesEDR record id (from cns_list_edr).
ParamTypeRequiredDefaultDescription
idstringyesSettings id (from cns_list_pii_scan_settings).

[CyberCNS (ConnectSecure)] List external attack-surface scan results (subdomains, emails, leaked creds/hashes, DNS/SPF/DMARC/MX findings, S3 buckets, exposed employees) discovered for the company's monitored domains. Offset paginated (skip/limit, max 5000), optional condition and order_by. Scans are launched against domains managed via cns_list_attack_surface_domain / cns_save_attack_surface_domain.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "company_id=123".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List compliance assessments for the company (template name/status, completed sections, type, completion time). Offset paginated (skip/limit, max 5000), optional condition (e.g. "template_status:true") and order_by. Available assessment templates come from cns_list_compliance_types. Create/update via cns_save_compliance_assessment; delete via cns_delete_compliance_assessment.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "template_status:true".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List custom compliance/scan profiles defined for the company (tailored check sets layered on top of the built-in compliance templates). Offset paginated (skip/limit, max 5000), optional condition and order_by. Create/update via cns_save_custom_profile; delete via cns_delete_custom_profile.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "name:contains:cis".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List EDR (endpoint detection & response) coverage definitions for the company — which EDR products are recognized/expected on assets. Offset paginated (skip/limit, max 5000), optional condition and order_by. Create/update via cns_save_edr; delete via cns_delete_edr.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "name:contains:sentinel".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List PII-scan settings for the company (which sensitive-data patterns/paths the scanner looks for). Offset paginated (skip/limit, max 5000), optional condition (e.g. "name:contains:example") and order_by. Create/update via cns_save_pii_scan_settings; delete via cns_delete_pii_scan_settings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "name:contains:example".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] Create or update a compliance assessment. Pass the full object as JSON (include the id to update; omit to create). Requires company_id and tenantid per the assessment schema.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the compliance assessment. Include the id to update; omit to create.

[CyberCNS (ConnectSecure)] Create or update a custom compliance/scan profile. Pass the full object as JSON (include the id to update; omit to create).

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the custom profile. Include the id to update; omit to create.

[CyberCNS (ConnectSecure)] Create or update an EDR coverage definition. Pass the full object as JSON (include the id to update; omit to create).

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the EDR record. Include the id to update; omit to create.

[CyberCNS (ConnectSecure)] Create or update a PII-scan-settings record. Pass the full object as JSON (include the id to update; omit to create).

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the PII-scan settings. Include the id to update; omit to create.

Tags & Domains

ToolPlanAccessSummary
cns_delete_attack_surface_domainProDestructivePermanently delete a monitored attack-surface domain by id, stopping future scans of it.
cns_delete_tag_rulesProDestructivePermanently delete an auto-tagging rule by id.
cns_delete_tagsProDestructivePermanently delete a tag by id.
cns_get_attack_surface_domainFreeRead-onlyGet a single monitored attack-surface domain by its id (from cns_list_attack_surface_domain).
cns_get_custom_domainsFreeRead-onlyGet a single custom domain by its id (from cns_list_custom_domains).
cns_get_tag_rulesFreeRead-onlyGet a single auto-tagging rule by its id (from cns_list_tag_rules).
cns_get_tagsFreeRead-onlyGet a single tag by its id (from cns_list_tags).
cns_list_attack_surface_domainFreeRead-onlyList the external domains monitored for attack-surface scanning.
cns_list_custom_domainsFreeRead-onlyList custom domains configured for the company (e.g. white-label / branding domains and their status).
cns_list_tag_rulesFreeRead-onlyList auto-tagging rules — conditions that automatically apply tags (from cns_list_tags) to matching assets.
cns_list_tagsFreeRead-onlyList tags defined for the company (labels applied to assets/companies for grouping and filtering across reports).
cns_save_attack_surface_domainProWriteAdd or update a monitored attack-surface domain.
cns_save_tag_rulesProWriteCreate or update an auto-tagging rule.
cns_save_tagsProWriteCreate or update a tag.
cns_set_custom_domainProWriteSet the company's custom branding domain and upload its SSL certificate.

[CyberCNS (ConnectSecure)] Permanently delete a monitored attack-surface domain by id, stopping future scans of it. This cannot be undone. id comes from cns_list_attack_surface_domain.

ParamTypeRequiredDefaultDescription
idstringyesDomain record id to delete (from cns_list_attack_surface_domain).

[CyberCNS (ConnectSecure)] Permanently delete an auto-tagging rule by id. Existing tags already applied are left in place; only the automatic rule is removed. This cannot be undone. id comes from cns_list_tag_rules.

ParamTypeRequiredDefaultDescription
idstringyesTag-rule id to delete (from cns_list_tag_rules).

[CyberCNS (ConnectSecure)] Permanently delete a tag by id. It is removed from every asset/company it was applied to — this cannot be undone. id comes from cns_list_tags.

ParamTypeRequiredDefaultDescription
idstringyesTag id to delete (from cns_list_tags).
ParamTypeRequiredDefaultDescription
idstringyesDomain record id (from cns_list_attack_surface_domain).
ParamTypeRequiredDefaultDescription
idstringyesCustom-domain record id (from cns_list_custom_domains).
ParamTypeRequiredDefaultDescription
idstringyesTag-rule id (from cns_list_tag_rules).
ParamTypeRequiredDefaultDescription
idstringyesTag id (from cns_list_tags).

[CyberCNS (ConnectSecure)] List the external domains monitored for attack-surface scanning. Offset paginated (skip/limit, max 5000), optional condition (e.g. "domain=example.com") and order_by. Scan findings for these domains are read via cns_list_attack_surface_results. Create/update via cns_save_attack_surface_domain; delete via cns_delete_attack_surface_domain.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "domain=example.com".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List custom domains configured for the company (e.g. white-label / branding domains and their status). Offset paginated (skip/limit, max 5000), optional condition (e.g. "status:active") and order_by. The company branding domain + SSL is set via cns_set_custom_domain.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "status:active".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List auto-tagging rules — conditions that automatically apply tags (from cns_list_tags) to matching assets. Offset paginated (skip/limit, max 5000), optional condition and order_by. Create/update via cns_save_tag_rules; delete via cns_delete_tag_rules.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "tag_id=123".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] List tags defined for the company (labels applied to assets/companies for grouping and filtering across reports). Offset paginated (skip/limit, max 5000), optional condition and order_by. Create/update via cns_save_tags; delete via cns_delete_tags. Auto-tagging rules are managed via cns_list_tag_rules.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition filter, e.g. "name:contains:prod".
limitintegerno100Max rows to return. Default 100, capped at 5000.
orderBystringnonullOptional order_by field, e.g. "created".
skipintegerno0Rows to skip (offset pagination). Default 0.

[CyberCNS (ConnectSecure)] Add or update a monitored attack-surface domain. Pass the full object as JSON (include the id to update; omit to create). Newly added domains become eligible for external attack-surface scanning.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the attack-surface domain. Include the id to update; omit to create.

[CyberCNS (ConnectSecure)] Create or update an auto-tagging rule. Pass the full object as JSON (include the id to update; omit to create).

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the tag rule. Include the id to update; omit to create.

[CyberCNS (ConnectSecure)] Create or update a tag. Pass the full object as JSON (include the id to update; omit to create).

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the tag. Include the id to update; omit to create.

[CyberCNS (ConnectSecure)] Set the company's custom branding domain and upload its SSL certificate. Sent as multipart/form-data. Pass a JSON object whose properties become form fields: domain_name (the branding domain), ssl_cert (the SSL certificate, PEM text) and ssl_privkey (the private key, PEM text) are attached as file parts; any other properties are sent as plain text fields. Note: the exact multipart field set is inferred from the V4 API documentation and may need adjustment against a live pod.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Expected: domain_name (string), ssl_cert (PEM certificate text), ssl_privkey (PEM private-key text).

Asset Inventory

ToolPlanAccessSummary
cns_delete_assetsProDestructiveDelete an asset by id (from cns_list_assets).
cns_get_asset_compliance_report_cardFreeRead-onlyGet a single asset compliance report-card record by id (discover ids with cns_list_asset_compliance_report_card).
cns_get_asset_interfaceFreeRead-onlyGet a single asset network-interface record by id (discover ids with cns_list_asset_interface).
cns_get_asset_portsFreeRead-onlyGet a single asset open-port record by id (discover ids with cns_list_asset_ports).
cns_get_asset_security_report_dataFreeRead-onlyGet a single asset security-report-data record by id (discover ids with cns_list_asset_security_report_data).
cns_get_asset_sharesFreeRead-onlyGet a single asset network-share record by id (discover ids with cns_list_asset_shares).
cns_get_asset_statsFreeRead-onlyGet a single asset-statistics record by id (discover ids with cns_list_asset_stats).
cns_get_asset_unqouted_servicesFreeRead-onlyGet a single unquoted-service-path record by id (discover ids with cns_list_asset_unqouted_services).
cns_get_asset_user_sharesFreeRead-onlyGet a single asset user-share record by id (discover ids with cns_list_asset_user_shares).
cns_get_asset_viewFreeRead-onlyGet a single enriched asset-view record by id (discover ids with cns_list_asset_view).
cns_get_assetsFreeRead-onlyGet a single asset by id (discover ids with cns_list_assets).
cns_list_asset_compliance_report_cardFreeRead-onlyList per-asset compliance report-card records (an asset's pass/fail posture against the compliance benchmarks it is assessed on).
cns_list_asset_interfaceFreeRead-onlyList network interfaces discovered on assets (NIC name, MAC, IP addresses, and link state).
cns_list_asset_portsFreeRead-onlyList open network ports discovered on assets (port number, protocol, state, and the service behind it).
cns_list_asset_security_report_dataFreeRead-onlyList per-asset security report data (the asset-level security posture rows backing the security report).
cns_list_asset_sharesFreeRead-onlyList network shares discovered on assets (SMB/CIFS share name, path, and permissions).
cns_list_asset_statsFreeRead-onlyList per-asset statistics (vulnerability, problem and compliance counts rolled up per asset).
cns_list_asset_unqouted_servicesFreeRead-onlyList Windows services with unquoted service paths on assets — a privilege-escalation weakness (CyberCNS spells the endpoint 'unqouted').
cns_list_asset_user_sharesFreeRead-onlyList per-user share access discovered on assets (which users/groups can reach each network share).
cns_list_asset_viewFreeRead-onlyList the enriched asset-view records (a denormalized asset summary joining company, OS, risk and scan metadata).
cns_list_assetsFreeRead-onlyList the assets (endpoints, servers, network/firewall devices) discovered and scanned across your ConnectSecure companies.
cns_save_assetsProWriteCreate or update an asset.

[CyberCNS (ConnectSecure)] Delete an asset by id (from cns_list_assets). This permanently removes the asset and its scan history from ConnectSecure — it cannot be undone. A 401/403 means the CyberCNS API key lacks delete access — re-issue it for a user with the required role.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the asset to delete (from cns_list_assets).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the compliance report-card record (from cns_list_asset_compliance_report_card).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the interface record (from cns_list_asset_interface).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the asset-port record (from cns_list_asset_ports).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the security-report-data record (from cns_list_asset_security_report_data).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the asset-share record (from cns_list_asset_shares).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the asset-stats record (from cns_list_asset_stats).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the unquoted-service record (from cns_list_asset_unqouted_services).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the user-share record (from cns_list_asset_user_shares).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the asset-view record (from cns_list_asset_view).

[CyberCNS (ConnectSecure)] Get a single asset by id (discover ids with cns_list_assets). Returns the asset's full inventory record. For narrower per-asset detail see cns_get_asset_view, cns_get_asset_stats, or the hardware tools (cns_get_bios_info, cns_get_asset_storages, …).

ParamTypeRequiredDefaultDescription
idstringyesThe id of the asset (from cns_list_assets).

[CyberCNS (ConnectSecure)] List per-asset compliance report-card records (an asset's pass/fail posture against the compliance benchmarks it is assessed on). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123, company_id:123). Use cns_get_asset_compliance_report_card for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List network interfaces discovered on assets (NIC name, MAC, IP addresses, and link state). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_asset_interface for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List open network ports discovered on assets (port number, protocol, state, and the service behind it). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_asset_ports for one record; the report-query cns_query_ports_assets_details joins ports to asset detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List per-asset security report data (the asset-level security posture rows backing the security report). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Note: cns_query_asset_security_report_data is a distinct report-query variant with the same underlying data. Use cns_get_asset_security_report_data for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List network shares discovered on assets (SMB/CIFS share name, path, and permissions). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_asset_shares for one record; see cns_list_asset_user_shares for the per-user share breakdown.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List per-asset statistics (vulnerability, problem and compliance counts rolled up per asset). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. company_id:123). Use cns_get_asset_stats for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. company_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List Windows services with unquoted service paths on assets — a privilege-escalation weakness (CyberCNS spells the endpoint 'unqouted'). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_asset_unqouted_services for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List per-user share access discovered on assets (which users/groups can reach each network share). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_asset_user_shares for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List the enriched asset-view records (a denormalized asset summary joining company, OS, risk and scan metadata). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. company_id:123). Use cns_get_asset_view for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. company_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List the assets (endpoints, servers, network/firewall devices) discovered and scanned across your ConnectSecure companies. Offset-paginated via skip/limit (max 5000). Use the condition filter to scope by company (e.g. company_id:123) or other fields (field:operator:value, e.g. created:gt:2022-01-01). Use cns_get_assets for one asset's full detail, and the returned id with cns_delete_assets. Related detail lives in cns_list_asset_view / cns_list_asset_stats.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. company_id:123, created:gt:2022-01-01).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] Create or update an asset. Provide a JSON object body with the asset fields (include the record id to update an existing asset, omit it to create). This is a write (Pro tier). A 401/403 means the CyberCNS API key lacks write access — re-issue it for a user with the required role.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body describing the asset to create or update (include id to update).

Asset Hardware

ToolPlanAccessSummary
cns_get_asset_installed_driversFreeRead-onlyGet a single installed-driver record by id (discover ids with cns_list_asset_installed_drivers).
cns_get_asset_msdtFreeRead-onlyGet a single MSDT-finding record by id (discover ids with cns_list_asset_msdt).
cns_get_asset_storagesFreeRead-onlyGet a single storage-volume record by id (discover ids with cns_list_asset_storages).
cns_get_asset_video_infoFreeRead-onlyGet a single video/GPU-info record by id (discover ids with cns_list_asset_video_info).
cns_get_asset_windows_reboot_requiredFreeRead-onlyGet a single Windows reboot-required record by id (discover ids with cns_list_asset_windows_reboot_required).
cns_get_bios_infoFreeRead-onlyGet a single BIOS/firmware-info record by id (discover ids with cns_list_bios_info).
cns_get_browser_extensionsFreeRead-onlyGet a single browser-extension record by id (discover ids with cns_list_browser_extensions).
cns_get_ciphers_viewFreeRead-onlyGet a single TLS/SSL cipher record by id (discover ids with cns_list_ciphers_view).
cns_get_windows_protection_statusFreeRead-onlyGet a single Windows protection-status record by id (discover ids with cns_list_windows_protection_status).
cns_list_asset_installed_driversFreeRead-onlyList device drivers installed on assets (driver name, version, provider, and signing status).
cns_list_asset_msdtFreeRead-onlyList Microsoft Support Diagnostic Tool (MSDT) findings on assets — used to surface the Follina-class MSDT exposure.
cns_list_asset_storagesFreeRead-onlyList storage volumes and disks discovered on assets (drive letter/mount, filesystem, total and free capacity, encryption state).
cns_list_asset_video_infoFreeRead-onlyList video/GPU adapter info discovered on assets (adapter name, driver version, resolution, VRAM).
cns_list_asset_windows_reboot_requiredFreeRead-onlyList Windows assets that have a pending reboot (patches/updates staged but not yet applied until restart).
cns_list_bios_infoFreeRead-onlyList BIOS/firmware info discovered on assets (vendor, version, release date, serial).
cns_list_browser_extensionsFreeRead-onlyList browser extensions/add-ons discovered on assets (browser, extension name, version, and enabled state) — used to surface risky or unwanted add-ons.
cns_list_ciphers_viewFreeRead-onlyList the TLS/SSL cipher suites observed on assets (protocol version, cipher name, and strength) — used to flag weak or deprecated ciphers.
cns_list_windows_protection_statusFreeRead-onlyList Windows protection (Defender/antivirus) status per asset — real-time protection, definition freshness, firewall and tamper-protection state.
ParamTypeRequiredDefaultDescription
idstringyesThe id of the installed-driver record (from cns_list_asset_installed_drivers).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the MSDT record (from cns_list_asset_msdt).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the storage record (from cns_list_asset_storages).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the video-info record (from cns_list_asset_video_info).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the reboot-required record (from cns_list_asset_windows_reboot_required).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the BIOS-info record (from cns_list_bios_info).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the browser-extension record (from cns_list_browser_extensions).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the cipher record (from cns_list_ciphers_view).
ParamTypeRequiredDefaultDescription
idstringyesThe id of the protection-status record (from cns_list_windows_protection_status).

[CyberCNS (ConnectSecure)] List device drivers installed on assets (driver name, version, provider, and signing status). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_asset_installed_drivers for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List Microsoft Support Diagnostic Tool (MSDT) findings on assets — used to surface the Follina-class MSDT exposure. Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_asset_msdt for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List storage volumes and disks discovered on assets (drive letter/mount, filesystem, total and free capacity, encryption state). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_asset_storages for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List video/GPU adapter info discovered on assets (adapter name, driver version, resolution, VRAM). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_asset_video_info for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List Windows assets that have a pending reboot (patches/updates staged but not yet applied until restart). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123, company_id:123). Use cns_get_asset_windows_reboot_required for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List BIOS/firmware info discovered on assets (vendor, version, release date, serial). Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_bios_info for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List browser extensions/add-ons discovered on assets (browser, extension name, version, and enabled state) — used to surface risky or unwanted add-ons. Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_browser_extensions for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List the TLS/SSL cipher suites observed on assets (protocol version, cipher name, and strength) — used to flag weak or deprecated ciphers. Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123). Use cns_get_ciphers_view for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

[CyberCNS (ConnectSecure)] List Windows protection (Defender/antivirus) status per asset — real-time protection, definition freshness, firewall and tamper-protection state. Offset-paginated via skip/limit (max 5000); condition filter is field:operator:value (e.g. asset_id:123, company_id:123). Use cns_get_windows_protection_status for one record.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter in field:operator:value form (e.g. asset_id:123).
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional field name to sort by (e.g. created).
skipintegerno0Number of records to skip for offset pagination (default 0).

Firewall & Vulnerabilities

ToolPlanAccessSummary
cns_delete_suppress_vulnerabilityProDestructiveDelete a vulnerability suppression by its id (from cns_list_suppress_vulnerability).
cns_get_asset_firewall_policyFreeRead-onlyGet a single asset firewall policy by its id (from cns_list_asset_firewall_policy).
cns_get_firewall_groupsFreeRead-onlyGet a single firewall group by its id (from cns_list_firewall_groups).
cns_get_firewall_interfacesFreeRead-onlyGet a single firewall interface by its id (from cns_list_firewall_interfaces).
cns_get_firewall_licenseFreeRead-onlyGet a single firewall license by its id (from cns_list_firewall_license).
cns_get_firewall_rulesFreeRead-onlyGet a single firewall rule by its id (from cns_list_firewall_rules).
cns_get_firewall_usersFreeRead-onlyGet a single firewall user by its id (from cns_list_firewall_users).
cns_get_firewall_zonesFreeRead-onlyGet a single firewall zone by its id (from cns_list_firewall_zones).
cns_get_remediatedFreeRead-onlyGet a single remediated software/asset record by its id (from cns_list_remediated).
cns_get_suppress_vulnerabilityFreeRead-onlyGet a single suppressed vulnerability by its id (from cns_list_suppress_vulnerability).
cns_list_asset_firewall_policyFreeRead-onlyList asset firewall policies discovered by network/firewall scans.
cns_list_firewall_groupsFreeRead-onlyList firewall address/service groups discovered on scanned firewall assets.
cns_list_firewall_interfacesFreeRead-onlyList firewall interfaces discovered on scanned firewall assets.
cns_list_firewall_licenseFreeRead-onlyList firewall license records discovered on scanned firewall assets.
cns_list_firewall_rulesFreeRead-onlyList firewall rules discovered on scanned firewall assets.
cns_list_firewall_usersFreeRead-onlyList firewall users discovered on scanned firewall assets.
cns_list_firewall_zonesFreeRead-onlyList firewall security zones discovered on scanned firewall assets.
cns_list_remediatedFreeRead-onlyList remediated software/assets — software whose vulnerabilities have been resolved.
cns_list_suppress_vulnerabilityFreeRead-onlyList suppressed vulnerabilities.
cns_save_suppress_vulnerabilityProWriteCreate or update a vulnerability suppression — marks a vulnerability as suppressed so it is excluded from future reports.

[CyberCNS (ConnectSecure)] Delete a vulnerability suppression by its id (from cns_list_suppress_vulnerability). This permanently removes the suppression, so the vulnerability will reappear in scans and reports. A 403 means the API key's user lacks write permission — re-issue the key from an operator/write role.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the suppression to delete (from cns_list_suppress_vulnerability).

[CyberCNS (ConnectSecure)] Get a single asset firewall policy by its id (from cns_list_asset_firewall_policy). Returns the full policy detail: policy_type, path, policy_status, last_updated, asset_id, company_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the asset firewall policy (from cns_list_asset_firewall_policy).

[CyberCNS (ConnectSecure)] Get a single firewall group by its id (from cns_list_firewall_groups). Returns the full group detail: name, description, group_type, members, additional_info, group_id, asset_id, company_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the firewall group (from cns_list_firewall_groups).

[CyberCNS (ConnectSecure)] Get a single firewall interface by its id (from cns_list_firewall_interfaces). Returns the full interface detail: name, description, parent_interface, zone, interface_type, ip, additional_info, interface_id, asset_id, company_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the firewall interface (from cns_list_firewall_interfaces).

[CyberCNS (ConnectSecure)] Get a single firewall license by its id (from cns_list_firewall_license). Returns the full license detail: name, expires, status, type, version, additional_info, license_id, asset_id, company_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the firewall license (from cns_list_firewall_license).

[CyberCNS (ConnectSecure)] Get a single firewall rule by its id (from cns_list_firewall_rules). Returns the full rule detail: name, description, rule_type, action, status, protocol, source/destination address, port, interface, additional_info, rule_id, asset_id, company_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the firewall rule (from cns_list_firewall_rules).

[CyberCNS (ConnectSecure)] Get a single firewall user by its id (from cns_list_firewall_users). Returns the full user detail: name, email, description, user_type, group_name, additional_info, user_id, asset_id, company_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the firewall user (from cns_list_firewall_users).

[CyberCNS (ConnectSecure)] Get a single firewall zone by its id (from cns_list_firewall_zones). Returns the full zone detail: name, interfaces, description, zone_type, additional_info, zone_id, asset_id, company_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the firewall zone (from cns_list_firewall_zones).

[CyberCNS (ConnectSecure)] Get a single remediated software/asset record by its id (from cns_list_remediated). Returns the full detail: name, full_name, release, port, version, publisher, software_type, problem_key, first_discovered, and vulnerability counts.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the remediated record (from cns_list_remediated).

[CyberCNS (ConnectSecure)] Get a single suppressed vulnerability by its id (from cns_list_suppress_vulnerability). Returns the full suppression detail: problem_id, problem_name, solution_id, check_id, reason, comments, suppression_status, suppressed_on/till, approver, requester, asset, and company.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the suppressed-vulnerability record (from cns_list_suppress_vulnerability).

[CyberCNS (ConnectSecure)] List asset firewall policies discovered by network/firewall scans. Each item includes policy_type, path, policy_status, last_updated, asset_id, and company_id. Filter with the condition grammar (e.g. condition=policy_type=web, condition=asset_id=123, condition=company_id=456), sort with order_by (e.g. last_updated), and page with skip/limit. Use cns_get_asset_firewall_policy for one policy's full detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'policy_type=web' or 'company_id=456'. Grammar: field:op:value or field=value.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'last_updated' or 'created:desc'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List firewall address/service groups discovered on scanned firewall assets. Each item includes name, description, group_type, members, group_id, asset_id, and company_id. Filter with the condition grammar (e.g. condition=name:contains:example, condition=group_type:eq:custom, condition=company_id:eq:123), sort with order_by, page with skip/limit. Use cns_get_firewall_groups for one group's detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'group_type:eq:custom' or 'name:contains:example'.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'created:desc'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List firewall interfaces discovered on scanned firewall assets. Each item includes name, description, parent_interface, zone, interface_type, ip, interface_id, asset_id, and company_id. Filter with the condition grammar (e.g. condition=name:contains:eth, condition=zone:in:dmz,internal, condition=interface_type:eq:physical, condition=ip:startswith:192.168.), sort with order_by, page with skip/limit. Use cns_get_firewall_interfaces for one interface's detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'zone:in:dmz,internal' or 'interface_type:eq:physical'.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'name'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List firewall license records discovered on scanned firewall assets. Each item includes name, expires, status, type, version, license_id, asset_id, and company_id. Filter with the condition grammar (e.g. condition=status=active, condition=type=subscription, condition=expires<2023-06-30, condition=company_id=123), sort with order_by (e.g. expires), page with skip/limit. Use cns_get_firewall_license for one license's detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'status=active' or 'expires<2023-06-30'.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'expires'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List firewall rules discovered on scanned firewall assets. Each item includes name, description, rule_type, action, status, protocol, source_address/port/interface, destination_address/port/interface, rule_id, asset_id, and company_id. Filter with the condition grammar (e.g. condition=rule_type='allow', condition=status='active', condition=source_address='192.168.1.0/24'), sort with order_by, page with skip/limit. Use cns_get_firewall_rules for one rule's detail. NOTE: this is the /r/asset/firewall_rules asset-inventory read — the OS-level firewall ruleset from live scans is a separate tool, cns_query_asset_firewall_rules.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. "rule_type='allow'" or "status='active'".
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'created'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List firewall users discovered on scanned firewall assets. Each item includes name, email, description, user_type, group_name, user_id, asset_id, and company_id. Filter with the condition grammar (e.g. condition=name:John, condition=user_type:admin, condition=email:john@example.com), sort with order_by, page with skip/limit. Use cns_get_firewall_users for one user's detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'user_type:admin' or 'name:John'.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'created'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List firewall security zones discovered on scanned firewall assets. Each item includes name, interfaces, description, zone_type, zone_id, asset_id, and company_id. Filter with the condition grammar (e.g. condition=name='Zone 1', condition=zone_type='internal', condition=asset_id=123), sort with order_by (e.g. name), page with skip/limit. Use cns_get_firewall_zones for one zone's detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. "zone_type='internal'".
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'name'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List remediated software/assets — software whose vulnerabilities have been resolved. Each item includes name, full_name, release, version, publisher, software_type, problem_key, first_discovered, vulnerability counts (critical_vuls_count, high_vuls_count, medium_vuls_count, low_vuls_count, vul_count), asset_id, and company_id. Filter with the condition grammar (e.g. condition=critical_vuls_count>0, condition=high_vuls_count>0), sort with order_by, page with skip/limit. Use cns_get_remediated for one record's detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'critical_vuls_count>0'.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'first_discovered'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List suppressed vulnerabilities. Each item includes problem_id, problem_name, solution_id, check_id, url, reason, suppress_comments, suppression_status, suppressed_on, suppressed_till, approved_by, requested_by, company_name, asset_name, asset_id, and company_id. Filter with the condition grammar (e.g. condition=custom, condition=approved, condition=pending, condition=all), sort with order_by, page with skip/limit. Use cns_get_suppress_vulnerability for one record's detail, cns_save_suppress_vulnerability to create/update, and cns_delete_suppress_vulnerability to remove a suppression.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'approved' or 'pending'.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'created'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] Create or update a vulnerability suppression — marks a vulnerability as suppressed so it is excluded from future reports. Provide a JSON object body with the vulnerability's identifying fields: problem_id (the vulnerability/problem id), problem_name, solution_id, check_id, reason (why it is being suppressed), plus optional suppress_comments, suppressed_till, and asset_id/company_id scope. A 403 means the API key's user lacks write permission — re-issue the key from an operator/write role. NOTE (documented-floor gap): the vendor DOCX shows these fields as query params; StackJack posts them as a JSON body per the connector's uniform write convention — verify field placement against your pod's live Swagger if a write is rejected.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: problem_id, problem_name, solution_id, check_id, reason (required for a suppression); optional suppress_comments, suppressed_till, asset_id, company_id.

Integrations

ToolPlanAccessSummary
cns_delete_company_mappingsProDestructiveDelete an integration company mapping by its id (from cns_list_company_mappings).
cns_delete_integration_credentialsProDestructiveDelete an integration credential by its id (from cns_list_integration_credentials).
cns_delete_integration_rulesProDestructiveDelete an integration rule by its id (from cns_list_integration_rules).
cns_get_company_mappingsFreeRead-onlyGet a single integration company mapping by its id (from cns_list_company_mappings).
cns_get_integration_credentialsFreeRead-onlyGet a single integration credential by its id (from cns_list_integration_credentials).
cns_get_integration_rulesFreeRead-onlyGet a single integration rule by its id (from cns_list_integration_rules).
cns_list_company_mappingsFreeRead-onlyList integration company mappings — each links a ConnectSecure source company to a destination integration company/site.
cns_list_integration_credentialsFreeRead-onlyList integration credentials — the stored connections to third-party PSA/RMM/ticketing systems.
cns_list_integration_rulesFreeRead-onlyList integration rules — the automation rules that map ConnectSecure events to third-party actions (e.g. ticket creation).
cns_save_company_mappingsProWriteCreate or update an integration company mapping — links a ConnectSecure source company to a destination integration company/site.
cns_save_integration_credentialsProWriteCreate or update an integration credential — the stored connection to a third-party PSA/RMM/ticketing system.
cns_save_integration_rulesProWriteCreate or update an integration rule — the automation that maps ConnectSecure events to a third-party action (e.g. ticket creation).

[CyberCNS (ConnectSecure)] Delete an integration company mapping by its id (from cns_list_company_mappings). This permanently removes the link between the source company and the destination integration company/site. A 403 means the API key's user lacks write permission — re-issue the key from an operator/write role.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the company mapping to delete (from cns_list_company_mappings).

[CyberCNS (ConnectSecure)] Delete an integration credential by its id (from cns_list_integration_credentials). This permanently removes the stored connection to the third-party system; integration rules and company mappings that reference it will stop working. A 403 means the API key's user lacks write permission — re-issue the key from an operator/write role.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the integration credential to delete (from cns_list_integration_credentials).

[CyberCNS (ConnectSecure)] Delete an integration rule by its id (from cns_list_integration_rules). This permanently removes the event-to-action automation. A 403 means the API key's user lacks write permission — re-issue the key from an operator/write role.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the integration rule to delete (from cns_list_integration_rules).

[CyberCNS (ConnectSecure)] Get a single integration company mapping by its id (from cns_list_company_mappings). Returns the full mapping detail: integration_name, source/destination company and site, notification and consent settings, configuration, integration_rules, credential_id, company_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the company mapping (from cns_list_company_mappings).

[CyberCNS (ConnectSecure)] Get a single integration credential by its id (from cns_list_integration_credentials). Returns the credential detail: name, integration_name, params, ticket_url, company_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the integration credential (from cns_list_integration_credentials).

[CyberCNS (ConnectSecure)] Get a single integration rule by its id (from cns_list_integration_rules). Returns the rule detail: name, is_default, integration_name, integration_params, credential_id, event_set_id.

ParamTypeRequiredDefaultDescription
idstringyesThe id of the integration rule (from cns_list_integration_rules).

[CyberCNS (ConnectSecure)] List integration company mappings — each links a ConnectSecure source company to a destination integration company/site. Items include integration_name, source_company_name, dest_company_name, dest_company_id, site_name, site_id, notification settings, credential_id, company_id, and id. Filter with the condition grammar (e.g. condition=source_company_name:ABC, condition=dest_company_id:123, condition=integration_name:MyIntegration), sort with order_by, page with skip/limit. Use cns_get_company_mappings for one mapping's detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'integration_name:MyIntegration' or 'source_company_name:ABC'.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'created'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List integration credentials — the stored connections to third-party PSA/RMM/ticketing systems. Items include name, integration_name, params, ticket_url, company_id, and id. Filter with the condition grammar (e.g. condition=name:example_integration, condition=company_id:123, condition=tenantid:456), sort with order_by, page with skip/limit. Use cns_get_integration_credentials for one credential's detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'name:example_integration' or 'company_id:123'.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'created'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] List integration rules — the automation rules that map ConnectSecure events to third-party actions (e.g. ticket creation). Items include name, is_default, integration_name, integration_params, credential_id, event_set_id, and id. Filter with the condition grammar (e.g. condition=name:test, condition=integration_name:salesforce, condition=tenantid:123), sort with order_by, page with skip/limit. Use cns_get_integration_rules for one rule's detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter, e.g. 'integration_name:salesforce' or 'name:test'.
limitintegerno100Max records to return (default 100, capped at 5000).
orderBystringnonullOptional sort field, e.g. 'created'.
skipintegerno0Number of records to skip for pagination (default 0).

[CyberCNS (ConnectSecure)] Create or update an integration company mapping — links a ConnectSecure source company to a destination integration company/site. Provide a JSON object body with fields such as integration_name, source_company_name, dest_company_name, dest_company_id, site_name, site_id, credential_id, integration_rules, and notification/consent settings (enable_notification, no_notification, consent_enabled). Include the existing id to update an existing mapping. A 403 means the API key's user lacks write permission — re-issue the key from an operator/write role.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: integration_name, source_company_name, dest_company_name, dest_company_id, site_name, site_id, credential_id, integration_rules, enable_notification, consent_enabled; include id to update.

[CyberCNS (ConnectSecure)] Create or update an integration credential — the stored connection to a third-party PSA/RMM/ticketing system. Provide a JSON object body with fields such as name, integration_name, params (the integration's connection settings, which may include API keys/tokens), and ticket_url. Include the existing id to update. WARNING: the params object may carry SECRET credential material for the external system — treat the body as sensitive. A 403 means the API key's user lacks write permission — re-issue the key from an operator/write role.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name, integration_name, params (connection settings — MAY contain third-party secrets), ticket_url; include id to update.

[CyberCNS (ConnectSecure)] Create or update an integration rule — the automation that maps ConnectSecure events to a third-party action (e.g. ticket creation). Provide a JSON object body with fields such as name, is_default, integration_name, integration_params, credential_id (from cns_list_integration_credentials), and event_set_id. Include the existing id to update. A 403 means the API key's user lacks write permission — re-issue the key from an operator/write role.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name, is_default, integration_name, integration_params, credential_id, event_set_id; include id to update.

Report Queries — Inventory

ToolPlanAccessSummary
cns_query_asset_ports_viewFreeRead-onlyQuery the asset open-ports report: TCP/UDP ports discovered across assets with protocol, service, and secure/insecure classification.
cns_query_asset_softwareFreeRead-onlyQuery the installed-software inventory across assets (software name, version, publisher, type).
cns_query_cert_info_viewFreeRead-onlyQuery discovered SSL/TLS certificate information across assets (subject, issuer, validity window, expiry).
cns_query_compliance_countFreeRead-onlyQuery aggregate compliance pass/fail counts across the environment.
cns_query_distinct_agents_nameFreeRead-onlyQuery the distinct list of agent names — a lookup helper for building filters and dropdowns.
cns_query_distinct_asset_ipFreeRead-onlyQuery the distinct list of asset IP addresses — a lookup helper for building filters.
cns_query_distinct_asset_nameFreeRead-onlyQuery the distinct list of asset (host) names — a lookup helper for building filters.
cns_query_distinct_discovered_protocolsFreeRead-onlyQuery the distinct list of discovered network protocols — a lookup helper for building filters.
cns_query_distinct_osFreeRead-onlyQuery the distinct list of operating systems observed across assets — a lookup helper for building OS filters.
cns_query_distinct_platformFreeRead-onlyQuery the distinct list of platforms (Windows / Linux / macOS / network / etc.) — a lookup helper for building filters.
cns_query_distinct_tagsFreeRead-onlyQuery the distinct list of tags applied across assets and companies — a lookup helper for building tag filters.
cns_query_event_ticketsFreeRead-onlyQuery the event-generated tickets report (tickets raised from monitored events).
cns_query_get_assets_by_problemFreeRead-onlyQuery assets grouped/filtered by a specific problem (vulnerability or misconfiguration) — which assets are affected by a given problem.
cns_query_lightweight_assetsFreeRead-onlyQuery one company's lightweight asset list (minimal fields — id, host name, company) for fast per-company enumeration.
cns_query_notification_tickets_viewFreeRead-onlyQuery the notification-tickets report (tickets raised from notifications).
cns_query_os_pending_patchesFreeRead-onlyQuery pending OS patches across assets (missing operating-system updates).
cns_query_ports_assets_detailsFreeRead-onlyQuery per-asset open-port details (open ports joined to their host asset).
cns_query_problems_ssl_for_assetFreeRead-onlyQuery SSL/TLS-related problems for assets (weak ciphers, expired/invalid certificates, protocol issues).
cns_query_tags_viewFreeRead-onlyQuery the tags report (tag assignments with counts).
cns_query_total_asset_countFreeRead-onlyQuery the total asset-count aggregate for the environment (optionally scoped via the condition filter).
cns_query_unconfirmed_key_checkFreeRead-onlyQuery the unconfirmed-key-check report (discovery keys awaiting confirmation).
cns_query_unconfirmed_open_ports_key_checkFreeRead-onlyQuery the unconfirmed open-ports key-check report (open-port discovery keys awaiting confirmation).

[CyberCNS (ConnectSecure)] Query the asset open-ports report: TCP/UDP ports discovered across assets with protocol, service, and secure/insecure classification. Pair with cns_query_ports_assets_details for the per-asset join. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. port=80 AND protocol='tcp', or is_secure=false).
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by (e.g. is_secure DESC).
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the installed-software inventory across assets (software name, version, publisher, type). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. software_type='Browser' AND version>'100').
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by (e.g. created DESC).
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query discovered SSL/TLS certificate information across assets (subject, issuer, validity window, expiry). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. valid_to<'2025-01-01').
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by (e.g. valid_to ASC).
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query aggregate compliance pass/fail counts across the environment. See the Slice 7 compliance query tools (cns_query_compliance_check_count, cns_query_asset_compliance_details) for per-check and per-asset breakdowns. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the distinct list of agent names — a lookup helper for building filters and dropdowns. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the distinct list of asset IP addresses — a lookup helper for building filters. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the distinct list of asset (host) names — a lookup helper for building filters. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the distinct list of discovered network protocols — a lookup helper for building filters. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the distinct list of operating systems observed across assets — a lookup helper for building OS filters. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. a.os_name LIKE '%Windows%').
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the distinct list of platforms (Windows / Linux / macOS / network / etc.) — a lookup helper for building filters. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the distinct list of tags applied across assets and companies — a lookup helper for building tag filters. See cns_query_tags_view for tag assignments with counts. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the event-generated tickets report (tickets raised from monitored events). See cns_query_notification_tickets_view for the notification-ticket view. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query assets grouped/filtered by a specific problem (vulnerability or misconfiguration) — which assets are affected by a given problem. See the Slice 6 problems tools for problem summaries. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. filter by problem_id).
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query one company's lightweight asset list (minimal fields — id, host name, company) for fast per-company enumeration. companyId is REQUIRED: CyberCNS returns an EMPTY result (HTTP 200, no error) when company_id is missing, so there is no tenant-wide form of this query. For full asset detail use cns_list_assets / cns_get_assets. Offset-paged (skip/limit) with a SQL-style condition WHERE filter (e.g. host_name LIKE '%DESKTOP%') and an order_by sort.

ParamTypeRequiredDefaultDescription
companyIdstringyesREQUIRED. The CyberCNS company id whose assets to list (from cns_list_companies), passed as company_id.
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. host_name LIKE '%DESKTOP%').
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the notification-tickets report (tickets raised from notifications). This is the canonical form of the notification_tickets_view report. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query pending OS patches across assets (missing operating-system updates). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query per-asset open-port details (open ports joined to their host asset). The asset-joined companion to cns_query_asset_ports_view. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query SSL/TLS-related problems for assets (weak ciphers, expired/invalid certificates, protocol issues). Complements cns_query_cert_info_view. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the tags report (tag assignments with counts). See cns_query_distinct_tags for the distinct tag lookup. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the total asset-count aggregate for the environment (optionally scoped via the condition filter). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the unconfirmed-key-check report (discovery keys awaiting confirmation). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the unconfirmed open-ports key-check report (open-port discovery keys awaiting confirmation). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

Report Queries — System (Linux/Windows)

ToolPlanAccessSummary
cns_query_asset_firewall_rulesFreeRead-onlyQuery per-asset host firewall rules (OS firewall configuration across assets).
cns_query_asset_iptables_rulesFreeRead-onlyQuery Linux iptables rules across assets.
cns_query_asset_patches_infoFreeRead-onlyQuery per-asset patch information (installed and pending patch detail across assets).
cns_query_asset_processes_runningFreeRead-onlyQuery running processes across assets (process name, path, owner, state).
cns_query_asset_registry_misconfigurationFreeRead-onlyQuery Windows registry misconfigurations across assets (insecure registry key/value settings).
cns_query_asset_servicesFreeRead-onlyQuery OS services across assets (service name, state, start type).
cns_query_asset_usersFreeRead-onlyQuery local/OS user accounts across assets (username, admin status, last logon).
cns_query_cron_jobsFreeRead-onlyQuery Linux cron jobs across assets (scheduled tasks, schedule expression, command).
cns_query_job_details_viewFreeRead-onlyQuery job execution details (scan/agent job detail report — job status, timing, target).
cns_query_kernel_modulesFreeRead-onlyQuery loaded Linux kernel modules across assets (module name, size, used-by count).
cns_query_selinux_settingsFreeRead-onlyQuery SELinux configuration/status across Linux assets (mode, policy).
cns_query_suid_permissionsFreeRead-onlyQuery SUID/SGID file permissions across Linux assets (privileged-escalation-relevant file permissions).
cns_query_system_events_viewFreeRead-onlyQuery the system-events report (OS/security event-log entries with category, severity, timestamp).
cns_query_system_events_view_ticketidFreeRead-onlyQuery system events joined to their generated ticket IDs (which events raised which tickets).
cns_query_ufw_firewall_rulesFreeRead-onlyQuery UFW (Uncomplicated Firewall) rules across Linux assets.

[CyberCNS (ConnectSecure)] Query per-asset host firewall rules (OS firewall configuration across assets). For device firewall appliances see the Slice 4 firewall tools. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query Linux iptables rules across assets. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query per-asset patch information (installed and pending patch detail across assets). See cns_query_os_pending_patches for the OS-pending rollup. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query running processes across assets (process name, path, owner, state). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query Windows registry misconfigurations across assets (insecure registry key/value settings). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query OS services across assets (service name, state, start type). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. name LIKE '%service%').
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by (e.g. created DESC).
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query local/OS user accounts across assets (username, admin status, last logon). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query Linux cron jobs across assets (scheduled tasks, schedule expression, command). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query job execution details (scan/agent job detail report — job status, timing, target). See cns_list_jobs_view / cns_list_report_jobs_view for the company-scoped job lists. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query loaded Linux kernel modules across assets (module name, size, used-by count). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. used_by!='0').
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by (e.g. name DESC).
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query SELinux configuration/status across Linux assets (mode, policy). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query SUID/SGID file permissions across Linux assets (privileged-escalation-relevant file permissions). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the system-events report (OS/security event-log entries with category, severity, timestamp). See cns_query_system_events_view_ticketid for the ticket-joined variant. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. e.category_name='Critical' AND e.created > '2023-01-01').
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query system events joined to their generated ticket IDs (which events raised which tickets). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. e.created > '2023-01-01' AND e.status != 'CLOSED').
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by (e.g. e.created DESC).
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query UFW (Uncomplicated Firewall) rules across Linux assets. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

Report Queries — Directory (AD/Azure)

ToolPlanAccessSummary
cns_query_ad_groups_viewFreeRead-onlyQuery the Active Directory groups report (group name, mail-enabled flag, scope, membership metadata).
cns_query_ad_password_policiesFreeRead-onlyQuery Active Directory password policies (length, complexity, lockout, age requirements).
cns_query_ad_rolesFreeRead-onlyQuery Active Directory / directory roles (role name, scope).
cns_query_ad_user_licensesFreeRead-onlyQuery directory user license assignments (which licenses are assigned to which directory users).
cns_query_azure_ad_logsFreeRead-onlyQuery Azure AD / Entra ID sign-in and audit logs (actor, activity, result, timestamp).
cns_query_azure_licensesFreeRead-onlyQuery the Azure / Microsoft 365 license inventory (SKUs, assigned/available counts).
cns_query_azure_secure_scoreFreeRead-onlyQuery the Azure / Microsoft Secure Score report (current score, max score, improvement actions over time).

[CyberCNS (ConnectSecure)] Query the Active Directory groups report (group name, mail-enabled flag, scope, membership metadata). See the Slice 6 cns_query_ad_group_users / cns_query_ad_group_computers tools for per-group membership. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. g.mail_enabled=true AND g.when_created > '2023-01-01').
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by (e.g. g.name ASC).
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query Active Directory password policies (length, complexity, lockout, age requirements). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query Active Directory / directory roles (role name, scope). See the Slice 6 cns_query_ad_roles_details / cns_query_ad_roles_member tools for role detail and membership. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query directory user license assignments (which licenses are assigned to which directory users). See cns_query_azure_licenses for the tenant license inventory. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query Azure AD / Entra ID sign-in and audit logs (actor, activity, result, timestamp). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the Azure / Microsoft 365 license inventory (SKUs, assigned/available counts). See cns_query_ad_user_licenses for per-user assignments. Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition.
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by.
skipintegerno0Row offset for pagination (skip). Default 0.

[CyberCNS (ConnectSecure)] Query the Azure / Microsoft Secure Score report (current score, max score, improvement actions over time). Offset-paged (skip/limit) with a SQL-style condition WHERE filter and an order_by sort.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional SQL-style WHERE filter passed verbatim as condition (e.g. current_score < 70).
limitintegerno100Max rows to return (skip/limit paging; capped at 5000). Default 100.
orderBystringnonullOptional sort column with optional ASC/DESC passed verbatim as order_by (e.g. created DESC).
skipintegerno0Row offset for pagination (skip). Default 0.

Reports: Remediation

ToolPlanAccessSummary
cns_get_data_remediate_records_assetFreeRead-onlyFetch the raw remediate-records dataset scoped to a single asset (the /r/get_data/remediate_records_asset feed).
cns_get_data_remediation_plan_assetFreeRead-onlyFetch the raw remediation-plan dataset scoped to a single asset (the /r/get_data/remediation_plan_asset feed): the ordered set of fixes recommended for one asset.
cns_get_data_remediation_plan_companiesFreeRead-onlyFetch the raw remediation-plan dataset rolled up per company (the /r/get_data/remediation_plan_companies feed).
cns_get_data_remediation_plan_globalFreeRead-onlyFetch the raw remediation-plan dataset across the whole tenant (the /r/get_data/remediation_plan_global feed) — the global prioritized fix list spanning every company.
cns_query_get_remediate_recordsFreeRead-onlyReport query returning remediate records (the /r/report_queries/get_remediate_records view) — the actions taken or pending to remediate findings.
cns_query_get_remediationFreeRead-onlyReport query returning remediation detail (the /r/report_queries/get_remediation view).
cns_query_remediate_recordsFreeRead-onlyReport query listing remediate records (the /r/report_queries/remediate_records view).
cns_query_remediate_records_assetsFreeRead-onlyReport query with remediate records rolled up per asset (the /r/report_queries/remediate_records_assets view).
cns_query_remediate_records_companiesFreeRead-onlyReport query with remediate records rolled up per company (the /r/report_queries/remediate_records_companies view).
cns_query_remediation_companiesFreeRead-onlyReport query listing companies with remediation activity (the /r/report_queries/remediation_companies view).
cns_query_remediation_plan_asset_details_by_epssFreeRead-onlyReport query returning remediation-plan asset details ranked by EPSS (Exploit Prediction Scoring System) — the /r/report_queries/remediation_plan_asset_details_by_epss view — so fixes for the most…
cns_query_remediation_plan_by_companyFreeRead-onlyReport query returning the remediation plan grouped by company (the /r/report_queries/remediation_plan_by_company view).
cns_query_remediation_plan_include_companyFreeRead-onlyReport query returning the remediation plan with company context inlined on each row (the /r/report_queries/remediation_plan_include_company view).
cns_query_remediation_velocity_applicationFreeRead-onlyReport query returning remediation velocity (how quickly findings are being resolved over time) broken down by application (the /r/report_queries/remediation_velocity_application view).
cns_query_remediation_velocity_companyFreeRead-onlyReport query returning remediation velocity (how quickly findings are being resolved over time) broken down by company (the /r/report_queries/remediation_velocity_company view).

[CyberCNS (ConnectSecure)] Fetch the raw remediate-records dataset scoped to a single asset (the /r/get_data/remediate_records_asset feed). Use the `condition` filter to pin the asset (e.g. an asset id) and page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Fetch the raw remediation-plan dataset scoped to a single asset (the /r/get_data/remediation_plan_asset feed): the ordered set of fixes recommended for one asset. Filter with `condition` and page with skip/limit. Read-only. Compare with cns_get_data_remediation_plan_companies / cns_get_data_remediation_plan_global for wider scopes.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Fetch the raw remediation-plan dataset rolled up per company (the /r/get_data/remediation_plan_companies feed). Filter with `condition` and page with skip/limit. Read-only. See cns_get_data_remediation_plan_asset (single asset) and cns_get_data_remediation_plan_global (all companies).

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Fetch the raw remediation-plan dataset across the whole tenant (the /r/get_data/remediation_plan_global feed) — the global prioritized fix list spanning every company. Filter with `condition` and page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning remediate records (the /r/report_queries/get_remediate_records view) — the actions taken or pending to remediate findings. Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning remediation detail (the /r/report_queries/get_remediation view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing remediate records (the /r/report_queries/remediate_records view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. See cns_query_remediate_records_assets and cns_query_remediate_records_companies for the asset- and company-scoped rollups.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query with remediate records rolled up per asset (the /r/report_queries/remediate_records_assets view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query with remediate records rolled up per company (the /r/report_queries/remediate_records_companies view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing companies with remediation activity (the /r/report_queries/remediation_companies view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning remediation-plan asset details ranked by EPSS (Exploit Prediction Scoring System) — the /r/report_queries/remediation_plan_asset_details_by_epss view — so fixes for the most likely-to-be-exploited vulnerabilities surface first. Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning the remediation plan grouped by company (the /r/report_queries/remediation_plan_by_company view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. See cns_query_remediation_plan_include_company for the variant that inlines company context.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning the remediation plan with company context inlined on each row (the /r/report_queries/remediation_plan_include_company view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning remediation velocity (how quickly findings are being resolved over time) broken down by application (the /r/report_queries/remediation_velocity_application view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. See cns_query_remediation_velocity_company for the per-company breakdown.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning remediation velocity (how quickly findings are being resolved over time) broken down by company (the /r/report_queries/remediation_velocity_company view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

Reports: Problems

ToolPlanAccessSummary
cns_query_asset_wise_vulnerabilitiesFreeRead-onlyReport query returning vulnerabilities broken down per asset (the /r/report_queries/asset_wise_vulnerabilities view).
cns_query_companies_by_problem_group_suppressedFreeRead-onlyReport query listing companies affected by each problem group, counting SUPPRESSED problems (the /r/report_queries/companies_by_problem_group_suppressed view).
cns_query_problem_group_summaryFreeRead-onlyReport query returning a summary per problem group (the /r/report_queries/problem_group_summary view) — counts and severity rollups for each grouped finding.
cns_query_problem_group_summary_asset_company_countFreeRead-onlyReport query returning per-problem-group summaries with affected-asset and affected-company counts (the /r/report_queries/problem_group_summary_asset_company_count view).
cns_query_problems_infoFreeRead-onlyReport query returning detailed problem records (the /r/report_queries/problems_info view) — the individual findings with their metadata.
cns_query_problems_remediations_summaryFreeRead-onlyReport query summarizing problems alongside their remediation status (the /r/report_queries/problems_remediations_summary view) — how many findings are open vs remediated.
cns_query_problems_summaryFreeRead-onlyReport query returning an overall problems summary (the /r/report_queries/problems_summary view) — aggregate finding counts by severity/type.
cns_query_problems_summary_asset_detailsFreeRead-onlyReport query returning the problems summary expanded to per-asset detail (the /r/report_queries/problems_summary_asset_details view).
cns_query_problems_summary_group_by_companiesFreeRead-onlyReport query returning the problems summary grouped per company (the /r/report_queries/problems_summary_group_by_companies view).
cns_query_problems_summary_tagFreeRead-onlyReport query returning the problems summary grouped by asset tag (the /r/report_queries/problems_summary_tag view).
cns_query_registry_problems_companyFreeRead-onlyReport query returning Windows-registry misconfiguration problems rolled up per company (the /r/report_queries/registry_problems_company view).
cns_query_registry_problems_remediationFreeRead-onlyReport query returning remediation guidance for Windows-registry problems (the /r/report_queries/registry_problems_remediation view).
cns_query_registry_problems_remediation_asset_detailsFreeRead-onlyReport query returning registry-problem remediation expanded to per-asset detail (the /r/report_queries/registry_problems_remediation_asset_details view).
cns_query_registry_problems_summaryFreeRead-onlyReport query returning a summary of Windows-registry misconfiguration problems (the /r/report_queries/registry_problems_summary view).
cns_query_suppressed_problemsFreeRead-onlyReport query listing problems that have been SUPPRESSED (acknowledged/excepted so they no longer count against posture) — the /r/report_queries/suppressed_problems view.

[CyberCNS (ConnectSecure)] Report query returning vulnerabilities broken down per asset (the /r/report_queries/asset_wise_vulnerabilities view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing companies affected by each problem group, counting SUPPRESSED problems (the /r/report_queries/companies_by_problem_group_suppressed view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning a summary per problem group (the /r/report_queries/problem_group_summary view) — counts and severity rollups for each grouped finding. Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning per-problem-group summaries with affected-asset and affected-company counts (the /r/report_queries/problem_group_summary_asset_company_count view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning detailed problem records (the /r/report_queries/problems_info view) — the individual findings with their metadata. Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query summarizing problems alongside their remediation status (the /r/report_queries/problems_remediations_summary view) — how many findings are open vs remediated. Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning an overall problems summary (the /r/report_queries/problems_summary view) — aggregate finding counts by severity/type. Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. See the _asset_details, _group_by_companies, and _tag variants for finer breakdowns.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning the problems summary expanded to per-asset detail (the /r/report_queries/problems_summary_asset_details view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning the problems summary grouped per company (the /r/report_queries/problems_summary_group_by_companies view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning the problems summary grouped by asset tag (the /r/report_queries/problems_summary_tag view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning Windows-registry misconfiguration problems rolled up per company (the /r/report_queries/registry_problems_company view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning remediation guidance for Windows-registry problems (the /r/report_queries/registry_problems_remediation view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning registry-problem remediation expanded to per-asset detail (the /r/report_queries/registry_problems_remediation_asset_details view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning a summary of Windows-registry misconfiguration problems (the /r/report_queries/registry_problems_summary view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing problems that have been SUPPRESSED (acknowledged/excepted so they no longer count against posture) — the /r/report_queries/suppressed_problems view. Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. Suppressions are managed under the asset suppress-vulnerability tools.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

Reports: Directory Detail

ToolPlanAccessSummary
cns_query_ad_basic_infoFreeRead-onlyReport query returning Active Directory basic information (the report_queries/ad_basic_info view) — high-level domain/forest facts.
cns_query_ad_computers_viewFreeRead-onlyReport query listing Active Directory computer objects (the report_queries/ad_computers_view view).
cns_query_ad_domain_detailsFreeRead-onlyReport query returning Active Directory domain details (the report_queries/ad_domain_details view).
cns_query_ad_gpos_detailsFreeRead-onlyReport query returning Group Policy Object (GPO) details (the report_queries/ad_gpos_details view).
cns_query_ad_gpos_viewFreeRead-onlyReport query listing Group Policy Objects (the report_queries/ad_gpos_view view).
cns_query_ad_group_computersFreeRead-onlyReport query listing computer members of Active Directory groups (the report_queries/ad_group_computers view).
cns_query_ad_group_usersFreeRead-onlyReport query listing user members of Active Directory groups (the report_queries/ad_group_users view).
cns_query_ad_ous_viewFreeRead-onlyReport query listing Active Directory Organizational Units (the report_queries/ad_ous_view view).
cns_query_ad_roles_detailsFreeRead-onlyReport query returning Active Directory role details (the report_queries/ad_roles_details view).
cns_query_ad_roles_memberFreeRead-onlyReport query listing members of Active Directory roles (the report_queries/ad_roles_member view).
cns_query_ad_users_viewFreeRead-onlyReport query listing Active Directory user objects (the report_queries/ad_users_view view).
cns_query_get_computer_detailsFreeRead-onlyReport query returning full detail for Active Directory computer objects (the report_queries/get_computer_details view).
cns_query_get_ous_detailsFreeRead-onlyReport query returning full detail for Active Directory Organizational Units (the report_queries/get_ous_details view).
cns_query_get_user_detailsFreeRead-onlyReport query returning full detail for Active Directory user objects (the report_queries/get_user_details view).

[CyberCNS (ConnectSecure)] Report query returning Active Directory basic information (the report_queries/ad_basic_info view) — high-level domain/forest facts. Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing Active Directory computer objects (the report_queries/ad_computers_view view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. See cns_query_get_computer_details for a single computer's full detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning Active Directory domain details (the report_queries/ad_domain_details view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning Group Policy Object (GPO) details (the report_queries/ad_gpos_details view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. See cns_query_ad_gpos_view for the summary listing.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing Group Policy Objects (the report_queries/ad_gpos_view view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing computer members of Active Directory groups (the report_queries/ad_group_computers view). Filter with `condition` (e.g. by group), sort with `order_by`, page with skip/limit. Read-only. See cns_query_ad_group_users for user members.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing user members of Active Directory groups (the report_queries/ad_group_users view). Filter with `condition` (e.g. by group), sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing Active Directory Organizational Units (the report_queries/ad_ous_view view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. See cns_query_get_ous_details for a single OU's full detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning Active Directory role details (the report_queries/ad_roles_details view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. See cns_query_ad_roles_member for role membership.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing members of Active Directory roles (the report_queries/ad_roles_member view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query listing Active Directory user objects (the report_queries/ad_users_view view). Filter with `condition`, sort with `order_by`, page with skip/limit. Read-only. See cns_query_get_user_details for a single user's full detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning full detail for Active Directory computer objects (the report_queries/get_computer_details view). Use `condition` to pin a specific computer; sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning full detail for Active Directory Organizational Units (the report_queries/get_ous_details view). Use `condition` to pin a specific OU; sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

[CyberCNS (ConnectSecure)] Report query returning full detail for Active Directory user objects (the report_queries/get_user_details view). Use `condition` to pin a specific user; sort with `order_by`, page with skip/limit. Read-only.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS condition/filter expression (the endpoint's `condition` query param), passed verbatim. Leave null for all rows.
limitintegerno100Maximum rows to return; clamped to the CyberCNS page-size ceiling of 5000. Default 100.
orderBystringnonullOptional sort expression passed verbatim as the `order_by` query param.
skipintegerno0Row offset to skip for pagination (the CyberCNS `skip` param). Default 0.

Application Vulnerability Reports

ToolPlanAccessSummary
cns_query_app_vulnerabilities_by_os_software_details_suppressedFreeRead-onlyQuery per-software vulnerability detail for the by-OS application-vulnerability report, INCLUDING suppressed findings.
cns_query_application_vulnerabilitiesFreeRead-onlyQuery the application-vulnerability report — vulnerable applications/products detected across the tenant's assets, with CVE, severity, and affected-asset rollups.
cns_query_application_vulnerabilities_by_osFreeRead-onlyQuery application vulnerabilities grouped by operating system — vulnerable-application counts and severity rollups per OS.
cns_query_application_vulnerabilities_by_os_software_detailsFreeRead-onlyQuery per-software vulnerability detail for the by-OS application-vulnerability report — the specific software packages driving each OS's vulnerability counts.
cns_query_application_vulnerabilities_by_productFreeRead-onlyQuery application vulnerabilities grouped by product — vulnerability and affected-asset counts per software product.
cns_query_application_vulnerabilities_by_product_suppressedFreeRead-onlyQuery application vulnerabilities grouped by product, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_by_product_suppressed_tagFreeRead-onlyQuery application vulnerabilities grouped by product and scoped to tags, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_by_product_tagFreeRead-onlyQuery application vulnerabilities grouped by product and scoped to tags.
cns_query_application_vulnerabilities_netFreeRead-onlyQuery the net application-vulnerability report — the deduplicated/net-effective vulnerability set after roll-up.
cns_query_application_vulnerabilities_net_suppressedFreeRead-onlyQuery the net application-vulnerability report, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_net_suppressed_tagFreeRead-onlyQuery the net application-vulnerability report scoped to tags, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_net_tagFreeRead-onlyQuery the net application-vulnerability report scoped to tags.
cns_query_application_vulnerabilities_os_patchFreeRead-onlyQuery the OS-patch view of the application-vulnerability report — vulnerabilities remediable via OS patches and their patch status.
cns_query_application_vulnerabilities_patching_asset_detailsFreeRead-onlyQuery per-asset patching detail for the application-vulnerability report — which assets need which application/OS patches to close vulnerabilities.
cns_query_application_vulnerabilities_suppressedFreeRead-onlyQuery the application-vulnerability report INCLUDING suppressed findings.
cns_query_application_vulnerabilities_suppressed_by_osFreeRead-onlyQuery application vulnerabilities grouped by OS INCLUDING suppressed findings.
cns_query_application_vulnerabilities_suppressed_tagFreeRead-onlyQuery the application-vulnerability report scoped to tags INCLUDING suppressed findings.
cns_query_application_vulnerabilities_suppressed_tag_by_osFreeRead-onlyQuery application vulnerabilities scoped to tags and grouped by OS, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_tagFreeRead-onlyQuery the application-vulnerability report scoped to tags.
cns_query_application_vulnerabilities_tag_by_osFreeRead-onlyQuery application vulnerabilities scoped to tags and grouped by OS.
cns_query_application_vulnerabilities_v2FreeRead-onlyQuery the v2 application-vulnerability report — the newer schema/format of the application-vulnerability rollup.

[CyberCNS (ConnectSecure)] Query per-software vulnerability detail for the by-OS application-vulnerability report, INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities_by_os_software_details for the non-suppressed view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the application-vulnerability report — vulnerable applications/products detected across the tenant's assets, with CVE, severity, and affected-asset rollups. Use cns_query_application_vulnerabilities_by_os / _by_product for OS- or product-grouped views, and the _suppressed / _tag variants to include suppressed findings or scope to tags. Offset-paginated; supports the condition filter grammar.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query application vulnerabilities grouped by operating system — vulnerable-application counts and severity rollups per OS. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities for the ungrouped view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query per-software vulnerability detail for the by-OS application-vulnerability report — the specific software packages driving each OS's vulnerability counts. Offset-paginated; supports the condition filter grammar. Use the _suppressed variant to include suppressed findings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query application vulnerabilities grouped by product — vulnerability and affected-asset counts per software product. Offset-paginated; supports the condition filter grammar. Use the _tag / _suppressed / _suppressed_tag variants to scope to tags or include suppressed findings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query application vulnerabilities grouped by product, INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities_by_product for the non-suppressed view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query application vulnerabilities grouped by product and scoped to tags, INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities_by_product_tag for the non-suppressed tag view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query application vulnerabilities grouped by product and scoped to tags. Offset-paginated; supports the condition filter grammar. Use the _suppressed_tag variant to include suppressed findings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the net application-vulnerability report — the deduplicated/net-effective vulnerability set after roll-up. Offset-paginated; supports the condition filter grammar. Use the _tag / _suppressed / _suppressed_tag variants to scope to tags or include suppressed findings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the net application-vulnerability report, INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities_net for the non-suppressed view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the net application-vulnerability report scoped to tags, INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities_net_tag for the non-suppressed tag view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the net application-vulnerability report scoped to tags. Offset-paginated; supports the condition filter grammar. Use the _net_suppressed_tag variant to include suppressed findings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the OS-patch view of the application-vulnerability report — vulnerabilities remediable via OS patches and their patch status. Offset-paginated; supports the condition filter grammar.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query per-asset patching detail for the application-vulnerability report — which assets need which application/OS patches to close vulnerabilities. Offset-paginated; supports the condition filter grammar.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the application-vulnerability report INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities for the non-suppressed view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query application vulnerabilities grouped by OS INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities_by_os for the non-suppressed view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the application-vulnerability report scoped to tags INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities_tag for the non-suppressed tag view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query application vulnerabilities scoped to tags and grouped by OS, INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities_tag_by_os for the non-suppressed view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the application-vulnerability report scoped to tags. Offset-paginated; supports the condition filter grammar. Use the _suppressed_tag variant to include suppressed findings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query application vulnerabilities scoped to tags and grouped by OS. Offset-paginated; supports the condition filter grammar. Use the _suppressed_tag_by_os variant to include suppressed findings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the v2 application-vulnerability report — the newer schema/format of the application-vulnerability rollup. Offset-paginated; supports the condition filter grammar. See cns_query_application_vulnerabilities for the original view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'severity:eq:Critical', 'product:startswith:Chrome', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

Compliance & Vulnerability Reports

ToolPlanAccessSummary
cns_list_compliance_typesFreeRead-onlyList the compliance frameworks/benchmark types available in this tenant (e.g. CIS, HIPAA, PCI, NIST).
cns_query_asset_compliance_detailsFreeRead-onlyQuery per-asset compliance detail — the pass/fail status of individual compliance checks for each asset against the selected benchmark.
cns_query_asset_compliance_report_dataFreeRead-onlyQuery the asset-compliance report data — the report-shaped compliance rollup per asset (score, passed/failed check counts, benchmark).
cns_query_asset_security_report_dataFreeRead-onlyQuery the asset-security report data — the report-shaped security rollup per asset (security score, risk, problem counts).
cns_query_assets_by_applicationFreeRead-onlyQuery assets grouped by installed application — which assets run a given application/product, for software-inventory and exposure analysis.
cns_query_assets_by_application_suppressedFreeRead-onlyQuery assets grouped by installed application INCLUDING suppressed findings.
cns_query_companies_by_applicationFreeRead-onlyQuery companies grouped by installed application — which managed companies run a given application/product across their fleet.
cns_query_companies_by_application_suppressedFreeRead-onlyQuery companies grouped by installed application INCLUDING suppressed findings.
cns_query_compliance_asset_infoFreeRead-onlyQuery compliance asset info — the asset-level metadata used by compliance reporting (asset identity, OS, applicable benchmarks).
cns_query_compliance_check_countFreeRead-onlyQuery compliance check counts — aggregate passed/failed/total check counts for the selected compliance benchmark.
cns_query_compliance_check_count_by_sectionFreeRead-onlyQuery compliance check counts broken down by benchmark section/control family — passed/failed/total per section.
cns_query_compliance_internal_checksFreeRead-onlyQuery compliance internal checks — the individual internal control checks evaluated for compliance, with their definitions and results.
cns_query_vulnerabilitiesFreeRead-onlyQuery vulnerabilities across your environment — vulnerability records with internal and CVE IDs, severity ratings, status (open/fixed/in-remediation), affected-asset details (hostname/IP), and…
cns_query_vulnerabilities_detailsFreeRead-onlyQuery vulnerability details — per-vulnerability records (CVE, CVSS/EPSS, description, affected assets) across the tenant.
cns_query_vulnerabilities_details_suppressedFreeRead-onlyQuery vulnerability details INCLUDING suppressed vulnerabilities.

[CyberCNS (ConnectSecure)] List the compliance frameworks/benchmark types available in this tenant (e.g. CIS, HIPAA, PCI, NIST). Use the returned type identifiers to scope the compliance report queries in this group. Offset-paginated; supports the condition filter grammar.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query per-asset compliance detail — the pass/fail status of individual compliance checks for each asset against the selected benchmark. Offset-paginated; supports the condition filter grammar. See cns_query_asset_compliance_report_data for the report-shaped rollup.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the asset-compliance report data — the report-shaped compliance rollup per asset (score, passed/failed check counts, benchmark). Offset-paginated; supports the condition filter grammar. See cns_query_asset_compliance_details for per-check detail.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query the asset-security report data — the report-shaped security rollup per asset (security score, risk, problem counts). This is the report_queries variant; for the raw per-asset security record use cns_get_asset_security_report_data (asset domain). Offset-paginated; supports the condition filter grammar.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query assets grouped by installed application — which assets run a given application/product, for software-inventory and exposure analysis. Offset-paginated; supports the condition filter grammar. Use the _suppressed variant to include suppressed findings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query assets grouped by installed application INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_assets_by_application for the non-suppressed view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query companies grouped by installed application — which managed companies run a given application/product across their fleet. Offset-paginated; supports the condition filter grammar. Use the _suppressed variant to include suppressed findings.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query companies grouped by installed application INCLUDING suppressed findings. Offset-paginated; supports the condition filter grammar. See cns_query_companies_by_application for the non-suppressed view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query compliance asset info — the asset-level metadata used by compliance reporting (asset identity, OS, applicable benchmarks). Offset-paginated; supports the condition filter grammar.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query compliance check counts — aggregate passed/failed/total check counts for the selected compliance benchmark. Offset-paginated; supports the condition filter grammar. See cns_query_compliance_check_count_by_section for the per-section breakdown.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query compliance check counts broken down by benchmark section/control family — passed/failed/total per section. Offset-paginated; supports the condition filter grammar. See cns_query_compliance_check_count for the benchmark total.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query compliance internal checks — the individual internal control checks evaluated for compliance, with their definitions and results. Offset-paginated; supports the condition filter grammar.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query vulnerabilities across your environment — vulnerability records with internal and CVE IDs, severity ratings, status (open/fixed/in-remediation), affected-asset details (hostname/IP), and discovery/remediation dates. Offset-paginated; supports the condition filter grammar (e.g. severity, status, asset_id, or CVE filters). See cns_query_vulnerabilities_details for the per-vulnerability detail rollup and cns_query_application_vulnerabilities for the application-scoped report.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query vulnerability details — per-vulnerability records (CVE, CVSS/EPSS, description, affected assets) across the tenant. Offset-paginated; supports the condition filter grammar. Use the _suppressed variant to include suppressed vulnerabilities.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Query vulnerability details INCLUDING suppressed vulnerabilities. Offset-paginated; supports the condition filter grammar. See cns_query_vulnerabilities_details for the non-suppressed view.

ParamTypeRequiredDefaultDescription
conditionstringnonullOptional CyberCNS filter expression in the field:op:value grammar (e.g. 'benchmark:eq:CIS', 'company_id:eq:123', 'created:gt:2024-01-01'); combine clauses with commas. Passed through verbatim.
limitintegerno100Max rows to return (default 100, capped at 5000).
orderBystringnonullOptional sort expression (a field name, optionally with a direction) passed through verbatim.
skipintegerno0Row offset for pagination (default 0).

Report Builder

ToolPlanAccessSummary
cns_create_report_jobProWriteEnqueue a new report-generation job.
cns_download_default_templateFreeRead-onlyRetrieve the default report template.
cns_get_report_linkFreeRead-onlyGet the downloadable report link for a completed report job.
cns_get_standard_report_settingsFreeRead-onlyGet the settings/metadata for a standard report by report type (e.g. 'sales', 'inventory').
cns_list_standard_reportsFreeRead-onlyList the standard reports available in the report builder.
cns_set_cover_pageProWriteSet/upload the report cover page.
cns_update_standard_report_settingsProWriteUpdate the settings for a standard report (header, footer, watermark, and other customization).
cns_upload_templateProWriteUpload a custom report template.

[CyberCNS (ConnectSecure)] Enqueue a new report-generation job. Provide a JSON object body with the report parameters: company_id, reportName, reportType, fileType (e.g. 'pdf'), and optionally isFilter plus a nested reportFilter object (e.g. {"startDate":"2024-01-01","endDate":"2024-12-31"}). Once complete, fetch the download link with cns_get_report_link. (Parameters are sent as query params per the documented API.)

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object of report parameters. Typical fields: company_id, reportName, reportType, fileType; optional isFilter and a nested reportFilter object.

[CyberCNS (ConnectSecure)] Retrieve the default report template. Returns JSON with the template details (NOT raw binary), so it is a straight read. Upload a custom template with cns_upload_template.

[CyberCNS (ConnectSecure)] Get the settings/metadata for a standard report by report type (e.g. 'sales', 'inventory'). Set isGlobal=true for the global settings or isGlobal=false for tenant-specific settings; omit for the server default. Update these settings with cns_update_standard_report_settings.

ParamTypeRequiredDefaultDescription
isGlobalbooleannonullOptional: true = global settings, false = tenant-specific settings. Omit for the server default.
reportTypestringyesThe report type whose settings to fetch (e.g. 'sales', 'inventory'). Passed verbatim.

[CyberCNS (ConnectSecure)] List the standard reports available in the report builder. Set isGlobal=true for global (platform) reports or isGlobal=false for user/tenant-specific reports; omit to use the server default. Offset-paginated (skip/limit, limit capped at 5000).

ParamTypeRequiredDefaultDescription
isGlobalbooleannonullOptional: true = only global reports, false = only user/tenant-specific reports. Omit for the server default.
limitintegerno100Max rows to return (default 100, capped at 5000).
skipintegerno0Row offset for pagination (default 0).

[CyberCNS (ConnectSecure)] Set/upload the report cover page. Provide a JSON object body: put the cover-page image as a base64 string in a 'file' property (decoded and uploaded as multipart/form-data), and include any other fields such as isGlobal and fileName as plain values. Retrieve current cover-page settings via the report builder UI.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Put the cover image as base64 in 'file'; other scalar fields (e.g. isGlobal, fileName) are sent as form fields.

[CyberCNS (ConnectSecure)] Update the settings for a standard report (header, footer, watermark, and other customization). Provide a JSON object body with id (the report settings id, from cns_get_standard_report_settings), is_global, and the fields to change (e.g. watermark). (Parameters are sent as query params per the documented API.)

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object of settings to update. Typical fields: id (required), is_global, watermark, header, footer.

[CyberCNS (ConnectSecure)] Upload a custom report template. Provide a JSON object body with fileName (the template file name), templateImage (the file content as a base64 string, decoded and uploaded as multipart/form-data), and optionally isGlobal (true = available globally, false = current user only).

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Required: fileName, templateImage (base64 file content). Optional: isGlobal. templateImage is decoded to a binary multipart part.