Skip to main content
Connector guides

Connect CyberCNS (ConnectSecure)

CyberCNS — now branded ConnectSecure — is a vulnerability-management and attack-surface platform built for MSPs. It scans your managed companies for vulnerabilities, inventories assets and installed…

Written By Christopher Scaminaci

Last updated 6 days ago

CyberCNS — now branded ConnectSecure — is a vulnerability-management and attack-surface platform built for MSPs. It scans your managed companies for vulnerabilities, inventories assets and installed software, monitors external attack surface, runs compliance assessments, and reports on Active Directory and Azure posture. StackJack connects to its V4 API.

Connecting CyberCNS to StackJack gives your AI assistant a broad family of cns_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Inventory managed companies, agents, assets, installed software, hardware detail, firewall configuration, ports, and certificates
  • Assess vulnerabilities, attack-surface findings, compliance posture, and security baselines across your clients
  • Report on remediation plans and velocity, problem summaries, and AD/Azure directory posture through the built-in report queries
  • Manage (on Pro plans) companies, credentials, discovery settings, scan schedules, tags, EDR and PII settings, integrations, and vulnerability suppressions
  • Build (on Pro plans) standard report jobs and manage report templates and cover pages

How StackJack authenticates to CyberCNS

CyberCNS V4 uses a bespoke token exchange rather than standard OAuth. You provide three things — your Tenant Name, a Client ID, and a Client Secret — and StackJack presents them to your pod's authorize endpoint to receive a short-lived access token. StackJack caches that token and re-mints a fresh one automatically when it expires. There is no refresh token and nothing for you to rotate beyond the API key itself.

The Client ID and Client Secret are a per-user API key. In the current ConnectSecure portal, create it under Global → Settings → Users → the user's three-dot action menu → API Key. Every tool call runs with that user's permissions — a 403 from a tool means the key's user lacks access to that resource, not an account-wide block. Create the key on a dedicated user whose access matches what you want your AI to see and do.

Your pod host

CyberCNS has no single global address — each tenant lives on a numbered pod (for example https://pod401.myconnectsecure.com), which you can read from your browser's address bar while signed in to ConnectSecure. On-premises installations use your own ConnectSecure host with the same API. You enter this host as the Pod URL; it must match where the API key was created. The ConnectSecure sign-in address https://portal.myconnectsecure.com is not a pod host — it carries no API, so saving it fails with a 405 even when your Tenant Name, Client ID and Client Secret are correct.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In ConnectSecure: access sufficient to view Global → Settings → Users and create an API key for a user.
  • Know your pod host — the https://podNNN.myconnectsecure.com (or on-prem) address shown in the portal.
  • Review ConnectSecure's current API FAQ. Your pod's live Swagger documentation is available under Profile → API Documentation.

Step 1 — Find your pod host and tenant name

  1. Sign in to ConnectSecure.
  2. Note the host in your browser's address bar — that is your Pod URL (for example https://pod401.myconnectsecure.com).
  3. Note your Tenant Name — the account/company identifier your ConnectSecure account is known by. It is the first component of the API authorization and is required.

Step 2 — Create an API key

  1. Go to Global → Settings → Users.
  2. Find the user the API should act as. Prefer a dedicated user whose access matches what you want your AI to do rather than a personal admin login.
  3. Open that user's three-dot action menu, choose API Key, and generate the credential. This yields a Client ID and Client Secret.

Step 3 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Select the CyberCNS (ConnectSecure) tile to open its details. Choose How To Connect to review the inline setup guide, or Configure to reveal the credential form in the drawer.
  3. Enter the Pod URL (your pod or on-prem host, no trailing path).
  4. Enter the Tenant Name, the Client ID, and the Client Secret.
  5. Click Save.

What happens when you save

  • The Tenant Name, Client ID, and Client Secret are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure CyberCNS, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the credentials by minting a token and requesting a one-record company list. Validation never blocks the save.
  • After saving, the form collapses and the connector drawer stays open. It shows Connected / Valid on success, or Needs Attention with Re-test and recovery guidance if validation failed.

Plans and available tools

  • Free includes list/get operations across companies, agents, assets, hardware, firewall, ports and certificates; plus the report-query surface — inventory, AD/Azure directory, problems and remediation plans, application and environment-wide vulnerabilities, and compliance.
  • Pro adds write and delete operations for companies, credentials, discovery settings, scan schedules, tags, EDR, PII and custom profiles, integrations, and vulnerability suppressions; external scan starts; and report-builder writes (create report jobs, upload templates, set cover pages).
  • Business offers the same tool set as Pro with a higher monthly call quota.

See the generated ConnectSecure (CyberCNS) tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Safety note — destructive tools. StackJack marks these irreversible Pro operations as destructive: the cns_delete_* tools (delete a company, credential, asset, tag, suppression, and so on), plus cns_reset_agents and cns_remove_schedule. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and scope your AI's access deliberately — use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.

CyberCNS has no per-user OAuth, so there is no per-user attribution — all AI traffic authenticates as the single API-key user. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Rate limits

CyberCNS allows up to 300 requests per minute (and 2,000 per hour, 30,000 per day). StackJack paces requests towards the per-minute limit and backs off automatically if the API signals it is busy, so a long multi-page inventory or report read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Filtering and paging results

Most list and report tools accept a condition filter and an order_by sort in ConnectSecure's query language (for example condition=name:startswith:acme or order_by=created:desc), and page with skip and limit. ConnectSecure documents a default limit of 100 and recommends larger supported pages when high call counts cause 429 responses. Ask your AI to narrow a large query by company, severity, or date and continue paging until complete.

Rotating or replacing the credentials

The API key is the recovery secret. If you regenerate or delete the API key in ConnectSecure — or the key's user loses access — the stored credential becomes invalid. To restore access, create a new key and open Connectors → CyberCNS (ConnectSecure) → Configure in StackJack, enter the new Client ID and Client Secret (re-enter the Pod URL and Tenant Name if needed), then Save.

Disconnecting ConnectSecure

StackJack's Disconnect action removes the stored tenant name and API credential and stops future calls. It does not delete the per-user API key or disable its user in ConnectSecure. Revoke that key from the user's three-dot menu, and disable the dedicated user if it is no longer needed anywhere else. Subscription changes are separate from credential removal.

Troubleshooting

SymptomLikely causeWhat to do
Needs Attention immediately after savingWrong pod host, mis-typed Tenant Name, or a bad Client ID / Client SecretRe-check the Pod URL and credential, save, then use Re-test
Tools worked, then started failingThe API key was regenerated or deleted in ConnectSecure, or its user lost accessCreate a new API key and update the credential in Connectors → CyberCNS → Configure
One tool returns a 403 while others succeedThe API key's user lacks access to that resourceGrant the user the needed access in ConnectSecure, or create the key on a user who has it
Write or delete tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the CyberCNS connector plan and check your tool selections on the MCP Setup page
A report or inventory read is slowStackJack is pacing requests under the rate limit for a large multi-page resultExpected; narrow the query with a condition filter, or let it finish

CyberCNS (ConnectSecure) tools

cns_ · 295 tools · Free 243 · Pro 52

Companies

ToolWhat it does
cns_delete_companies
Pro · Destructive
Permanently delete a managed company by id (from cns_list_companies).
cns_delete_custom_ticketing_template
Pro · Destructive
Permanently delete a custom ticketing template by id (from cns_list_custom_ticketing_template).
cns_get_app_baseline_plan_global
Free · Read-only
Get a single global application-baseline plan entry by id (from cns_list_app_baseline_plan_global).
cns_get_companies
Free · Read-only
Get a single managed company by its id (discover ids with cns_list_companies).
cns_get_company_stats
Free · Read-only
Get the rolled-up statistics for a single company by id.
cns_get_custom_ticketing_template
Free · Read-only
Get a single custom ticketing template by id (from cns_list_custom_ticketing_template).
cns_list_app_baseline_plan_global
Free · Read-only
List the global application-baseline plan entries — the tenant-wide baseline of approved/expected applications used to flag baseline deviations.
cns_list_asset_windows_compatibility
Free · Read-only
List Windows OS patch/upgrade compatibility status across assets (e.g. which assets can move to a newer Windows build).
cns_list_companies
Free · Read-only
List the managed companies (clients) in your ConnectSecure tenant.
cns_list_company_stats
Free · Read-only
List rolled-up statistics per company (asset counts, external/internal totals, risk figures).
cns_list_custom_ticketing_template
Free · Read-only
List the custom ticketing templates configured for the tenant (used to shape tickets pushed to integrated PSA/ticketing systems).
cns_save_companies
Pro · Write
Create or update a managed company.
cns_save_custom_ticketing_template
Pro · Write
Create or update a custom ticketing template.

Agents & Credentials

ToolWhat it does
cns_delete_agent_discoverysettings_mapping
Pro · Destructive
Permanently delete an agent-to-discovery-settings mapping by id (from cns_list_agent_discoverysettings_mapping).
cns_delete_credentials
Pro · Destructive
Permanently delete a scan credential by id (from cns_list_credentials).
cns_delete_discovery_settings
Pro · Destructive
Permanently delete a discovery-settings record by id (from cns_list_discovery_settings).
cns_get_agent_credentials_mapping
Free · Read-only
Get a single agent-to-credentials mapping by id (from cns_list_agent_credentials_mapping).
cns_get_agent_discoverysettings_mapping
Free · Read-only
Get a single agent-to-discovery-settings mapping by id (from cns_list_agent_discoverysettings_mapping).
cns_get_agents
Free · Read-only
Get a single scanning agent by its id (from cns_list_agents).
cns_get_credentials
Free · Read-only
Get a single scan credential record by id (from cns_list_credentials).
cns_get_discovery_settings
Free · Read-only
Get a single discovery-settings record by id (from cns_list_discovery_settings).
cns_list_agent_credentials_mapping
Free · Read-only
List the mappings that bind scanning agents to the credentials they use.
cns_list_agent_discoverysettings_mapping
Free · Read-only
List the mappings that bind scanning agents to discovery settings.
cns_list_agents
Free · Read-only
List the scanning agents associated with your companies.
cns_list_credentials
Free · Read-only
List the scan credentials configured for a company (used by agents to authenticate to targets).
cns_list_discovery_settings
Free · Read-only
List the discovery settings for a company (the address ranges/targets, exclusions, tags, and profiles that steer network discovery).
cns_save_agent_credentials_mapping
Pro · Write
Create or update a mapping binding a scanning agent to a set of credentials.
cns_save_agent_discoverysettings_mapping
Pro · Write
Create or update a mapping binding a scanning agent to a set of discovery settings.
cns_save_credentials
Pro · Write
Create or update a scan credential.
cns_save_discovery_settings
Pro · Write
Create or update a discovery-settings record.

Scheduling & Events

ToolWhat it does
cns_delete_event_set
Pro · Destructive
Permanently delete an event set by id (from cns_list_event_set).
cns_delete_scheduler
Pro · Destructive
Permanently delete a scan scheduler by id (from cns_list_scheduler).
cns_external_scan
Pro · Destructive
Trigger an external (attack-surface) scan.
cns_get_event_set
Free · Read-only
Get a single event set by id (from cns_list_event_set).
cns_get_jobs_view
Free · Read-only
Get a single scan/processing job by id (from cns_list_jobs_view).
cns_get_report_jobs_view
Free · Read-only
Get a single report-generation job by id (from cns_list_report_jobs_view).
cns_get_scheduler
Free · Read-only
Get a single scan scheduler by id (from cns_list_scheduler).
cns_list_event_set
Free · Read-only
List the event sets (notification/alert rule groups) configured for the tenant.
cns_list_jobs_view
Free · Read-only
List scan/processing jobs for your companies (status, timing, and outcome of scans and background work).
cns_list_report_jobs_view
Free · Read-only
List report-generation jobs (status and outcome of report builds).
cns_list_scheduler
Free · Read-only
List the scan schedulers configured for your companies (the recurring scan/report schedules).
cns_remove_schedule
Pro · Destructive
Remove a scan schedule.
cns_reset_agents
Pro · Destructive
Reset one or more scanning agents.
cns_save_event_set
Pro · Write
Create or update an event set (notification/alert rule group).
cns_save_scheduler
Pro · Write
Create or update a scan scheduler.
cns_update_schedule
Pro · Write
Update an existing scan schedule.

Baselines

ToolWhat it does
cns_delete_application_baseline_rules
Pro · Destructive
Permanently delete an application-baseline rule by id.
cns_delete_backup_software
Pro · Destructive
Permanently delete a backup-software record by id.
cns_get_app_baseline_plan_assets
Free · Read-only
Get a single asset-level application-baseline-plan record by its id (from cns_list_app_baseline_plan_assets).
cns_get_app_baseline_plan_company
Free · Read-only
Get a single company-level application-baseline-plan record by its id (from cns_list_app_baseline_plan_company).
cns_get_application_baseline_rules
Free · Read-only
Get a single application-baseline rule by its id (from cns_list_application_baseline_rules).
cns_get_backup_software
Free · Read-only
Get a single backup-software record by its id (from cns_list_backup_software).
cns_list_app_baseline_plan_assets
Free · Read-only
List the application-baseline plan evaluated at the asset level — which baseline applications each asset has, is missing, or has extra.
cns_list_app_baseline_plan_company
Free · Read-only
List the application-baseline plan rolled up at the company level.
cns_list_application_baseline_rules
Free · Read-only
List the application-baseline rules — the policy of approved / unapproved applications used to grade assets.
cns_list_backup_software
Free · Read-only
List detected backup-software inventory across the company (e.g. Veeam, Acronis) used for backup-coverage posture.
cns_save_application_baseline_rules
Pro · Write
Create or update an application-baseline rule.
cns_save_backup_software
Pro · Write
Create or update a backup-software definition.

Security Posture

ToolWhat it does
cns_delete_compliance_assessment
Pro · Destructive
Permanently delete a compliance assessment by id, discarding its recorded progress and answers.
cns_delete_custom_profile
Pro · Destructive
Permanently delete a custom compliance/scan profile by id.
cns_delete_edr
Pro · Destructive
Permanently delete an EDR coverage definition by id.
cns_delete_pii_scan_settings
Pro · Destructive
Permanently delete a PII-scan-settings record by id.
cns_get_attack_surface_results
Free · Read-only
Get a single external attack-surface result by its id (from cns_list_attack_surface_results), including the full detail (target_ips, subdomains, breach creds/hashes, email spoof checks, raw headers).
cns_get_compliance_assessment
Free · Read-only
Get a single compliance assessment by its id (from cns_list_compliance_assessment).
cns_get_custom_profile
Free · Read-only
Get a single custom compliance/scan profile by its id (from cns_list_custom_profile).
cns_get_edr
Free · Read-only
Get a single EDR coverage definition by its id (from cns_list_edr).
cns_get_pii_scan_settings
Free · Read-only
Get a single PII-scan-settings record by its id (from cns_list_pii_scan_settings).
cns_list_attack_surface_results
Free · Read-only
List external attack-surface scan results (subdomains, emails, leaked creds/hashes, DNS/SPF/DMARC/MX findings, S3 buckets, exposed employees) discovered for the company's monitored domains.
cns_list_compliance_assessment
Free · Read-only
List compliance assessments for the company (template name/status, completed sections, type, completion time).
cns_list_custom_profile
Free · Read-only
List custom compliance/scan profiles defined for the company (tailored check sets layered on top of the built-in compliance templates).
cns_list_edr
Free · Read-only
List EDR (endpoint detection & response) coverage definitions for the company — which EDR products are recognized/expected on assets.
cns_list_pii_scan_settings
Free · Read-only
List PII-scan settings for the company (which sensitive-data patterns/paths the scanner looks for).
cns_save_compliance_assessment
Pro · Write
Create or update a compliance assessment.
cns_save_custom_profile
Pro · Write
Create or update a custom compliance/scan profile.
cns_save_edr
Pro · Write
Create or update an EDR coverage definition.
cns_save_pii_scan_settings
Pro · Write
Create or update a PII-scan-settings record.

Tags & Domains

ToolWhat it does
cns_delete_attack_surface_domain
Pro · Destructive
Permanently delete a monitored attack-surface domain by id, stopping future scans of it.
cns_delete_tag_rules
Pro · Destructive
Permanently delete an auto-tagging rule by id.
cns_delete_tags
Pro · Destructive
Permanently delete a tag by id.
cns_get_attack_surface_domain
Free · Read-only
Get a single monitored attack-surface domain by its id (from cns_list_attack_surface_domain).
cns_get_custom_domains
Free · Read-only
Get a single custom domain by its id (from cns_list_custom_domains).
cns_get_tag_rules
Free · Read-only
Get a single auto-tagging rule by its id (from cns_list_tag_rules).
cns_get_tags
Free · Read-only
Get a single tag by its id (from cns_list_tags).
cns_list_attack_surface_domain
Free · Read-only
List the external domains monitored for attack-surface scanning.
cns_list_custom_domains
Free · Read-only
List custom domains configured for the company (e.g. white-label / branding domains and their status).
cns_list_tag_rules
Free · Read-only
List auto-tagging rules — conditions that automatically apply tags (from cns_list_tags) to matching assets.
cns_list_tags
Free · Read-only
List tags defined for the company (labels applied to assets/companies for grouping and filtering across reports).
cns_save_attack_surface_domain
Pro · Write
Add or update a monitored attack-surface domain.
cns_save_tag_rules
Pro · Write
Create or update an auto-tagging rule.
cns_save_tags
Pro · Write
Create or update a tag.
cns_set_custom_domain
Pro · Write
Set the company's custom branding domain and upload its SSL certificate.

Asset Inventory

ToolWhat it does
cns_delete_assets
Pro · Destructive
Delete an asset by id (from cns_list_assets).
cns_get_asset_compliance_report_card
Free · Read-only
Get a single asset compliance report-card record by id (discover ids with cns_list_asset_compliance_report_card).
cns_get_asset_interface
Free · Read-only
Get a single asset network-interface record by id (discover ids with cns_list_asset_interface).
cns_get_asset_ports
Free · Read-only
Get a single asset open-port record by id (discover ids with cns_list_asset_ports).
cns_get_asset_security_report_data
Free · Read-only
Get a single asset security-report-data record by id (discover ids with cns_list_asset_security_report_data).
cns_get_asset_shares
Free · Read-only
Get a single asset network-share record by id (discover ids with cns_list_asset_shares).
cns_get_asset_stats
Free · Read-only
Get a single asset-statistics record by id (discover ids with cns_list_asset_stats).
cns_get_asset_unqouted_services
Free · Read-only
Get a single unquoted-service-path record by id (discover ids with cns_list_asset_unqouted_services).
cns_get_asset_user_shares
Free · Read-only
Get a single asset user-share record by id (discover ids with cns_list_asset_user_shares).
cns_get_asset_view
Free · Read-only
Get a single enriched asset-view record by id (discover ids with cns_list_asset_view).
cns_get_assets
Free · Read-only
Get a single asset by id (discover ids with cns_list_assets).
cns_list_asset_compliance_report_card
Free · Read-only
List per-asset compliance report-card records (an asset's pass/fail posture against the compliance benchmarks it is assessed on).
cns_list_asset_interface
Free · Read-only
List network interfaces discovered on assets (NIC name, MAC, IP addresses, and link state).
cns_list_asset_ports
Free · Read-only
List open network ports discovered on assets (port number, protocol, state, and the service behind it).
cns_list_asset_security_report_data
Free · Read-only
List per-asset security report data (the asset-level security posture rows backing the security report).
cns_list_asset_shares
Free · Read-only
List network shares discovered on assets (SMB/CIFS share name, path, and permissions).
cns_list_asset_stats
Free · Read-only
List per-asset statistics (vulnerability, problem and compliance counts rolled up per asset).
cns_list_asset_unqouted_services
Free · Read-only
List Windows services with unquoted service paths on assets — a privilege-escalation weakness (CyberCNS spells the endpoint 'unqouted').
cns_list_asset_user_shares
Free · Read-only
List per-user share access discovered on assets (which users/groups can reach each network share).
cns_list_asset_view
Free · Read-only
List the enriched asset-view records (a denormalized asset summary joining company, OS, risk and scan metadata).
cns_list_assets
Free · Read-only
List the assets (endpoints, servers, network/firewall devices) discovered and scanned across your ConnectSecure companies.
cns_save_assets
Pro · Write
Create or update an asset.

Asset Hardware

ToolWhat it does
cns_get_asset_installed_drivers
Free · Read-only
Get a single installed-driver record by id (discover ids with cns_list_asset_installed_drivers).
cns_get_asset_msdt
Free · Read-only
Get a single MSDT-finding record by id (discover ids with cns_list_asset_msdt).
cns_get_asset_storages
Free · Read-only
Get a single storage-volume record by id (discover ids with cns_list_asset_storages).
cns_get_asset_video_info
Free · Read-only
Get a single video/GPU-info record by id (discover ids with cns_list_asset_video_info).
cns_get_asset_windows_reboot_required
Free · Read-only
Get a single Windows reboot-required record by id (discover ids with cns_list_asset_windows_reboot_required).
cns_get_bios_info
Free · Read-only
Get a single BIOS/firmware-info record by id (discover ids with cns_list_bios_info).
cns_get_browser_extensions
Free · Read-only
Get a single browser-extension record by id (discover ids with cns_list_browser_extensions).
cns_get_ciphers_view
Free · Read-only
Get a single TLS/SSL cipher record by id (discover ids with cns_list_ciphers_view).
cns_get_windows_protection_status
Free · Read-only
Get a single Windows protection-status record by id (discover ids with cns_list_windows_protection_status).
cns_list_asset_installed_drivers
Free · Read-only
List device drivers installed on assets (driver name, version, provider, and signing status).
cns_list_asset_msdt
Free · Read-only
List Microsoft Support Diagnostic Tool (MSDT) findings on assets — used to surface the Follina-class MSDT exposure.
cns_list_asset_storages
Free · Read-only
List storage volumes and disks discovered on assets (drive letter/mount, filesystem, total and free capacity, encryption state).
cns_list_asset_video_info
Free · Read-only
List video/GPU adapter info discovered on assets (adapter name, driver version, resolution, VRAM).
cns_list_asset_windows_reboot_required
Free · Read-only
List Windows assets that have a pending reboot (patches/updates staged but not yet applied until restart).
cns_list_bios_info
Free · Read-only
List BIOS/firmware info discovered on assets (vendor, version, release date, serial).
cns_list_browser_extensions
Free · Read-only
List browser extensions/add-ons discovered on assets (browser, extension name, version, and enabled state) — used to surface risky or unwanted add-ons.
cns_list_ciphers_view
Free · Read-only
List the TLS/SSL cipher suites observed on assets (protocol version, cipher name, and strength) — used to flag weak or deprecated ciphers.
cns_list_windows_protection_status
Free · Read-only
List Windows protection (Defender/antivirus) status per asset — real-time protection, definition freshness, firewall and tamper-protection state.

Firewall & Vulnerabilities

ToolWhat it does
cns_delete_suppress_vulnerability
Pro · Destructive
Delete a vulnerability suppression by its id (from cns_list_suppress_vulnerability).
cns_get_asset_firewall_policy
Free · Read-only
Get a single asset firewall policy by its id (from cns_list_asset_firewall_policy).
cns_get_firewall_groups
Free · Read-only
Get a single firewall group by its id (from cns_list_firewall_groups).
cns_get_firewall_interfaces
Free · Read-only
Get a single firewall interface by its id (from cns_list_firewall_interfaces).
cns_get_firewall_license
Free · Read-only
Get a single firewall license by its id (from cns_list_firewall_license).
cns_get_firewall_rules
Free · Read-only
Get a single firewall rule by its id (from cns_list_firewall_rules).
cns_get_firewall_users
Free · Read-only
Get a single firewall user by its id (from cns_list_firewall_users).
cns_get_firewall_zones
Free · Read-only
Get a single firewall zone by its id (from cns_list_firewall_zones).
cns_get_remediated
Free · Read-only
Get a single remediated software/asset record by its id (from cns_list_remediated).
cns_get_suppress_vulnerability
Free · Read-only
Get a single suppressed vulnerability by its id (from cns_list_suppress_vulnerability).
cns_list_asset_firewall_policy
Free · Read-only
List asset firewall policies discovered by network/firewall scans.
cns_list_firewall_groups
Free · Read-only
List firewall address/service groups discovered on scanned firewall assets.
cns_list_firewall_interfaces
Free · Read-only
List firewall interfaces discovered on scanned firewall assets.
cns_list_firewall_license
Free · Read-only
List firewall license records discovered on scanned firewall assets.
cns_list_firewall_rules
Free · Read-only
List firewall rules discovered on scanned firewall assets.
cns_list_firewall_users
Free · Read-only
List firewall users discovered on scanned firewall assets.
cns_list_firewall_zones
Free · Read-only
List firewall security zones discovered on scanned firewall assets.
cns_list_remediated
Free · Read-only
List remediated software/assets — software whose vulnerabilities have been resolved.
cns_list_suppress_vulnerability
Free · Read-only
List suppressed vulnerabilities.
cns_save_suppress_vulnerability
Pro · Write
Create or update a vulnerability suppression — marks a vulnerability as suppressed so it is excluded from future reports.

Integrations

ToolWhat it does
cns_delete_company_mappings
Pro · Destructive
Delete an integration company mapping by its id (from cns_list_company_mappings).
cns_delete_integration_credentials
Pro · Destructive
Delete an integration credential by its id (from cns_list_integration_credentials).
cns_delete_integration_rules
Pro · Destructive
Delete an integration rule by its id (from cns_list_integration_rules).
cns_get_company_mappings
Free · Read-only
Get a single integration company mapping by its id (from cns_list_company_mappings).
cns_get_integration_credentials
Free · Read-only
Get a single integration credential by its id (from cns_list_integration_credentials).
cns_get_integration_rules
Free · Read-only
Get a single integration rule by its id (from cns_list_integration_rules).
cns_list_company_mappings
Free · Read-only
List integration company mappings — each links a ConnectSecure source company to a destination integration company/site.
cns_list_integration_credentials
Free · Read-only
List integration credentials — the stored connections to third-party PSA/RMM/ticketing systems.
cns_list_integration_rules
Free · Read-only
List integration rules — the automation rules that map ConnectSecure events to third-party actions (e.g. ticket creation).
cns_save_company_mappings
Pro · Write
Create or update an integration company mapping — links a ConnectSecure source company to a destination integration company/site.
cns_save_integration_credentials
Pro · Write
Create or update an integration credential — the stored connection to a third-party PSA/RMM/ticketing system.
cns_save_integration_rules
Pro · Write
Create or update an integration rule — the automation that maps ConnectSecure events to a third-party action (e.g. ticket creation).

Report Queries — Inventory

ToolWhat it does
cns_query_asset_ports_view
Free · Read-only
Query the asset open-ports report: TCP/UDP ports discovered across assets with protocol, service, and secure/insecure classification.
cns_query_asset_software
Free · Read-only
Query the installed-software inventory across assets (software name, version, publisher, type).
cns_query_cert_info_view
Free · Read-only
Query discovered SSL/TLS certificate information across assets (subject, issuer, validity window, expiry).
cns_query_compliance_count
Free · Read-only
Query aggregate compliance pass/fail counts across the environment.
cns_query_distinct_agents_name
Free · Read-only
Query the distinct list of agent names — a lookup helper for building filters and dropdowns.
cns_query_distinct_asset_ip
Free · Read-only
Query the distinct list of asset IP addresses — a lookup helper for building filters.
cns_query_distinct_asset_name
Free · Read-only
Query the distinct list of asset (host) names — a lookup helper for building filters.
cns_query_distinct_discovered_protocols
Free · Read-only
Query the distinct list of discovered network protocols — a lookup helper for building filters.
cns_query_distinct_os
Free · Read-only
Query the distinct list of operating systems observed across assets — a lookup helper for building OS filters.
cns_query_distinct_platform
Free · Read-only
Query the distinct list of platforms (Windows / Linux / macOS / network / etc.) — a lookup helper for building filters.
cns_query_distinct_tags
Free · Read-only
Query the distinct list of tags applied across assets and companies — a lookup helper for building tag filters.
cns_query_event_tickets
Free · Read-only
Query the event-generated tickets report (tickets raised from monitored events).
cns_query_get_assets_by_problem
Free · Read-only
Query assets grouped/filtered by a specific problem (vulnerability or misconfiguration) — which assets are affected by a given problem.
cns_query_lightweight_assets
Free · Read-only
Query one company's lightweight asset list (minimal fields — id, host name, company) for fast per-company enumeration.
cns_query_notification_tickets_view
Free · Read-only
Query the notification-tickets report (tickets raised from notifications).
cns_query_os_pending_patches
Free · Read-only
Query pending OS patches across assets (missing operating-system updates).
cns_query_ports_assets_details
Free · Read-only
Query per-asset open-port details (open ports joined to their host asset).
cns_query_problems_ssl_for_asset
Free · Read-only
Query SSL/TLS-related problems for assets (weak ciphers, expired/invalid certificates, protocol issues).
cns_query_tags_view
Free · Read-only
Query the tags report (tag assignments with counts).
cns_query_total_asset_count
Free · Read-only
Query the total asset-count aggregate for the environment (optionally scoped via the condition filter).
cns_query_unconfirmed_key_check
Free · Read-only
Query the unconfirmed-key-check report (discovery keys awaiting confirmation).
cns_query_unconfirmed_open_ports_key_check
Free · Read-only
Query the unconfirmed open-ports key-check report (open-port discovery keys awaiting confirmation).

Report Queries — System (Linux/Windows)

ToolWhat it does
cns_query_asset_firewall_rules
Free · Read-only
Query per-asset host firewall rules (OS firewall configuration across assets).
cns_query_asset_iptables_rules
Free · Read-only
Query Linux iptables rules across assets.
cns_query_asset_patches_info
Free · Read-only
Query per-asset patch information (installed and pending patch detail across assets).
cns_query_asset_processes_running
Free · Read-only
Query running processes across assets (process name, path, owner, state).
cns_query_asset_registry_misconfiguration
Free · Read-only
Query Windows registry misconfigurations across assets (insecure registry key/value settings).
cns_query_asset_services
Free · Read-only
Query OS services across assets (service name, state, start type).
cns_query_asset_users
Free · Read-only
Query local/OS user accounts across assets (username, admin status, last logon).
cns_query_cron_jobs
Free · Read-only
Query Linux cron jobs across assets (scheduled tasks, schedule expression, command).
cns_query_job_details_view
Free · Read-only
Query job execution details (scan/agent job detail report — job status, timing, target).
cns_query_kernel_modules
Free · Read-only
Query loaded Linux kernel modules across assets (module name, size, used-by count).
cns_query_selinux_settings
Free · Read-only
Query SELinux configuration/status across Linux assets (mode, policy).
cns_query_suid_permissions
Free · Read-only
Query SUID/SGID file permissions across Linux assets (privileged-escalation-relevant file permissions).
cns_query_system_events_view
Free · Read-only
Query the system-events report (OS/security event-log entries with category, severity, timestamp).
cns_query_system_events_view_ticketid
Free · Read-only
Query system events joined to their generated ticket IDs (which events raised which tickets).
cns_query_ufw_firewall_rules
Free · Read-only
Query UFW (Uncomplicated Firewall) rules across Linux assets.

Report Queries — Directory (AD/Azure)

ToolWhat it does
cns_query_ad_groups_view
Free · Read-only
Query the Active Directory groups report (group name, mail-enabled flag, scope, membership metadata).
cns_query_ad_password_policies
Free · Read-only
Query Active Directory password policies (length, complexity, lockout, age requirements).
cns_query_ad_roles
Free · Read-only
Query Active Directory / directory roles (role name, scope).
cns_query_ad_user_licenses
Free · Read-only
Query directory user license assignments (which licenses are assigned to which directory users).
cns_query_azure_ad_logs
Free · Read-only
Query Azure AD / Entra ID sign-in and audit logs (actor, activity, result, timestamp).
cns_query_azure_licenses
Free · Read-only
Query the Azure / Microsoft 365 license inventory (SKUs, assigned/available counts).
cns_query_azure_secure_score
Free · Read-only
Query the Azure / Microsoft Secure Score report (current score, max score, improvement actions over time).

Reports: Remediation

ToolWhat it does
cns_get_data_remediate_records_asset
Free · Read-only
Fetch the raw remediate-records dataset scoped to a single asset (the /r/get_data/remediate_records_asset feed).
cns_get_data_remediation_plan_asset
Free · Read-only
Fetch the raw remediation-plan dataset scoped to a single asset (the /r/get_data/remediation_plan_asset feed): the ordered set of fixes recommended for one asset.
cns_get_data_remediation_plan_companies
Free · Read-only
Fetch the raw remediation-plan dataset rolled up per company (the /r/get_data/remediation_plan_companies feed).
cns_get_data_remediation_plan_global
Free · Read-only
Fetch the raw remediation-plan dataset across the whole tenant (the /r/get_data/remediation_plan_global feed) — the global prioritized fix list spanning every company.
cns_query_get_remediate_records
Free · Read-only
Report query returning remediate records (the /r/report_queries/get_remediate_records view) — the actions taken or pending to remediate findings.
cns_query_get_remediation
Free · Read-only
Report query returning remediation detail (the /r/report_queries/get_remediation view).
cns_query_remediate_records
Free · Read-only
Report query listing remediate records (the /r/report_queries/remediate_records view).
cns_query_remediate_records_assets
Free · Read-only
Report query with remediate records rolled up per asset (the /r/report_queries/remediate_records_assets view).
cns_query_remediate_records_companies
Free · Read-only
Report query with remediate records rolled up per company (the /r/report_queries/remediate_records_companies view).
cns_query_remediation_companies
Free · Read-only
Report query listing companies with remediation activity (the /r/report_queries/remediation_companies view).
cns_query_remediation_plan_asset_details_by_epss
Free · Read-only
Report query returning remediation-plan asset details ranked by EPSS (Exploit Prediction Scoring System) — the /r/report_queries/remediation_plan_asset_details_by_epss view — so fixes for the most likely-to-be-exploited vulnerabilities surface first.
cns_query_remediation_plan_by_company
Free · Read-only
Report query returning the remediation plan grouped by company (the /r/report_queries/remediation_plan_by_company view).
cns_query_remediation_plan_include_company
Free · Read-only
Report query returning the remediation plan with company context inlined on each row (the /r/report_queries/remediation_plan_include_company view).
cns_query_remediation_velocity_application
Free · Read-only
Report query returning remediation velocity (how quickly findings are being resolved over time) broken down by application (the /r/report_queries/remediation_velocity_application view).
cns_query_remediation_velocity_company
Free · Read-only
Report query returning remediation velocity (how quickly findings are being resolved over time) broken down by company (the /r/report_queries/remediation_velocity_company view).

Reports: Problems

ToolWhat it does
cns_query_asset_wise_vulnerabilities
Free · Read-only
Report query returning vulnerabilities broken down per asset (the /r/report_queries/asset_wise_vulnerabilities view).
cns_query_companies_by_problem_group_suppressed
Free · Read-only
Report query listing companies affected by each problem group, counting SUPPRESSED problems (the /r/report_queries/companies_by_problem_group_suppressed view).
cns_query_problem_group_summary
Free · Read-only
Report query returning a summary per problem group (the /r/report_queries/problem_group_summary view) — counts and severity rollups for each grouped finding.
cns_query_problem_group_summary_asset_company_count
Free · Read-only
Report query returning per-problem-group summaries with affected-asset and affected-company counts (the /r/report_queries/problem_group_summary_asset_company_count view).
cns_query_problems_info
Free · Read-only
Report query returning detailed problem records (the /r/report_queries/problems_info view) — the individual findings with their metadata.
cns_query_problems_remediations_summary
Free · Read-only
Report query summarizing problems alongside their remediation status (the /r/report_queries/problems_remediations_summary view) — how many findings are open vs remediated.
cns_query_problems_summary
Free · Read-only
Report query returning an overall problems summary (the /r/report_queries/problems_summary view) — aggregate finding counts by severity/type.
cns_query_problems_summary_asset_details
Free · Read-only
Report query returning the problems summary expanded to per-asset detail (the /r/report_queries/problems_summary_asset_details view).
cns_query_problems_summary_group_by_companies
Free · Read-only
Report query returning the problems summary grouped per company (the /r/report_queries/problems_summary_group_by_companies view).
cns_query_problems_summary_tag
Free · Read-only
Report query returning the problems summary grouped by asset tag (the /r/report_queries/problems_summary_tag view).
cns_query_registry_problems_company
Free · Read-only
Report query returning Windows-registry misconfiguration problems rolled up per company (the /r/report_queries/registry_problems_company view).
cns_query_registry_problems_remediation
Free · Read-only
Report query returning remediation guidance for Windows-registry problems (the /r/report_queries/registry_problems_remediation view).
cns_query_registry_problems_remediation_asset_details
Free · Read-only
Report query returning registry-problem remediation expanded to per-asset detail (the /r/report_queries/registry_problems_remediation_asset_details view).
cns_query_registry_problems_summary
Free · Read-only
Report query returning a summary of Windows-registry misconfiguration problems (the /r/report_queries/registry_problems_summary view).
cns_query_suppressed_problems
Free · Read-only
Report query listing problems that have been SUPPRESSED (acknowledged/excepted so they no longer count against posture) — the /r/report_queries/suppressed_problems view.

Reports: Directory Detail

ToolWhat it does
cns_query_ad_basic_info
Free · Read-only
Report query returning Active Directory basic information (the report_queries/ad_basic_info view) — high-level domain/forest facts.
cns_query_ad_computers_view
Free · Read-only
Report query listing Active Directory computer objects (the report_queries/ad_computers_view view).
cns_query_ad_domain_details
Free · Read-only
Report query returning Active Directory domain details (the report_queries/ad_domain_details view).
cns_query_ad_gpos_details
Free · Read-only
Report query returning Group Policy Object (GPO) details (the report_queries/ad_gpos_details view).
cns_query_ad_gpos_view
Free · Read-only
Report query listing Group Policy Objects (the report_queries/ad_gpos_view view).
cns_query_ad_group_computers
Free · Read-only
Report query listing computer members of Active Directory groups (the report_queries/ad_group_computers view).
cns_query_ad_group_users
Free · Read-only
Report query listing user members of Active Directory groups (the report_queries/ad_group_users view).
cns_query_ad_ous_view
Free · Read-only
Report query listing Active Directory Organizational Units (the report_queries/ad_ous_view view).
cns_query_ad_roles_details
Free · Read-only
Report query returning Active Directory role details (the report_queries/ad_roles_details view).
cns_query_ad_roles_member
Free · Read-only
Report query listing members of Active Directory roles (the report_queries/ad_roles_member view).
cns_query_ad_users_view
Free · Read-only
Report query listing Active Directory user objects (the report_queries/ad_users_view view).
cns_query_get_computer_details
Free · Read-only
Report query returning full detail for Active Directory computer objects (the report_queries/get_computer_details view).
cns_query_get_ous_details
Free · Read-only
Report query returning full detail for Active Directory Organizational Units (the report_queries/get_ous_details view).
cns_query_get_user_details
Free · Read-only
Report query returning full detail for Active Directory user objects (the report_queries/get_user_details view).

Application Vulnerability Reports

ToolWhat it does
cns_query_app_vulnerabilities_by_os_software_details_suppressed
Free · Read-only
Query per-software vulnerability detail for the by-OS application-vulnerability report, INCLUDING suppressed findings.
cns_query_application_vulnerabilities
Free · Read-only
Query the application-vulnerability report — vulnerable applications/products detected across the tenant's assets, with CVE, severity, and affected-asset rollups.
cns_query_application_vulnerabilities_by_os
Free · Read-only
Query application vulnerabilities grouped by operating system — vulnerable-application counts and severity rollups per OS.
cns_query_application_vulnerabilities_by_os_software_details
Free · Read-only
Query per-software vulnerability detail for the by-OS application-vulnerability report — the specific software packages driving each OS's vulnerability counts.
cns_query_application_vulnerabilities_by_product
Free · Read-only
Query application vulnerabilities grouped by product — vulnerability and affected-asset counts per software product.
cns_query_application_vulnerabilities_by_product_suppressed
Free · Read-only
Query application vulnerabilities grouped by product, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_by_product_suppressed_tag
Free · Read-only
Query application vulnerabilities grouped by product and scoped to tags, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_by_product_tag
Free · Read-only
Query application vulnerabilities grouped by product and scoped to tags.
cns_query_application_vulnerabilities_net
Free · Read-only
Query the net application-vulnerability report — the deduplicated/net-effective vulnerability set after roll-up.
cns_query_application_vulnerabilities_net_suppressed
Free · Read-only
Query the net application-vulnerability report, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_net_suppressed_tag
Free · Read-only
Query the net application-vulnerability report scoped to tags, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_net_tag
Free · Read-only
Query the net application-vulnerability report scoped to tags.
cns_query_application_vulnerabilities_os_patch
Free · Read-only
Query the OS-patch view of the application-vulnerability report — vulnerabilities remediable via OS patches and their patch status.
cns_query_application_vulnerabilities_patching_asset_details
Free · Read-only
Query per-asset patching detail for the application-vulnerability report — which assets need which application/OS patches to close vulnerabilities.
cns_query_application_vulnerabilities_suppressed
Free · Read-only
Query the application-vulnerability report INCLUDING suppressed findings.
cns_query_application_vulnerabilities_suppressed_by_os
Free · Read-only
Query application vulnerabilities grouped by OS INCLUDING suppressed findings.
cns_query_application_vulnerabilities_suppressed_tag
Free · Read-only
Query the application-vulnerability report scoped to tags INCLUDING suppressed findings.
cns_query_application_vulnerabilities_suppressed_tag_by_os
Free · Read-only
Query application vulnerabilities scoped to tags and grouped by OS, INCLUDING suppressed findings.
cns_query_application_vulnerabilities_tag
Free · Read-only
Query the application-vulnerability report scoped to tags.
cns_query_application_vulnerabilities_tag_by_os
Free · Read-only
Query application vulnerabilities scoped to tags and grouped by OS.
cns_query_application_vulnerabilities_v2
Free · Read-only
Query the v2 application-vulnerability report — the newer schema/format of the application-vulnerability rollup.

Compliance & Vulnerability Reports

ToolWhat it does
cns_list_compliance_types
Free · Read-only
List the compliance frameworks/benchmark types available in this tenant (e.g. CIS, HIPAA, PCI, NIST).
cns_query_asset_compliance_details
Free · Read-only
Query per-asset compliance detail — the pass/fail status of individual compliance checks for each asset against the selected benchmark.
cns_query_asset_compliance_report_data
Free · Read-only
Query the asset-compliance report data — the report-shaped compliance rollup per asset (score, passed/failed check counts, benchmark).
cns_query_asset_security_report_data
Free · Read-only
Query the asset-security report data — the report-shaped security rollup per asset (security score, risk, problem counts).
cns_query_assets_by_application
Free · Read-only
Query assets grouped by installed application — which assets run a given application/product, for software-inventory and exposure analysis.
cns_query_assets_by_application_suppressed
Free · Read-only
Query assets grouped by installed application INCLUDING suppressed findings.
cns_query_companies_by_application
Free · Read-only
Query companies grouped by installed application — which managed companies run a given application/product across their fleet.
cns_query_companies_by_application_suppressed
Free · Read-only
Query companies grouped by installed application INCLUDING suppressed findings.
cns_query_compliance_asset_info
Free · Read-only
Query compliance asset info — the asset-level metadata used by compliance reporting (asset identity, OS, applicable benchmarks).
cns_query_compliance_check_count
Free · Read-only
Query compliance check counts — aggregate passed/failed/total check counts for the selected compliance benchmark.
cns_query_compliance_check_count_by_section
Free · Read-only
Query compliance check counts broken down by benchmark section/control family — passed/failed/total per section.
cns_query_compliance_internal_checks
Free · Read-only
Query compliance internal checks — the individual internal control checks evaluated for compliance, with their definitions and results.
cns_query_vulnerabilities
Free · Read-only
Query vulnerabilities across your environment — vulnerability records with internal and CVE IDs, severity ratings, status (open/fixed/in-remediation), affected-asset details (hostname/IP), and discovery/remediation dates.
cns_query_vulnerabilities_details
Free · Read-only
Query vulnerability details — per-vulnerability records (CVE, CVSS/EPSS, description, affected assets) across the tenant.
cns_query_vulnerabilities_details_suppressed
Free · Read-only
Query vulnerability details INCLUDING suppressed vulnerabilities.

Report Builder

ToolWhat it does
cns_create_report_job
Pro · Write
Enqueue a new report-generation job.
cns_download_default_template
Free · Read-only
Retrieve the default report template.
cns_get_report_link
Free · Read-only
Get the downloadable report link for a completed report job.
cns_get_standard_report_settings
Free · Read-only
Get the settings/metadata for a standard report by report type (e.g. 'sales', 'inventory').
cns_list_standard_reports
Free · Read-only
List the standard reports available in the report builder.
cns_set_cover_page
Pro · Write
Set/upload the report cover page.
cns_update_standard_report_settings
Pro · Write
Update the settings for a standard report (header, footer, watermark, and other customization).
cns_upload_template
Pro · Write
Upload a custom report template.