Cloud and infrastructure
Cloud providers, orchestration, and observability platforms an agent can inspect and operate. 16 integrations, 255 tools.
Tool names below are the fully qualified names an agent sees once the integration is connected. Where an integration offers more than one connection, the names shown use the primary connection’s prefix; connecting through another variant prefixes its tools with that variant’s own integration ID instead. See Tool Catalog for how tools are granted and named.
AWS Shield Advanced
Section titled “AWS Shield Advanced”6 tools. Credentials are supplied in the connection settings.
| Tool | Description | Arguments |
|---|---|---|
aws-shield_describe_attack | Describe a single DDoS attack by its attack id. Returns full attack detail: vectors, traffic counters, properties (top contributors, geos, sources), and applied mitigations. | required attack_id |
aws-shield_describe_protection | Describe a single AWS Shield Advanced protection by its protection id OR by the protected resource’s ARN — provide exactly one of the two. Returns the protection’s full metadata. | optional protection_id, resource_arn |
aws-shield_describe_subscription | Return the account’s AWS Shield Advanced subscription details: start/end time, auto-renew status, proactive engagement status, and subscription limits. Useful for billing reviews or expiration checks. | — |
aws-shield_get_subscription_state | Return the current AWS Shield Advanced subscription state for the account: ‘ACTIVE’ or ‘INACTIVE’. Use this as the fast preflight before any other Shield tool — most Shield APIs require an active subscription. | — |
aws-shield_list_attacks | List DDoS attack summaries observed by AWS Shield Advanced in a time window, optionally filtered by resource ARN. Returns lightweight attack metadata (id, target, vectors, start/end). Use describe_attack for full detail. | optional end_time, max_results, next_token, resource_arns, start_time |
aws-shield_list_protections | List AWS Shield Advanced protections in the account, optionally filtered by resource ARN, protection name, or AWS resource type. Returns protection metadata (id, name, resource ARN, health check associations). Paginate via next_token. | optional max_results, next_token, protection_names, resource_arns, resource_types |
Cisco Catalyst Center
Section titled “Cisco Catalyst Center”15 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
cisco-catalyst_apply_anc_policy | Apply Adaptive Network Control (ANC) policy to an endpoint | required epId, ancPolicyoptional granularAncPolicy |
cisco-catalyst_create_profiling_rule | Create a new profiling rule for device classification | required ruleName, conditions, actionsoptional priority |
cisco-catalyst_get_acl_statistics | Get performance statistics for a specific ACL | required deviceId, aclNameoptional timeRange |
cisco-catalyst_get_anc_policies | List all available ANC policies | optional limit, offset |
cisco-catalyst_get_client_details | Get detailed information about a network client device or user (macAddress or userId is required) | optional macAddress, userId |
cisco-catalyst_get_device | Get detailed information for a specific network device | required deviceId |
cisco-catalyst_get_device_acls | Get ACLs configured on a specific device | required deviceIdoptional interfaceType |
cisco-catalyst_get_endpoint_details | Get detailed information about a specific endpoint | required epId |
cisco-catalyst_get_issue_details | Get detailed context and recommended actions for a network issue or alert (issueId or clientMac is required) | optional clientMac, issueId |
cisco-catalyst_list_devices | List all network devices from Catalyst Center with optional filtering | optional managementIp, serialNumber |
cisco-catalyst_list_profiling_rules | List profiling rules with optional filters | optional limit, offset, ruleType |
cisco-catalyst_list_sites | List site hierarchy or filter by site name from Catalyst Center | optional name |
cisco-catalyst_query_endpoints | Query endpoints with optional filters | optional ipAddress, limit, macAddress, offset, profiling |
cisco-catalyst_register_endpoint | Register a new endpoint in the system | required macAddressoptional profileId, staticGroupAssignment |
cisco-catalyst_revoke_anc_policy | Revoke ANC policy from an endpoint | required epId |
Cisco Firepower Management Center
Section titled “Cisco Firepower Management Center”23 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
cisco-fmc_create_access_rule | Create a new access-control rule inside an AC policy. By default the rule is appended to the bottom of the rule list; set insert_before or insert_after to position it. | required policy_id, name, actionoptional destination_networks, destination_zones, domain_uuid, enabled, insert_after, insert_before, log_begin, log_end, send_events_to_fmc, source_networks, source_zones |
cisco-fmc_create_network_object | Create a new network-layer object. | required name, value, kindoptional description, domain_uuid |
cisco-fmc_delete_access_rule | Delete an access-control rule by ID. Does NOT deploy — call deploy_to_devices separately to push the removal to firewalls. | required policy_id, rule_idoptional domain_uuid |
cisco-fmc_deploy_to_devices | Push pending configuration changes to one or more devices. Returns a task descriptor immediately (deployment is async) — poll get_task_status with the returned id until state is Success or Failed. | required device_idsoptional deployment_note, domain_uuid, force_deploy, ignore_warning |
cisco-fmc_get_access_policy | Get a single AC policy by UUID (default action, inheritance, etc.). | required policy_idoptional domain_uuid |
cisco-fmc_get_device | Get full detail for a single managed device (interfaces, HA peer, health, deployment status, etc.) by its FMC UUID. | required device_idoptional domain_uuid |
cisco-fmc_get_intrusion_policy | Get a single intrusion policy by UUID (base policy, rule overrides, etc.). | required policy_idoptional domain_uuid |
cisco-fmc_get_network_object | Get a single network object by ID. kind selects the underlying type-specific endpoint (Host / Network / Range / FQDN). | required object_id, kindoptional domain_uuid |
cisco-fmc_get_server_info | Get the FMC server’s version metadata: serverVersion, geoVersion, vdbVersion, sruVersion (some optional depending on the FMC build). | — |
cisco-fmc_get_task_status | Get the state of an async FMC task (deployment, device push, etc.). State is one of: Pending, Running, Success, Failed, Retry. Returns the full task envelope including any error messages on Failed. | required task_idoptional domain_uuid |
cisco-fmc_list_access_policies | List access-control (AC) policies in the given domain. AC policies are the top-level rule containers attached to devices. | optional domain_uuid, limit |
cisco-fmc_list_access_rules | List access-control rules inside one AC policy. Returns the rules in policy-evaluation order. | required policy_idoptional domain_uuid, filter_expr, limit |
cisco-fmc_list_deployable_devices | List devices with pending (undeployed) configuration changes in the given domain. Each entry includes the device ID and the version that would be deployed. | optional domain_uuid, limit |
cisco-fmc_list_devices | List managed FTD / Firepower devices in the given FMC domain. Returns ID, name, model, software version, health, and HA / cluster membership for each device. Paginated. | optional domain_uuid, limit |
cisco-fmc_list_domains | List all FMC domains the current credentials can access. Returns a name → UUID mapping. Domains partition FMC for multi-tenant or segmented (defense) deployments; the result feeds the optional domain_uuid parameter on every other tool. | — |
cisco-fmc_list_intrusion_policies | List Snort 2 / Snort 3 intrusion-prevention policies in the given domain. Read-only — intrusion-rule CRUD lives in a separate admin workflow. | optional domain_uuid, limit |
cisco-fmc_list_network_groups | List network groups (named collections of network objects + inline IP/CIDR literals) in the given domain. | optional domain_uuid, limit, name_filter |
cisco-fmc_list_network_objects | List network-layer objects (Hosts, Networks, Ranges, FQDNs) in the given domain. | optional domain_uuid, limit, name_filter |
cisco-fmc_list_policy_assignments | List policy → device assignments in the given domain. Useful before mutating a policy to know which devices will receive the change on the next deployment. | optional domain_uuid, limit |
cisco-fmc_list_security_zones | List security zones in the given domain. Zone object IDs are needed when crafting access-control rules whose match criteria include source / destination zones. | optional domain_uuid, limit |
cisco-fmc_search_audit_records | Search the FMC audit trail. filter_expr accepts FMC audit filter keys joined by ;. Verified live against FMC 7.2.9: username. | optional domain_uuid, filter_expr, limit |
cisco-fmc_update_access_rule | Update fields on an existing access-control rule. | required policy_id, rule_idoptional action, destination_networks, domain_uuid, enabled, name, source_networks |
cisco-fmc_update_network_group_members | Append / remove / replace members of an existing network group. | required group_id, opoptional domain_uuid, literals, object_ids |
Cisco Secure Workload
Section titled “Cisco Secure Workload”25 tools. Credentials are supplied in the connection settings.
| Tool | Description | Arguments |
|---|---|---|
cisco-secure-workload_count_inventory | Count workloads matching an inventory filter. Faster than search when only the count is needed. | required filter_queryoptional scope_name |
cisco-secure-workload_create_alert | Create a new alert with a name, severity level, and trigger filter. Alerts notify when specific conditions are met in the workload environment. | required name, severity, alert_filter |
cisco-secure-workload_create_application | Create a new application (workspace) within a scope. Applications are containers for security policies. | required app_scope_id, nameoptional description, primary |
cisco-secure-workload_create_policy | Create a new micro-segmentation policy within an application. Defines traffic rules between consumer (source) and provider (destination) inventory filters with ALLOW or DENY action. | required application_id, consumer_filter_id, provider_filter_id, policy_actionoptional priority, rank, version |
cisco-secure-workload_create_scope | Create a new scope under a parent scope. Scopes use filter queries to define which workloads belong to them (e.g. by subnet or label). | required short_name, parent_app_scope_idoptional short_query |
cisco-secure-workload_delete_policy | Delete a policy by its ID. | required policy_id |
cisco-secure-workload_disable_enforcement | Disable policy enforcement for an application. This deactivates micro-segmentation rules without deleting policies. | required application_id |
cisco-secure-workload_enable_enforcement | Enable policy enforcement for an application. This activates micro-segmentation rules on workloads in the scope. | required application_id |
cisco-secure-workload_get_alert | Get details of a specific alert by its ID. | required alert_id |
cisco-secure-workload_get_application | Get details of a specific application (workspace) by its ID. | required application_id |
cisco-secure-workload_get_application_details | Get full details of an application including its policies, clusters, and enforcement status. More comprehensive than get_application. | required application_id |
cisco-secure-workload_get_policy | Get details of a specific policy by its ID. | required policy_id |
cisco-secure-workload_get_scope | Get details of a specific scope by its ID. | required scope_id |
cisco-secure-workload_get_sensor | Get details of a specific sensor (software agent) by its ID. | required sensor_id |
cisco-secure-workload_get_top_flows | Get the top N flows ranked by a metric (packets, bytes) for a given dimension (source IP, destination port, protocol). Useful for identifying top talkers or busiest connections. | required filter_query, start_time, end_time, dimensionoptional metric, threshold |
cisco-secure-workload_get_workload | Get detailed information about a specific workload including hostname, OS, interfaces, labels, and running processes. | required workload_id |
cisco-secure-workload_get_workload_vulnerabilities | Get known vulnerabilities (CVEs) for a specific workload. Returns vulnerability details based on installed packages. | required workload_id |
cisco-secure-workload_list_alerts | List all configured alerts in Cisco Secure Workload. | — |
cisco-secure-workload_list_applications | List all applications (workspaces) in Cisco Secure Workload. Applications group policies for a given scope. | — |
cisco-secure-workload_list_policies | List all policies for an application. Policies define allowed or denied traffic between consumer and provider inventory filters. | required application_idoptional version |
cisco-secure-workload_list_scopes | List all scopes (organizational groupings) in Cisco Secure Workload. Scopes define the boundaries for policy enforcement and visibility. | — |
cisco-secure-workload_list_sensors | List all sensors (software agents) deployed on workloads. Shows sensor status, version, and host information. | — |
cisco-secure-workload_search_change_logs | Search the audit change logs for API operations performed on the Cisco Secure Workload instance. Useful for tracking who made what changes and when. | required start_time, end_timeoptional limit, method, uri |
cisco-secure-workload_search_flows | Search network flow records with filters. Returns flow data including source/destination IPs, ports, protocols, byte/packet counts, and policy decisions. | required filter_query, start_time, end_timeoptional limit, offset |
cisco-secure-workload_search_inventory | Search the workload inventory using filter queries. Returns matching hosts, VMs, and containers with their attributes (IP, hostname, OS, labels, tags). | required filter_queryoptional limit, offset, scope_name |
Cisco Wireless LAN Controller
Section titled “Cisco Wireless LAN Controller”13 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
cisco-wireless-lan-controller_create_wlan | Create a new WLAN/SSID on the controller. Requires a unique profile name, a WLAN ID (1-4096), and the broadcast SSID. The WLAN is created disabled unless ‘enabled’ is set to true. | required profile_name, wlan_id, ssidoptional enabled |
cisco-wireless-lan-controller_delete_wlan | Delete a WLAN/SSID from the controller by its profile name. | required profile_name |
cisco-wireless-lan-controller_get_access_point | Get a single access point’s CAPWAP operational data by its radio MAC address (wtp-mac), e.g. ‘aaaa.bbbb.cccc’ or ‘aa:bb:cc:dd:ee:ff’. | required wtp_mac |
cisco-wireless-lan-controller_get_client | Get a single wireless client’s operational data by its MAC address (client-mac list key). | required client_mac |
cisco-wireless-lan-controller_get_controller_summary | Get controller-wide AP operational summary (AP join statistics, per-band radio counts, predownload status) from ap-global-oper-data. | optional depth |
cisco-wireless-lan-controller_get_wlan | Get a single WLAN/SSID configuration by its profile name. | required profile_name |
cisco-wireless-lan-controller_list_access_points | List access points joined to the Catalyst 9800 controller (CAPWAP operational data: AP name, radio MAC, model, IP, join state). RESTCONF returns the full AP list; use ‘fields’/‘depth’ to trim the payload and ‘limit’ to cap results. | optional depth, fields, limit |
cisco-wireless-lan-controller_list_clients | List wireless clients currently associated to the controller (common operational data: client MAC, AP name/MAC, WLAN ID, association state). Use ‘fields’/‘depth’ to trim and ‘limit’ to cap. | optional depth, fields, limit |
cisco-wireless-lan-controller_list_rogue_aps | List rogue access points detected by the controller, including classification, RSSI, and containment state. | optional depth, fields, limit |
cisco-wireless-lan-controller_list_rrm_radio_data | List Radio Resource Management (RRM) / RF operational data per AP radio. Choose a category: ‘auto-rf’ (channel/tx-power neighbor data), ‘radar’ (DFS radar events), ‘spectrum’ (spectrum analysis), or ‘radio-slot’ (per-slot radio info). | optional category, limit |
cisco-wireless-lan-controller_list_wlans | List configured WLAN/SSID entries on the controller (profile name, WLAN ID, SSID, admin status, security settings). | optional depth, fields, limit |
cisco-wireless-lan-controller_reset_access_point | Reset (reboot) an access point via the ap-reset RPC. Identify the AP by EITHER its name or its MAC address (provide exactly one). This is a disruptive operation: the AP and its clients drop while it reboots. | optional ap_name, mac_addr |
cisco-wireless-lan-controller_update_wlan | Update an existing WLAN by profile name. Only the provided fields are changed (PATCH/merge). Use ‘enabled’ to toggle admin status, ‘ssid’ to rename the broadcast SSID. | required profile_nameoptional enabled, ssid |
Cloudflare (API Key)
Section titled “Cloudflare (API Key)”35 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
cloudflare-api_export_all_rules | Export combined IP access, legacy firewall, custom WAF, lockdown, and UA rules. | optional account_id, output_format, zone_id |
cloudflare-api_export_custom_rules | Export custom WAF rules from the http_request_firewall_custom entrypoint. | optional output_format, zone_id |
cloudflare-api_export_ip_access_rules | Export all zone and account IP access rules as JSON or CSV. | optional account_id, output_format, zone_id |
cloudflare-api_get_account_ip_access_rule | Get a specific account-level IP access rule (account_id required). | required rule_id, account_id |
cloudflare-api_get_account_rulesets | List account-level rulesets (all accounts or one account_id). | optional account_id, summary_only |
cloudflare-api_get_dns_query_analytics | DNS query analytics via GraphQL (Pro+ / analytics entitlements often required). Cross-references low-traffic query names with configured DNS records. | optional days, query_threshold, zone_id |
cloudflare-api_get_dns_record | Get a DNS record by ID (zone_id required). | required zone_id, record_id |
cloudflare-api_get_dns_statistics | Aggregate DNS record counts by type and proxied vs DNS-only. | optional zone_id |
cloudflare-api_get_dnssec_status | DNSSEC status and configuration for zone(s). | optional zone_id |
cloudflare-api_get_rule_statistics | Security posture overview: aggregated rule counts by category per zone. | optional zone_id |
cloudflare-api_get_ruleset_details | Fetch one ruleset by ID (tries each zone if zone_id omitted). | required ruleset_idoptional zone_id |
cloudflare-api_get_security_level | Get zone security_level setting (off/low/medium/high/under_attack). | optional zone_id |
cloudflare-api_get_ssl_settings | Get SSL/TLS mode (off/flexible/full/strict) for zone(s). | optional zone_id |
cloudflare-api_get_ssl_verification_status | SSL certificate verification / DCV status for zone(s). | optional zone_id |
cloudflare-api_get_tls_version | Get minimum TLS version setting for zone(s). | optional zone_id |
cloudflare-api_get_ua_rule | Get a User-Agent rule by ID (searches zones if zone_id omitted). | required rule_idoptional zone_id |
cloudflare-api_get_waf_package_rules | List rules inside a legacy WAF package (paginated internally). | required package_idoptional summary_only, zone_id |
cloudflare-api_get_waf_rule_details | Get a single legacy WAF rule (tries all zones if zone_id omitted). | required package_id, rule_idoptional zone_id |
cloudflare-api_get_zone_ip_access_rule | Get one zone IP access rule by ID (searches zones if zone_id omitted). | required rule_idoptional zone_id |
cloudflare-api_get_zone_lockdown | Get one Zone Lockdown by ID (searches zones if zone_id omitted). | required lockdown_idoptional zone_id |
cloudflare-api_get_zone_security_settings | Return all zone settings (includes security-related keys). | optional summary_only, zone_id |
cloudflare-api_list_account_ip_access_rules | List account-wide IP access rules (paginated per account). | optional account_id, summary_only |
cloudflare-api_list_accounts | List Cloudflare accounts visible to the API token (paginated internally). | optional summary_only |
cloudflare-api_list_custom_rules | List custom WAF rules from the http_request_firewall_custom entrypoint ruleset. | optional summary_only, zone_id |
cloudflare-api_list_dns_records | List DNS records for zone(s); optional type/name filters. | optional name, record_type, summary_only, zone_id |
cloudflare-api_list_firewall_rules | List legacy firewall rules for a zone (deprecated API; read-only). | optional summary_only, zone_id |
cloudflare-api_list_legacy_rate_limits | List legacy rate limit rules (deprecated /rate_limits) per zone. | optional summary_only, zone_id |
cloudflare-api_list_managed_rulesets | List rulesets configured on a zone (WAF managed rules entrypoints). | optional summary_only, zone_id |
cloudflare-api_list_rate_limit_rules | List new ruleset-based rate limit rules (http_ratelimit entrypoint). | optional summary_only, zone_id |
cloudflare-api_list_ssl_certificates | List SSL certificate packs for zone(s). | optional summary_only, zone_id |
cloudflare-api_list_ua_rules | List User-Agent blocking rules for a zone. | optional summary_only, zone_id |
cloudflare-api_list_waf_packages | List legacy WAF packages for a zone (or all zones if zone_id omitted). | optional summary_only, zone_id |
cloudflare-api_list_zone_ip_access_rules | List zone-level IP access rules (allow/block) with internal pagination. | optional summary_only, zone_id |
cloudflare-api_list_zone_lockdowns | List Zone Lockdown rules for a zone (or all zones). | optional summary_only, zone_id |
cloudflare-api_list_zones | List Cloudflare zones (domains) in scope for the token, or all if not filtered. | optional summary_only |
Datadog
Section titled “Datadog”36 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
datadog_cancel_downtime | Cancel a Datadog downtime | required downtime_id |
datadog_create_dashboard | Create a new Datadog dashboard | required title, layout_type, widgetsoptional description, notify_list, tags, template_variables |
datadog_create_downtime | Create a downtime in Datadog | required scope, startoptional end, message, monitor_id, monitor_tags, recurrence, timezone |
datadog_create_event | Create an event in Datadog | required title, textoptional aggregation_key, alert_type, date_happened, host, priority, related_event_id, source_type_name, tags |
datadog_create_monitor | Create a new Datadog monitor | required name, monitor_type, queryoptional message, options, priority, tags |
datadog_delete_dashboard | Delete a Datadog dashboard | required dashboard_id |
datadog_delete_monitor | Delete a Datadog monitor | required monitor_idoptional force |
datadog_get_dashboard | Get details of a specific Datadog dashboard | required dashboard_id |
datadog_get_downtime | Get details of a specific Datadog downtime | required downtime_id |
datadog_get_event | Get details of a specific Datadog event | required event_id |
datadog_get_logs_aggregates | Get aggregated logs data from Datadog | required query, from_time, tooptional compute, group_by, timezone |
datadog_get_metric_metadata | Get metadata for a specific metric | required metric_name |
datadog_get_monitor | Get details of a specific Datadog monitor | required monitor_idoptional group_states, with_downtimes |
datadog_get_usage_analyzed_logs | Get analyzed logs usage from Datadog | required start_hroptional end_hr |
datadog_get_usage_hosts | Get host usage from Datadog | required start_hroptional end_hr |
datadog_get_usage_logs | Get logs usage from Datadog | required start_hroptional end_hr |
datadog_get_usage_network_hosts | Get network hosts usage from Datadog | required start_hroptional end_hr |
datadog_get_usage_summary | Get usage summary from Datadog | required start_monthoptional end_month, include_org_details |
datadog_get_usage_synthetics | Get synthetics usage from Datadog | required start_hroptional end_hr |
datadog_get_usage_timeseries | Get timeseries usage from Datadog | required start_hroptional end_hr |
datadog_list_dashboards | List all Datadog dashboards | optional count, filter_deleted, filter_shared, start |
datadog_list_downtimes | List all Datadog downtimes | optional current_only, with_creator |
datadog_list_events | List events in Datadog | required start, endoptional exclude_aggregate, page, priority, sources, tags, unaggregated |
datadog_list_metrics | List available metrics in Datadog | optional query |
datadog_list_monitors | List all Datadog monitors | optional group_states, id_offset, monitor_tags, name, page, page_size, tags, with_downtimes |
datadog_query_metrics | Query metrics from Datadog | required query, from_ts, to |
datadog_query_timeseries_points | Query timeseries data points from Datadog | required query, from_ts, tooptional interval |
datadog_search_logs | Search for logs in Datadog | required query, from_time, tooptional paginate, sort, timezone |
datadog_submit_logs | Submit logs to Datadog | required logs |
datadog_submit_metrics | Submit metrics to Datadog | required series |
datadog_submit_service_checks | Submit multiple service checks to Datadog | required service_checks |
datadog_update_dashboard | Update an existing Datadog dashboard | required dashboard_id, title, layout_type, widgetsoptional description, notify_list, tags, template_variables |
datadog_update_downtime | Update an existing Datadog downtime | required downtime_idoptional end, message, monitor_id, monitor_tags, scope, start, timezone |
datadog_update_metric_metadata | Update metadata for a specific metric | required metric_nameoptional description, metric_type, per_unit, short_name, statsd_interval, unit |
datadog_update_monitor | Update an existing Datadog monitor | required monitor_idoptional message, monitor_type, name, options, priority, query, tags |
datadog_validate_monitor | Validate a Datadog monitor definition (type and query) | required monitor_type, query |
Dynatrace
Section titled “Dynatrace”0 tools. Available as 2 connections: Dynatrace (OAuth) (OAuth 2.0 client credentials), Dynatrace (Platform Token) (API key).
FireMon
Section titled “FireMon”13 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
firemon_create_policy_planner_ticket | Create a new policy change request ticket (packet) in FireMon Policy Planner under a specific workflow | required workflow_id, subject, requester_name, requester_emailoptional domain_id, due_date, priority |
firemon_get_collector | Get detailed information and status for a specific FireMon data collector | required collector_id |
firemon_get_device | Get detailed information about a specific FireMon managed device by ID, including management IP, vendor, and status | required device_idoptional domain_id |
firemon_get_device_status | Get connectivity and retrieval status for a specific FireMon managed device | required device_idoptional domain_id |
firemon_get_latest_revision | Get the most recent successful configuration revision for a FireMon managed device | required device_idoptional domain_id |
firemon_get_policy_planner_ticket | Get detailed information about a specific FireMon policy planner ticket (packet) by ID | required ticket_id, workflow_idoptional domain_id |
firemon_get_rule_usage | Get rule hit count and usage statistics for a FireMon managed device. Returns total rule usage stats. | required device_idoptional domain_id, page, page_size |
firemon_list_collectors | List data collectors and their status in FireMon | — |
firemon_list_device_revisions | List configuration revisions for a FireMon managed device | required device_idoptional domain_id, page, page_size |
firemon_list_devices | List managed devices (firewalls, routers, switches) in FireMon with filtering by name, vendor, or IP | optional domain_id, mgmt_ip, name, page, page_size, vendor |
firemon_list_domains | List configured domains in FireMon Security Manager | optional page, page_size |
firemon_list_policy_planner_tickets | List policy planner tickets (packets) for a specific workflow in FireMon. Requires a workflow ID. | required workflow_idoptional domain_id, page, page_size |
firemon_search_security_rules | Search security rules across devices using FireMon’s SIQL (Security Intelligence Query Language). Examples: ‘action = allow’, ‘source network = 10.0.0.0/8’, ‘rule unused > 90’ | required queryoptional domain_id, page, page_size |
Grafana
Section titled “Grafana”21 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
grafana_get_dashboard | Get dashboard configuration and panel details by UID | required uid |
grafana_get_data_source | Get specific data source details by ID. This tool is vital to conduct any Grafana investigation, as data source UIDs are required to run any queries. | required id |
grafana_get_health | Check Grafana instance health and availability | — |
grafana_get_trace_by_id | Get detailed information about a specific trace by its ID | required dataSourceUid, traceId |
grafana_list_dashboards | List available dashboards with optional search filtering | optional limit, query |
grafana_list_data_sources | List all configured data sources in Grafana. This tool is vital to conduct any Grafana investigation, as data source UIDs are required to run any queries. | — |
grafana_list_folders | List dashboard folders for organization structure | optional limit |
grafana_list_loki_label_names | List all available label names in Loki within an optional time range | required dataSourceUidoptional end, start |
grafana_list_loki_label_values | Get available values for a specific label name in Loki | required dataSourceUid, labelNameoptional end, start |
grafana_list_prometheus_label_names | List label names in Prometheus with optional filtering by series selectors and time range | required dataSourceUidoptional endRfc3339, limit, matches, startRfc3339 |
grafana_list_prometheus_label_values | Get values for a specific label name in Prometheus with optional filtering | required dataSourceUid, labelNameoptional endRfc3339, limit, matches, startRfc3339 |
grafana_list_prometheus_metric_metadata | Get metadata about Prometheus metrics including type, help text, and units | required dataSourceUidoptional limit, limitPerMetric, metric |
grafana_list_prometheus_metric_names | List metric names in Prometheus with optional regex filtering and pagination | required dataSourceUidoptional limit, page, regex |
grafana_query_loki_logs | Execute LogQL queries to retrieve logs from Loki. Returns log entries with timestamps, labels, and either log lines or metric values. Supports full LogQL syntax | required dataSourceUid, logQLoptional direction, end, limit, start |
grafana_query_loki_stats | Get statistics about a LogQL query including bytes and lines processed | required dataSourceUid, logQLoptional end, start |
grafana_query_prometheus | Query Prometheus using PromQL expressions. Supports both instant queries (single point in time) and range queries (time series). | required dataSourceUid, expr, startTimeoptional endTime, queryType, stepSeconds |
grafana_query_tempo | Query traces from Tempo using TraceQL. Returns matching traces with their spans | required dataSourceUid, query, start, endoptional limit, spss, step |
grafana_search_annotations | Search for annotations and events for APM correlation | optional alertId, dashboardId, from, limit, panelId, tags, to |
grafana_search_metrics | Search available metrics and resources | required queryoptional limit, type |
grafana_search_tempo_tag_values | Get available values for a specific tag in Tempo | required dataSourceUid, tagNameoptional end, query, start |
grafana_search_tempo_tags | Search available tags in Tempo | required dataSourceUid |
Harness
Section titled “Harness”11 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
harness_abort_pipeline_execution | Abort (or mark-as-failed) a running pipeline execution. This is a mutating action that interrupts an in-progress run. | required org_id, project_id, plan_execution_idoptional interrupt_type |
harness_get_pipeline | Get a single pipeline’s metadata and full YAML definition by its identifier. | required org_id, project_id, pipeline_id |
harness_get_pipeline_execution | Get full details of a single pipeline execution by its planExecutionId, including stage/step breakdown and failure info. Use this to debug why a run failed. | required org_id, project_id, plan_execution_id |
harness_get_pipeline_runtime_inputs | Fetch the runtime input template (YAML) for a pipeline. The template shows the ’<+input>’ placeholders that must be supplied as inputs_yaml when calling run_pipeline. Call this first when a pipeline has runtime inputs. | required org_id, project_id, pipeline_id |
harness_list_environments | List Harness environments in a project (deploy destinations). | required org_id, project_idoptional page, search_term, size |
harness_list_organizations | List Harness organizations in the account. Use this to discover the orgIdentifier needed by project and pipeline tools. | optional page, search_term, size |
harness_list_pipeline_executions | List pipeline executions (runs) in a project, optionally filtered by a specific pipeline. Returns execution summaries including status and the planExecutionId used by get_pipeline_execution. | required org_id, project_idoptional page, pipeline_id, search_term, size |
harness_list_pipelines | List pipelines in a Harness project, with optional search and module (ci/cd) filtering. | required org_id, project_idoptional module, page, search_term, size |
harness_list_projects | List Harness projects, optionally scoped to an organization. Use this to discover the projectIdentifier needed by pipeline tools. | optional org_id, page, search_term, size |
harness_list_services | List Harness services in a project (deployment targets). | required org_id, project_idoptional page, search_term, size |
harness_run_pipeline | Trigger (execute) a pipeline. This is a mutating action that starts a real CI/CD run. If the pipeline has runtime inputs, first call get_pipeline_runtime_inputs and pass the filled-in YAML as inputs_yaml. | required org_id, project_id, pipeline_idoptional inputs_yaml, module, notes |
Microsoft Azure
Section titled “Microsoft Azure”18 tools. Available as 4 connections: Microsoft Azure (OAuth 2.0), Microsoft Azure (Application) (OAuth 2.0 client credentials), Microsoft Azure (Government) (OAuth 2.0), Microsoft Azure (Government, Application) (OAuth 2.0 client credentials).
| Tool | Description | Arguments |
|---|---|---|
microsoft-azure_get_management_group | Get a single Azure management group by ID. Optionally expand its child management groups and subscriptions recursively. | required group_idoptional expand_children |
microsoft-azure_get_policy_assignment | Get a single Azure Policy assignment by name at a scope. Returns the assignment’s policy definition reference, parameters, and enforcement mode. | required assignment_nameoptional scope, subscription_id |
microsoft-azure_get_policy_compliance_summary | Summarize Azure Policy compliance for a subscription, optionally scoped to a single policy assignment. Returns aggregated compliant vs non-compliant counts by policy assignment and definition. | optional policy_assignment_name, subscription_id |
microsoft-azure_get_policy_definition | Get a single Azure Policy definition by name within a subscription. Returns the definition’s rule, parameters, and metadata. | required definition_nameoptional subscription_id |
microsoft-azure_get_role_assignment | Get a single Azure RBAC role assignment by name at a scope. Returns the assigned principal, role definition ID, and scope. | required role_assignment_nameoptional scope, subscription_id |
microsoft-azure_get_role_definition | Get a single Azure RBAC role definition by ID at a scope. Returns the role’s name, description, and actions/notActions/dataActions permission sets. | required role_definition_idoptional scope, subscription_id |
microsoft-azure_get_subscription | Get details for a single Azure subscription by its subscription ID, including display name, state, and tenant ID. | required subscription_id |
microsoft-azure_list_management_group_descendants | List the flattened descendant tree of a management group, including nested management groups and subscriptions beneath it. | required group_idoptional top |
microsoft-azure_list_management_groups | List the Azure management groups visible to the authenticated identity. Management groups organize subscriptions into a governance hierarchy. | — |
microsoft-azure_list_noncompliant_resources | List resources that are currently non-compliant with Azure Policy in a subscription. Returns the latest policy state records filtered to ComplianceState eq ‘NonCompliant’. | optional subscription_id, top |
microsoft-azure_list_policy_assignments | List Azure Policy assignments at a scope. Provide an explicit ARM scope (subscription, resource group, or management group ID) or fall back to the configured subscription. | optional odata_filter, scope, subscription_id, top |
microsoft-azure_list_policy_definitions | List Azure Policy definitions (built-in and custom) available at a scope. Provide an explicit ARM scope or fall back to the configured subscription. | optional scope, subscription_id, top |
microsoft-azure_list_resource_groups | List resource groups in a subscription. Returns each group’s name, location, and tags. Defaults to the connection’s configured subscription when subscription_id is omitted. | optional subscription_id |
microsoft-azure_list_resources | List Azure resources in a subscription, optionally narrowed to a single resource group. Supports an OData $filter (e.g. “resourceType eq ‘Microsoft.Compute/virtualMachines’”) and a result cap. | optional odata_filter, resource_group, subscription_id, top |
microsoft-azure_list_role_assignments | List Azure RBAC role assignments at a scope. Optionally filter by principal (user/group/service principal object ID) and/or restrict to assignments defined directly at the scope (atScope()). | optional at_scope, principal_id, scope, subscription_id, top |
microsoft-azure_list_role_definitions | List Azure RBAC role definitions available at a scope. Optionally restrict to custom roles only. Returns role names, descriptions, and their actions/notActions/dataActions permission sets. | optional custom_only, scope, subscription_id, top |
microsoft-azure_list_subscriptions | List all Azure subscriptions the authenticated identity can access within the tenant. Returns subscription IDs, display names, and state. Use this to discover which subscriptions to target with other tools. | — |
microsoft-azure_query_resources | Run an Azure Resource Graph (KQL) query across one or more subscriptions or management groups. | required queryoptional limit, management_groups, subscriptions, top |
Nagios XI
Section titled “Nagios XI”14 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
nagios-xi_cancel_downtime | Cancel a scheduled downtime entry by its downtime ID (from list_downtime). | required downtime_id |
nagios-xi_get_contacts | Get contact definitions — who gets notified. Omit contact_name for all contacts. | optional contact_name |
nagios-xi_get_host_status | — | optional host_name |
nagios-xi_get_hostgroups | Get host group definitions. Omit hostgroup_name for all groups. | optional hostgroup_name |
nagios-xi_get_hosts | Get host configuration definitions — address, check settings, templates. Omit host_name for all hosts. | optional host_name |
nagios-xi_get_log_entries | Get recent monitoring log / alert events. Filter by host_name and a Unix-timestamp time window (start_time / end_time). | optional end_time, host_name, start_time |
nagios-xi_get_service_status | — | optional host_name, service_description |
nagios-xi_get_servicegroups | Get service group definitions. Omit servicegroup_name for all groups. | optional servicegroup_name |
nagios-xi_get_services | Get service configuration definitions. Filter by host_name and/or service_description. | optional host_name, service_description |
nagios-xi_get_state_history | Get the historical state-change trail for hosts/services — the audit of when state transitions happened. Filter by host_name and/or service_description. | optional host_name, service_description |
nagios-xi_list_comments | List comments recorded on hosts and services. Filter by host_name and/or service_description. | optional host_name, service_description |
nagios-xi_list_downtime | List scheduled downtime entries for hosts and services. | — |
nagios-xi_list_problems | List every host and service NOT in an OK/UP state — the triage workhorse. Returns host_problems and service_problems with counts. | optional host_name |
nagios-xi_schedule_downtime | Schedule a downtime window on hosts, host groups, and/or service groups. start_time and end_time are Unix timestamps (epoch seconds). At least one target — individual hosts, host groups, or service groups — must be provided. | required comment, start_time, end_timeoptional host_names, hostgroup_names, servicegroup_names |
Palo Alto NGFW
Section titled “Palo Alto NGFW”15 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
palo-alto-ngfw_commit_changes | Commit the PAN-OS candidate configuration to running config. Returns the commit job ID for tracking. | optional description, force |
palo-alto-ngfw_create_address_group | Create a new PAN-OS address group (static with member list or dynamic with filter) | required nameoptional description, device_group, dynamic_filter, location, static, tag, vsys |
palo-alto-ngfw_create_address_object | Create a new PAN-OS address object (IP netmask, IP range, or FQDN) | required name, address_type, valueoptional description, device_group, location, tag, vsys |
palo-alto-ngfw_create_nat_rule | Create a new PAN-OS NAT rule with source/destination translation | required name, source, destination, source_zoneoptional description, destination_translation, destination_zone, device_group, disabled, location, service, source_translation, tag, vsys |
palo-alto-ngfw_create_security_rule | Create a new PAN-OS security policy rule with source, destination, zones, application, service, and action | required name, source, destination, source_zone, destination_zone, application, serviceoptional action, description, device_group, disabled, location, log_end, log_start, tag, vsys |
palo-alto-ngfw_delete_address_object | Delete a PAN-OS address object by name | required nameoptional device_group, location, vsys |
palo-alto-ngfw_get_job_status | Check the status of a PAN-OS commit or push job by job ID | required job_id |
palo-alto-ngfw_get_nat_rule | Get a specific PAN-OS NAT rule by name | required nameoptional device_group, location, vsys |
palo-alto-ngfw_get_security_rule | Get a specific PAN-OS security rule by name | required nameoptional device_group, location, vsys |
palo-alto-ngfw_get_system_info | Get PAN-OS firewall system information including model, software version, serial number, and uptime | — |
palo-alto-ngfw_list_address_groups | List PAN-OS address groups (static and dynamic) | optional device_group, location, vsys |
palo-alto-ngfw_list_address_objects | List PAN-OS address objects (IP, FQDN, range) with optional location filtering | optional device_group, location, vsys |
palo-alto-ngfw_list_nat_rules | List PAN-OS NAT policy rules with location/vsys/device-group filtering | optional device_group, location, vsys |
palo-alto-ngfw_list_security_rules | List PAN-OS security policy rules with location/vsys/device-group filtering | optional device_group, location, vsys |
palo-alto-ngfw_update_security_rule | Update an existing PAN-OS security rule’s properties (source, destination, action, etc.) | required nameoptional action, application, description, destination, destination_zone, device_group, disabled, location, log_end, log_start, service, source, source_zone, tag, vsys |
Supabase
Section titled “Supabase”0 tools. Connect with OAuth 2.0.
Zabbix
Section titled “Zabbix”10 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
zabbix_acknowledge_event | — | required event_idsoptional actions, message, severity |
zabbix_get_host | Fetch a single host by ID with full interfaces, groups, and tags. | required host_id |
zabbix_get_item_history | Fetch time-series history values for a single item. value_type MUST match the item’s stored value type (see list_items.value_type). | required item_id, value_typeoptional limit, time_from, time_until |
zabbix_get_trigger | Fetch a single trigger by ID with its expression and host context. | required trigger_id |
zabbix_list_events | List historical events with filters for source, time range, host(s), and severity. | optional host_ids, limit, min_severity, source, time_from, time_until |
zabbix_list_host_groups | List host groups (used as the input filter for list_hosts). | optional limit, search |
zabbix_list_hosts | List monitored hosts. Filter by host group, name search, and monitored/unmonitored status. | optional group_ids, limit, search, status |
zabbix_list_items | List monitored items (metrics) for one or more hosts. Each item has a value_type that determines which history table backs it. | optional host_ids, limit, only_enabled, search |
zabbix_list_problems | List CURRENT open problems (the SOC workhorse view). Filter by host, host group, minimum severity, and acknowledged status. | optional acknowledged, group_ids, host_ids, limit, min_severity |
zabbix_list_triggers | List trigger (alert-rule) definitions. Useful for investigation: ‘why did this fire?’. | optional group_ids, host_ids, limit, min_severity, only_enabled, search |
