Skip to content

Vulnerability and exposure

Scanners and exposure-management platforms an agent can query for findings and asset coverage. 19 integrations, 281 tools.

Tool names below are the fully qualified names an agent sees once the integration is connected. Where an integration offers more than one connection, the names shown use the primary connection’s prefix; connecting through another variant prefixes its tools with that variant’s own integration ID instead. See Tool Catalog for how tools are granted and named.

9 tools. Connect with API key.

ToolDescriptionArguments
armis_get_alertFetch a single Armis alert by its numeric ID. Returns full alert metadata including severity, status, policy, affected device, and evidence. Returns an empty object if the alert is not found.required alert_id
armis_get_deviceFetch a single Armis device by its numeric ID. Returns the full device profile including risk score, OS, category, network info, tags, first/last seen, and any attached vulnerabilities. Returns an empty object if the device is not found.required device_id
armis_get_vulnerability—required vulnerability_id
armis_get_vulnerability_exposureList the device-CVE matches for ONE CVE or ONE device, each with its VIPR remediation lifecycle status — this answers ‘who is exposed to this CVE, and where does each exposure stand?’.optional cve_id, device_id, limit, offset, status
armis_run_asq_query—required aql
optional limit
armis_search_alerts—optional asq_filter, limit
armis_search_devices—optional asq_filter, limit
armis_search_vulnerabilities—optional asq_filter, limit
armis_summarize_remediation_postureSummarize VIPR remediation posture for a scope: how many findings sit in each lifecycle status and severity tier, plus the highest-priority open findings.optional asq_filter, top

19 tools. Connect with Basic auth.

ToolDescriptionArguments
bitsight_create_company_requestRequest that a company be added to the Bitsight inventory by domain so it can later be monitored. Mapping is asynchronous (typically 3-10 days). Optionally set a subscription_type to auto-subscribe once added.required domain
optional subscription_type
bitsight_get_companyGet full details for a single company: current rating, rating history, and risk-vector grades. Requires a company_guid (use search_companies to resolve one from a name or domain).required company_guid
bitsight_get_company_requestGet the details and status of a single company-addition request.required request_guid
bitsight_get_portfolio_risk_vector_gradesGet per-risk-vector letter grades for companies in your portfolio (e.g. Botnet Infections, Patching Cadence). Optionally scope to a folder, tier, or single company, and choose latest grades or a 1-year monthly history.optional company_guid, folder_guid, limit, period, tier_guid
bitsight_get_portfolio_statisticsGet aggregate statistics across your portfolio: distribution by rating category (advanced/intermediate/basic), highest/lowest/median ratings, and risk-vector averages.—
bitsight_get_subscription_infoGet subscription/entitlement information: per-product quotas and remaining capacity. Useful to distinguish a 403 ‘not entitled’ from a genuine error and to check available monitoring slots.—
bitsight_get_threat_evidenceGet a specific company’s evidence for a given threat: certainty, exposure detection, and evidence tags. Requires both the threat_guid (from list_threats) and the company_guid.required threat_guid, company_guid
optional limit
bitsight_get_vendor_action_planGet vendor company GUIDs grouped by recommended action plan (monitor / review / escalate) across your tiers.—
bitsight_list_alertsList Continuous Monitoring alerts (rating changes, threshold breaches, risk-vector grade changes, public disclosures, vulnerabilities). Filter by type, severity, company, folder, and date range.optional alert_type, company_guid, end_date, folder_guid, latest, limit, severity, start_date
bitsight_list_breach_eventsList public-disclosure ‘company events’ (breaches and security incidents) impacting portfolio companies. Optionally scope to a single company. Each event includes type, category, description, severity, and the affected company.optional company_guid, limit
bitsight_list_company_findingsList security findings for a company, or a rolled-up summary. Findings are the underlying evidence (events/records) behind a company’s rating. Set summary=true for aggregate counts instead of individual findings.required company_guid
optional limit, summary
bitsight_list_company_requestsList existing company-addition requests and their status.optional limit
bitsight_list_company_treeList a company’s ratings tree — the company plus its subsidiaries (recursive corporate hierarchy) — for fourth-party / supply-chain analysis.required company_guid
bitsight_list_foldersList the folders used to group portfolio companies (and that drive alerts and reporting). Returns folder GUIDs, names, and sharing details.—
bitsight_list_portfolioList the companies in your Continuous Monitoring portfolio along with their current security ratings. Optionally scope to a folder or tier.optional folder_guid, limit, tier_guid
bitsight_list_ratings_tree_product_typesList the product types used by all companies in a third party’s ratings tree (parent + subsidiaries), for fourth-party concentration / supply-chain risk analysis.required company_guid
bitsight_list_threatsList portfolio threats (vulnerabilities and vulnerability groups) detected across monitored companies. Filter by impact scope, severity, folder, and tier. Each threat reports exposed/mitigated counts and CVSS.optional folder_guid, impact, limit, severity, tier_guid
bitsight_list_tiersList vendor tiers used to prioritize vendors by criticality. Set summary=true for per-tier summary statistics instead of tier records.optional summary
bitsight_search_companiesSearch the Bitsight inventory by company name and/or domain to find a company_guid. This is the entry point for most workflows — almost every other tool needs a company_guid that this call resolves.optional domain, limit, name

14 tools. Connect with API key.

ToolDescriptionArguments
black-duck_generate_sbom_reportTrigger SBOM (Software Bill of Materials) report generation for a project version. Supports SPDX 2.2 (JSON, YAML, RDF, TAG_VALUE) and CycloneDX 1.4 (JSON, YAML, XML). Note: TAG_VALUE is SPDX-only; XML is CycloneDX-only.required project_id, version_id
optional sbom_format, sbom_type
black-duck_get_component_vulnerabilitiesGet all vulnerabilities for a specific component version. Returns CVE/BDSA IDs, CVSS v3 scores, severity, and descriptions (CVSS v4 fields are populated only on Black Duck 2025.1+).required component_id, component_version_id
optional limit, offset
black-duck_get_projectGet details of a single Black Duck project by its project ID.required project_id
black-duck_get_project_versionGet details of a specific project version including its risk profile (vulnerability counts broken down by CRITICAL, HIGH, MEDIUM, LOW severity).required project_id, version_id
black-duck_get_project_vulnerability_digestGet per-project vulnerability digest showing severity breakdown. Available in Black Duck 2025.10 and later. Returns each project’s vulnerability counts by severity.optional limit, offset
black-duck_get_vulnerability_digest_summaryGet an org-wide summary of vulnerability counts broken down by severity (CRITICAL, HIGH, MEDIUM, LOW). Available in Black Duck 2025.10 and later. Useful for a quick health overview across all projects.—
black-duck_get_vulnerability_remediationGet the remediation details for a specific vulnerability on a BOM component in a project version. Returns current remediation status, CVSS v3 scores (CVSS v4 fields require Black Duck 2025.1+), fix guidance, and comments.required project_id, version_id, component_id, component_version_id, vulnerability_id
black-duck_list_bom_componentsList all bill-of-materials (BOM) components for a project version. Returns open-source components with their license info and policy status.required project_id, version_id
optional limit, offset
black-duck_list_policy_rulesList all Black Duck policy rules. Policy rules define conditions (e.g., CRITICAL severity, specific licenses) that flag BOM components as policy violations.optional limit, offset
black-duck_list_project_versionsList all versions (scans) for a Black Duck project. Each version has a risk profile showing vulnerability counts by severity.required project_id
optional limit, offset
black-duck_list_projectsList Black Duck SCA projects. Optionally filter by name substring. Returns project IDs, names, descriptions, and creation metadata.optional limit, name, offset
black-duck_list_reportsList generated reports for a project version. Returns report IDs, types, formats, and status (REQUESTED, IN_PROGRESS, COMPLETED).required project_id, version_id
optional limit, offset
black-duck_list_vulnerable_bom_componentsList only the vulnerable open-source components in a project version’s BOM. Each result includes CVSS scores, severity, and current remediation status. Filter by severity or remediation status to focus the results.required project_id, version_id
optional limit, offset, remediation_status, severity
black-duck_update_vulnerability_remediationUpdate the remediation status for a specific vulnerability on a BOM component. Use to mark vulnerabilities as AFFECTED, NOT_AFFECTED, REMEDIATED, IGNORED, etc.required project_id, version_id, component_id, component_version_id, vulnerability_id, remediation_status
optional comment

15 tools. Connect with API key.

ToolDescriptionArguments
burp-suite_cancel_scanCancel a running or queued Burp Suite DAST scan. This is irreversible — the scan cannot be resumed and any incomplete results are discarded. Returns the scan’s id and updated status so the caller can verify cancellation.required scan_id
burp-suite_create_siteRegister a new target site in Burp Suite DAST with scope URLs and optional scan configuration. Returns the created site’s id, name, parent_id, scope (included_urls, excluded_urls), and scan_configuration_ids.required name, included_urls
optional excluded_urls, parent_id, scan_configuration_ids
burp-suite_get_compliance_reportGet a compliance report for a Burp Suite DAST scan. Supported report types: ‘PCI DSS v4.0.1’ or ‘OWASP Top 10 2025’. Returns the plain-text report content describing each requirement’s status.required scan_id, report_type
burp-suite_get_issueGet full details of a specific vulnerability from a Burp Suite DAST scan, including plain-text description, remediation guidance, evidence, vulnerability classifications, and references.required scan_id, serial_number
burp-suite_get_scanGet full details of a Burp Suite DAST scan by ID, including status, site_id, site_name, start/end time, scan_configuration_ids, issue counts by severity, and delta vs. the previous scan.required scan_id
burp-suite_get_scan_event_logGet the event timeline for a Burp Suite DAST scan. Each entry includes an event type, message, and timestamp. Useful for diagnosing stuck, failed, or unexpectedly short scans. Use limit to cap the number of entries returned.required scan_id
optional event_type, limit
burp-suite_get_siteGet details of a specific Burp Suite DAST site by ID, including scope (included/excluded URLs and protocol options), assigned scan configurations, agent pool assignment, and configured application logins.required site_id
burp-suite_list_agentsList all scanning agents registered in Burp Suite DAST, with their enabled/active status, max concurrent scans, agent pool assignment, and machine endpoints (ip/port). Useful for checking scanning capacity before scheduling large scans.—
burp-suite_list_issuesList vulnerabilities found in a Burp Suite DAST scan. Returns issue type, name, path, severity, confidence, and triage status. Supports pagination via start (0-based offset) and count (max 500).required scan_id
optional count, start
burp-suite_list_scan_configurationsList all available scan configurations in Burp Suite DAST — both PortSwigger built-in configurations and custom configurations. Returns ID and name for each configuration.—
burp-suite_list_scansList scans in Burp Suite DAST with optional filtering by site, sort order, and result limit. Returns scan status, timing, issue counts by severity, and delta vs. the previous scan per row.optional limit, site_id, sort_column, sort_order
burp-suite_list_sitesList all sites and folders in the Burp Suite DAST site tree. Returns an object with two keys: ‘folders’ (list of folder records with id, name, parent_id) and ‘sites’ (list of site records with id, name, parent_id).—
burp-suite_run_pre_scan_checkVerify that a Burp Suite DAST site is reachable before scheduling a scan. Returns the reachability check state and any failure message. Run this before schedule_scan to avoid wasted scan capacity.required site_id
burp-suite_schedule_scanSchedule a new scan for a Burp Suite DAST site. Supports one-time scans and recurring scans via an iCalendar RRULE string.required site_id, initial_run_time
optional rrule, scan_configuration_id
burp-suite_update_issueTriage a Burp Suite DAST vulnerability: mark it as a false positive, mark it as accepted risk, or adjust its severity. At least one of false_positive, accepted_risk, or severity must be provided.required scan_id, serial_number
optional accepted_risk, false_positive, severity

39 tools. Connect with API key.

ToolDescriptionArguments
cyberhaven__body_action_tool—required resource_id, body
cyberhaven__create_tool—required body
cyberhaven__delete_tool—required resource_id
cyberhaven__get_list_tool—optional filters
cyberhaven__get_tool—required resource_id
cyberhaven__post_list_tool—optional filters, limit, next_id
cyberhaven__update_tool—required resource_id, body
cyberhaven__upsert_tool—required body
optional resource_id
cyberhaven_add_list_itemsAdd one or more items to a Cyberhaven list.required list_id, items
cyberhaven_add_risk_group_userAdd a user to a manual Cyberhaven user risk group by alias.required risk_group_id, user_alias
cyberhaven_build_incident_filter_templateBuild a local Cyberhaven incident-filter template without making an API call.optional date_from, date_to, policy, severity, status, user
cyberhaven_bulk_add_risk_group_usersAdd multiple users to a manual Cyberhaven user risk group in a single workflow. Used by the IRM workflow to flag contractors, departing employees, or watchlisted users.required risk_group_id, user_aliases
cyberhaven_bulk_assign_incidentsFind incidents matching filters, then assign them to a Cyberhaven analyst or owner using per-incident PATCH calls. Individual PATCH failures do not abort the batch.required filters, assignee
optional max_updates, note
cyberhaven_bulk_close_incidentsFind incidents matching filters, then close them in a batch workflow using per-incident PATCH calls. Individual PATCH failures do not abort the batch.required filters
optional max_updates, note
cyberhaven_check_risk_group_userQuick lookup to check if a user is part of a specific risk group.required risk_group_id, user_alias
cyberhaven_compare_periodsReturn side-by-side Cyberhaven incident metrics for two explicit filter periods.required current_filters, previous_filters
optional max_results
cyberhaven_correlate_user_activityCorrelate Cyberhaven incidents and IRM activity for a user-centric investigation. Resolves the user via IRM search and uses their canonical identifier (email/alias/id) for the incident filter.required user
optional incident_filters, max_incidents
cyberhaven_format_report_dataFormat arbitrary data as markdown or return it unchanged as JSON without making an API call.required title, data
optional output_format
cyberhaven_generate_reportGenerate a compact Cyberhaven report from incident, policy, or user-focused workflows. Returns a markdown string when output_format is MARKDOWN (default), or the raw report dict when output_format is JSON.required report_type
optional filters, output_format
cyberhaven_get_activity_timelineBuild a simple chronological activity timeline for a Cyberhaven user investigation. Returns an empty list when no IRM user matches the query — this tool will not silently operate on an arbitrary user.required user
cyberhaven_get_event_detailsGet full Cyberhaven event details for one or more event identifiers. Use this to enrich incident investigations with raw event context.required event_ids
cyberhaven_get_event_lineageGet Cyberhaven event lineage or chain-of-custody context between two events. Useful when tracking how data moved across users, endpoints, or applications.required start_event_id, end_event_id
cyberhaven_get_incidentGet a single Cyberhaven incident by ID. Cyberhaven does not expose a direct GET endpoint, so this filters /v2/incidents/list by ID and returns the matching incident. Returns an empty object if not found.required resource_id
cyberhaven_get_irm_userGet a single Cyberhaven IRM user (including risk-profile fields) by alias. Cyberhaven does not expose a direct GET endpoint, so this filters /v2/irm/users by alias and returns the matching user.required resource_id
cyberhaven_get_list_itemsGet paginated items of a Cyberhaven list.required list_id
optional page_id, page_size
cyberhaven_get_streaming_profile_connection_logGet streaming profile connection log entries. Use this when a forwarding target is failing or dropping events.required profile_id
optional end_time, error_filter, page_id, page_size, start_time
cyberhaven_get_user_activityGet a consolidated Cyberhaven activity view for a user, including incidents and risky dataflows. Returns empty incidents/dataflows when no IRM user matches the query — this tool will not silently operate on an arbitrary user.required user
cyberhaven_investigate_userRun a focused user investigation using IRM user search, risky dataflows, and matching incidents. User matching is an exact match on id/email/alias and a substring match on name.required user
optional incident_filters, max_incidents
cyberhaven_list_irm_user_risky_dataflowsList risky dataflows associated with a Cyberhaven IRM user.required user_id
optional events_time_from, events_time_to, limit
cyberhaven_list_risk_group_usersList user aliases in a Cyberhaven user risk group.required risk_group_id
cyberhaven_merge_filter_setsMerge two local Cyberhaven filter objects without making an API call.required base_filters, override_filters
cyberhaven_policy_effectivenessGrade policies by correlating Cyberhaven policy resources with incident volume.optional incident_filters, max_incidents, policy_filters
cyberhaven_remove_list_itemsRemove one or more items from a Cyberhaven list.required list_id, items
cyberhaven_remove_risk_group_userRemove a user from a manual Cyberhaven user risk group by alias.required risk_group_id, user_alias
cyberhaven_replace_risk_group_usersDESTRUCTIVE: full replacement — overwrites the complete user membership of a manual Cyberhaven user risk group with the supplied list.required risk_group_id, user_aliases
cyberhaven_reset_irm_user_risk_scoresReset Cyberhaven IRM risk scores for one or more users.required user_ids
cyberhaven_search_irm_usersSearch Cyberhaven IRM users by free-text query. Matches against display name, alias, title, department, and hostname fields on the IRM user record. For an exact alias lookup use get_irm_user.required query
optional filters, limit
cyberhaven_summarize_incidentsSummarize Cyberhaven incidents for the supplied filter window. Returns counts grouped by status and severity, with a truncated flag indicating whether the per-period cap was hit.required current_filters
optional max_results, previous_filters
cyberhaven_update_incidentPatch an incident to change ownership, workflow status, severity, or attach additional Cyberhaven fields. Use this for single-incident response actions.required resource_id
optional assignee, fields, note, severity, status

5 tools. Connect with Basic auth.

ToolDescriptionArguments
cyera_get_datastore_objectsList the data objects (tables, buckets, files) within a single Cyera data store by ID, including object type, location, and classification summary. Supports pagination.required datastore_id
optional limit, offset
cyera_list_classificationsList Cyera classification results — the sensitive-data findings (e.g., PII, PCI, PHI) detected across data stores. Supports pagination and optional datastore filtering.optional datastore_id, limit, offset
cyera_list_datastoresList data stores discovered by Cyera, including cloud provider, type, classification summary, and risk posture. Supports pagination and optional provider/type filtering.optional datastore_type, limit, offset, provider
cyera_list_eventsList Cyera events (audit/activity records such as discovery, classification, and issue changes) with optional time-range filtering and pagination.optional end_date, limit, offset, start_date
cyera_list_issuesList Cyera security issues (data-risk findings) with optional filtering by severity and status. Returns issue summaries including title, severity, affected datastore, and status.optional limit, offset, severity, status

13 tools. Connect with API key.

ToolDescriptionArguments
horizon3-nodezero_cancel_pentestCancel a running NodeZero pentest by its operation ID.required op_id
horizon3-nodezero_get_pentestGet detailed information about a specific NodeZero pentest by its operation ID.required op_id
horizon3-nodezero_get_pentest_report_urlGet a download URL for a pentest’s reports ZIP file.required op_id
horizon3-nodezero_get_runnerGet detailed information about a specific NodeZero Runner (agent) by its UUID or name. Runners automate deployment of the NodeZero Docker container for internal pentests. Provide either uuid or name to identify the runner.optional name, uuid
horizon3-nodezero_get_weaknessGet detailed information about a specific weakness found in a pentest.required op_id, weakness_id
horizon3-nodezero_list_action_logsList MITRE ATT&CK-mapped action logs for a specific pentest. Shows what NodeZero did during the pentest.required op_id
optional page, page_size
horizon3-nodezero_list_attack_pathsList attack paths discovered during a specific pentest. Shows how NodeZero chained vulnerabilities.required op_id
optional page, page_size
horizon3-nodezero_list_credentialsList credentials discovered during a specific pentest.required op_id
optional page, page_size
horizon3-nodezero_list_hostsList hosts discovered during a specific pentest.required op_id
optional page, page_size
horizon3-nodezero_list_pentestsList all NodeZero pentests with pagination. Returns pentest IDs, names, states, and summary counts.optional page, page_size, text_search
horizon3-nodezero_list_runnersList all NodeZero Runners (agents) configured in the account with pagination.optional page, page_size, text_search
horizon3-nodezero_list_weaknessesList weaknesses (vulnerabilities/findings) discovered in a specific pentest.required op_id
optional page, page_size, text_search
horizon3-nodezero_run_pentestSchedule and launch a new NodeZero pentest. Returns the operation ID and runner script URL.required name
optional op_type

9 tools. Available as 2 connections: Microsoft Defender for Cloud (OAuth 2.0), Microsoft Defender for Cloud (Government) (OAuth 2.0).

ToolDescriptionArguments
microsoft-defender-for-cloud_get_alertGet detailed information for a specific Defender for Cloud security alert. Returns full alert properties including severity, entities, attack tactics, remediation steps, and timeline.required alert_name, location
microsoft-defender-for-cloud_get_compliance_overviewGet regulatory compliance status for a specific standard (e.g. Azure CIS, NIST, PCI-DSS, SOC 2). Shows which controls are passing/failing and their assessment counts. Use list_security_coverage first to see available standards.required standard_name
microsoft-defender-for-cloud_get_recommendationGet detailed information for a specific security recommendation (assessment). Returns the recommendation status, severity, affected resource details, and remediation guidance.required assessment_name
optional resource_id
microsoft-defender-for-cloud_get_secure_scoreGet the subscription’s secure score with a breakdown by security controls. The secure score (0-100%) measures overall security posture. Each control groups related recommendations and contributes weighted points.—
microsoft-defender-for-cloud_list_alertsList Microsoft Defender for Cloud security alerts for the subscription. Alerts represent detected threats from enabled Defender plans (Defender for Servers, Storage, SQL, etc.).optional severity, status, top
microsoft-defender-for-cloud_list_recommendation_findingsList sub-assessments (individual findings) for a recommendation. Shows which specific resources are affected and their individual status. For example, a recommendation ‘Enable disk encryption’ would show each VM that is missing encryption.required assessment_name
optional resource_id, top
microsoft-defender-for-cloud_list_recommendationsList Defender for Cloud security recommendations (assessments) for the subscription. Recommendations identify misconfigurations and security gaps. Available in both free CSPM and paid plans.optional status, top
microsoft-defender-for-cloud_list_security_coverageList enabled Defender plans (pricing tiers) and available compliance standards. Helps understand what protection is active: free tier gives recommendations only, paid plans (Servers, Storage, SQL, Containers, etc.) add threat alerts.—
microsoft-defender-for-cloud_update_alertUpdate the status of a Defender for Cloud security alert. Use ‘Dismissed’ for false positives, ‘Resolved’ for handled threats, ‘InProgress’ for alerts under investigation, ‘Active’ to reactivate.required alert_name, location, status

5 tools. Connect with API key.

ToolDescriptionArguments
nvd_get_cpeGet detailed information about a specific CPE (Common Platform Enumeration) entryrequired cpeIdentifier
nvd_get_cveGet detailed information about a specific CVE by its IDrequired cveId
nvd_search_cpesSearch for CPE (Common Platform Enumeration) entries to identify specific products and versionsoptional cpeMatchString, cpeNameId, keywordExactMatch, keywordSearch, lastModEndDate, lastModStartDate, matchCriteriaId, resultsPerPage, startIndex
nvd_search_cvesSearch for CVE vulnerabilities with various filters including keywords, dates, severity levels, and moreoptional cpeName, cvssV2Severity, cvssV3Severity, cweId, hasCertAlerts, hasCertNotes, hasKev, hasOval, isVulnerable, keyword, keywordExactMatch, lastModEndDate, lastModStartDate, noRejected, pubEndDate, pubStartDate, resultsPerPage, sourceIdentifier, startIndex
nvd_search_vulnerabilities_by_cpeFind vulnerabilities that affect a specific CPE (Common Platform Enumeration)required cpeName
optional resultsPerPage, startIndex

14 tools. Connect with API key.

ToolDescriptionArguments
prisma-cloud_dismiss_alertsDismiss or snooze one or more Prisma Cloud alerts. Provide a snooze duration to temporarily snooze instead of permanently dismissing.required alert_ids, dismissal_note
optional snooze_amount, snooze_unit
prisma-cloud_get_alertGet detailed information for a specific Prisma Cloud alert by IDrequired alert_id
optional detailed
prisma-cloud_get_alert_remediationGet remediation CLI commands for a specific Prisma Cloud alert. Returns actionable commands to fix the security issue.required alert_id
prisma-cloud_get_assetGet detailed information for a specific cloud asset by its RRN or IDrequired asset_id
prisma-cloud_get_compliance_postureGet compliance posture summary for a specific compliance standard, showing pass/fail statistics across requirementsrequired compliance_id
optional cloud_account, cloud_type
prisma-cloud_get_policyGet detailed information for a specific Prisma Cloud policy by IDrequired policy_id
prisma-cloud_list_alert_rulesList configured alert rules in Prisma Cloud—
prisma-cloud_list_alertsList Prisma Cloud security alerts with filtering by status, severity, cloud type, account, and policy name. Returns paginated results.optional account_name, cloud_type, detailed, limit, offset, policy_name, severity, status, time_amount, time_unit
prisma-cloud_list_asset_inventoryList cloud asset inventory with filtering by cloud type, account, resource type, and region. Provides a breakdown of pass/fail statistics.optional account_name, cloud_type, group_by, region, resource_type, time_amount, time_unit
prisma-cloud_list_compliance_standardsList all compliance standards and frameworks available in Prisma Cloud—
prisma-cloud_list_policiesList Prisma Cloud security policies with filtering by severity, cloud type, policy type, compliance standard, and enabled statusoptional cloud_type, compliance_standard, enabled, policy_type, severity
prisma-cloud_reopen_alertsReopen previously dismissed or snoozed Prisma Cloud alertsrequired alert_ids
prisma-cloud_search_configSearch cloud resources using Prisma Cloud RQL (Resource Query Language) config queries. Example: “config from cloud.resource where cloud.type = ‘aws’ AND resource.type = ‘aws_s3_bucket‘“required query
optional limit, time_amount, time_unit
prisma-cloud_update_policy_statusEnable or disable a Prisma Cloud security policyrequired policy_id, enabled

58 tools. Connect with Basic auth.

ToolDescriptionArguments
qualys_activate_agentActivate one or more Qualys modules (e.g. AGENT_VM, AGENT_PC) for a single asset’s Cloud Agent. Additive and reversible via deactivate_agents.required asset_id, modules
optional base_url, pod
qualys_add_excluded_hostsExclude IPs from vulnerability scanning. Excluded hosts will be skipped in future scans.required ips
optional comment
qualys_count_agentsCount Cloud Agent host assets matching a tag filter (default tag ‘Cloud Agent’) plus optional QPS criteria. Cheap first call: use it before list_agents or any bulk action to gauge fleet size and blast radius. Uses the Qualys QPS REST API.optional base_url, criteria, pod, tag_name
qualys_create_asset_groupCreate a new asset group with a title and optional IP set.required title
optional comments, ips
qualys_create_tagCreate a new asset tag.required name
optional color, parent_tag_id
qualys_csam_assets_by_tagSearch CSAM/Global AssetView inventory for assets carrying a specific tag (tags.name filter). Convenience wrapper over csam_search_assets; returns the raw JSON response with lastSeenAssetId cursor pagination.required tag_name
optional base_url, last_seen_asset_id, page_size, pod
qualys_csam_assign_asset_business_metadataAssign business metadata (environment, ownership, businessAppIds, assignedLocation, etc.) to a CSAM asset. WRITE operation: dry-runs by default, returning the payload it would send; set confirm=True to execute.required qualys_asset_id, metadata
optional base_url, confirm, pod
qualys_csam_count_assetsCount assets in the CSAM/Global AssetView inventory matching filter criteria (GAV/CSAM QQL field tokens). Uses the Qualys Gateway API. Optionally target a specific Qualys POD or override the gateway base URL.optional asset_last_updated, base_url, filters, last_seen_asset_id, pod
qualys_csam_get_assetGet full CSAM/Global AssetView details for a specific asset by its asset ID. Uses the Qualys Gateway API.required asset_id
optional base_url, pod
qualys_csam_list_business_appsList distinct business applications associated with assets in the CSAM inventory, derived from asset businessAppListData. Returns hasMore/lastSeenAssetId so additional asset pages can be swept for more apps.optional base_url, filters, last_seen_asset_id, page_size, pod
qualys_csam_search_assetsSearch the CSAM/Global AssetView asset inventory with filter criteria (GAV/CSAM QQL field tokens). Returns the raw JSON response including assetListData, hasMore, and lastSeenAssetId; pass lastSeenAssetId back to page through results.optional asset_last_updated, base_url, exclude_fields, filters, include_fields, last_seen_asset_id, page_size, pod
qualys_csam_upsert_business_appCreate or update (upsert) a business application’s metadata in CSAM. WRITE operation: dry-runs by default, returning the payload it would send; set confirm=True to execute.required business_app_id, name
optional base_url, confirm, created_epoch_millis, fields, last_updated_epoch_millis, pod
qualys_deactivate_agentsDeactivate Qualys modules across a set of Cloud Agents (stops data collection for those modules). DESTRUCTIVE but reversible via activate_agent. Target by exactly one of asset_ids or tag_name.required modules
optional asset_ids, base_url, confirm, expected_count, pod, tag_name
qualys_delete_asset_groupDelete an asset group by ID. DESTRUCTIVE AND IRREVERSIBLE.required group_id
optional confirm
qualys_delete_tagDelete an asset tag by ID. DESTRUCTIVE AND IRREVERSIBLE. Dry-runs by default, returning the tag’s name and child-tag count for review; you MUST ask the user for explicit confirmation before re-calling with confirm=True to execute.required tag_id
optional confirm
qualys_export_compliance_policyExport a compliance policy definition by ID.required policy_id
optional response_format
qualys_export_option_profileExport one option profile’s full configuration (scan settings, ports, search lists, performance) for VM (user), PC (compliance), or PCI profiles. Select by exactly one of profile_id or title (title must match exactly).optional profile_id, profile_type, response_format, title
qualys_fo_requestEscape hatch: call any Qualys FO classic API endpoint under /api/2.0/fo/ when no dedicated tool covers it.required path
optional base_url, body, extra_headers, method, pod, query_params
qualys_gateway_requestEscape hatch: call any Qualys Gateway API endpoint under /rest/2.0/ (GAV/CSAM) or /csapi/ (Container Security) (JSON) when no dedicated tool covers it.required path
optional base_url, body, extra_headers, method, pod, query_params
qualys_get_hostGet detailed information about a specific host by ID or IP address.optional host_id, ip
qualys_get_host_detection_countGet a count of vulnerability detections matching filters. Quick summary without full detection data.optional ag_ids, ips, severities, status
qualys_get_scanner_applianceGet detailed information about a specific scanner appliance by ID.required appliance_id
qualys_get_vulnerabilityGet detailed information about a specific vulnerability by its QID (Qualys ID). Returns description, solution, CVSS score, and CVE mappings.required qid
qualys_ignore_vulnerabilityIgnore a vulnerability (by QID) on specific hosts so it won’t appear in reports. Specify hosts by IPs, asset group IDs, or tag names. Up to 10 QIDs per request.required qids
optional ag_ids, comments, ips, tag_set_by, tag_set_include
qualys_launch_reportLaunch a report generation with specified template, output format (PDF/HTML/XML/CSV/DOCX), and target scope.required template_id
optional asset_group_ids, ips, output_format, report_title
qualys_launch_scanLaunch a vulnerability scan against target IPs, asset groups, or tags with a specified scan title and option profile.required scan_title
optional asset_group_ids, ip, option_id, option_title, priority, scanner_name
qualys_list_activation_keysList Cloud Agent activation keys (provisioning inputs for agent installs). Uses the Qualys QPS REST API. Paginate while has_more is true by passing the previous response’s last_id; stop when has_more is false.optional base_url, criteria, last_id, limit, pod, title_contains
qualys_list_agentsList Cloud Agents with lifecycle state (version, status, last check-in, activation key, modules, OS). Filters by tag (default ‘Cloud Agent’) plus optional QPS criteria — prefer narrowing criteria over raising limit.optional base_url, criteria, last_id, limit, pod, tag_name
qualys_list_asset_group_scannersList scanner appliances assigned to an asset group.required group_id
qualys_list_asset_groupsList asset groups with filtering by ID and title. Returns group definitions with IP sets and member info.optional id_min, ids, limit, title, truncation_limit
qualys_list_auth_recordsList authentication records by type. Defaults to ‘windows’ if no record_type is specified. Use record_type to query unix, ms_sql, or cisco records.optional details, id_max, id_min, ids, limit, record_type
qualys_list_compliance_exceptionsList compliance exceptions (approved deviations from policy controls).optional id_max, id_min, limit, policy_id, status
qualys_list_compliance_policiesList policy compliance policies with filtering.optional details, id_max, id_min, ids, limit, updated_after_datetime
qualys_list_compliance_scansList policy compliance scans with filtering by state and date range.optional launched_after_datetime, launched_before_datetime, limit, scan_ref, state
qualys_list_excluded_hostsList IPs currently excluded from scanning.optional limit
qualys_list_host_detectionsList vulnerability detections across hosts with filtering by IP, asset group, severity, QID, status (New/Active/Fixed/Re-Opened), and date range. Returns host records with their detected vulnerabilities.optional ag_ids, ag_titles, detection_updated_before, detection_updated_since, id_min, ids, ips, limit, qids, severities, show_qds, show_results, status, truncation_limit, vm_scan_date_after
qualys_list_hostsList host assets with filtering by IP, asset group, OS, tags, and scan dates. Returns host inventory with IPs, OS, DNS, and last scan info.optional ag_ids, ag_titles, details, id_min, ids, ips, limit, no_vm_scan_since, os_pattern, show_asset_id, show_tags, truncation_limit, use_tags, vm_scan_since
qualys_list_ignored_vulnsList currently-ignored vulnerability detections (the audit counterpart to ignore_vulnerability/restore_vulnerability).optional ag_ids, id_min, ips, limit, qids, severities, truncation_limit
qualys_list_pc_option_profilesList Policy Compliance scan option profiles. Returns profile names, IDs, and configuration.optional limit, profile_id, title
qualys_list_pc_scan_schedulesList scheduled Policy Compliance scan tasks.optional active, limit, schedule_id
qualys_list_reportsList available reports with filtering by state (Running/Finished/Canceled/Errors).optional expires_before_datetime, limit, report_id, state
qualys_list_scanner_appliancesList all scanner appliances in the subscription with status and configuration details.optional limit, output_mode
qualys_list_scansList vulnerability scans with filtering by state (Running/Finished/Error), type (On-Demand/Scheduled/API), target, and date range.optional launched_after_datetime, launched_before_datetime, limit, scan_ref, scan_type, show_ags, show_status, state, target
qualys_list_tagsList asset tags using the Qualys QPS REST API. Returns tag definitions with IDs and names.optional limit, name
qualys_list_vm_option_profilesList VM scan option profiles. Returns profile names, IDs, and configuration.optional limit, profile_id, title
qualys_list_vm_scan_schedulesList scheduled VM scan tasks.optional active, limit, schedule_id, show_cloud_details, show_notifications
qualys_manage_asset_group_ipsAdd, remove, or set the IP addresses of an existing asset group. action=add/remove edit the set incrementally and apply immediately.required group_id, action, ips
optional confirm
qualys_manage_asset_group_scannersAdd, remove, or set scanner appliances for an asset group.required group_id
optional add_appliance_ids, remove_appliance_ids, set_appliance_ids
qualys_manage_compliance_policy_groupsAdd, remove, or set asset groups associated with a compliance policy.required policy_id, action, group_ids
qualys_manage_compliance_policy_tagsAdd, remove, or set asset tags associated with a compliance policy. Tags control which assets are evaluated against the policy.required policy_id, action, tag_set_include
optional tag_set_by
qualys_manage_scanCancel, pause, or resume an in-progress vulnerability scan by its scan reference.required scan_ref, action
qualys_purge_host_dataPurge scan data for specified hosts. WARNING: This is DESTRUCTIVE AND IRREVERSIBLE. Vulnerability data, scan history, and optionally compliance data will be permanently deleted.required ips
optional compliance_purge, confirm
qualys_qps_requestEscape hatch: call any Qualys QPS REST API endpoint under /qps/rest/ (JSON) when no dedicated tool covers it.required path
optional base_url, body, extra_headers, method, pod, query_params
qualys_remove_excluded_hostsRemove IPs from the scan exclusion list, re-enabling them for scanning.required ips
optional comment
qualys_restore_vulnerabilityRestore (un-ignore) a previously ignored vulnerability on specific hosts, re-enabling it in reports.required qids
optional ag_ids, comments, ips, tag_set_by, tag_set_include
qualys_search_knowledge_baseSearch the Qualys vulnerability Knowledge Base by QID, CVE, or date range.optional cve, details, discovery_method, id_max, id_min, ids, is_patchable, last_modified_after, limit, published_after
qualys_tag_assetAdd or remove a tag on a host asset by asset ID. Returns a trimmed acknowledgement, not the full asset record.required asset_id, tag_id, action
qualys_uninstall_agentsUninstall the Cloud Agent from one or more hosts by explicit asset ID. DESTRUCTIVE AND IRREVERSIBLE: the agent software is removed and reinstall requires re-deployment; uninstall completes asynchronously on each agent’s next check-in.required asset_ids
optional base_url, confirm, pod

12 tools. Connect with API key.

ToolDescriptionArguments
rapid7-insightappsec_create_appCreate a new InsightAppSec application to group scan targetsrequired name
optional description
rapid7-insightappsec_get_appGet a single InsightAppSec application by its UUIDrequired app_id
rapid7-insightappsec_get_scanGet details of a single scan by ID, including status and progressrequired scan_id
rapid7-insightappsec_get_scan_configGet a single scan configuration by its UUIDrequired scan_config_id
rapid7-insightappsec_get_vulnerabilityGet full details for a single vulnerability by its UUIDrequired vulnerability_id
rapid7-insightappsec_list_appsList InsightAppSec applications with optional name search and paginationoptional index, name, size
rapid7-insightappsec_list_attack_templatesList available attack templates that can be used in scan configurationsoptional index, size
rapid7-insightappsec_list_scan_configsList scan configurations, optionally filtered by application IDoptional app_id, index, size
rapid7-insightappsec_list_scansList scans with optional filtering by application ID or statusoptional app_id, index, size, status
rapid7-insightappsec_search_vulnerabilitiesSearch for vulnerabilities found by InsightAppSec scans. Use the query parameter with InsightAppSec search syntax, e.g. “vulnerability.scans.id=‘<scan-uuid>’” to filter by scan, or “vulnerability.severity=‘HIGH’” to filter by severity.optional app_id, index, query, scan_id, severity, size
rapid7-insightappsec_start_scanStart a new DAST scan using an existing scan configurationrequired scan_config_id
rapid7-insightappsec_stop_scanSubmit a control action (stop, pause, or resume) to a scanrequired scan_id
optional action

12 tools. Connect with API key.

ToolDescriptionArguments
rapid7-insightcloudsec_get_clouds_summaryGet a summary report across all connected cloud accounts: total cloud count, breakdown by cloud provider (AWS/Azure/GCP/etc.), and resource counts by resource type per cloud.—
rapid7-insightcloudsec_get_insightGet the full definition of a single Insight, including its filters, applicable resource types, severity, and metadata.required insight_id
optional insight_source
rapid7-insightcloudsec_get_resourceGet full details for a single InsightCloudSec resource by its resource ID, including normalized properties, tags, dependencies (VPCs, subnets, encryption keys), and noncompliance status.required resource_id
rapid7-insightcloudsec_get_resource_sourcesGet the raw cloud provider source documents that InsightCloudSec harvested for a resource (e.g. the original AWS DescribeInstances response).required resource_id
rapid7-insightcloudsec_list_applicationsList Applications — user-defined groupings of cloud resources used for scoping (e.g. by business unit, environment, or criticality). Returns each Application’s name, category, resource count, account count, and cloud providers.optional order_by, page, page_size, search
rapid7-insightcloudsec_list_cloud_findingsList Insight findings (policy violations) for an entire cloud account. Use to check the compliance posture of a specific cloud. Use ‘cursor’ from the previous response for pagination.required organization_service_id
optional cursor
rapid7-insightcloudsec_list_cloudsList all cloud accounts (AWS, Azure, GCP, OCI, Alibaba, etc.) configured in InsightCloudSec, including their connection status, account IDs, harvesting strategy, and resource counts.—
rapid7-insightcloudsec_list_filter_registryList every query filter available for use with search_resources. Returns each filter’s name and the shape of its config object — use this to discover what filters can be applied when searching resources.—
rapid7-insightcloudsec_list_insight_packsList Insight Packs — collections of Insights grouped by compliance framework (CIS, PCI DSS, NIST, SOC 2, HIPAA, etc.) or by Rapid7-curated categories. Use to discover available compliance frameworks and their pack IDs.—
rapid7-insightcloudsec_list_insightsList all available Insights (compliance checks and security policies) in InsightCloudSec. Optionally filter by labels (e.g. ‘cis controls’), Insight packs, or resource types.optional detail, labels, pack_ids, resource_types
rapid7-insightcloudsec_list_resource_violationsList all Insight findings (policy violations) for a single resource. Returns each matching Insight with its severity, description, and the date it was identified.required resource_id
rapid7-insightcloudsec_search_resourcesSearch InsightCloudSec’s normalized resource inventory across all connected cloud accounts.optional badge_filter_operator, badges, cursor, filters, insight, limit, offset, scopes, selected_resource_type, tags

18 tools. Connect with Basic auth.

ToolDescriptionArguments
rapid7-insightvm_control_scanSend a control action to a scan: ‘pause’ (running -> paused), ‘resume’ (paused -> running), ‘stop’ (running or paused -> stopped; non-reversible).required scan_id, action
rapid7-insightvm_generate_reportTrigger generation of a new report instance from an existing report config.required report_id
optional report_format
rapid7-insightvm_get_assetGet a single asset’s full detail by ID: hostnames, IPs, OS, MAC addresses, installed software, configurations, services, user accounts, risk score, and vulnerability counts by severity.required asset_id
rapid7-insightvm_get_scanGet a single scan’s status: state (e.g. running, finished, paused, stopped, aborted), vulnerability counts (critical/severe/moderate), discovered asset count, duration, and engine.required scan_id
rapid7-insightvm_get_siteGet a single site’s detail by ID.required site_id
rapid7-insightvm_get_vulnerabilityGet full detail for a single vulnerability: CVSS v2/v3 vectors, PCI severity, CVE references, exploit and malware-kit data, categorical tags, and human-readable description.required vulnerability_id
rapid7-insightvm_list_asset_groupsList asset groups defined on the console (static or dynamic): group ID, name, type, asset count, and risk-score aggregate.optional page, size
rapid7-insightvm_list_asset_vulnerabilitiesList vulnerabilities affecting a specific asset. Returns the vulnerability ID, first/most-recent observation, port/protocol context, exception status, and proof string.required asset_id
optional page, size
rapid7-insightvm_list_assetsList all assets known to the InsightVM console with paginated results. Returns asset summaries including hostnames, IPs, OS fingerprint, risk score, and last-scanned timestamp.optional page, size, sort
rapid7-insightvm_list_reportsList all report configurations defined on the console: report ID, name, format, template, owner, and scope. Use generate_report with one of these IDs to trigger a fresh report instance.optional page, size
rapid7-insightvm_list_scansList scans across the console with optional active-only filter. Returns scan ID, site, status, start/end times, duration, engine, and discovered-vulnerability counts.optional active_only, page, size
rapid7-insightvm_list_sitesList all scan sites configured on the InsightVM console: site names, scan template, scan engine, target asset count, and last-scan summary.optional page, size
rapid7-insightvm_list_tagsList tags configured on the console (custom, location, owner, criticality, etc.). Tags drive dynamic asset-group membership and reporting scope.optional page, size
rapid7-insightvm_list_vulnerabilitiesList vulnerabilities in the InsightVM vulnerability catalog. Optional severity filter narrows results to Critical / Severe / Moderate. Returns paged summaries with CVSS scores, exploit and malware-kit availability flags.optional page, severity, size
rapid7-insightvm_list_vulnerability_exceptionsList vulnerability exceptions (accepted-risk decisions) on the console: exception ID, vulnerability, scope, reason, expiration, submitter, and approval status.optional page, size
rapid7-insightvm_list_vulnerability_solutionsList remediation solutions for a vulnerability: patch references, configuration changes, workarounds, and the estimated time / effort required. Use to inform a remediation playbook.required vulnerability_id
optional page, size
rapid7-insightvm_search_assetsSearch assets using InsightVM filter expressions. Supply a list of {field, operator, value} filters and a match mode (‘all’ for AND, ‘any’ for OR).required filters
optional match, page, size
rapid7-insightvm_start_site_scanStart a new scan against a site. Optionally override the scan engine, scan template, hosts (IP / hostname list), or assign a human-readable scan name. Returns the new scan ID.required site_id
optional engine_id, hosts, name, template_id

10 tools. Connect with API key.

ToolDescriptionArguments
rapid7-insightvm-cloud_get_assetGet a single asset’s full detail by ID: hostnames, IPs, OS, MAC addresses, installed software, services, risk score, and vulnerability counts by severity.required asset_id
rapid7-insightvm-cloud_get_scanGet a single scan’s status: state (e.g. running, finished, paused, stopped, aborted), vulnerability counts (critical/severe/moderate), discovered asset count, duration, and engine.required scan_id
rapid7-insightvm-cloud_get_siteGet a single site’s detail by ID: name, description, scan template, scan engine, target asset count, vulnerability counts, and last-scan summary.required site_id
rapid7-insightvm-cloud_get_vulnerabilityGet full detail for a single vulnerability: CVSS v2/v3 vectors, PCI severity, CVE references, exploit and malware-kit data, categorical tags, and human-readable description.required vulnerability_id
rapid7-insightvm-cloud_list_asset_vulnerabilitiesList vulnerabilities affecting a specific asset. Returns the vulnerability ID, first/most-recent observation, port/protocol context, and proof string. Use get_vulnerability for the full vulnerability description and severity.required asset_id
optional page, size
rapid7-insightvm-cloud_list_assetsList assets known to the InsightVM Cloud platform with paginated results. Returns asset summaries including hostnames, IPs, OS fingerprint, risk score, and last-scanned timestamp.optional page, size, sort
rapid7-insightvm-cloud_list_scan_enginesList scan engines available to the Cloud platform: engine ID, name, status, address, port, last-refresh time, and engine pool membership. Useful for confirming which engines are online before correlating recent scan results.optional page, size
rapid7-insightvm-cloud_list_scansList scans across the Cloud platform with optional active-only filter. Returns scan ID, site, status, start/end times, duration, engine, and discovered-vulnerability counts.optional active_only, page, size
rapid7-insightvm-cloud_list_sitesList all scan sites configured on the InsightVM Cloud platform: site names, scan template, scan engine, target asset count, and last-scan summary.optional page, size
rapid7-insightvm-cloud_list_vulnerabilitiesList vulnerabilities in the InsightVM Cloud catalog. Optional severity filter narrows results to Critical / Severe / Moderate. Returns paged summaries with CVSS scores, exploit and malware-kit availability flags.optional page, severity, size

8 tools. Connect with API key.

ToolDescriptionArguments
snyk_get_api_security_findingRetrieve a single Snyk API Security finding by id. Note: endpoint shape is best-effort and may need adjustment against real tenant.required org_id, finding_id
snyk_get_issueRetrieve a single Snyk security issue by id. Returns full detail including CWE/CVE classes, problem references, coordinate paths, and risk scoring.required org_id, issue_id
snyk_get_organizationRetrieve a single Snyk organization by id.required org_id
snyk_get_projectRetrieve a single Snyk project by id within an organization.required org_id, project_id
snyk_list_api_security_findingsList Snyk API Security findings in an organization — API risk discoveries from Snyk’s API Security product. Filter by severity or status. Cursor-paginated.required org_id
optional ending_before, limit, severity, starting_after, status
snyk_list_issuesList Snyk security issues (vulnerabilities, license issues, code issues) in an organization. Scope to a single project by passing project_id. Filter by severity, status, type, or ignored state. Cursor-paginated.required org_id
optional effective_severity_levels, ending_before, ignored, limit, project_id, starting_after, statuses, types
snyk_list_organizationsList Snyk organizations the authenticated token can access. Cursor-paginated via starting_after / ending_before.optional ending_before, limit, starting_after
snyk_list_projectsList Snyk projects in an organization. Optional filters: origins (e.g. github, gitlab, cli), types (e.g. npm, maven, docker), target_id. Cursor-paginated.required org_id
optional ending_before, limit, origins, starting_after, target_id, types

16 tools. Connect with API key.

ToolDescriptionArguments
tenable-vulnerability-management_check_asset_export_statusPoll the status of a running asset export job. Indicates completion % or chunk availability for Nessus-scanned assets.required export_job_id
tenable-vulnerability-management_check_vuln_export_statusPoll the status of a running vulnerability export job. Indicates completion % or chunk availability for Nessus findings.required export_job_id
tenable-vulnerability-management_get_asset_activity_logGet activity log for a Nessus-scanned asset showing discovery, scans, attribute changes, tagging events, updates, and source information over time.required asset_uuid
tenable-vulnerability-management_get_asset_detailsGet detailed information for a specific Nessus-scanned asset including vulnerabilities, tags, installed software, cloud metadata (AWS/Azure/GCP), and Lumin metrics.required asset_uuid
tenable-vulnerability-management_get_asset_export_chunkRetrieve a chunk of exported asset data. Each chunk contains Nessus-scanned asset records with details and tags.required export_job_id, chunk_id
tenable-vulnerability-management_get_asset_vuln_outputsRetrieve Nessus plugin outputs (evidence details) for a specific vulnerability on a specific asset. Shows the proof of vulnerability occurrence.required asset_id, plugin_id
tenable-vulnerability-management_get_plugin_detailsGet detailed Nessus plugin information including description, solution, CVSS scores, VPR, exploit availability, and references. Supports filtering to scope results.required plugin_id
optional date_range, filter_search_type, filters
tenable-vulnerability-management_get_vuln_export_chunkRetrieve a chunk of exported vulnerability data. Once an export is ready, fetch Nessus vulnerabilities.required export_job_id, chunk_id
tenable-vulnerability-management_list_asset_filtersList available Nessus asset filters with their names, operators, and validation rules. Use this to discover valid filter names and operators for the list_assets and list_assets_with_vulnerabilities tools.—
tenable-vulnerability-management_list_asset_vulnerabilitiesList up to 5,000 Nessus-detected vulnerabilities found on a specific asset with summary info (plugin ID, severity, VPR, state). Supports filtering.required asset_id
optional date_range, filter_search_type, filters
tenable-vulnerability-management_list_assetsList up to 5,000 Nessus-scanned assets with summary info (IP addresses, OS, agent status, sources). Supports filtering. For larger datasets, use asset export tools.optional all_fields, date_range, filter_search_type, filters
tenable-vulnerability-management_list_assets_with_vulnerabilitiesList up to 5,000 Nessus-scanned assets that have vulnerabilities, showing each asset with severity counts (info/low/medium/high/critical).optional date_range, filter_search_type, filters
tenable-vulnerability-management_list_vulnerabilitiesList up to 5,000 Nessus-detected vulnerabilities with summary info (plugin ID, severity, VPR, state). Limited to 450 days of data. For larger exports, use vuln export tools.optional date_range, filter_search_type, filters
tenable-vulnerability-management_list_vulnerability_filtersList available Nessus vulnerability filters with their names, operators, and validation rules. Use this to discover valid filter names and operators for the list_vulnerabilities, get_plugin_details, and list_asset_vulnerabilities tools.—
tenable-vulnerability-management_start_asset_exportInitiate an export of assets with tags and metadata. Includes assets discovered by Nessus scans.optional chunk_size, filters, include_open_ports
tenable-vulnerability-management_start_vuln_exportInitiate an export of vulnerabilities matching criteria. Starts a Tenable vuln export job. Exports Nessus scan findings.optional chunk_size, filters, since, state

4 tools. Connect with API key.

ToolDescriptionArguments
traceable_api_spec_conformance_resultsQuery API spec conformance results — shadow endpoints, orphan endpoints, parameter diffs, and summaries.required spec_id, query_type
optional limit, offset
traceable_entitiesQuery Traceable entities (API, SERVICE, BACKEND, DOMAIN, ACTOR). Always returns id, type, and labels. Optionally include metrics (provide metric_key), attributes (provide attribute_key), or edges (provide edge_neighbor_type).optional attribute_key, between, edge_neighbor_scope, edge_neighbor_type, edge_type, entity_type, filter_by, include_inactive, limit, metric_key, offset, order_by, scope, space
traceable_parameter_insightsQuery API parameter insights — names, types, PII classification, and change tracking.optional aggregation_key, aggregation_type, entity_type, filter_by, group_by, limit, offset, order_by, selection_fields
traceable_threat_activityQuery threat activity records. Always returns selection fields (default: ID, TYPE, SEVERITY_LEVEL, ACTIVITY_STATUS, IS_BLOCKED, ACTOR_ENTITY_ID, SERVICE_NAME, API_NAME, CATEGORIES, START_TIME_MILLIS, LAST_SEEN_MILLIS, EVENTS_COUNT).optional aggregation_key, aggregation_type, filter_by, group_by, limit, offset, order_by, selection_fields, unnest

1 tool. Connect with OAuth 2.0 client credentials.

ToolDescriptionArguments
wiz-cc_list_all_vulnerability_findingsReturn a COMPLETE, deterministic set of Wiz vulnerability findings by walking the cursor server-side, instead of relying on the model to paginate. Repeated identical queries return identical counts.optional fields, filters, max_results, order_by_direction, order_by_field, page_size, source_tool