Skip to main content
The RoboShadow API tool gives Neo agents read access to RoboShadow, the vulnerability management and endpoint security platform. The common use is a request like “analyse the missing CVEs for Contoso and remediate them”: the agent reads the client’s CVE report, the fix for each CVE, the affected devices and RoboShadow’s own remediation attempts, then updates the devices with your RMM tools.
Automatically enabled when you configure RoboShadow permissions in your agent workflow.

What It Does

  • Read the organisations your RoboShadow login reaches
  • Read devices with their health scores, CVE counts and missing-update counts, and each device’s installed applications, services, disks and hardware
  • Read the CVE, CPE and vulnerable-application reports, with CVSS, EPSS and the known-exploited flag, and the fixes RoboShadow lists for each CVE
  • Read missing Windows updates per device, and RoboShadow’s remediation attempts with the CVEs each one addressed
  • Read antivirus, ransomware protection, detected threats, Windows Defender and firewall status
  • Read the users on each device and the Microsoft 365 MFA report
  • Read external vulnerability scans and what each scanned IP address exposes
Neo reads RoboShadow and changes nothing there. To fix what it finds, the agent uses the RMM tools you give it, under their own approval rules, and reports what it changed.

Permission Groups

Every group is read only. Device rows in the other groups still name the logged-on user and carry IP and MAC addresses and serial numbers.

Setup

See Connecting RoboShadow to Neo.