WatchGuard Endpoint Threat Response
Unified threat response capability combining WatchGuard Cloud Platform account management with Endpoint Security device management, security event monitoring, and risk assessment. Designed for security operations teams responding to endpoint threats, managing device isolation, and reviewing security posture.
What You Can Do
MCP Tools
get-account
Get WatchGuard Cloud account information and status.
get-managed-accounts
List all managed sub-accounts in WatchGuard Cloud.
list-devices
List all WatchGuard managed endpoint devices with protection status.
get-devices-protection-status
Get the protection status of all WatchGuard managed endpoint devices.
isolate-devices
Isolate compromised WatchGuard endpoint devices from the network.
remove-device-isolation
Remove network isolation from WatchGuard endpoint devices after remediation.
start-immediate-scan
Start an immediate malware scan on WatchGuard endpoint devices.
get-security-overview
Get a WatchGuard endpoint security overview for 1, 7, or 30 days.
get-company-risk-summary
Get company-wide endpoint security risk summary by severity level.
get-detected-risks
Get WatchGuard endpoint detected risks broken down by type and device.
activate-device-or-license
Activate WatchGuard hardware devices or software license keys.
get-recent-activations
Get recent WatchGuard device and license activation history.
get-operators
List WatchGuard Cloud operator users for an account.
create-operators
Create new WatchGuard Cloud operator users.