Skip to main content
39 skills in this category.

Liongard Access Pattern

The base pattern for reading ANY system's config/state through Liongard — resolve environment, find the inspector launchpoint by systemType, verify it last ran successfully, then query the dataprint. Use it directly for systems without a dedicated skill, and follow it inside every liongard-inspectors skill.

Liongard Active Directory Read

Answer on-prem Active Directory questions from the Liongard AD inspector — privileged group membership, stale accounts, password-policy posture, GPO changes, FSMO roles, and DC health — without a domain login.

Liongard AWS Read

Answer AWS account questions from the Liongard AWS inspector — IAM users and access-key age, root/MFA posture, S3 exposure flags, security groups, and resource census — without console access.

Liongard Azure Read

Answer Azure subscription questions from the Liongard Azure/Microsoft Cloud inspector — resource inventory, spend signals, NSG rule changes, public exposure, and unattached resources — without portal access.

Liongard Bitdefender Read

Interrogate a client's Bitdefender GravityZone tenant through the Liongard Bitdefender inspector — protected endpoints, agent/module status, threat detections, policy assignment, admins. Use for "are their Bitdefender endpoints protected?", coverage-gap checks, or AV/EDR posture questions during triage.

Liongard Cisco ASA Read

Interrogate a client's Cisco ASA firewall through the Liongard Cisco ASA inspector — software version, interfaces, access lists/NAT, VPN (IPsec/AnyConnect) config, admin access. Use for "what's their ASA config?", ACL/exposure review during triage, or version-currency checks.

Liongard Cisco Network Read

Interrogate a client's Cisco switches/routers (IOS/IOS-XE) through Liongard — IOS versions across the fleet, running-config change detections, port/interface inventory, VLAN layout. Use for "what changed on the switch", IOS-currency sweeps, or port/VLAN facts during connectivity triage.

Liongard ConnectWise Automate Read

Interrogate a client's ConnectWise Automate (LabTech) footprint through the Liongard Automate inspector — managed computer inventory, agent check-in status, patch state, monitors, locations. Use for "what does Automate manage for them?", offline-agent checks, or patch-currency questions during triage.

Liongard Cross-Client Census

Answer "which clients run <system>?" across the whole book of business via Liongard's launchpoint inventory — install-base census for zero-day response, EOL waves, vendor-risk events, and standardization planning.

Liongard Datto RMM Read

Interrogate a client's Datto RMM footprint through the Liongard Datto RMM inspector — managed device inventory, agent/online status, patch state, monitored alerts, sites. Use for "what devices does RMM manage for them?", agent-coverage gaps, or patch-currency checks during triage.

Liongard Duo Read

Answer Duo MFA posture questions from the Liongard Duo inspector — enrollment coverage, bypass users, admin list, and protected-integration inventory — for coverage audits and QBR evidence.

Liongard Email Security Config Read

Read a client's email-security platform configuration (Mimecast/Proofpoint-class) through its Liongard inspector — policy posture, connector state, and config drift — to answer "how is their mail filtering actually set up" without an admin console.

Liongard Exchange On-Prem Read

Interrogate a client's on-premises Microsoft Exchange through the Liongard Exchange inspector — server version/CU/build, databases, mailbox inventory, connectors, and admin access. Use for "what's their Exchange config?", CU/patch-currency checks, database/mailbox inventory, or mail-flow triage context.

Liongard FortiGate Read

Interrogate a client's FortiGate through the Liongard Fortinet inspector — firmware/FortiOS version, policy count and changes, VPN tunnel inventory, admin accounts, license/support state. Use for firewall config questions during triage, VPN incident context, or security-posture checks.

Liongard Google Workspace Read

Answer Google Workspace tenant questions from the Liongard inspector — super admin roles, 2SV coverage, license usage, and Drive-sharing posture — for clients living in Google instead of Microsoft.

Liongard Hyper-V Read

Interrogate a client's Hyper-V hosts through Liongard — host and VM inventory, checkpoint sprawl, replica health, VM placement and state. Use for "what runs on their Hyper-V", checkpoint hygiene, replication-status checks, or virtual-estate context during triage.

Liongard Internet Domain & TLS Read

Answer domain, DNS, and certificate questions from Liongard's Internet Domain/DNS and TLS/SSL inspectors — registrar and expiry, DNS record changes, mail-auth records, and cert-expiry sweeps across one client or all of them.

Liongard JumpCloud Read

Interrogate a client's JumpCloud directory through the Liongard JumpCloud inspector — users, MFA enrollment, admins, groups, bound devices/systems, SSO app assignments. Use for "who's in their JumpCloud?", MFA-coverage or admin reviews, or offboarding checks during triage.

Liongard Kaseya VSA Read

Interrogate a client's Kaseya VSA footprint through the Liongard Kaseya VSA inspector — managed agent inventory, online/check-in status, patch state, monitor sets, organizations/machine groups. Use for "what does VSA manage for them?", offline-agent checks, or patch-currency questions during triage.

Liongard M365 Tenant Read

Answer tenant-level Microsoft 365 questions from the Liongard M365 inspector's dataprint — license inventory and assignment, mailbox statistics, admin roles, secure-score inputs, and sharing settings — without touching the tenant.

Liongard Meraki Read

Interrogate a client's Cisco Meraki org through the Liongard Meraki inspector — SSIDs, VLANs, firmware, admin list, device inventory, license state. Use for "what's on their Meraki", wireless/VLAN config questions during triage, or license-expiry checks.

Liongard Mimecast Read

Interrogate a client's Mimecast tenant through the Liongard Mimecast inspector — managed domains, users/licenses, policies, connectors/routing, admins. Use for "what's their Mimecast config?", mail-security posture checks, or domain-coverage questions during triage.

Liongard N-central Read

Interrogate a client's N-able N-central footprint through the Liongard N-central inspector — managed device inventory, agent/probe status, patch state, monitored services, customers/sites. Use for "what does N-central manage for them?", offline-agent checks, or patch-currency questions during triage.

Liongard Network Documentation Sync

Keep network documentation honest by diffing what Liongard inspectors actually see (firewalls, switches, wireless, hypervisors, servers) against what the doc platform says, then drafting corrections. Use for "is our documentation for <client> accurate", pre-onboarding/QBR doc audits, or after a project to true-up the docs.

Liongard Okta Read

Answer Okta tenant questions from the Liongard Okta inspector — app assignments, admin roles, MFA policies, and deactivated-user hygiene — for clients using Okta as their identity front door.

Liongard Palo Alto Read

Interrogate a client's Palo Alto firewall through Liongard — PAN-OS version, config changes and commit history, admin accounts/activity, HA state, policy posture. Use for change-window questions on PAN gear, admin-access review, or HA sanity checks during incidents.

Liongard pfSense Read

Interrogate a client's pfSense firewall through the Liongard pfSense inspector — version, interfaces, firewall/NAT rules, VPN config, packages, admin access. Use for "what's their pfSense config?", rule/exposure review during triage, or version-currency checks.

Liongard Proofpoint Read

Interrogate a client's Proofpoint Essentials tenant through the Liongard Proofpoint inspector — protected domains, users/licenses, filtering policy, spooling, admins. Use for "what's their Proofpoint config?", mail-security posture checks, or domain-coverage questions during triage.

Liongard QBR Evidence Pack

Assemble QBR-grade posture evidence for one client from multiple Liongard inspectors — identity risks, EOL exposure, cert and domain hygiene, and config drift — as a dated, sourced evidence pack the QBR deck can stand on.

Liongard SentinelOne Read

Interrogate a client's SentinelOne tenant through the Liongard SentinelOne inspector — protected agents, agent/version health, threat detections, policy/site assignment, admins. Use for "are their S1 agents healthy?", coverage-gap checks, or EDR posture questions during triage.

Liongard SonicWall Read

Interrogate a client's SonicWall through the Liongard inspector — SonicOS firmware, security-services licensing and expiry, access rules, VPN policies, admin accounts. Use for firewall triage context, the classic "security services just expired" check, or posture review.

Liongard Sophos Central Read

Interrogate a client's Sophos Central tenant through the Liongard Sophos Central inspector — protected endpoints, threat/health status, tamper protection, policy assignment, admin list. Use for "are their Sophos endpoints healthy?", coverage-gap checks during triage, or endpoint-security posture questions.

Liongard Sophos Firewall Read

Interrogate a client's Sophos Firewall (XG/SFOS) through the Liongard Sophos Firewall inspector — firmware, firewall rules, port-forwards/NAT, VPN config, interfaces, admin access. Use for "what's their Sophos firewall config?", rule/exposure review during triage, or firmware-currency checks.

Liongard UniFi Read

Interrogate a client's Ubiquiti UniFi controller through the Liongard inspector — device inventory, adoption state, firmware drift, WLAN/network config. Use for "what UniFi gear do they have", wifi triage context, or firmware-currency checks.

Liongard Veeam Posture Read

Interrogate a client's Veeam deployment through Liongard — job inventory and schedules, repository capacity, protected-VM census, license state. Use for "what does Veeam protect at <client>", coverage-gap checks, and repo-capacity questions; for a job FAILURE alert use vendor-runbooks/veeam-job-failures instead.

Liongard VMware Read

Interrogate a client's vCenter/ESXi estate through Liongard — host versions/build levels, datastore capacity, snapshot sprawl, VM inventory and placement. Use for "what's on their VMware", capacity questions, snapshot hygiene, or host-version currency during triage and QBR prep.

Liongard WatchGuard Config Read

Interrogate a client's WatchGuard Firebox posture through Liongard — Fireware version, subscription/licensing state, policy inventory, VPN config, admin accounts. Use for config/state questions on WatchGuard gear; for responding to live WatchGuard ALERTS use vendor-runbooks/watchguard-firewall-alerts instead.

Liongard Webroot Read

Interrogate a client's Webroot (GSM) console through the Liongard Webroot inspector — protected endpoints, agent status, infection/threat state, policy assignment, sites. Use for "are their Webroot endpoints protected?", coverage-gap checks, or AV posture questions during triage.

Liongard Windows Server Read

Interrogate a client's Windows Servers through Liongard — installed roles, local admin members, services, patch level, OS version and EOL flags. Use for "what does this server do", local-admin audits, EOL-OS sweeps, or patch-posture checks per server.