Cybereason Remediation API
The Remediation API from Cybereason — 3 operation(s) for remediation.
The Remediation API from Cybereason — 3 operation(s) for remediation.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/cybereason-remediation-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Cybereason Authentication Remediation API
version: 23.x
description: 'Cybereason EDR/XDR REST API. Exposes Malop investigation, hunting
via Visual Search, sensor management, isolation rules, custom
detection rules, reputation lists, threat-intel lookups, malware
queries, and remediation actions against a Cybereason tenant.
Best-effort spec derived from publicly indexed Cybereason API
documentation references (api-doc.cybereason.com URI/endpoints
pages, docs.cybereason.com 23.2 docs, Cortex XSOAR / Demisto
Cybereason integration, and the open-source CybereasonAPI
PowerShell module). Cybereason''s primary API documentation is
customer/partner-gated; the operational surface modelled here
matches the publicly described endpoints.
Authentication is performed via a POST to /login.html which
returns a JSESSIONID cookie used on subsequent calls. JWT
authentication is also supported on version 20.1+ deployments.
'
contact:
name: Cybereason Nest
url: https://nest.cybereason.com/documentation/api-documentation
license:
name: Proprietary
servers:
- url: https://{tenant}.cybereason.net
description: Cybereason tenant
variables:
tenant:
default: example
description: Your Cybereason tenant hostname prefix.
security:
- SessionCookie: []
tags:
- name: Remediation
paths:
/rest/remediate:
post:
tags:
- Remediation
summary: Trigger remediation actions on a Malop
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RemediationRequest'
responses:
'200':
description: Remediation accepted
content:
application/json:
schema:
$ref: '#/components/schemas/RemediationResponse'
/rest/remediate/status/{malopId}:
parameters:
- in: path
name: malopId
required: true
schema:
type: string
get:
tags:
- Remediation
summary: Get remediation status for a Malop
responses:
'200':
description: Remediation status
content:
application/json:
schema:
type: object
/rest/remediate/abort:
post:
tags:
- Remediation
summary: Abort remediation
requestBody:
required: true
content:
application/json:
schema:
type: object
responses:
'200':
description: Aborted
components:
schemas:
RemediationResponse:
type: object
properties:
remediationId:
type: string
initiatingUser:
type: string
start:
type: integer
format: int64
statusLog:
type: array
items:
type: object
RemediationRequest:
type: object
properties:
initiatorUserName:
type: string
malopId:
type: string
actionsByMachine:
type: object
additionalProperties:
type: array
items:
type: object
properties:
targetId:
type: string
actionType:
type: string
enum:
- KILL_PROCESS
- QUARANTINE_FILE
- DELETE_REGISTRY_KEY
- UNQUARANTINE_FILE
- BLOCK_FILE
securitySchemes:
SessionCookie:
type: apiKey
in: cookie
name: JSESSIONID
description: Session cookie returned by POST /login.html.
BearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
description: Available on Cybereason 20.1+ for token-based access.
externalDocs:
description: Cybereason API documentation
url: https://nest.cybereason.com/documentation/api-documentation