Malwarebytes Case Management API

The Case Management APIs are for managing Managed Detection and Response (MDR) and Managed Threat Hunting (MTH) cases.

Business capability
Threat Detection & Response Management BC-620.30

Operations 24

GET /nebula/v1/casemgmt/cases/comments Get cases comments #
POST /nebula/v1/casemgmt/cases/comments Post cases comments #
GET /nebula/v1/casemgmt/cases/file Get cases file #
GET /nebula/v1/casemgmt/cases/overview Get cases overview #
GET /nebula/v1/casemgmt/cases/wall Get cases wall #
GET /nebula/v1/casemgmt/multiplexer/cases Get multiplexer cases #
GET /nebula/v1/casemgmt/multiplexer/cases/events Get Case events #
GET /nebula/v1/casemgmt/multiplexer/metrics Get multiplexer metrics #
POST /nebula/v1/casemgmt/cases/action Post cases Action #
POST /nebula/v1/casemgmt/cases/requests Post cases Requests #
POST /nebula/v1/casemgmt/cases/search Post cases search #
PUT /nebula/v1/casemgmt/cases/favorite Put cases favorite #
GET /oneview/v1/casemgmt/accounts/{account_id}/cases/comments Get cases comments #
POST /oneview/v1/casemgmt/accounts/{account_id}/cases/comments Post cases comments #
GET /oneview/v1/casemgmt/accounts/{account_id}/cases/file Get Cases file #
GET /oneview/v1/casemgmt/accounts/{account_id}/cases/overview Get cases overview #
GET /oneview/v1/casemgmt/accounts/{account_id}/cases/wall Get cases wall #
GET /oneview/v1/casemgmt/accounts/{account_id}/multiplexer/cases/events Get Case events #
POST /oneview/v1/casemgmt/accounts/{account_id}/cases/action Placeholder. Please extend this #
POST /oneview/v1/casemgmt/accounts/{account_id}/cases/requests Post Cases Requests #
POST /oneview/v1/casemgmt/cases/search Search Cases #
POST /oneview/v1/casemgmt/multiplexer/cases/bulk Post multiplexer cases bulk #
POST /oneview/v1/casemgmt/multiplexer/metrics/bulk Post multiplexer metrics bulk #
PUT /oneview/v1/casemgmt/accounts/{account_id}/cases/favorite Put Cases favorite #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/malwarebytes-case-management-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

malwarebytes-case-management-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Malwarebytes Case Management API
  version: 1.0.0
  x-logo:
    altText: ThreatDown logo
    url: https://assets.threatdown.com/hermes/ThreatDown_Horizontal_Navy.png
    backgroundColor: '#FFFFFF'
  description: 'Operations tagged Case Management across 2 of this provider''s published API definitions: malwarebytes-threatdown-nebula-openapi.json, malwarebytes-threatdown-oneview-openapi.json. Each path carries the servers of the definition it was published in.'
servers:
- url: https://api.threatdown.com
tags:


# --- truncated at 32 KB (214 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/malwarebytes/refs/heads/main/openapi/malwarebytes-case-management-api-openapi.yml