Malwarebytes MXDR API
The MXDR API from Malwarebytes — 4 operation(s) for mxdr.
The MXDR API from Malwarebytes — 4 operation(s) for mxdr.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/malwarebytes-mxdr-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: ThreatDown MXDR API
description: '# Introduction
ThreatDown Nebula API lets you remotely manage the security of your `Endpoints`, analyze their `assets`, perform advanced analysis on `Detections` of `Malware`, `Ransomware`, `Exploits` and other threats found by the `ThreatDown Endpoint Agent`, and issue jobs like `Scan`, `Isolate`, `Remediate` or `Reboot`.'
version: 1.0.0
x-logo:
altText: ThreatDown logo
url: https://assets.threatdown.com/hermes/ThreatDown_Horizontal_Navy.png
backgroundColor: '#FFFFFF'
servers:
- url: https://api.threatdown.com
tags:
- name: MXDR
paths:
/nebula/v1/mxdr/config:
post:
summary: Post MXDR Config
security:
- client_credentials:
- write
- user_permissions:
- xdr.update
status:
outage:
- auth
parameters:
- name: authorization
required: true
in: header
description: Authorization token
schema:
type: string
- name: accountid
required: true
in: header
description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
schema:
type: string
pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
requestBody:
content:
application/json:
schema:
type: object
title: MXDR configuration object
oneOf:
- properties:
type:
const: entra
config:
type: object
properties:
code:
type: string
title: Code
redirect_uri:
type: string
title: redirect_uri
required:
- code
required:
- type
- config
- properties:
type:
const: okta
config:
type: object
properties:
domain:
type: string
title: Okta Domain
api_token:
type: string
title: Okta API Token
required:
- domain
- api_token
required:
- type
- config
- properties:
type:
const: meraki
config:
type: array
items:
type: object
properties:
machine_name:
type: string
title: Machine Name
syslog_ip:
type: string
format: ipv4
title: Syslog IP
syslog_port:
type: integer
minimum: 1
maximum: 65535
title: Syslog Port
machine_id:
type: string
format: uuid
title: Machine ID
required:
- machine_name
- syslog_ip
- syslog_port
- machine_id
required:
- type
- config
- properties:
type:
const: fortinet
config:
type: object
properties:
syslog_port:
type: integer
minimum: 1
maximum: 65535
title: Fortinet Syslog Port
syslog_ip:
type: string
format: ipv4
title: Fortinet Syslog IP
machine_id:
type: string
format: uuid
title: Endpoint Machine ID
machine_name:
type: string
title: Endpoint Machine Name
required:
- syslog_ip
- syslog_port
- machine_id
- machine_name
required:
- type
- config
- properties:
type:
const: watchguard
config:
type: object
properties:
syslog_port:
type: integer
minimum: 1
maximum: 65535
title: Watchguard Syslog Port
syslog_ip:
type: string
format: ipv4
title: Watchguard Syslog IP
machine_id:
type: string
format: uuid
title: Endpoint Machine ID
machine_name:
type: string
title: Endpoint Machine Name
required:
- syslog_ip
- syslog_port
- machine_id
- machine_name
required:
- type
- config
- properties:
type:
const: sonicwall
config:
type: array
items:
type: object
properties:
machine_name:
type: string
title: Machine Name
syslog_ip:
type: string
format: ipv4
title: Syslog IP
syslog_port:
type: integer
minimum: 1
maximum: 65535
title: Syslog Port
machine_id:
type: string
format: uuid
title: Machine ID
required:
- machine_name
- syslog_ip
- syslog_port
- machine_id
required:
- type
- config
- properties:
type:
const: pan
config:
type: array
items:
type: object
properties:
machine_name:
type: string
title: Machine Name
syslog_ip:
type: string
format: ipv4
title: Syslog IP
syslog_port:
type: integer
minimum: 1
maximum: 65535
title: Syslog Port
machine_id:
type: string
format: uuid
title: Machine ID
required:
- machine_name
- syslog_ip
- syslog_port
- machine_id
required:
- type
- config
- properties:
type:
const: msgraphapi
config:
type: object
properties:
tenant_id:
type: string
title: Tenant ID
required:
- tenant_id
required:
- type
- config
responses:
'200':
description: Successful response
tags:
- MXDR
operationId: api.nebula.mxdr.config.post
/nebula/v1/mxdr/config/{type}:
delete:
summary: Delete MXDR Config
security:
- client_credentials:
- write
- user_permissions:
- xdr.update
status:
outage:
- auth
parameters:
- name: type
required: true
in: path
description: Type
schema:
type: string
- name: authorization
required: true
in: header
description: Authorization token
schema:
type: string
- name: accountid
required: true
in: header
description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
schema:
type: string
pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
responses:
'200':
description: Successful response
tags:
- MXDR
operationId: api.nebula.mxdr.config.delete
/nebula/v1/mxdr/config/status:
get:
summary: Get all MXDR Config Status
security:
- client_credentials:
- read
- user_permissions:
- xdr.view
status:
outage:
- auth
parameters:
- name: authorization
required: true
in: header
description: Authorization token
schema:
type: string
- name: accountid
required: true
in: header
description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
schema:
type: string
pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
responses:
'200':
description: response schema
content:
application/json:
schema:
title: MXDR Config Status
type: array
items:
type: object
properties:
source:
type: string
enum:
- entra
- okta
- meraki
- msgraphapi
- fortinet
- watchguard
- sonicwall
- internal
- internal_ARW
- internal_PUM
- internal_MWAC
- internal_AE
- internal_PUP
- internal_MALWARE
- internal_SA
- internal_RID
- internal_VULNERABLE_DRIVER
- internal_DNS
- internal_FIREWALL
- internal_BPP
status:
type: boolean
last_log_seen:
type:
- string
- 'null'
format: date-time
required:
- source
- status
- last_log_seen
examples:
- - source: entra
status: true
last_log_seen: '2025-05-23T01:50:29.958684100Z'
- source: okta
status: false
last_log_seen: null
- source: meraki
status: true
last_log_seen: '2025-05-23T01:50:29.958684100Z'
- source: fortinet
status: false
last_log_seen: null
- source: watchguard
status: false
last_log_seen: null
- source: internal
status: false
last_log_seen: null
tags:
- MXDR
operationId: api.nebula.mxdr.config.status.get
/nebula/v1/mxdr/config/all:
get:
summary: Get all MXDR Configs
security:
- client_credentials:
- read
- user_permissions:
- xdr.view
status:
outage:
- auth
parameters:
- name: authorization
required: true
in: header
description: Authorization token
schema:
type: string
- name: accountid
required: true
in: header
description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
schema:
type: string
pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
responses:
'200':
description: response schema
content:
application/json:
schema:
title: MXDR configuration objects
type: array
items:
- type: object
properties:
account_id:
type: string
type:
type: string
config:
type: object
created_at:
type: string
updated_at:
type: string
required: []
examples:
- - account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
type: MDR
config:
primary_contact:
user_id: f8f08d43-ce09-46ad-ab43-beede8546f9c
phone: '8767865765'
secondary_contact:
user_id: f7059ed8-be2f-4ccd-8d5a-237e2480f02a
phone: '5435467687'
tertiary_contact:
user_id: 973e6b1d-a81a-4cc2-a8f3-f7f73eb55f1a
phone: '6457658674'
endpoint_isolation: true
identity_response_authorization:
mode: full
config:
disable_identity: true
reset_password: true
force_password_update: true
revoke_session: true
remove_identity_from_groups: true
enforce_mfa: true
region: sec_ops
collaboration_method: Do it for me
is_trial: null
environment_name: ''
created_at: '2024-04-25T11:10:32.724Z'
updated_at: '2024-04-25T08:11:18.392605Z'
- account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
type: okta
config:
domain: trial-6711724-admin.okta.com
created_at: '2025-01-29T14:22:46.219864Z'
updated_at: '2025-01-29T14:22:46.219864Z'
- account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
type: entra
config: {}
created_at: '2025-01-29T14:22:46.219864Z'
updated_at: '2025-01-29T14:22:46.219864Z'
- account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
type: meraki
config:
- machine_name: MachineA
syslog_ip: 1.1.1.3
syslog_port: 5140
machine_id: 14425b5a-c097-49d8-90c9-e6b2a26aa76d
plugin_id: 14425b5a-c097-1234-90c9-e6b2a26aa76d
- machine_name: MachineB
syslog_ip: 1.1.1.2
syslog_port: 5140
machine_id: 14425b5a-c097-49d8-90c9-e6b2a90aa76d
plugin_id: 14425b5a-c097-1234-90c9-e6b2a26aa76d
created_at: '2025-02-20T10:52:04.028218+02:00'
updated_at: '2025-02-20T10:52:04.028218+02:00'
- account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
type: fortinet
config:
machine_name: MachineA
syslog_ip: 1.1.1.3
syslog_port: 5140
machine_id: 14425b5a-c097-49d8-90c9-e6b2a26aa76d
plugin_id: 14425b5a-c097-1234-90c9-e6b2a26aa76d
created_at: '2025-02-20T10:52:04.028218+02:00'
updated_at: '2025-02-20T10:52:04.028218+02:00'
- account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
type: watchguard
config:
machine_name: MachineB
syslog_ip: 1.1.1.2
syslog_port: 5140
machine_id: 14425b5a-c097-49d8-90c9-e6b2a90aa76d
plugin_id: 14425b5a-c097-1234-90c9-e6b2a26aa76d
created_at: '2025-02-20T10:52:04.028218+02:00'
updated_at: '2025-02-20T10:52:04.028218+02:00'
tags:
- MXDR
operationId: api.nebula.mxdr.config.all.get
components:
securitySchemes:
client_credentials:
type: oauth2
flows:
clientCredentials:
tokenUrl: /token
scopes:
read: Read data of your Nebula account
write: Write data, such as groups, policies, exclusions. Create Webhook subscriptions
execute: Issue jobs on your endpoints, like Scan, Reboot or Isolate.
user_permissions:
type: http
scheme: bearer