Malwarebytes MXDR API

The MXDR API from Malwarebytes — 4 operation(s) for mxdr.

Operations 4

POST /nebula/v1/mxdr/config Post MXDR Config #
DELETE /nebula/v1/mxdr/config/{type} Delete MXDR Config #
GET /nebula/v1/mxdr/config/status Get all MXDR Config Status #
GET /nebula/v1/mxdr/config/all Get all MXDR Configs #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/malwarebytes-mxdr-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

malwarebytes-mxdr-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: ThreatDown MXDR API
  description: '# Introduction

    ThreatDown Nebula API lets you remotely manage the security of your `Endpoints`, analyze their `assets`, perform advanced analysis on `Detections` of `Malware`, `Ransomware`, `Exploits` and other threats found by the `ThreatDown Endpoint Agent`, and issue jobs like `Scan`, `Isolate`, `Remediate` or `Reboot`.'
  version: 1.0.0
  x-logo:
    altText: ThreatDown logo
    url: https://assets.threatdown.com/hermes/ThreatDown_Horizontal_Navy.png
    backgroundColor: '#FFFFFF'
servers:
- url: https://api.threatdown.com
tags:
- name: MXDR
paths:
  /nebula/v1/mxdr/config:
    post:
      summary: Post MXDR Config
      security:
      - client_credentials:
        - write
      - user_permissions:
        - xdr.update
      status:
        outage:
        - auth
      parameters:
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              title: MXDR configuration object
              oneOf:
              - properties:
                  type:
                    const: entra
                  config:
                    type: object
                    properties:
                      code:
                        type: string
                        title: Code
                      redirect_uri:
                        type: string
                        title: redirect_uri
                    required:
                    - code
                required:
                - type
                - config
              - properties:
                  type:
                    const: okta
                  config:
                    type: object
                    properties:
                      domain:
                        type: string
                        title: Okta Domain
                      api_token:
                        type: string
                        title: Okta API Token
                    required:
                    - domain
                    - api_token
                required:
                - type
                - config
              - properties:
                  type:
                    const: meraki
                  config:
                    type: array
                    items:
                      type: object
                      properties:
                        machine_name:
                          type: string
                          title: Machine Name
                        syslog_ip:
                          type: string
                          format: ipv4
                          title: Syslog IP
                        syslog_port:
                          type: integer
                          minimum: 1
                          maximum: 65535
                          title: Syslog Port
                        machine_id:
                          type: string
                          format: uuid
                          title: Machine ID
                      required:
                      - machine_name
                      - syslog_ip
                      - syslog_port
                      - machine_id
                required:
                - type
                - config
              - properties:
                  type:
                    const: fortinet
                  config:
                    type: object
                    properties:
                      syslog_port:
                        type: integer
                        minimum: 1
                        maximum: 65535
                        title: Fortinet Syslog Port
                      syslog_ip:
                        type: string
                        format: ipv4
                        title: Fortinet Syslog IP
                      machine_id:
                        type: string
                        format: uuid
                        title: Endpoint Machine ID
                      machine_name:
                        type: string
                        title: Endpoint Machine Name
                    required:
                    - syslog_ip
                    - syslog_port
                    - machine_id
                    - machine_name
                required:
                - type
                - config
              - properties:
                  type:
                    const: watchguard
                  config:
                    type: object
                    properties:
                      syslog_port:
                        type: integer
                        minimum: 1
                        maximum: 65535
                        title: Watchguard Syslog Port
                      syslog_ip:
                        type: string
                        format: ipv4
                        title: Watchguard Syslog IP
                      machine_id:
                        type: string
                        format: uuid
                        title: Endpoint Machine ID
                      machine_name:
                        type: string
                        title: Endpoint Machine Name
                    required:
                    - syslog_ip
                    - syslog_port
                    - machine_id
                    - machine_name
                required:
                - type
                - config
              - properties:
                  type:
                    const: sonicwall
                  config:
                    type: array
                    items:
                      type: object
                      properties:
                        machine_name:
                          type: string
                          title: Machine Name
                        syslog_ip:
                          type: string
                          format: ipv4
                          title: Syslog IP
                        syslog_port:
                          type: integer
                          minimum: 1
                          maximum: 65535
                          title: Syslog Port
                        machine_id:
                          type: string
                          format: uuid
                          title: Machine ID
                      required:
                      - machine_name
                      - syslog_ip
                      - syslog_port
                      - machine_id
                required:
                - type
                - config
              - properties:
                  type:
                    const: pan
                  config:
                    type: array
                    items:
                      type: object
                      properties:
                        machine_name:
                          type: string
                          title: Machine Name
                        syslog_ip:
                          type: string
                          format: ipv4
                          title: Syslog IP
                        syslog_port:
                          type: integer
                          minimum: 1
                          maximum: 65535
                          title: Syslog Port
                        machine_id:
                          type: string
                          format: uuid
                          title: Machine ID
                      required:
                      - machine_name
                      - syslog_ip
                      - syslog_port
                      - machine_id
                required:
                - type
                - config
              - properties:
                  type:
                    const: msgraphapi
                  config:
                    type: object
                    properties:
                      tenant_id:
                        type: string
                        title: Tenant ID
                    required:
                    - tenant_id
                required:
                - type
                - config
      responses:
        '200':
          description: Successful response
      tags:
      - MXDR
      operationId: api.nebula.mxdr.config.post
  /nebula/v1/mxdr/config/{type}:
    delete:
      summary: Delete MXDR Config
      security:
      - client_credentials:
        - write
      - user_permissions:
        - xdr.update
      status:
        outage:
        - auth
      parameters:
      - name: type
        required: true
        in: path
        description: Type
        schema:
          type: string
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      responses:
        '200':
          description: Successful response
      tags:
      - MXDR
      operationId: api.nebula.mxdr.config.delete
  /nebula/v1/mxdr/config/status:
    get:
      summary: Get all MXDR Config Status
      security:
      - client_credentials:
        - read
      - user_permissions:
        - xdr.view
      status:
        outage:
        - auth
      parameters:
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema:
                title: MXDR Config Status
                type: array
                items:
                  type: object
                  properties:
                    source:
                      type: string
                      enum:
                      - entra
                      - okta
                      - meraki
                      - msgraphapi
                      - fortinet
                      - watchguard
                      - sonicwall
                      - internal
                      - internal_ARW
                      - internal_PUM
                      - internal_MWAC
                      - internal_AE
                      - internal_PUP
                      - internal_MALWARE
                      - internal_SA
                      - internal_RID
                      - internal_VULNERABLE_DRIVER
                      - internal_DNS
                      - internal_FIREWALL
                      - internal_BPP
                    status:
                      type: boolean
                    last_log_seen:
                      type:
                      - string
                      - 'null'
                      format: date-time
                  required:
                  - source
                  - status
                  - last_log_seen
                examples:
                - - source: entra
                    status: true
                    last_log_seen: '2025-05-23T01:50:29.958684100Z'
                  - source: okta
                    status: false
                    last_log_seen: null
                  - source: meraki
                    status: true
                    last_log_seen: '2025-05-23T01:50:29.958684100Z'
                  - source: fortinet
                    status: false
                    last_log_seen: null
                  - source: watchguard
                    status: false
                    last_log_seen: null
                  - source: internal
                    status: false
                    last_log_seen: null
      tags:
      - MXDR
      operationId: api.nebula.mxdr.config.status.get
  /nebula/v1/mxdr/config/all:
    get:
      summary: Get all MXDR Configs
      security:
      - client_credentials:
        - read
      - user_permissions:
        - xdr.view
      status:
        outage:
        - auth
      parameters:
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema:
                title: MXDR configuration objects
                type: array
                items:
                - type: object
                  properties:
                    account_id:
                      type: string
                    type:
                      type: string
                    config:
                      type: object
                    created_at:
                      type: string
                    updated_at:
                      type: string
                  required: []
                examples:
                - - account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
                    type: MDR
                    config:
                      primary_contact:
                        user_id: f8f08d43-ce09-46ad-ab43-beede8546f9c
                        phone: '8767865765'
                      secondary_contact:
                        user_id: f7059ed8-be2f-4ccd-8d5a-237e2480f02a
                        phone: '5435467687'
                      tertiary_contact:
                        user_id: 973e6b1d-a81a-4cc2-a8f3-f7f73eb55f1a
                        phone: '6457658674'
                      endpoint_isolation: true
                      identity_response_authorization:
                        mode: full
                        config:
                          disable_identity: true
                          reset_password: true
                          force_password_update: true
                          revoke_session: true
                          remove_identity_from_groups: true
                          enforce_mfa: true
                      region: sec_ops
                      collaboration_method: Do it for me
                      is_trial: null
                      environment_name: ''
                    created_at: '2024-04-25T11:10:32.724Z'
                    updated_at: '2024-04-25T08:11:18.392605Z'
                  - account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
                    type: okta
                    config:
                      domain: trial-6711724-admin.okta.com
                    created_at: '2025-01-29T14:22:46.219864Z'
                    updated_at: '2025-01-29T14:22:46.219864Z'
                  - account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
                    type: entra
                    config: {}
                    created_at: '2025-01-29T14:22:46.219864Z'
                    updated_at: '2025-01-29T14:22:46.219864Z'
                  - account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
                    type: meraki
                    config:
                    - machine_name: MachineA
                      syslog_ip: 1.1.1.3
                      syslog_port: 5140
                      machine_id: 14425b5a-c097-49d8-90c9-e6b2a26aa76d
                      plugin_id: 14425b5a-c097-1234-90c9-e6b2a26aa76d
                    - machine_name: MachineB
                      syslog_ip: 1.1.1.2
                      syslog_port: 5140
                      machine_id: 14425b5a-c097-49d8-90c9-e6b2a90aa76d
                      plugin_id: 14425b5a-c097-1234-90c9-e6b2a26aa76d
                    created_at: '2025-02-20T10:52:04.028218+02:00'
                    updated_at: '2025-02-20T10:52:04.028218+02:00'
                  - account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
                    type: fortinet
                    config:
                      machine_name: MachineA
                      syslog_ip: 1.1.1.3
                      syslog_port: 5140
                      machine_id: 14425b5a-c097-49d8-90c9-e6b2a26aa76d
                      plugin_id: 14425b5a-c097-1234-90c9-e6b2a26aa76d
                    created_at: '2025-02-20T10:52:04.028218+02:00'
                    updated_at: '2025-02-20T10:52:04.028218+02:00'
                  - account_id: 1b5b34fe-ccde-4423-b2a2-8df4b02c13e0
                    type: watchguard
                    config:
                      machine_name: MachineB
                      syslog_ip: 1.1.1.2
                      syslog_port: 5140
                      machine_id: 14425b5a-c097-49d8-90c9-e6b2a90aa76d
                      plugin_id: 14425b5a-c097-1234-90c9-e6b2a26aa76d
                    created_at: '2025-02-20T10:52:04.028218+02:00'
                    updated_at: '2025-02-20T10:52:04.028218+02:00'
      tags:
      - MXDR
      operationId: api.nebula.mxdr.config.all.get
components:
  securitySchemes:
    client_credentials:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: /token
          scopes:
            read: Read data of your Nebula account
            write: Write data, such as groups, policies, exclusions. Create Webhook subscriptions
            execute: Issue jobs on your endpoints, like Scan, Reboot or Isolate.
    user_permissions:
      type: http
      scheme: bearer