# Malwarebytes Notifications API

**Canonical:** https://apis.io/apis/malwarebytes/malwarebytes-notifications-api/  
**Provider:** Malwarebytes — https://apis.io/providers/malwarebytes/  
**Base URL:** https://api.threatdown.com  
**Documentation:** https://api.threatdown.com/nebula/v1/docs

Malwarebytes Notifications API is one of 52 APIs that [Malwarebytes](https://apis.io/providers/malwarebytes/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. Tagged areas include Notification. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API offers a powerful tool to create notification subscriptions. There are different categories of notifications, for each category different constraints and output fields can be specified. Please see the documentation below for the category descriptions. Notifications can be delivered by email or webhooks. In both cases, it's possible to choose the output fields, but the value could be different for the two methods. In the email, some values are mapped to friendly names, as in the Nebula Console. For webhooks the values are the raw level ones. Here's a list of the mapped values. | Output field | Email values | Webhook values | |--------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | role | Super Admin<br>Admin<br>Read Only User | SuperAdmin<br>Admin<br>ReadOnlyUser | | os_platform | Windows<br>MacOS<br>Linux | 1<br>2<br>3 | | category | Malware<br>PUP<br>PUM<br>Exploit<br>Ransomware<br>Remote<br>Website<br>Vulnerable Driver | MALWARE<br>PUP<br>PUM<br>AE<br>ARW<br>RID<br>MWAC<br>VULNERABLE_DRIVER | | status | Blocked<br>Found<br>Quarantined<br>Deleted<br>Restored | blocked<br>found<br>quarantined<br>deleted<br>restored | | threat_name | Malicious Website | web | | command | Scan<br>Restart<br>Restart<br>Remediate<br>Isolate<br>Remove isolation<br>Refresh Endpoint & Software Info<br>Check for protection updates<br>Check for software updates<br>Install software updates<br>Generate diagnostic logs<br>Delete active block rule<br>Upload file for analysis<br>Remove endpoint isolation<br>Isolate<br>Remediated endpoint<br>Endpoint logging level changed<br>Delete from quarantine<br>Restore from quarantine<br>Refresh policy<br>Apply OS Patch<br>Update Installed Software<br>Uninstall Software | command.threat.scan<br>command.service.restart<br>command.asset.reboot<br>command.threat.scan.remediate<br>command.edr.isolation<br>command.edr.unlock<br>command.asset.refresh<br>command.protection.update.now<br>command.machine.update.now<br>command.machine.plugin.updateparts<br>command.service.diag<br>command.bfp.rules.delete<br>command.edr.fileupload<br>command.edr.unlock.force<br>command.edr.lock<br>command.sequence.remediate<br>command.logging.level.set<br>command.threat.quarantine.remove<br>command.threat.quarantine.restore<br>command.policy.refresh<br>command.asset.patch<br>command.asset.updatesoftware<br>command.asset.uninstallsoftware |

## Machine-readable artifacts (4)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/malwarebytes/refs/heads/main/openapi/malwarebytes-notifications-api-openapi.yml
- **Documentation** — https://api.threatdown.com/nebula/v1/docs
- **APIReference** — https://api.threatdown.com/nebula/v1/docs
- **Documentation** — https://cloud.malwarebytes.com/api/v2/oneview/docs

## Other Malwarebytes APIs (12)

- [Malwarebytes Account API](https://apis.io/apis/malwarebytes/malwarebytes-account-api/)
- [Malwarebytes AI Detection & Response API](https://apis.io/apis/malwarebytes/malwarebytes-ai-detection-response-api/)
- [Malwarebytes App Block API](https://apis.io/apis/malwarebytes/malwarebytes-app-block-api/)
- [Malwarebytes Assets API](https://apis.io/apis/malwarebytes/malwarebytes-assets-api/)
- [Malwarebytes Authentication API](https://apis.io/apis/malwarebytes/malwarebytes-authentication-api/)
- [Malwarebytes Case Management API](https://apis.io/apis/malwarebytes/malwarebytes-case-management-api/)
- [Malwarebytes Content Filtering API](https://apis.io/apis/malwarebytes/malwarebytes-content-filtering-api/)
- [Malwarebytes Copilot API](https://apis.io/apis/malwarebytes/malwarebytes-copilot-api/)
- [Malwarebytes Detections API](https://apis.io/apis/malwarebytes/malwarebytes-detections-api/)
- [Malwarebytes Device Control API](https://apis.io/apis/malwarebytes/malwarebytes-device-control-api/)
- [Malwarebytes DNS API](https://apis.io/apis/malwarebytes/malwarebytes-dns-api/)
- [Malwarebytes DNS Logs API](https://apis.io/apis/malwarebytes/malwarebytes-dns-logs-api/)

## Tags

Notification

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/malwarebytes/malwarebytes-notifications-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/malwarebytes/.
