Malwarebytes Sandbox API

The Sandbox API from Malwarebytes — 2 operation(s) for sandbox.

Business capability
Threat Detection & Response Management BC-620.30

Operations 2

POST /nebula/v1/sandbox/submissions Search the sandbox submission results #
POST /nebula/v1/sandbox/upload Upload file to the sandbox #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/malwarebytes-sandbox-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

malwarebytes-sandbox-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: ThreatDown Sandbox API
  description: '# Introduction

    ThreatDown Nebula API lets you remotely manage the security of your `Endpoints`, analyze their `assets`, perform advanced analysis on `Detections` of `Malware`, `Ransomware`, `Exploits` and other threats found by the `ThreatDown Endpoint Agent`, and issue jobs like `Scan`, `Isolate`, `Remediate` or `Reboot`.'
  version: 1.0.0
  x-logo:
    altText: ThreatDown logo
    url: https://assets.threatdown.com/hermes/ThreatDown_Horizontal_Navy.png
    backgroundColor: '#FFFFFF'
servers:
- url: https://api.threatdown.com
tags:
- name: Sandbox
paths:
  /nebula/v1/sandbox/submissions:
    post:
      summary: Search the sandbox submission results
      security:
      - client_credentials:
        - read
      - user_permissions:
        - edr.manage
      status:
        outage:
        - auth
        - edr
      parameters:
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      requestBody:
        content:
          application/json:
            schema:
              title: Sandbox submissions search request
              type: object
              additionalProperties: false
              properties:
                file_name:
                  type: string
                md5:
                  type: string
                  pattern: ^[a-fA-F0-9]{32}$
                result:
                  type: array
                  items:
                    type: string
                    enum:
                    - clean
                    - malicious
                    - unknown
                status:
                  type: array
                  items:
                    type: string
                    enum:
                    - pending
                    - processing
                ext:
                  type: array
                  items:
                    type: string
                    enum:
                    - exe32
                    - exe64
                    - dll32
                    - dll64
                upload_source:
                  type: string
                  items:
                    type: string
                    enum:
                    - ars
                    - automatic
                    - frs
                    - manual
                    - sa
                timestamp:
                  gte:
                    type: string
                    examples:
                    - '2023-11-16 00:00:00'
                  lte:
                    type: string
                    examples:
                    - '2023-11-16 23:59:59'
                  time_zone:
                    type: string
                    examples:
                    - +02:00
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema:
                title: Sandbox submissions response schema
                type: object
                additionalProperties: false
                properties:
                  data:
                    total_unfiltered:
                      type: number
                    total:
                      type: number
                    rows:
                      type: array
                      items:
                        type: object
                        properties:
                          id:
                            type: number
                          upload_source:
                            type: string
                          account_id:
                            type: string
                            format: uuid
                          file_path:
                            type: string
                          machine_id:
                            type: string
                            format: uuid
                          pc_hostname:
                            type: string
                          timestamp:
                            type: string
                          file_name:
                            type: string
                          file_size:
                            type: number
                          rule_count:
                            type: number
                          status:
                            type: string
                          result:
                            type: string
                          md5:
                            type: string
                          sha512:
                            type: string
                          sha1:
                            type: string
                          sha256:
                            type: string
                          ext:
                            type: string
                          file_format:
                            type: string
      tags:
      - Sandbox
      operationId: api.nebula.search.sandbox.submissions
  /nebula/v1/sandbox/upload:
    post:
      summary: Upload file to the sandbox
      security:
      - client_credentials:
        - write
      - user_permissions:
        - edr.manage
      status:
        outage:
        - auth
        - edr
      parameters:
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      requestBody:
        content:
          application/json:
            schema:
              title: Sandbox file upload request
              type: object
              additionalProperties: false
              properties:
                machine_id:
                  type: string
                  format: uuid
                  title: Machine ID
                process_path:
                  type: string
                  title: Process Path
                pc_hostname:
                  type: string
                  title: PC Hostname
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema:
                title: Sandbox file upload request
                type: object
                additionalProperties: false
                properties:
                  status:
                    type: string
                    title: status
      tags:
      - Sandbox
      operationId: api.nebula.sandbox.upload
components:
  securitySchemes:
    client_credentials:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: /token
          scopes:
            read: Read data of your Nebula account
            write: Write data, such as groups, policies, exclusions. Create Webhook subscriptions
            execute: Issue jobs on your endpoints, like Scan, Reboot or Isolate.
    user_permissions:
      type: http
      scheme: bearer