Malwarebytes XDR API

The XDR API from Malwarebytes — 4 operation(s) for xdr.

Business capability
Threat Detection & Response Management BC-620.30

Operations 4

GET /nebula/v1/xdr/alerts/{id} Get alert details #
PUT /nebula/v1/xdr/alerts/{id}/action Set alert action taken #
PUT /nebula/v1/xdr/alerts/status Set alert status #
PUT /nebula/v1/xdr/alerts/action Set alert action taken in bulk #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/malwarebytes-xdr-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

malwarebytes-xdr-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: ThreatDown XDR API
  description: '# Introduction

    ThreatDown Nebula API lets you remotely manage the security of your `Endpoints`, analyze their `assets`, perform advanced analysis on `Detections` of `Malware`, `Ransomware`, `Exploits` and other threats found by the `ThreatDown Endpoint Agent`, and issue jobs like `Scan`, `Isolate`, `Remediate` or `Reboot`.'
  version: 1.0.0
  x-logo:
    altText: ThreatDown logo
    url: https://assets.threatdown.com/hermes/ThreatDown_Horizontal_Navy.png
    backgroundColor: '#FFFFFF'
servers:
- url: https://api.threatdown.com
tags:
- name: XDR
paths:
  /nebula/v1/xdr/alerts/{id}:
    get:
      description: Get an XDR alert and its full details by ID.
      summary: Get alert details
      security:
      - client_credentials:
        - read
      - user_permissions:
        - xdr.view
      status:
        outage:
        - auth
      parameters:
      - name: id
        required: true
        in: path
        schema:
          type: number
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      - name: source
        required: true
        in: query
        description: Alert source
        schema:
          type: string
          enum:
          - edr
          - okta
          - entra
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema:
                type: object
                title: Get XDR alert by id
                additionalProperties: true
                required:
                - id
                properties:
                  id:
                    type: integer
                    title: Alert ID
                    examples:
                    - 123456
                  account_id:
                    type: string
                    title: Account ID
                    examples:
                    - 00000000-0000-0000-0000-000000000001
                  account_name:
                    type: string
                    title: Account name
                  metadata:
                    type: object
                    title: Alert actor metadata
                    additionalProperties: true
                    properties:
                      action:
                        type: object
                        additionalProperties: false
                        properties:
                          user_email:
                            type:
                            - string
                            - 'null'
                            title: Action actor email
                          user_name:
                            type:
                            - string
                            - 'null'
                            title: Action actor name
                  source:
                    type: string
                    title: Alert source
                    examples:
                    - okta
                    - entra
                    - edr
                  severity:
                    type: string
                    title: Alert severity
                    examples:
                    - low
                    - medium
                    - high
                    - critical
                  status:
                    type: string
                    title: Alert status
                    examples:
                    - open
                    - closed
                    - in_progress
                    - new
                    - reopen
                  category:
                    type: string
                    title: Alert category
                  alert_name:
                    type: string
                    title: Alert name
                  action_taken:
                    type: string
                    title: Action taken
                    examples:
                    - false_positive
                  action_user_email:
                    type: string
                    title: Action actor email
                  action_user_name:
                    type: string
                    title: Action actor name
                  action_outcome:
                    type: string
                    title: Action outcome
                    examples:
                    - allow
                    - block
                    - challenge
                    - fail
                  has_impacted_asset_hostname:
                    type: boolean
                    title: Whether any impacted asset has a non-empty hostname
                  comments:
                    type: string
                    title: Analyst comments
                  created_at:
                    type: string
                    title: Creation timestamp
                    format: date-time
                  updated_at:
                    type: string
                    title: Update timestamp
                    format: date-time
                  respond_audit_event:
                    type: object
                    title: Latest matching respond audit event
                    additionalProperties: false
                    properties:
                      user_email:
                        type:
                        - string
                        - 'null'
                        title: Respond action user email
                      user_name:
                        type:
                        - string
                        - 'null'
                        title: Respond action user name
                      logged_at:
                        type:
                        - string
                        - 'null'
                        title: Respond action timestamp
                        format: date-time
                  rules_triggered:
                    type: array
                    title: Triggered rules
                    items:
                      type: string
                  tactics:
                    type: array
                    title: Mapped tactics
                    items:
                      type: string
                  tactic_technique:
                    type: array
                    title: Mapped tactic-technique pairs
                    items:
                      type: string
                  attack_technique:
                    type: array
                    title: Mapped attack-technique pairs
                    items:
                      type: string
                  impacted_asset_hostname:
                    type: array
                    title: Impacted asset hostnames
                    items:
                      type: string
                  attack_detection_type:
                    type: string
                    title: Attack detection type
                  attack_category:
                    type: string
                    title: Attack category
                  city:
                    type: string
                    title: City
                  country:
                    type: string
                    title: Country
                  ip:
                    type: string
                    title: IP address
                  domain:
                    type: string
                    title: Domain or URL
                  identity_primary_identifier:
                    type: string
                    title: Primary identity
                  event_type:
                    type: string
                    title: Identity event type
                  details:
                    type: object
                    title: Source-specific details
                    additionalProperties: true
                  impacted_assets:
                    type: array
                    title: Impacted assets
                    items:
                      type: object
                      additionalProperties: true
                  dynamic_fields:
                    type: object
                    title: Dynamic fields
                    additionalProperties: true
                  tag:
                    type: string
                    title: Tag
                  message:
                    type: string
                    title: Message
                  pid:
                    type: string
                    title: Process ID
                  process_path:
                    type: string
                    title: Process path
                  detection_id:
                    type:
                    - integer
                    - string
                    title: Detection ID
                  machine_id:
                    type: string
                    title: Machine ID
                    format: uuid
                  module_name:
                    type: string
                    title: Module name
                  visible:
                    type: integer
                    title: Visibility flag
                  installation_type:
                    type: integer
                    title: Installation type
                  technique:
                    type: string
                    title: Technique
                  tactics_description:
                    type: array
                    title: Mapped tactic labels
                    items:
                      type: string
                  techniques_description:
                    type: array
                    title: Mapped technique labels
                    items:
                      type: string
      tags:
      - XDR
      operationId: api.nebula.xdr.get.alert
  /nebula/v1/xdr/alerts/{id}/action:
    put:
      description: Set alert action taken and comment
      summary: Set alert action taken
      security:
      - client_credentials:
        - write
      - user_permissions:
        - xdr.update
      status:
        outage:
        - auth
      parameters:
      - name: id
        required: true
        in: path
        schema:
          type: number
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              title: Change xdr alert action
              properties:
                action:
                  type: string
                  description: Supported values are the raw XDR/ITDR action identifiers Orion accepts on write.
                  enum:
                  - DisableUser
                  - ResetUserPassword
                  - RevokeUserSessions
                  - EnforceMFAForUser
                  - ForcePasswordChange
                  - RemoveUserFromGroup
                  - false_positive
                  examples:
                  - false_positive
                  - DisableUser
                comment:
                  type: string
              required:
              - action
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema: {}
      tags:
      - XDR
      operationId: api.nebula.xdr.put.alert.action
  /nebula/v1/xdr/alerts/status:
    put:
      summary: Set alert status
      security:
      - client_credentials:
        - write
      - user_permissions:
        - xdr.update
      status:
        outage:
        - auth
      parameters:
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              title: Change xdr alert status
              properties:
                status:
                  type: string
                  enum:
                  - open
                  - closed
                  - in_progress
                  - new
                  - reopen
                alert_ids:
                  type: array
                  minItems: 1
                  items:
                    type: integer
              required:
              - status
              - alert_ids
              additionalProperties: false
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema: {}
      tags:
      - XDR
      operationId: api.nebula.xdr.put.alert.status
  /nebula/v1/xdr/alerts/action:
    put:
      description: Set alert action taken and comment for multiple XDR alerts
      summary: Set alert action taken in bulk
      security:
      - client_credentials:
        - write
      - user_permissions:
        - xdr.update
      status:
        outage:
        - auth
      parameters:
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              title: Change xdr alert action in bulk
              properties:
                action:
                  type: string
                  description: Supported values are the raw XDR/ITDR action identifiers Orion accepts on write.
                  enum:
                  - DisableUser
                  - ResetUserPassword
                  - RevokeUserSessions
                  - EnforceMFAForUser
                  - ForcePasswordChange
                  - RemoveUserFromGroup
                  - false_positive
                  examples:
                  - false_positive
                  - DisableUser
                comment:
                  type: string
                alert_ids:
                  type: array
                  minItems: 1
                  items:
                    type: integer
              required:
              - action
              - alert_ids
              additionalProperties: false
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema: {}
      tags:
      - XDR
      operationId: api.nebula.xdr.put.alerts.action
components:
  securitySchemes:
    client_credentials:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: /token
          scopes:
            read: Read data of your Nebula account
            write: Write data, such as groups, policies, exclusions. Create Webhook subscriptions
            execute: Issue jobs on your endpoints, like Scan, Reboot or Isolate.
    user_permissions:
      type: http
      scheme: bearer