Cybereason website screenshot

Cybereason

Cybereason is an enterprise cybersecurity company (now part of LevelBlue) that provides a defense platform spanning Extended Detection and Response (XDR), Endpoint Detection and Response (EDR), Next-Generation Antivirus (NGAV), Managed Detection and Response (MDR), mobile threat defense, and digital forensics and incident response. Its signature MalOp (Malicious Operation) engine correlates alerts across endpoints and identities into a single operation-centric attack story. Cybereason exposes a gated regional REST API (api..cybereason.net) for partner and customer integrations with SIEMs, SOARs, and security tooling.

Cybereason publishes 9 APIs on the APIs.io network, including Authentication API, CustomDetectionRules API, IsolationRules API, and 6 more. Tagged areas include Cybersecurity, XDR, EDR, NGAV, and MDR.

Cybereason’s developer surface includes authentication, developer portal, documentation, engineering blog, support, and 10 more developer resources.

41.3/100 thin ▬ flat Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreeSelf serve⚡ Free to try
10 APIs 10 Features 5 Use Cases
CybersecurityXDREDRNGAVMDREndpoint SecurityThreat Detection

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 41.3/100 · thin
Contract Quality 12.6 / 25
Developer Ergonomics 7.0 / 20
Commercial Clarity 11.6 / 20
Operational Transparency 2.7 / 13
Governance 0.0 / 12
Discoverability 7.4 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/cybereason: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 10

Individual APIs this provider publishes, each with its own machine-readable definition.

Cybereason REST API

The Cybereason REST API is a gated, region-scoped API hosted at api..cybereason.net that allows customers and integration partners to query MalOps, retrieve sensor inven...

Cybereason Authentication API

The Authentication API from Cybereason — 2 operation(s) for authentication.

Cybereason CustomDetectionRules API

The CustomDetectionRules API from Cybereason — 3 operation(s) for customdetectionrules.

Cybereason IsolationRules API

The IsolationRules API from Cybereason — 2 operation(s) for isolationrules.

Cybereason Malops API

The Malops API from Cybereason — 2 operation(s) for malops.

Cybereason Remediation API

The Remediation API from Cybereason — 3 operation(s) for remediation.

Cybereason Reputation API

The Reputation API from Cybereason — 1 operation(s) for reputation.

Cybereason Sensors API

The Sensors API from Cybereason — 6 operation(s) for sensors.

Cybereason ThreatIntel API

The ThreatIntel API from Cybereason — 3 operation(s) for threatintel.

Cybereason VisualSearch API

The VisualSearch API from Cybereason — 1 operation(s) for visualsearch.

Scroll for all 10

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Cybereason API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Cybereason Rate Limits

2 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 10

Notable capabilities this provider offers.

MalOp Engine

Operation-centric detection that consolidates alerts and telemetry into a single contextualized attack story

XDR

Extended Detection and Response correlating endpoint, identity, network, and cloud signals

EDR

AI-powered Endpoint Detection and Response with deep behavioral analytics

NGAV

Multi-layered Next-Generation Antivirus prevention including anti-ransomware

MDR

24x7 Managed Detection and Response across MDR Essentials, Essentials + XR, and MDR Complete tiers

Mobile Threat Defense

Threat detection and response for iOS and Android endpoints

Vulnerability Management

Proactive risk reduction across the endpoint estate

Threat Hunting

Proactive hunting across historical and live endpoint telemetry

Digital Forensics and Incident Response

DFIR services and 24x7 incident response on-call retainers

Threat Intelligence

Threat intelligence and research from the Cybereason Nocturnus team

Scroll for all 10

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Cybereason Authentication

apiKey/http · 2 schemes

SECURITY

Cybereason Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Cybereason Vulnerability Disclosure

disclosure policy published

SECURITY

Cybereason Trust Center

SOC 2, ISO 27001, ISO 27017, ISO 27018, GDPR

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Cybereason Agentic Access

26 operations · 18 acting

26 operations · 18 acting

AGENTIC

Use Cases 5

What developers build with this provider.

SOC Operations

Surface and triage MalOps directly inside the SOC with full attack-story context

SIEM Enrichment

Stream detections and MalOps into Splunk, Sentinel, Chronicle, and other SIEMs via REST API

Managed Detection and Response

Outsource 24x7 detection and response to the Cybereason MDR team

Incident Response

Engage Cybereason DFIR services for breach investigation, containment, and recovery

Compromise Assessment

Run targeted compromise assessments and cyber posture assessments across the environment

Integrations 4

Pre-built integrations with other platforms and tools.

SIEM

REST API and event forwarding integrations with Splunk, Microsoft Sentinel, Google Chronicle, and others

SOAR

Bidirectional integrations with SOAR platforms for automated containment and response actions

Identity Providers

Identity-based detections across major IdPs as part of the XDR coverage

Mobile Device Management

Mobile Threat Defense integrations with leading UEM/MDM platforms

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Access & Security 4

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 4

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: cybereason
url: https://raw.githubusercontent.com/api-evangelist/cybereason/refs/heads/main/apis.yml
name: Cybereason
type: Index
accessModel:
  pricing: free
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Free · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cybereason.png
tags:
- Cybersecurity
- XDR
- EDR
- NGAV
- MDR
- Endpoint Security
- Threat Detection
description: Cybereason is an enterprise cybersecurity company (now part of LevelBlue) that provides a defense platform spanning
  Extended Detection and Response (XDR), Endpoint Detection and Response (EDR), Next-Generation Antivirus (NGAV), Managed
  Detection and Response (MDR), mobile threat defense, and digital forensics and incident response. Its signature MalOp (Malicious
  Operation) engine correlates alerts across endpoints and identities into a single operation-centric attack story. Cybereason
  exposes a gated regional REST API (api.<region>.cybereason.net) for partner and customer integrations with SIEMs, SOARs,
  and security tooling.
created: '2026-05-23'
modified: '2026-05-23'
specificationVersion: '0.19'
apis:
- aid: cybereason:cybereason-rest-api
  name: Cybereason REST API
  tags:
  - MalOp
  - Sensors
  - Threat Hunting
  - Investigation
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  properties:
  - url: https://nest.cybereason.com/documentation/api-documentation
    type: Documentation
  - url: https://nest.cybereason.com/
    type: Portal
    title: Cybereason Nest Customer Portal (gated)
  description: The Cybereason REST API is a gated, region-scoped API hosted at api.<region>.cybereason.net that allows customers
    and integration partners to query MalOps, retrieve sensor inventory and status, run threat-hunting investigations across
    endpoint telemetry, manage isolation and remediation actions, and stream detections into SIEM, SOAR, and ticketing systems.
    Documentation and credentials are issued through the Cybereason Nest customer portal and are not generally available to
    the public.
- aid: cybereason:cybereason-authentication-api
  name: Cybereason Authentication API
  description: The Authentication API from Cybereason — 2 operation(s) for authentication.
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  tags:
  - Authentication
  properties:
  - type: OpenAPI
    url: openapi/cybereason-authentication-api-openapi.yml
- aid: cybereason:cybereason-customdetectionrules-api
  name: Cybereason CustomDetectionRules API
  description: The CustomDetectionRules API from Cybereason — 3 operation(s) for customdetectionrules.
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  tags:
  - CustomDetectionRules
  properties:
  - type: OpenAPI
    url: openapi/cybereason-customdetectionrules-api-openapi.yml
- aid: cybereason:cybereason-isolationrules-api
  name: Cybereason IsolationRules API
  description: The IsolationRules API from Cybereason — 2 operation(s) for isolationrules.
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  tags:
  - IsolationRules
  properties:
  - type: OpenAPI
    url: openapi/cybereason-isolationrules-api-openapi.yml
- aid: cybereason:cybereason-malops-api
  name: Cybereason Malops API
  description: The Malops API from Cybereason — 2 operation(s) for malops.
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  tags:
  - Malops
  properties:
  - type: OpenAPI
    url: openapi/cybereason-malops-api-openapi.yml
- aid: cybereason:cybereason-remediation-api
  name: Cybereason Remediation API
  description: The Remediation API from Cybereason — 3 operation(s) for remediation.
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  tags:
  - Remediation
  properties:
  - type: OpenAPI
    url: openapi/cybereason-remediation-api-openapi.yml
- aid: cybereason:cybereason-reputation-api
  name: Cybereason Reputation API
  description: The Reputation API from Cybereason — 1 operation(s) for reputation.
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  tags:
  - Reputation
  properties:
  - type: OpenAPI
    url: openapi/cybereason-reputation-api-openapi.yml
- aid: cybereason:cybereason-sensors-api
  name: Cybereason Sensors API
  description: The Sensors API from Cybereason — 6 operation(s) for sensors.
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  tags:
  - Sensors
  properties:
  - type: OpenAPI
    url: openapi/cybereason-sensors-api-openapi.yml
- aid: cybereason:cybereason-threatintel-api
  name: Cybereason ThreatIntel API
  description: The ThreatIntel API from Cybereason — 3 operation(s) for threatintel.
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  tags:
  - ThreatIntel
  properties:
  - type: OpenAPI
    url: openapi/cybereason-threatintel-api-openapi.yml
- aid: cybereason:cybereason-visualsearch-api
  name: Cybereason VisualSearch API
  description: The VisualSearch API from Cybereason — 1 operation(s) for visualsearch.
  humanURL: https://nest.cybereason.com/documentation/api-documentation
  baseURL: https://api.cybereason.net
  tags:
  - VisualSearch
  properties:
  - type: OpenAPI
    url: openapi/cybereason-visualsearch-api-openapi.yml
common:
- type: AgenticAccess
  url: agentic-access/cybereason-agentic-access.yml
- type: TrustCenter
  url: security/cybereason-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/cybereason-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/cybereason-domain-security.yml
- type: Authentication
  url: authentication/cybereason-authentication.yml
- type: LinkedIn
  url: https://www.linkedin.com/company/cybereason
- type: Website
  url: https://www.cybereason.com/
- type: Portal
  url: https://nest.cybereason.com/
  title: Cybereason Nest (Customer Portal)
- type: Documentation
  url: https://nest.cybereason.com/documentation/api-documentation
- type: Blog
  url: https://www.cybereason.com/blog
- type: Support
  url: https://www.cybereason.com/services/incident-response
- type: ContactSales
  url: https://www.cybereason.com/contact
- type: Careers
  url: https://www.cybereason.com/company/careers
- type: PrivacyPolicy
  url: https://www.cybereason.com/privacy-policy
- type: TermsOfService
  url: https://www.cybereason.com/terms-of-use
- type: Features
  data:
  - name: MalOp Engine
    description: Operation-centric detection that consolidates alerts and telemetry into a single contextualized attack story
  - name: XDR
    description: Extended Detection and Response correlating endpoint, identity, network, and cloud signals
  - name: EDR
    description: AI-powered Endpoint Detection and Response with deep behavioral analytics
  - name: NGAV
    description: Multi-layered Next-Generation Antivirus prevention including anti-ransomware
  - name: MDR
    description: 24x7 Managed Detection and Response across MDR Essentials, Essentials + XR, and MDR Complete tiers
  - name: Mobile Threat Defense
    description: Threat detection and response for iOS and Android endpoints
  - name: Vulnerability Management
    description: Proactive risk reduction across the endpoint estate
  - name: Threat Hunting
    description: Proactive hunting across historical and live endpoint telemetry
  - name: Digital Forensics and Incident Response
    description: DFIR services and 24x7 incident response on-call retainers
  - name: Threat Intelligence
    description: Threat intelligence and research from the Cybereason Nocturnus team
- type: UseCases
  data:
  - name: SOC Operations
    description: Surface and triage MalOps directly inside the SOC with full attack-story context
  - name: SIEM Enrichment
    description: Stream detections and MalOps into Splunk, Sentinel, Chronicle, and other SIEMs via REST API
  - name: Managed Detection and Response
    description: Outsource 24x7 detection and response to the Cybereason MDR team
  - name: Incident Response
    description: Engage Cybereason DFIR services for breach investigation, containment, and recovery
  - name: Compromise Assessment
    description: Run targeted compromise assessments and cyber posture assessments across the environment
- type: Integrations
  data:
  - name: SIEM
    description: REST API and event forwarding integrations with Splunk, Microsoft Sentinel, Google Chronicle, and others
  - name: SOAR
    description: Bidirectional integrations with SOAR platforms for automated containment and response actions
  - name: Identity Providers
    description: Identity-based detections across major IdPs as part of the XDR coverage
  - name: Mobile Device Management
    description: Mobile Threat Defense integrations with leading UEM/MDM platforms
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com