# Cybereason

**Canonical:** https://apis.io/providers/cybereason/  
**Website:** https://www.cybereason.com/  
**APIs profiled:** 10

Cybereason is an enterprise cybersecurity company (now part of LevelBlue) that provides a defense platform spanning Extended Detection and Response (XDR), Endpoint Detection and Response (EDR), Next-Generation Antivirus (NGAV), Managed Detection and Response (MDR), mobile threat defense, and digital forensics and incident response. Its signature MalOp (Malicious Operation) engine correlates alerts across endpoints and identities into a single operation-centric attack story. Cybereason exposes a gated regional REST API (api.<region>.cybereason.net) for partner and customer integrations with SIEMs, SOARs, and security tooling.

## Kin Score — 40.8 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 40.8).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 49.5 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 21.1 |
| Developer Ergonomics | 33.3 |
| Commercial Clarity | 57.9 |
| Access Clarity | 57.9 |

## Agent readiness — 29.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Free · Self-serve signup — onboarding: self-serve, pricing: free, trial: no (confidence: high).

## APIs (10)

- **Cybereason REST API** — The Cybereason REST API is a gated, region-scoped API hosted at api.<region>.cybereason.net that allows customers and integration partners to query MalOps, retrieve sensor inven...
- **Cybereason Authentication API** — The Authentication API from Cybereason — 2 operation(s) for authentication.
- **Cybereason CustomDetectionRules API** — The CustomDetectionRules API from Cybereason — 3 operation(s) for customdetectionrules.
- **Cybereason IsolationRules API** — The IsolationRules API from Cybereason — 2 operation(s) for isolationrules.
- **Cybereason Malops API** — The Malops API from Cybereason — 2 operation(s) for malops.
- **Cybereason Remediation API** — The Remediation API from Cybereason — 3 operation(s) for remediation.
- **Cybereason Reputation API** — The Reputation API from Cybereason — 1 operation(s) for reputation.
- **Cybereason Sensors API** — The Sensors API from Cybereason — 6 operation(s) for sensors.
- **Cybereason ThreatIntel API** — The ThreatIntel API from Cybereason — 3 operation(s) for threatintel.
- **Cybereason VisualSearch API** — The VisualSearch API from Cybereason — 1 operation(s) for visualsearch.

## Agentic access (1)

- **Cybereason Agentic Access** — 26 operations · 18 acting

## Security (4)

- **Cybereason Authentication** — apiKey/http · 2 schemes
- **Cybereason Domain Security** — TLSv1.3 · HSTS · DMARC
- **Cybereason Vulnerability Disclosure** — disclosure policy published
- **Cybereason Trust Center** — SOC 2, ISO 27001, ISO 27017, ISO 27018, GDPR

## Plans (1)

- **Cybereason Plans Pricing**

## Use cases (5)

- **SOC Operations** — Surface and triage MalOps directly inside the SOC with full attack-story context
- **SIEM Enrichment** — Stream detections and MalOps into Splunk, Sentinel, Chronicle, and other SIEMs via REST API
- **Managed Detection and Response** — Outsource 24x7 detection and response to the Cybereason MDR team
- **Incident Response** — Engage Cybereason DFIR services for breach investigation, containment, and recovery
- **Compromise Assessment** — Run targeted compromise assessments and cyber posture assessments across the environment

## Tags

Cybersecurity, XDR, EDR, NGAV, MDR, Endpoint Security, Threat Detection

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/cybereason/). Scores are computed from the provider's own public artifacts under a published rubric.
