Malwarebytes
Malwarebytes is an American anti-malware and endpoint security company founded in 2008 and headquartered in Santa Clara, California. It sells consumer protection under the Malwarebytes brand (Premium Security, Mobile Security, Browser Guard, Privacy VPN, Identity Theft Protection, Personal Data Remover, AdwCleaner) and business endpoint security under the ThreatDown brand, powered by Malwarebytes. The programmable surface is ThreatDown: two large OAuth2-protected REST APIs — the Nebula API for direct-tenant endpoint security management and the OneView API for multi-tenant MSP management of sites and subscriptions — both served from api.threatdown.com and documented with public OpenAPI 3.0 definitions covering endpoints, detections, jobs, policies, quarantine, vulnerability and patch management, EDR/XDR, DNS filtering, device control, email protection and webhooks.
Malwarebytes publishes 52 APIs on the APIs.io network, including Account API, AI Detection & Response API, App Block API, and 49 more. Tagged areas include Company, Security, Cybersecurity, Endpoint Security, and Anti-Malware.
The Malwarebytes catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Malwarebytes’ developer surface includes documentation, API reference, getting-started guide, support, engineering blog, pricing, signup flow, and 31 more developer resources.
52 APIs
1 MCP Servers
CompanySecurityCybersecurityEndpoint SecurityAnti-MalwareEndpoint Detection and ResponseThreat DetectionVulnerability ManagementPatch ManagementManaged Service ProvidersDNS FilteringWebhooks
Individual APIs this provider publishes, each with its own machine-readable definition.
The Account API from Malwarebytes — 2 operation(s) for account.
Manage governance rules and settings for AI Detection & Response (AIDR). Use these APIs to create per-tool authorization rules that determine whether specific AI tools are autho...
The App Block API from Malwarebytes — 20 operation(s) for app block.
The Assets API from Malwarebytes — 8 operation(s) for assets.
The Authentication API from Malwarebytes — 2 operation(s) for authentication.
The Case Management APIs are for managing Managed Detection and Response (MDR) and Managed Threat Hunting (MTH) cases.
The Content Filtering APIs are for managing content filtering rules used by the DNS module. These rules control what domains or categories of domains your endpoints have access to.
The Copilot API from Malwarebytes — 10 operation(s) for copilot.
Detections contain information on threats such as malware, ransomware, and malicious URLs found across your account. Use the detection APIs to export detection data and retrieve...
The Device Control feature manages access to USB storage drives. Activity is logged every time a USB device is blocked or restricted to read-only. Use the Device Control APIs to...
The DNS API from Malwarebytes — 4 operation(s) for dns.
The DNS Filtering module limits the number of domain-based threats in your environment by allowing and blocking access across the network. Each time this occurs, a record is gen...
The Drive Encryption API from Malwarebytes — 5 operation(s) for drive encryption.
The Email Protection API from Malwarebytes — 79 operation(s) for email protection.
## Endpoints Introduction An Endpoint is a device which has the ThreatDown Endpoint Agent installed. Currently, there are available Endpoint Agents for Windows, macOS, and Linux...
An event is a general term for a threat that has occurred, remediation or other action taken on a threat, and other endpoint-related activity.
Exclusions allow you to prevent trusted applications, websites, and services from being detected by our security engine. This means they won't be scanned or blocked. Use these A...
The Firewall Management API from Malwarebytes — 20 operation(s) for firewall management.
EDR customers can use Flight Recorder to search event data captured on endpoints that have suspicious activity monitoring enabled. Use these APIs to search through files, regist...
# Grid Introduction Using the following API, you can search endpoints, detections, software inventory, vulnerabilities, rid rules, os-patches, device control events and dns logs...
Groups are used to contain and organize endpoints. Policies, which determine the software settings, and endpoints, are assigned to groups. Endpoints use the policies in the grou...
The Ignore Rules API from Malwarebytes — 4 operation(s) for ignore rules.
The Info API from Malwarebytes — 1 operation(s) for info.
Use these APIs to generate, send, and revoke installation tokens used to activate Mobile Security for Business.
The Installers APIs allow you to deploy the endpoint agent to Windows and macOS devices.
The ITDR API from Malwarebytes — 29 operation(s) for itdr.
Jobs are tasks that are issued to endpoints. Use these APIs to manage, search, and export jobs.
The Licensing API from Malwarebytes — 1 operation(s) for licensing.
The MDR API from Malwarebytes — 2 operation(s) for mdr.
The MXDR API from Malwarebytes — 4 operation(s) for mxdr.
This API offers a powerful tool to create notification subscriptions. There are different categories of notifications, for each category different constraints and output fields ...
The OS Patches API from Malwarebytes — 8 operation(s) for os patches.
A policy is a set of configurations that determine how the endpoint agent monitors your endpoints, such as protection and scan settings. Once a policy has been created, it needs...
The Preferences APIs allow you to enable or disable all notifications of a specific type (email, webhook, slack, teams, admin app), without needing to modify or delete multiple ...
The Products API from Malwarebytes — 3 operation(s) for products.
When a harmful file is found on a device, it can be neutralized and placed in quarantine, preventing it from posing a threat. You can utilize the Quarantine APIs to export or ch...
The Remediation API from Malwarebytes — 3 operation(s) for remediation.
A remote intrusion detection (RID) occurs when a brute force protection rule is triggered according to policy settings. Use these APIs to export and search for RID rules by spec...
The Reports API from Malwarebytes — 8 operation(s) for reports.
The Sandbox API from Malwarebytes — 2 operation(s) for sandbox.
Scheduled scans allow you to automate scans to run based on a certain schedule, rather than manually triggering a scan. Use these APIs to create and manage your scan schedules.
The Security Advisor API from Malwarebytes — 8 operation(s) for security advisor.
Create and manage sites through APIs. Using sites APIs you can easily segment the usage and the subscriptions for your customers. In order to obtain an `account_id` for one of y...
Subscriptions allow you to enable and manage ThreatDown security services for your customers by setting terms, volume and duration.
Suspicious Activities are found using Endpoint Detection and Response (EDR). When Suspicious Activity Monitoring is enabled via the policy, EDR watches for potentially malicious...
The Syslog API from Malwarebytes — 5 operation(s) for syslog.
The Usage API from Malwarebytes — 9 operation(s) for usage.
The Users API from Malwarebytes — 5 operation(s) for users.
The Vulnerability Assessment API from Malwarebytes — 5 operation(s) for vulnerability assessment.
The Vulnerability Management API from Malwarebytes — 14 operation(s) for vulnerability management.
## Using Webhooks ThreatDown can send webhook events that notify your application any time an event happens on your account. This is useful for transactions which are not report...
The XDR API from Malwarebytes — 4 operation(s) for xdr.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Model Context Protocol servers that expose these APIs to AI agents.
Documented rate limits and quota policies.
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
OAuth scopes governing access to this provider's APIs.
aid: malwarebytes
name: Malwarebytes
description: 'Malwarebytes is an American anti-malware and endpoint security company founded in 2008 and headquartered in
Santa Clara, California. It sells consumer protection under the Malwarebytes brand (Premium Security, Mobile Security, Browser
Guard, Privacy VPN, Identity Theft Protection, Personal Data Remover, AdwCleaner) and business endpoint security under the
ThreatDown brand, powered by Malwarebytes. The programmable surface is ThreatDown: two large OAuth2-protected REST APIs
— the Nebula API for direct-tenant endpoint security management and the OneView API for multi-tenant MSP management of sites
and subscriptions — both served from api.threatdown.com and documented with public OpenAPI 3.0 definitions covering endpoints,
detections, jobs, policies, quarantine, vulnerability and patch management, EDR/XDR, DNS filtering, device control, email
protection and webhooks.'
url: https://raw.githubusercontent.com/api-evangelist/malwarebytes/refs/heads/main/apis.yml
image: https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/01/Malwarebytes-wordmark-horiz-Brand-Blue.png?w=810
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-08-04'
modified: '2026-08-04'
tags:
- Company
- Security
- Cybersecurity
- Endpoint Security
- Anti-Malware
- Endpoint Detection and Response
- Threat Detection
- Vulnerability Management
- Patch Management
- Managed Service Providers
- DNS Filtering
- Webhooks
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
- FN: APIs.json
email: info@apis.io
apis:
- aid: malwarebytes:malwarebytes-account-api
name: Malwarebytes Account API
description: The Account API from Malwarebytes — 2 operation(s) for account.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Account
properties:
- type: OpenAPI
url: openapi/malwarebytes-account-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-ai-detection-response-api
name: Malwarebytes AI Detection & Response API
description: 'Manage governance rules and settings for AI Detection & Response (AIDR).
Use these APIs to create per-tool authorization rules that determine whether specific AI tools are authorized, unauthorized,
or pending review. Configure account-level defaults as a fallback when no matching rule exists.'
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- AI Detection & Response
properties:
- type: OpenAPI
url: openapi/malwarebytes-ai-detection-response-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-app-block-api
name: Malwarebytes App Block API
description: The App Block API from Malwarebytes — 20 operation(s) for app block.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- App Block
properties:
- type: OpenAPI
url: openapi/malwarebytes-app-block-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-assets-api
name: Malwarebytes Assets API
description: The Assets API from Malwarebytes — 8 operation(s) for assets.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Assets
properties:
- type: OpenAPI
url: openapi/malwarebytes-assets-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-authentication-api
name: Malwarebytes Authentication API
description: The Authentication API from Malwarebytes — 2 operation(s) for authentication.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Authentication
properties:
- type: OpenAPI
url: openapi/malwarebytes-authentication-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-case-management-api
name: Malwarebytes Case Management API
description: The Case Management APIs are for managing Managed Detection and Response (MDR) and Managed Threat Hunting (MTH)
cases.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Case Management
properties:
- type: OpenAPI
url: openapi/malwarebytes-case-management-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-content-filtering-api
name: Malwarebytes Content Filtering API
description: The Content Filtering APIs are for managing content filtering rules used by the DNS module. These rules control
what domains or categories of domains your endpoints have access to.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Content Filtering
properties:
- type: OpenAPI
url: openapi/malwarebytes-content-filtering-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-copilot-api
name: Malwarebytes Copilot API
description: The Copilot API from Malwarebytes — 10 operation(s) for copilot.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Copilot
properties:
- type: OpenAPI
url: openapi/malwarebytes-copilot-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-detections-api
name: Malwarebytes Detections API
description: "Detections contain information on threats such as malware, ransomware, and malicious URLs found across your\
\ account. \n\nUse the detection APIs to export detection data and retrieve details about a specific detection."
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Detections
properties:
- type: OpenAPI
url: openapi/malwarebytes-detections-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-device-control-api
name: Malwarebytes Device Control API
description: 'The Device Control feature manages access to USB storage drives. Activity is logged every time a USB device
is blocked or restricted to read-only.
Use the Device Control APIs to export device control activity, obtain information about a specific device control event,
search for device control events, and view device control activity grouped by a selected parameter.
If your endpoints are running Endpoint Agent version 2.0.0.81 or newer, you can utilize the APIs that manage the Allowlist,
or exclusions, for Device Control. The Allowlist provides the ability to override policy controls and prevent certain
USB devices from being blocked by Device Control.'
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Device Control
properties:
- type: OpenAPI
url: openapi/malwarebytes-device-control-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-dns-api
name: Malwarebytes DNS API
description: The DNS API from Malwarebytes — 4 operation(s) for dns.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- DNS
properties:
- type: OpenAPI
url: openapi/malwarebytes-dns-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-dns-logs-api
name: Malwarebytes DNS Logs API
description: 'The DNS Filtering module limits the number of domain-based threats in your environment by allowing and blocking
access across the network. Each time this occurs, a record is generated.
Use these APIs to export the DNS activity and search through the logs.'
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- DNS Logs
properties:
- type: OpenAPI
url: openapi/malwarebytes-dns-logs-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-drive-encryption-api
name: Malwarebytes Drive Encryption API
description: The Drive Encryption API from Malwarebytes — 5 operation(s) for drive encryption.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Drive Encryption
properties:
- type: OpenAPI
url: openapi/malwarebytes-drive-encryption-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-email-protection-api
name: Malwarebytes Email Protection API
description: The Email Protection API from Malwarebytes — 79 operation(s) for email protection.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Email Protection
properties:
- type: OpenAPI
url: openapi/malwarebytes-email-protection-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-endpoints-api
name: Malwarebytes Endpoints API
description: '## Endpoints Introduction
An Endpoint is a device which has the ThreatDown Endpoint Agent installed. Currently, there are available Endpoint Agents
for Windows, macOS, and Linux. Refer to the installation guide for more information on registering a new Endpoint.
Using the Endpoint API, you can search your registered endpoints and retrieve their last known status. The API allows
you to perform advanced queries and offers grouping capabilities so that you can perform deep analysis of your company''s
devices and the found threats, such as Detections or Suspicious Activities.
You can scan, isolate, remediate, and reboot your endpoints remotely through the Job APIs.
## How to deploy an endpoint agent
**Endpoint software can be installed in the following ways**:
- Active Directory (AD) Group Policy
- System Center Configuration Manager (SCCM)
- Third-party deployment tools
- Manually on the endpoints
- Discovery & Deployment Tool
Once the installation is complete, the endpoints will be displayed in the console.
You can retrieve installers for your account through the `Installers` APIs.'
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Endpoints
properties:
- type: OpenAPI
url: openapi/malwarebytes-endpoints-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-events-api
name: Malwarebytes Events API
description: An event is a general term for a threat that has occurred, remediation or other action taken on a threat, and
other endpoint-related activity.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Events
properties:
- type: OpenAPI
url: openapi/malwarebytes-events-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-exclusions-api
name: Malwarebytes Exclusions API
description: 'Exclusions allow you to prevent trusted applications, websites, and services from being detected by our security
engine. This means they won''t be scanned or blocked.
Use these APIs to manage the exclusions across your account.'
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Exclusions
properties:
- type: OpenAPI
url: openapi/malwarebytes-exclusions-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-firewall-management-api
name: Malwarebytes Firewall Management API
description: The Firewall Management API from Malwarebytes — 20 operation(s) for firewall management.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Firewall Management
properties:
- type: OpenAPI
url: openapi/malwarebytes-firewall-management-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-flight-recorder-api
name: Malwarebytes Flight Recorder API
description: "EDR customers can use Flight Recorder to search event data captured on endpoints that have suspicious activity\
\ monitoring enabled. \n\nUse these APIs to search through files, registry, processes, networking activity, and suspicious\
\ activities. This information can be used to investigate or identify indicators of compromise."
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Flight-recorder
properties:
- type: OpenAPI
url: openapi/malwarebytes-flight-recorder-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-grid-api
name: Malwarebytes Grid API
description: "# Grid Introduction\n\nUsing the following API, you can search endpoints, detections, software inventory,\
\ vulnerabilities, rid rules, os-patches, device control events and dns logs. This API allows to perform filtering, sorting,\
\ grouping and aggregating of data by specifying constraints based on the field type.\n\nAvailable constraints for searching\
\ based on value type\n\n| Value Type | Constraints |\n| --- |----|\n| Simple String | equals, not_equals, contains, not_contains\
\ |\n| String (with enum) | equals, not_equals |\n| String/UUID (entity reference) | equals, not_equals |\n| Version |\
\ equals, not_equals |\n| Number | gt, lt, gte, lte |\n| Timestamp | start, end |\n| IP | ip |\n| Boolean | equals, not_equals\
\ |\n\nGrid API also supports compound constraints that can be constructed with the keywords **allOf**, **anyOf**, **noneOf**\n\
\nExample of compound constraint:\n\n```json\n{\n\"constraints\": [\n {\n \"allOf\": [\n {\n \"field\"\
: \"agent.host_name\",\n \"operator\": \"contains\",\n \"value\": \"a\"\n },\n {\n \"\
field\": \"machine.is_deleted\",\n \"operator\": \"equals\",\n \"value\": false\n },\n {\n\
\ \"anyOf\": [\n {\n \"field\": \"agent.os_info.os_platform\",\n \"operator\": \"\
equals\",\n \"value\": \"Linux\"\n },\n {\n \"field\": \"agent.os_info.os_platform\"\
,\n \"operator\": \"equals\",\n \"value\": \"MacOS\"\n }\n ]\n }\n ]\n \
\ }\n]\n}\n```\nIn this example all the records that contain **a** in the ***agent.host_name***, have ***machine.is_deleted***\
\ set to false and whose ***os_platform*** is equal to **either** ***Linux*** or ***MacOS*** will be returned."
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Grid
properties:
- type: OpenAPI
url: openapi/malwarebytes-grid-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-groups-api
name: Malwarebytes Groups API
description: 'Groups are used to contain and organize endpoints. Policies, which determine the software settings, and endpoints,
are assigned to groups. Endpoints use the policies in the groups they are assigned to determine which software settings
are enabled.
Use these APIs to create, manage, and move endpoints into groups.'
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Groups
properties:
- type: OpenAPI
url: openapi/malwarebytes-groups-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-ignore-rules-api
name: Malwarebytes Ignore Rules API
description: The Ignore Rules API from Malwarebytes — 4 operation(s) for ignore rules.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Ignore Rules
properties:
- type: OpenAPI
url: openapi/malwarebytes-ignore-rules-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-info-api
name: Malwarebytes Info API
description: The Info API from Malwarebytes — 1 operation(s) for info.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Info
properties:
- type: OpenAPI
url: openapi/malwarebytes-info-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-installation-tokens-api
name: Malwarebytes Installation Tokens API
description: Use these APIs to generate, send, and revoke installation tokens used to activate Mobile Security for Business.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Installation Tokens
properties:
- type: OpenAPI
url: openapi/malwarebytes-installation-tokens-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-installers-api
name: Malwarebytes Installers API
description: The Installers APIs allow you to deploy the endpoint agent to Windows and macOS devices.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Installers
properties:
- type: OpenAPI
url: openapi/malwarebytes-installers-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-itdr-api
name: Malwarebytes ITDR API
description: The ITDR API from Malwarebytes — 29 operation(s) for itdr.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- ITDR
properties:
- type: OpenAPI
url: openapi/malwarebytes-itdr-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-jobs-api
name: Malwarebytes Jobs API
description: Jobs are tasks that are issued to endpoints. Use these APIs to manage, search, and export jobs.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Jobs
properties:
- type: OpenAPI
url: openapi/malwarebytes-jobs-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-licensing-api
name: Malwarebytes Licensing API
description: The Licensing API from Malwarebytes — 1 operation(s) for licensing.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- Licensing
properties:
- type: OpenAPI
url: openapi/malwarebytes-licensing-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-mdr-api
name: Malwarebytes MDR API
description: The MDR API from Malwarebytes — 2 operation(s) for mdr.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- MDR
properties:
- type: OpenAPI
url: openapi/malwarebytes-mdr-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-mxdr-api
name: Malwarebytes MXDR API
description: The MXDR API from Malwarebytes — 4 operation(s) for mxdr.
humanURL: https://api.threatdown.com/nebula/v1/docs
baseURL: https://api.threatdown.com
tags:
- MXDR
properties:
- type: OpenAPI
url: openapi/malwarebytes-mxdr-api-openapi.yml
- type: Documentation
url: https://api.threatdown.com/nebula/v1/docs
- type: APIReference
url: https://api.threatdown.com/nebula/v1/docs
- type: Documentation
url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-notifications-api
name: Malwarebytes Notifications API
description: 'This API offers a powerful tool to create notification subscriptions. There are different categories of notifications,
for each category different constraints and output fields can be specified. Please see the documentation below for the
category descriptions.
Notifications can be delivered by email or webhooks. In both cases, it''s possible to choose the output fields, but the
value could be different for the two methods. In the email, some values are mapped to friendly names, as in the Nebula
Console. For webhooks the values are the raw level ones. Here''s a list of the mapped values.
| Output field | Email values |
Webhook values |
|--------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| role | Super Admin<br>Admin<br>Read Only User |
SuperAdmin<br>Admin<br>ReadOnlyUser |
| os_platform | Windows<br>MacOS<br>Linux |
1<br>2<br>3 |
| category | Malware<br>PUP<br>PUM<br>Exploit<br>Ransomware<br>Remote<br>Website<br>Vulnerable Driver |
MALWARE<br>PUP<br>PUM<br>AE<br>ARW<br>RID<br>MWAC<br>VULNERABLE_DRIVER |
| status | Blocked<br>Found<br>Quarantined<br>Deleted<br>Restored |
blocked<br>found<br>quarantined<br>deleted<br>restored
# --- truncated at 32 KB (132 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/malwarebytes/refs/heads/main/apis.yml