Malwarebytes website screenshot

Malwarebytes

Malwarebytes is an American anti-malware and endpoint security company founded in 2008 and headquartered in Santa Clara, California. It sells consumer protection under the Malwarebytes brand (Premium Security, Mobile Security, Browser Guard, Privacy VPN, Identity Theft Protection, Personal Data Remover, AdwCleaner) and business endpoint security under the ThreatDown brand, powered by Malwarebytes. The programmable surface is ThreatDown: two large OAuth2-protected REST APIs — the Nebula API for direct-tenant endpoint security management and the OneView API for multi-tenant MSP management of sites and subscriptions — both served from api.threatdown.com and documented with public OpenAPI 3.0 definitions covering endpoints, detections, jobs, policies, quarantine, vulnerability and patch management, EDR/XDR, DNS filtering, device control, email protection and webhooks.

Malwarebytes publishes 52 APIs on the APIs.io network, including Account API, AI Detection & Response API, App Block API, and 49 more. Tagged areas include Company, Security, Cybersecurity, Endpoint Security, and Anti-Malware.

The Malwarebytes catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Malwarebytes’ developer surface includes documentation, API reference, getting-started guide, support, engineering blog, pricing, signup flow, and 31 more developer resources.

58.4/100 strong ▬ flat Agent 46/100 agent ready Full breakdown ↓
scored 2026-08-17 · rubric v0.11.0
52 APIs 1 MCP Servers
CompanySecurityCybersecurityEndpoint SecurityAnti-MalwareEndpoint Detection and ResponseThreat DetectionVulnerability ManagementPatch ManagementManaged Service ProvidersDNS FilteringWebhooks

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-17 · rubric v0.11.0
Composite quality — 58.4/100 · strong
Contract Quality 16.4 / 25
Developer Ergonomics 11.2 / 20
Commercial Clarity 12.1 / 20
Operational Transparency 10.9 / 13
Governance 1.4 / 12
Discoverability 6.3 / 10
Agent readiness — 46/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 10
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 6 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 3 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/malwarebytes: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 52

Individual APIs this provider publishes, each with its own machine-readable definition.

Malwarebytes Account API

The Account API from Malwarebytes — 2 operation(s) for account.

Malwarebytes AI Detection & Response API

Manage governance rules and settings for AI Detection & Response (AIDR). Use these APIs to create per-tool authorization rules that determine whether specific AI tools are autho...

Malwarebytes App Block API

The App Block API from Malwarebytes — 20 operation(s) for app block.

Malwarebytes Assets API

The Assets API from Malwarebytes — 8 operation(s) for assets.

Malwarebytes Authentication API

The Authentication API from Malwarebytes — 2 operation(s) for authentication.

Malwarebytes Case Management API

The Case Management APIs are for managing Managed Detection and Response (MDR) and Managed Threat Hunting (MTH) cases.

Malwarebytes Content Filtering API

The Content Filtering APIs are for managing content filtering rules used by the DNS module. These rules control what domains or categories of domains your endpoints have access to.

Malwarebytes Copilot API

The Copilot API from Malwarebytes — 10 operation(s) for copilot.

Malwarebytes Detections API

Detections contain information on threats such as malware, ransomware, and malicious URLs found across your account. Use the detection APIs to export detection data and retrieve...

Malwarebytes Device Control API

The Device Control feature manages access to USB storage drives. Activity is logged every time a USB device is blocked or restricted to read-only. Use the Device Control APIs to...

Malwarebytes DNS API

The DNS API from Malwarebytes — 4 operation(s) for dns.

Malwarebytes DNS Logs API

The DNS Filtering module limits the number of domain-based threats in your environment by allowing and blocking access across the network. Each time this occurs, a record is gen...

Malwarebytes Drive Encryption API

The Drive Encryption API from Malwarebytes — 5 operation(s) for drive encryption.

Malwarebytes Email Protection API

The Email Protection API from Malwarebytes — 79 operation(s) for email protection.

Malwarebytes Endpoints API

## Endpoints Introduction An Endpoint is a device which has the ThreatDown Endpoint Agent installed. Currently, there are available Endpoint Agents for Windows, macOS, and Linux...

Malwarebytes Events API

An event is a general term for a threat that has occurred, remediation or other action taken on a threat, and other endpoint-related activity.

Malwarebytes Exclusions API

Exclusions allow you to prevent trusted applications, websites, and services from being detected by our security engine. This means they won't be scanned or blocked. Use these A...

Malwarebytes Firewall Management API

The Firewall Management API from Malwarebytes — 20 operation(s) for firewall management.

Malwarebytes Flight Recorder API

EDR customers can use Flight Recorder to search event data captured on endpoints that have suspicious activity monitoring enabled. Use these APIs to search through files, regist...

Malwarebytes Grid API

# Grid Introduction Using the following API, you can search endpoints, detections, software inventory, vulnerabilities, rid rules, os-patches, device control events and dns logs...

Malwarebytes Groups API

Groups are used to contain and organize endpoints. Policies, which determine the software settings, and endpoints, are assigned to groups. Endpoints use the policies in the grou...

Malwarebytes Ignore Rules API

The Ignore Rules API from Malwarebytes — 4 operation(s) for ignore rules.

Malwarebytes Info API

The Info API from Malwarebytes — 1 operation(s) for info.

Malwarebytes Installation Tokens API

Use these APIs to generate, send, and revoke installation tokens used to activate Mobile Security for Business.

Malwarebytes Installers API

The Installers APIs allow you to deploy the endpoint agent to Windows and macOS devices.

Malwarebytes ITDR API

The ITDR API from Malwarebytes — 29 operation(s) for itdr.

Malwarebytes Jobs API

Jobs are tasks that are issued to endpoints. Use these APIs to manage, search, and export jobs.

Malwarebytes Licensing API

The Licensing API from Malwarebytes — 1 operation(s) for licensing.

Malwarebytes MDR API

The MDR API from Malwarebytes — 2 operation(s) for mdr.

Malwarebytes MXDR API

The MXDR API from Malwarebytes — 4 operation(s) for mxdr.

Malwarebytes Notifications API

This API offers a powerful tool to create notification subscriptions. There are different categories of notifications, for each category different constraints and output fields ...

Malwarebytes OS Patches API

The OS Patches API from Malwarebytes — 8 operation(s) for os patches.

Malwarebytes Policies API

A policy is a set of configurations that determine how the endpoint agent monitors your endpoints, such as protection and scan settings. Once a policy has been created, it needs...

Malwarebytes Preferences API

The Preferences APIs allow you to enable or disable all notifications of a specific type (email, webhook, slack, teams, admin app), without needing to modify or delete multiple ...

Malwarebytes Products API

The Products API from Malwarebytes — 3 operation(s) for products.

Malwarebytes Quarantine API

When a harmful file is found on a device, it can be neutralized and placed in quarantine, preventing it from posing a threat. You can utilize the Quarantine APIs to export or ch...

Malwarebytes Remediation API

The Remediation API from Malwarebytes — 3 operation(s) for remediation.

Malwarebytes Remote Intrusion Detection API

A remote intrusion detection (RID) occurs when a brute force protection rule is triggered according to policy settings. Use these APIs to export and search for RID rules by spec...

Malwarebytes Reports API

The Reports API from Malwarebytes — 8 operation(s) for reports.

Malwarebytes Sandbox API

The Sandbox API from Malwarebytes — 2 operation(s) for sandbox.

Malwarebytes Schedules API

Scheduled scans allow you to automate scans to run based on a certain schedule, rather than manually triggering a scan. Use these APIs to create and manage your scan schedules.

Malwarebytes Security Advisor API

The Security Advisor API from Malwarebytes — 8 operation(s) for security advisor.

Malwarebytes Sites API

Create and manage sites through APIs. Using sites APIs you can easily segment the usage and the subscriptions for your customers. In order to obtain an `account_id` for one of y...

Malwarebytes Subscriptions API

Subscriptions allow you to enable and manage ThreatDown security services for your customers by setting terms, volume and duration.

Malwarebytes Suspicious Activity API

Suspicious Activities are found using Endpoint Detection and Response (EDR). When Suspicious Activity Monitoring is enabled via the policy, EDR watches for potentially malicious...

Malwarebytes Syslog API

The Syslog API from Malwarebytes — 5 operation(s) for syslog.

Malwarebytes Usage API

The Usage API from Malwarebytes — 9 operation(s) for usage.

Malwarebytes Users API

The Users API from Malwarebytes — 5 operation(s) for users.

Malwarebytes Vulnerability Assessment API

The Vulnerability Assessment API from Malwarebytes — 5 operation(s) for vulnerability assessment.

Malwarebytes Vulnerability Management API

The Vulnerability Management API from Malwarebytes — 14 operation(s) for vulnerability management.

Malwarebytes Webhooks API

## Using Webhooks ThreatDown can send webhook events that notify your application any time an event happens on your account. This is useful for transactions which are not report...

Malwarebytes XDR API

The XDR API from Malwarebytes — 4 operation(s) for xdr.

Scroll for all 52

Open Collections 53

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

ThreatDown Account API

OPEN COLLECTION

Malwarebytes Assets API

OPEN COLLECTION

ThreatDown Copilot API

OPEN COLLECTION

ThreatDown DNS API

OPEN COLLECTION

ThreatDown DNS Logs API

OPEN COLLECTION

Malwarebytes Events API

OPEN COLLECTION

Malwarebytes Grid API

OPEN COLLECTION

Malwarebytes Groups API

OPEN COLLECTION

ThreatDown Info API

OPEN COLLECTION

ThreatDown ITDR API

OPEN COLLECTION

Malwarebytes Jobs API

OPEN COLLECTION

ThreatDown Licensing API

OPEN COLLECTION

Malwarebytes MDR API

OPEN COLLECTION

ThreatDown MXDR API

OPEN COLLECTION

Malwarebytes Policies API

OPEN COLLECTION

ThreatDown Products API

OPEN COLLECTION

Malwarebytes Reports API

OPEN COLLECTION

ThreatDown Sandbox API

OPEN COLLECTION

ThreatDown Sites API

OPEN COLLECTION

ThreatDown Syslog API

OPEN COLLECTION

Malwarebytes Usage API

OPEN COLLECTION

Malwarebytes Users API

OPEN COLLECTION

Malwarebytes Webhooks API

OPEN COLLECTION

ThreatDown XDR API

OPEN COLLECTION

Scroll for all 53

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Rate Limits 1

Documented rate limits and quota policies.

Malwarebytes Rate Limits

2 limits

RATE LIMITS

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Malwarebytes Authentication

2 schemes

SECURITY

Malwarebytes Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Malwarebytes Trust Center

SOC 2 Type II, ISO/IEC 27001, PCI DSS

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Malwarebytes Scopes

3 scopes · clientCredentials

3 scopes

SCOPES

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 8

Authentication, authorization, and security posture

Scroll for all 8

Operate 7

Status, limits, changes, and where to get help

Scroll for all 7

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: malwarebytes
name: Malwarebytes
description: 'Malwarebytes is an American anti-malware and endpoint security company founded in 2008 and headquartered in
  Santa Clara, California. It sells consumer protection under the Malwarebytes brand (Premium Security, Mobile Security, Browser
  Guard, Privacy VPN, Identity Theft Protection, Personal Data Remover, AdwCleaner) and business endpoint security under the
  ThreatDown brand, powered by Malwarebytes. The programmable surface is ThreatDown: two large OAuth2-protected REST APIs
  — the Nebula API for direct-tenant endpoint security management and the OneView API for multi-tenant MSP management of sites
  and subscriptions — both served from api.threatdown.com and documented with public OpenAPI 3.0 definitions covering endpoints,
  detections, jobs, policies, quarantine, vulnerability and patch management, EDR/XDR, DNS filtering, device control, email
  protection and webhooks.'
url: https://raw.githubusercontent.com/api-evangelist/malwarebytes/refs/heads/main/apis.yml
image: https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/01/Malwarebytes-wordmark-horiz-Brand-Blue.png?w=810
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-08-04'
modified: '2026-08-04'
tags:
- Company
- Security
- Cybersecurity
- Endpoint Security
- Anti-Malware
- Endpoint Detection and Response
- Threat Detection
- Vulnerability Management
- Patch Management
- Managed Service Providers
- DNS Filtering
- Webhooks
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
apis:
- aid: malwarebytes:malwarebytes-account-api
  name: Malwarebytes Account API
  description: The Account API from Malwarebytes — 2 operation(s) for account.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Account
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-account-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-ai-detection-response-api
  name: Malwarebytes AI Detection & Response API
  description: 'Manage governance rules and settings for AI Detection & Response (AIDR).


    Use these APIs to create per-tool authorization rules that determine whether specific AI tools are authorized, unauthorized,
    or pending review. Configure account-level defaults as a fallback when no matching rule exists.'
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - AI Detection & Response
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-ai-detection-response-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-app-block-api
  name: Malwarebytes App Block API
  description: The App Block API from Malwarebytes — 20 operation(s) for app block.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - App Block
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-app-block-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-assets-api
  name: Malwarebytes Assets API
  description: The Assets API from Malwarebytes — 8 operation(s) for assets.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Assets
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-assets-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-authentication-api
  name: Malwarebytes Authentication API
  description: The Authentication API from Malwarebytes — 2 operation(s) for authentication.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Authentication
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-authentication-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-case-management-api
  name: Malwarebytes Case Management API
  description: The Case Management APIs are for managing Managed Detection and Response (MDR) and Managed Threat Hunting (MTH)
    cases.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Case Management
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-case-management-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-content-filtering-api
  name: Malwarebytes Content Filtering API
  description: The Content Filtering APIs are for managing content filtering rules used by the DNS module. These rules control
    what domains or categories of domains your endpoints have access to.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Content Filtering
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-content-filtering-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-copilot-api
  name: Malwarebytes Copilot API
  description: The Copilot API from Malwarebytes — 10 operation(s) for copilot.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Copilot
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-copilot-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-detections-api
  name: Malwarebytes Detections API
  description: "Detections contain information on threats such as malware, ransomware, and malicious URLs found across your\
    \ account. \n\nUse the detection APIs to export detection data and retrieve details about a specific detection."
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Detections
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-detections-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-device-control-api
  name: Malwarebytes Device Control API
  description: 'The Device Control feature manages access to USB storage drives. Activity is logged every time a USB device
    is blocked or restricted to read-only.


    Use the Device Control APIs to export device control activity, obtain information about a specific device control event,
    search for device control events, and view device control activity grouped by a selected parameter.


    If your endpoints are running Endpoint Agent version 2.0.0.81 or newer, you can utilize the APIs that manage the Allowlist,
    or exclusions, for Device Control. The Allowlist provides the ability to override policy controls and prevent certain
    USB devices from being blocked by Device Control.'
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Device Control
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-device-control-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-dns-api
  name: Malwarebytes DNS API
  description: The DNS API from Malwarebytes — 4 operation(s) for dns.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - DNS
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-dns-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-dns-logs-api
  name: Malwarebytes DNS Logs API
  description: 'The DNS Filtering module limits the number of domain-based threats in your environment by allowing and blocking
    access across the network. Each time this occurs, a record is generated.


    Use these APIs to export the DNS activity and search through the logs.'
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - DNS Logs
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-dns-logs-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-drive-encryption-api
  name: Malwarebytes Drive Encryption API
  description: The Drive Encryption API from Malwarebytes — 5 operation(s) for drive encryption.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Drive Encryption
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-drive-encryption-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-email-protection-api
  name: Malwarebytes Email Protection API
  description: The Email Protection API from Malwarebytes — 79 operation(s) for email protection.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Email Protection
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-email-protection-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-endpoints-api
  name: Malwarebytes Endpoints API
  description: '## Endpoints Introduction


    An Endpoint is a device which has the ThreatDown Endpoint Agent installed. Currently, there are available Endpoint Agents
    for Windows, macOS, and Linux. Refer to the installation guide for more information on registering a new Endpoint.


    Using the Endpoint API, you can search your registered endpoints and retrieve their last known status. The API allows
    you to perform advanced queries and offers grouping capabilities so that you can perform deep analysis of your company''s
    devices and the found threats, such as Detections or Suspicious Activities.


    You can scan, isolate, remediate, and reboot your endpoints remotely through the Job APIs.


    ## How to deploy an endpoint agent


    **Endpoint software can be installed in the following ways**:


    - Active Directory (AD) Group Policy

    - System Center Configuration Manager (SCCM)

    - Third-party deployment tools

    - Manually on the endpoints

    - Discovery & Deployment Tool


    Once the installation is complete, the endpoints will be displayed in the console.


    You can retrieve installers for your account through the `Installers` APIs.'
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Endpoints
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-endpoints-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-events-api
  name: Malwarebytes Events API
  description: An event is a general term for a threat that has occurred, remediation or other action taken on a threat, and
    other endpoint-related activity.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Events
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-events-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-exclusions-api
  name: Malwarebytes Exclusions API
  description: 'Exclusions allow you to prevent trusted applications, websites, and services from being detected by our security
    engine. This means they won''t be scanned or blocked.


    Use these APIs to manage the exclusions across your account.'
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Exclusions
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-exclusions-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-firewall-management-api
  name: Malwarebytes Firewall Management API
  description: The Firewall Management API from Malwarebytes — 20 operation(s) for firewall management.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Firewall Management
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-firewall-management-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-flight-recorder-api
  name: Malwarebytes Flight Recorder API
  description: "EDR customers can use Flight Recorder to search event data captured on endpoints that have suspicious activity\
    \ monitoring enabled. \n\nUse these APIs to search through files, registry, processes, networking activity, and suspicious\
    \ activities. This information can be used to investigate or identify indicators of compromise."
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Flight-recorder
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-flight-recorder-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-grid-api
  name: Malwarebytes Grid API
  description: "# Grid Introduction\n\nUsing the following API, you can search endpoints, detections, software inventory,\
    \ vulnerabilities, rid rules, os-patches, device control events and dns logs. This API allows to perform filtering, sorting,\
    \ grouping and aggregating of data by specifying constraints based on the field type.\n\nAvailable constraints for searching\
    \ based on value type\n\n| Value Type | Constraints |\n| --- |----|\n| Simple String | equals, not_equals, contains, not_contains\
    \ |\n| String (with enum) | equals, not_equals |\n| String/UUID (entity reference) | equals, not_equals |\n| Version |\
    \ equals, not_equals |\n| Number | gt, lt, gte, lte |\n| Timestamp | start, end |\n| IP | ip |\n| Boolean | equals, not_equals\
    \ |\n\nGrid API also supports compound constraints that can be constructed with the keywords **allOf**, **anyOf**, **noneOf**\n\
    \nExample of compound constraint:\n\n```json\n{\n\"constraints\": [\n  {\n    \"allOf\": [\n      {\n        \"field\"\
    : \"agent.host_name\",\n        \"operator\": \"contains\",\n        \"value\": \"a\"\n      },\n      {\n          \"\
    field\": \"machine.is_deleted\",\n          \"operator\": \"equals\",\n          \"value\": false\n      },\n      {\n\
    \        \"anyOf\": [\n          {\n            \"field\": \"agent.os_info.os_platform\",\n            \"operator\": \"\
    equals\",\n            \"value\": \"Linux\"\n          },\n          {\n            \"field\": \"agent.os_info.os_platform\"\
    ,\n            \"operator\": \"equals\",\n            \"value\": \"MacOS\"\n          }\n        ]\n      }\n    ]\n \
    \ }\n]\n}\n```\nIn this example all the records that contain **a** in the ***agent.host_name***, have ***machine.is_deleted***\
    \ set to false and whose ***os_platform*** is equal to **either** ***Linux*** or ***MacOS*** will be returned."
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Grid
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-grid-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-groups-api
  name: Malwarebytes Groups API
  description: 'Groups are used to contain and organize endpoints. Policies, which determine the software settings, and endpoints,
    are assigned to groups. Endpoints use the policies in the groups they are assigned to determine which software settings
    are enabled.


    Use these APIs to create, manage, and move endpoints into groups.'
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Groups
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-groups-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-ignore-rules-api
  name: Malwarebytes Ignore Rules API
  description: The Ignore Rules API from Malwarebytes — 4 operation(s) for ignore rules.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Ignore Rules
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-ignore-rules-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-info-api
  name: Malwarebytes Info API
  description: The Info API from Malwarebytes — 1 operation(s) for info.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Info
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-info-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-installation-tokens-api
  name: Malwarebytes Installation Tokens API
  description: Use these APIs to generate, send, and revoke installation tokens used to activate Mobile Security for Business.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Installation Tokens
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-installation-tokens-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-installers-api
  name: Malwarebytes Installers API
  description: The Installers APIs allow you to deploy the endpoint agent to Windows and macOS devices.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Installers
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-installers-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-itdr-api
  name: Malwarebytes ITDR API
  description: The ITDR API from Malwarebytes — 29 operation(s) for itdr.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - ITDR
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-itdr-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-jobs-api
  name: Malwarebytes Jobs API
  description: Jobs are tasks that are issued to endpoints. Use these APIs to manage, search, and export jobs.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Jobs
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-jobs-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-licensing-api
  name: Malwarebytes Licensing API
  description: The Licensing API from Malwarebytes — 1 operation(s) for licensing.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - Licensing
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-licensing-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-mdr-api
  name: Malwarebytes MDR API
  description: The MDR API from Malwarebytes — 2 operation(s) for mdr.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - MDR
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-mdr-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-mxdr-api
  name: Malwarebytes MXDR API
  description: The MXDR API from Malwarebytes — 4 operation(s) for mxdr.
  humanURL: https://api.threatdown.com/nebula/v1/docs
  baseURL: https://api.threatdown.com
  tags:
  - MXDR
  properties:
  - type: OpenAPI
    url: openapi/malwarebytes-mxdr-api-openapi.yml
  - type: Documentation
    url: https://api.threatdown.com/nebula/v1/docs
  - type: APIReference
    url: https://api.threatdown.com/nebula/v1/docs
  - type: Documentation
    url: https://cloud.malwarebytes.com/api/v2/oneview/docs
- aid: malwarebytes:malwarebytes-notifications-api
  name: Malwarebytes Notifications API
  description: 'This API offers a powerful tool to create notification subscriptions. There are different categories of notifications,

    for each category different constraints and output fields can be specified. Please see the documentation below for the

    category descriptions.


    Notifications can be delivered by email or webhooks. In both cases, it''s possible to choose the output fields, but the

    value could be different for the two methods. In the email, some values are mapped to friendly names, as in the Nebula

    Console. For webhooks the values are the raw level ones. Here''s a list of the mapped values.


    | Output field | Email values                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
    Webhook values                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |

    |--------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

    | role         | Super Admin<br>Admin<br>Read Only User                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
    SuperAdmin<br>Admin<br>ReadOnlyUser                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |

    | os_platform  | Windows<br>MacOS<br>Linux                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
    1<br>2<br>3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

    | category     | Malware<br>PUP<br>PUM<br>Exploit<br>Ransomware<br>Remote<br>Website<br>Vulnerable Driver                                                                                                                                                                                                                                                                                                                                                                                                                                              |
    MALWARE<br>PUP<br>PUM<br>AE<br>ARW<br>RID<br>MWAC<br>VULNERABLE_DRIVER                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |

    | status       | Blocked<br>Found<br>Quarantined<br>Deleted<br>Restored                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
    blocked<br>found<br>quarantined<br>deleted<br>restored                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    

# --- truncated at 32 KB (132 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/malwarebytes/refs/heads/main/apis.yml