# Malwarebytes

**Canonical:** https://apis.io/providers/malwarebytes/  
**Website:** https://www.malwarebytes.com/  
**APIs profiled:** 52

Malwarebytes is an American anti-malware and endpoint security company founded in 2008 and headquartered in Santa Clara, California. It sells consumer protection under the Malwarebytes brand (Premium Security, Mobile Security, Browser Guard, Privacy VPN, Identity Theft Protection, Personal Data Remover, AdwCleaner) and business endpoint security under the ThreatDown brand, powered by Malwarebytes. The programmable surface is ThreatDown: two large OAuth2-protected REST APIs — the Nebula API for direct-tenant endpoint security management and the OneView API for multi-tenant MSP management of sites and subscriptions — both served from api.threatdown.com and documented with public OpenAPI 3.0 definitions covering endpoints, detections, jobs, policies, quarantine, vulnerability and patch management, EDR/XDR, DNS filtering, device control, email protection and webhooks.

## Kin Score — 58.4 / 100 (strong)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 58.4).

| Facet | Score |
|---|---|
| Discoverability | 63.0 |
| Contract Quality | 65.7 |
| Governance | 11.5 |
| Operational Transparency | 84.2 |
| Developer Ergonomics | 56.0 |
| Commercial Clarity | 60.5 |

## Agent readiness — 46.2 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | derived |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (52)

- **Malwarebytes Account API** — The Account API from Malwarebytes — 2 operation(s) for account.
- **Malwarebytes AI Detection & Response API** — Manage governance rules and settings for AI Detection & Response (AIDR). Use these APIs to create per-tool authorization rules that determine whether specific AI tools are autho...
- **Malwarebytes App Block API** — The App Block API from Malwarebytes — 20 operation(s) for app block.
- **Malwarebytes Assets API** — The Assets API from Malwarebytes — 8 operation(s) for assets.
- **Malwarebytes Authentication API** — The Authentication API from Malwarebytes — 2 operation(s) for authentication.
- **Malwarebytes Case Management API** — The Case Management APIs are for managing Managed Detection and Response (MDR) and Managed Threat Hunting (MTH) cases.
- **Malwarebytes Content Filtering API** — The Content Filtering APIs are for managing content filtering rules used by the DNS module. These rules control what domains or categories of domains your endpoints have access to.
- **Malwarebytes Copilot API** — The Copilot API from Malwarebytes — 10 operation(s) for copilot.
- **Malwarebytes Detections API** — Detections contain information on threats such as malware, ransomware, and malicious URLs found across your account. Use the detection APIs to export detection data and retrieve...
- **Malwarebytes Device Control API** — The Device Control feature manages access to USB storage drives. Activity is logged every time a USB device is blocked or restricted to read-only. Use the Device Control APIs to...
- **Malwarebytes DNS API** — The DNS API from Malwarebytes — 4 operation(s) for dns.
- **Malwarebytes DNS Logs API** — The DNS Filtering module limits the number of domain-based threats in your environment by allowing and blocking access across the network. Each time this occurs, a record is gen...
- **Malwarebytes Drive Encryption API** — The Drive Encryption API from Malwarebytes — 5 operation(s) for drive encryption.
- **Malwarebytes Email Protection API** — The Email Protection API from Malwarebytes — 79 operation(s) for email protection.
- **Malwarebytes Endpoints API** — ## Endpoints Introduction An Endpoint is a device which has the ThreatDown Endpoint Agent installed. Currently, there are available Endpoint Agents for Windows, macOS, and Linux...
- **Malwarebytes Events API** — An event is a general term for a threat that has occurred, remediation or other action taken on a threat, and other endpoint-related activity.
- **Malwarebytes Exclusions API** — Exclusions allow you to prevent trusted applications, websites, and services from being detected by our security engine. This means they won't be scanned or blocked. Use these A...
- **Malwarebytes Firewall Management API** — The Firewall Management API from Malwarebytes — 20 operation(s) for firewall management.
- **Malwarebytes Flight Recorder API** — EDR customers can use Flight Recorder to search event data captured on endpoints that have suspicious activity monitoring enabled. Use these APIs to search through files, regist...
- **Malwarebytes Grid API** — # Grid Introduction Using the following API, you can search endpoints, detections, software inventory, vulnerabilities, rid rules, os-patches, device control events and dns logs...
- **Malwarebytes Groups API** — Groups are used to contain and organize endpoints. Policies, which determine the software settings, and endpoints, are assigned to groups. Endpoints use the policies in the grou...
- **Malwarebytes Ignore Rules API** — The Ignore Rules API from Malwarebytes — 4 operation(s) for ignore rules.
- **Malwarebytes Info API** — The Info API from Malwarebytes — 1 operation(s) for info.
- **Malwarebytes Installation Tokens API** — Use these APIs to generate, send, and revoke installation tokens used to activate Mobile Security for Business.
- **Malwarebytes Installers API** — The Installers APIs allow you to deploy the endpoint agent to Windows and macOS devices.
- **Malwarebytes ITDR API** — The ITDR API from Malwarebytes — 29 operation(s) for itdr.
- **Malwarebytes Jobs API** — Jobs are tasks that are issued to endpoints. Use these APIs to manage, search, and export jobs.
- **Malwarebytes Licensing API** — The Licensing API from Malwarebytes — 1 operation(s) for licensing.
- **Malwarebytes MDR API** — The MDR API from Malwarebytes — 2 operation(s) for mdr.
- **Malwarebytes MXDR API** — The MXDR API from Malwarebytes — 4 operation(s) for mxdr.
- **Malwarebytes Notifications API** — This API offers a powerful tool to create notification subscriptions. There are different categories of notifications, for each category different constraints and output fields ...
- **Malwarebytes OS Patches API** — The OS Patches API from Malwarebytes — 8 operation(s) for os patches.
- **Malwarebytes Policies API** — A policy is a set of configurations that determine how the endpoint agent monitors your endpoints, such as protection and scan settings. Once a policy has been created, it needs...
- **Malwarebytes Preferences API** — The Preferences APIs allow you to enable or disable all notifications of a specific type (email, webhook, slack, teams, admin app), without needing to modify or delete multiple ...
- **Malwarebytes Products API** — The Products API from Malwarebytes — 3 operation(s) for products.
- **Malwarebytes Quarantine API** — When a harmful file is found on a device, it can be neutralized and placed in quarantine, preventing it from posing a threat. You can utilize the Quarantine APIs to export or ch...
- **Malwarebytes Remediation API** — The Remediation API from Malwarebytes — 3 operation(s) for remediation.
- **Malwarebytes Remote Intrusion Detection API** — A remote intrusion detection (RID) occurs when a brute force protection rule is triggered according to policy settings. Use these APIs to export and search for RID rules by spec...
- **Malwarebytes Reports API** — The Reports API from Malwarebytes — 8 operation(s) for reports.
- **Malwarebytes Sandbox API** — The Sandbox API from Malwarebytes — 2 operation(s) for sandbox.
- …and 12 more, listed in full on the page.

## MCP servers (1)

- **malwarebytes-mcp.yml**

## Security (4)

- **Malwarebytes Authentication** — 2 schemes
- **Malwarebytes Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Malwarebytes Vulnerability Disclosure** — Hackerone
- **Malwarebytes Trust Center** — SOC 2 Type II, ISO/IEC 27001, PCI DSS

## Tags

Company, Security, Cybersecurity, Endpoint Security, Anti-Malware, Endpoint Detection and Response, Threat Detection, Vulnerability Management, Patch Management, Managed Service Providers, DNS Filtering, Webhooks

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/malwarebytes/). Scores are computed from the provider's own public artifacts under a published rubric.
