# McAfee (Trellix)

**Canonical:** https://apis.io/providers/mcafee/  
**Website:** https://www.trellix.com/  
**APIs profiled:** 26

APIs for McAfee Enterprise security products and services. McAfee Enterprise rebranded as Trellix in 2022, but its on-premises and SaaS platforms (ePO, MVISION, ESM, Web Gateway, TIE, DXL) continue to expose REST APIs documented here for centralized security management, threat intelligence, EDR, messaging, and SIEM integration.

## Kin Score — 35.6 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 35.6).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 60.9 |
| Governance | 9.8 |
| Contract Governance | 9.8 |
| Operational Transparency | 5.3 |
| Developer Ergonomics | 21.4 |
| Commercial Clarity | 34.2 |
| Access Clarity | 34.2 |

## Agent readiness — 32.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Enterprise · Self-serve signup — onboarding: self-serve, pricing: enterprise, trial: no (confidence: high).

## APIs (26)

- **McAfee Threat Intelligence Exchange (TIE) API** — Real-time threat intelligence sharing and reputation services API.
- **McAfee Data Exchange Layer (DXL) API** — Messaging fabric for real-time security data exchange and integration.
- **McAfee (Trellix) Alarms API** — Manage security alarms
- **McAfee (Trellix) Authentication API** — Session authentication and management
- **McAfee (Trellix) Cases API** — Manage incident response cases
- **McAfee (Trellix) Core API** — Core server operations and authentication
- **McAfee (Trellix) Data Sources API** — Manage event data sources
- **McAfee (Trellix) Detections API** — EDR detection events and alerts
- **McAfee (Trellix) Devices API** — Manage ESM device hierarchy
- **McAfee (Trellix) Events API** — Query and retrieve security events
- **McAfee (Trellix) File Operations API** — Import and export configuration files
- **McAfee (Trellix) Investigations API** — Threat investigation workflows and actions
- **McAfee (Trellix) Lists API** — Manage URL and IP lists used in filtering
- **McAfee (Trellix) Monitoring API** — Appliance health and traffic monitoring
- **McAfee (Trellix) Policies API** — Manage and assign security policies
- **McAfee (Trellix) Policy Configuration API** — Manage proxy and policy settings
- **McAfee (Trellix) Queries API** — Execute ePO queries and retrieve results
- **McAfee (Trellix) Real-Time Search API** — Real-time data collection from endpoints
- **McAfee (Trellix) Rule Sets API** — Manage web security rule sets
- **McAfee (Trellix) Software API** — Manage software repositories and packages
- **McAfee (Trellix) System Groups API** — Manage the ePO System Tree groups
- **McAfee (Trellix) Systems API** — Manage endpoints and systems registered in ePO
- **McAfee (Trellix) Tasks API** — Manage client tasks and server tasks
- **McAfee (Trellix) Threat Events API** — Retrieve threat event data from managed endpoints
- **McAfee (Trellix) Threats API** — Retrieve and manage detected threats
- **McAfee (Trellix) Watchlists API** — Manage security watchlists

## Agentic access (1)

- **Mcafee Agentic Access** — 61 operations · 35 acting

## Security (2)

- **Mcafee Authentication** — apiKey/http · 4 schemes
- **Mcafee Domain Security** — TLSv1.3 · DMARC

## Plans (1)

- **Mcafee Plans Pricing**

## Tags

Antivirus, Cybersecurity, Endpoint Protection, Security, Threat Intelligence

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/mcafee/). Scores are computed from the provider's own public artifacts under a published rubric.
