Trellix website screenshot

Trellix

Trellix is a cybersecurity company that delivers comprehensive, open, and native extended detection and response (XDR) platform. The company provides threat detection, investigation, and response capabilities across endpoints, networks, data, and cloud environments.

Trellix publishes 14 APIs on the APIs.io network, including ePO API, Action History API, Affected Hosts API, and 11 more. Tagged areas include Cloud Security, Cybersecurity, Endpoint Security, Threat Detection, and Threat Intelligence.

The Trellix catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Trellix’s developer surface includes authentication, developer portal, documentation, getting-started guide, support, signup flow, engineering blog, and 27 more developer resources.

64.4/100 strong ▬ flat Agent 31/100 agent aware Full breakdown ↓
scored 2026-08-05 · rubric v0.9.1
AccessEnterpriseSelf serve
27 APIs
Cloud SecurityCybersecurityEndpoint SecurityThreat DetectionThreat IntelligenceXDR

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-05 · rubric v0.9.1
Composite quality — 64.4/100 · strong
Contract Quality 17.8 / 25
Developer Ergonomics 10.0 / 20
Commercial Clarity 12.6 / 20
Operational Transparency 7.5 / 13
Governance 8.3 / 12
Discoverability 8.2 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/trellix: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 27

Individual APIs this provider publishes, each with its own machine-readable definition.

Trellix ePO API

McAfee ePolicy Orchestrator (ePO) REST API for centralized security management, policy enforcement, and reporting across the enterprise.

Trellix ePO SaaS API

The Trellix ePO SaaS API provides cloud-based access to ePolicy Orchestrator management capabilities. It enables programmatic control of devices, events, tags, queries, and resp...

Trellix Insights API

API for accessing threat intelligence, security analytics, and insights from the Trellix threat research platform. Provides investigation of indicators of compromise, campaign t...

Trellix EDR API

Endpoint Detection and Response API for advanced threat hunting, investigation, and automated response capabilities. The EDR API supports querying threat data, searching devices...

Trellix Data Exchange Layer (DXL) API

Messaging fabric API that enables real-time communication between security tools and data sharing across the security ecosystem. OpenDXL provides client libraries in Python, Jav...

Trellix Endpoint Security (HX) API

REST API for the Trellix Endpoint Security (HX) platform, formerly FireEye HX. Provides programmatic access to endpoint information, acquisitions, alerts, indicators, conditions...

Trellix Data Loss Prevention (DLP) API

REST API for Trellix Data Loss Prevention Endpoint that enables programmatic management of DLP policies, retrieval and analysis of data loss incidents, and integration with clou...

Trellix Email Security Cloud API

RESTful API for Trellix Email Security Cloud (formerly FireEye ETP) providing custom integration capabilities for advanced threat detection in email. Supports APIs for querying ...

Trellix Helix API

API for the Trellix Helix security operations platform that integrates security controls from Trellix and over 500 third-party sources to create multi-vector threat detections a...

Trellix Intelligent Sandbox API

REST API for Trellix Intelligent Sandbox (formerly Advanced Threat Defense) that enables automated submission and analysis of files and URLs in a sandboxed environment. Supports...

Trellix Threat Intelligence Exchange (TIE) API

API for Trellix Threat Intelligence Exchange which acts as a reputation broker enabling real-time sharing of threat intelligence from global and local sources across the securit...

Trellix IOC (Indicators of Compromise) API

REST API interface for managing indicators of compromise within the Trellix security platform. Enables uploading, querying, and managing IOCs including file hashes, IP addresses...

Trellix Detection as a Service API

API-driven malware detection service that leverages the Trellix Multi-Vector Virtual Execution (MVX) engine and multiple dynamic machine learning, AI, and correlation engines to...

Trellix API Explorer

Interactive API documentation and testing tool for Trellix security products formerly under the FireEye brand. Provides a web-based interface for exploring and testing API endpo...

Trellix Action History API

Retrieve the history of response actions executed on managed endpoints through the EDR platform.

Trellix Affected Hosts API

Query detection counts, severity rankings, and first detection timestamps for systems affected by threats.

Trellix Alerts API

Access discrete detection alerts containing process, user, and host context with trace identifiers and severity scores.

Trellix Detections API

Retrieve individual detection events with process names, command lines, hash identifiers, and domain information.

Trellix Devices API

Manage and query endpoint devices registered in ePO SaaS, including device attributes, agent status, and system information.

Trellix Epo API

The Epo API from Trellix — 2 operation(s) for epo.

Trellix Events API

Retrieve threat events and security incidents detected across managed endpoints. Events have a 3-day retention period.

Trellix Groups API

Manage device groups and organizational hierarchy within the ePO SaaS console.

Trellix Queries API

Execute and manage saved queries against the ePO SaaS data store for reporting and analysis.

Trellix Reactions API

Execute response actions on endpoints such as killing processes, quarantining files, or isolating hosts.

Trellix Response Actions API

Trigger automated response actions on managed endpoints, including policy enforcement and remediation tasks.

Trellix Searches API

Execute real-time searches across managed endpoints to hunt for indicators of compromise and suspicious activity.

Trellix Threats API

Query aggregated threat intelligence including threat names, severity rankings, SHA256 hashes, and MITRE ATT&CK mappings.

Scroll for all 27

Postman Collections 13

Ready-to-run Postman collections for exercising this provider's APIs.

Scroll for all 13

Open Collections 2

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Trellix EDR API

OPEN COLLECTION

Trellix ePO SaaS API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Trellix Plans Pricing

1 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Trellix Rate Limits

1 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Trellix Context

22 classes · 8 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Trellix API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Trellix API Rules

17 rules · 3 errors 12 warnings 2 info

SPECTRAL

JSON Schema 18

Standalone JSON Schema definitions for this provider's data models.

ActionHistoryEntry

7 properties

JSON SCHEMA

AffectedHost

8 properties

JSON SCHEMA

Alert

12 properties

JSON SCHEMA

Detection

10 properties

JSON SCHEMA

Trellix Device

11 properties

JSON SCHEMA

Event

3 properties

JSON SCHEMA

Group

5 properties

JSON SCHEMA

PaginationMeta

3 properties

JSON SCHEMA

Query

5 properties

JSON SCHEMA

Reaction

5 properties

JSON SCHEMA

ReactionCreate

3 properties

JSON SCHEMA

ResponseAction

5 properties

JSON SCHEMA

ResponseActionCreate

3 properties

JSON SCHEMA

Search

7 properties

JSON SCHEMA

SearchCreate

2 properties

JSON SCHEMA

Tag

4 properties

JSON SCHEMA

TagCreate

3 properties

JSON SCHEMA

Trellix Threat

11 properties

JSON SCHEMA

Scroll for all 18

JSON Structure 2

JSON Structure definitions describing this provider's data shapes.

Trellix Structure

0 properties

JSON STRUCTURE

Trellix Threat Structure

0 properties

JSON STRUCTURE

Examples 1

Example request and response payloads for these APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Trellix Authentication

http · 1 scheme

SECURITY

Trellix Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Trellix Agentic Access

21 operations · 6 acting

21 operations · 6 acting

AGENTIC

Resources

Get Started 5

Portal, sign-up, and the first successful call

Documentation 5

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 4

Pagination, idempotency, versioning, errors, and events

Build 6

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
name: Trellix
description: Trellix is a cybersecurity company that delivers comprehensive, open, and native extended detection and response
  (XDR) platform. The company provides threat detection, investigation, and response capabilities across endpoints, networks,
  data, and cloud environments.
accessModel:
  pricing: enterprise
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Enterprise · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://www.trellix.com/favicon.ico
url: https://www.trellix.com
created: '2024'
modified: '2026-05-19'
tags:
- Cloud Security
- Cybersecurity
- Endpoint Security
- Threat Detection
- Threat Intelligence
- XDR
apis:
- name: Trellix ePO API
  description: McAfee ePolicy Orchestrator (ePO) REST API for centralized security management, policy enforcement, and reporting
    across the enterprise.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Endpoint Management
  - Enterprise Security
  - Policy Orchestration
  - Security Management
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/epolicy-orchestrator
  - type: Authentication
    url: https://developer.manage.trellix.com/mvision/docs/umam
  - type: GettingStarted
    url: https://developer.manage.trellix.com/mvision/docs/uma
  - type: APIReference
    url: https://developer.manage.trellix.com/mvision/apis/v2-devices
  contact:
  - FN: Trellix Support
    url: https://www.trellix.com/support/
- name: Trellix ePO SaaS API
  description: The Trellix ePO SaaS API provides cloud-based access to ePolicy Orchestrator management capabilities. It enables
    programmatic control of devices, events, tags, queries, and response actions through the Trellix cloud management platform.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator-saas-product-guide
  baseURL: https://api.manage.trellix.com
  tags:
  - Cloud Management
  - Endpoint Management
  - SaaS
  - Security Management
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/epolicy-orchestrator-saas-product-guide
  - type: Authentication
    url: https://developer.manage.trellix.com/mvision/docs/umam
  - type: GettingStarted
    url: https://developer.manage.trellix.com/mvision/docs/uma
- name: Trellix Insights API
  description: API for accessing threat intelligence, security analytics, and insights from the Trellix threat research platform.
    Provides investigation of indicators of compromise, campaign tracking, and prioritized threat intelligence for security
    operations.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/trellix-insights-product-guide
  baseURL: https://api.manage.trellix.com
  tags:
  - Analytics
  - Security Insights
  - Threat Intelligence
  - Threat Research
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/trellix-insights-product-guide
  - type: APIReference
    url: https://docs.trellix.com/bundle/trellix-insights-product-guide/page/UUID-e5e4730b-ac74-d923-f691-168ea880e3cd.html
- name: Trellix EDR API
  description: Endpoint Detection and Response API for advanced threat hunting, investigation, and automated response capabilities.
    The EDR API supports querying threat data, searching devices, retrieving action history, and executing real-time search
    and response actions across managed endpoints.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/mvision-endpoint-detection-and-response-product-guide
  baseURL: https://api.manage.trellix.com
  tags:
  - Endpoint Detection
  - Forensics
  - Incident Response
  - Threat Hunting
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/mvision-endpoint-detection-and-response-product-guide
  - type: APIReference
    url: https://docs.trellix.com/bundle/mvision-endpoint-detection-and-response-product-guide/page/UUID-d4602e2b-5adc-bdb4-c8cf-163997d5cd6e.html
  - type: Authentication
    url: https://developer.manage.trellix.com/mvision/docs/umam
  - type: GitHubRepository
    url: https://github.com/trellix-enterprise/EDR-Integration-Scripts
- name: Trellix Data Exchange Layer (DXL) API
  description: Messaging fabric API that enables real-time communication between security tools and data sharing across the
    security ecosystem. OpenDXL provides client libraries in Python, JavaScript, and Java for integrating applications with
    the DXL message bus, enabling automated threat response and security tool orchestration.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://opendxl.github.io/
  baseURL: https://dxl.trellix.com
  tags:
  - Automation
  - Data Exchange
  - Integration
  - Messaging
  properties:
  - type: Documentation
    url: https://opendxl.github.io/
  - type: GitHubOrganization
    url: https://github.com/opendxl
  - type: SDKs
    url: https://opendxl.github.io/opendxl-client-python/
- name: Trellix Endpoint Security (HX) API
  description: REST API for the Trellix Endpoint Security (HX) platform, formerly FireEye HX. Provides programmatic access
    to endpoint information, acquisitions, alerts, indicators, conditions, and containment operations. Uses role-based access
    control with api_admin and api_analyst user roles.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/hx_api_2020-2/page/UUID-973bb2b7-aeba-2ea1-afb9-7d20b136d3f6.html
  baseURL: https://{hx-appliance}/hx/api/v3
  tags:
  - Containment
  - Endpoint Security
  - Incident Response
  - Threat Detection
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/hx_api_2020-2/page/UUID-973bb2b7-aeba-2ea1-afb9-7d20b136d3f6.html
  - type: APIReference
    url: https://docs.trellix.com/bundle/hx_api_2020-2/page/UUID-33b4d7e3-a428-5137-d583-d40753483fbe.html
  - type: GettingStarted
    url: https://docs.trellix.com/bundle/api_1-0-0_ug/page/api-documentation-module-home-page/using-the-endpoint-security-apis.html
- name: Trellix Data Loss Prevention (DLP) API
  description: REST API for Trellix Data Loss Prevention Endpoint that enables programmatic management of DLP policies, retrieval
    and analysis of data loss incidents, and integration with cloud gateways. Supports applying DLP policies, querying incident
    IDs for data-in-use and data-in-motion events, and retrieving incident details.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/data-loss-prevention-landing-page/page/UUID-d99a9913-80b8-d1b9-e030-9186ad9648ff.html
  baseURL: https://{epo-server}:8443
  tags:
  - Compliance
  - Data Loss Prevention
  - Data Protection
  - Incident Management
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/data-loss-prevention-landing-page/page/UUID-d99a9913-80b8-d1b9-e030-9186ad9648ff.html
  - type: APIReference
    url: https://docs.trellix.com/bundle/data-loss-prevention-11.11.x-product-guide/page/UUID-fde8c193-c95f-0f3c-2ccf-926691ea31d8.html
- name: Trellix Email Security Cloud API
  description: RESTful API for Trellix Email Security Cloud (formerly FireEye ETP) providing custom integration capabilities
    for advanced threat detection in email. Supports APIs for querying advanced threats, email trace, and quarantine management
    operations.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/fe-email-cloud-landing/page/UUID-aa9b8905-c585-0327-7f24-f66ea402d3b6.html
  baseURL: https://etp.us.fireeye.com/api/v1
  tags:
  - Cloud Security
  - Email Security
  - Quarantine
  - Threat Detection
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/fe-email-cloud-landing/page/UUID-aa9b8905-c585-0327-7f24-f66ea402d3b6.html
  - type: APIReference
    url: https://docs.trellix.com/bundle/etp_api/page/UUID-30726aa3-e420-6f62-6b84-6ad0bdace483.html
- name: Trellix Helix API
  description: API for the Trellix Helix security operations platform that integrates security controls from Trellix and over
    500 third-party sources to create multi-vector threat detections and AI-guided responses. The Helix API supports querying
    alerts, managing cases, searching events, and automating security operations workflows.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://www.trellix.com/products/helix/
  baseURL: https://apps.fireeye.com/helix/api/v3
  tags:
  - Security Operations
  - SIEM
  - SOAR
  - Threat Detection
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/helix_pg/page/UUID-889d9be0-0cc8-3ab3-cdb3-9aab24208509.html
  - type: APIReference
    url: https://docs.trellix.com/bundle/helix_pg/page/UUID-1fa29a61-f2d5-601e-dd27-e72f93627e59.html
- name: Trellix Intelligent Sandbox API
  description: REST API for Trellix Intelligent Sandbox (formerly Advanced Threat Defense) that enables automated submission
    and analysis of files and URLs in a sandboxed environment. Supports file submission, analysis status queries, and report
    retrieval for malware detection and threat analysis.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/trellix-intelligent-sandbox-5.0.x-api-reference-guide/page/GUID-F600CDC5-827A-4435-BD37-E0DF91810AB1.html
  baseURL: https://{sandbox-server}/php
  tags:
  - File Analysis
  - Malware Analysis
  - Sandbox
  - Threat Detection
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/trellix-intelligent-sandbox-5.0.x-api-reference-guide/page/GUID-F600CDC5-827A-4435-BD37-E0DF91810AB1.html
  - type: GitHubRepository
    url: https://github.com/trellix-opensource/intelligent-sandbox-api
- name: Trellix Threat Intelligence Exchange (TIE) API
  description: API for Trellix Threat Intelligence Exchange which acts as a reputation broker enabling real-time sharing of
    threat intelligence from global and local sources across the security ecosystem via the Data Exchange Layer. The TIE API
    allows querying file and certificate reputations, setting local reputations, and receiving reputation change notifications.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/threat-intelligence-exchange-3.0.x-product-guide
  baseURL: https://dxl.trellix.com
  tags:
  - Data Exchange
  - Malware Detection
  - Reputation
  - Threat Intelligence
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/threat-intelligence-exchange-3.0.x-product-guide
  - type: SDKs
    url: https://github.com/opendxl/opendxl-tie-client-javascript
- name: Trellix IOC (Indicators of Compromise) API
  description: REST API interface for managing indicators of compromise within the Trellix security platform. Enables uploading,
    querying, and managing IOCs including file hashes, IP addresses, domains, and email addresses for threat detection and
    investigation.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://docs.trellix.com/bundle/iocs_1-2-144_ug/page/UUID-d981cbd0-d535-dd8f-7cf8-a287bf077392.html
  baseURL: https://{hx-appliance}/hx/api/v3
  tags:
  - Indicators of Compromise
  - Security Operations
  - Threat Detection
  - Threat Intelligence
  properties:
  - type: Documentation
    url: https://docs.trellix.com/bundle/iocs_1-2-144_ug/page/UUID-d981cbd0-d535-dd8f-7cf8-a287bf077392.html
  - type: APIReference
    url: https://docs.trellix.com/bundle/iocs_1-2-144_ug/page/UUID-11acd4c1-f095-333a-c394-5bfbf0a69823.html
- name: Trellix Detection as a Service API
  description: API-driven malware detection service that leverages the Trellix Multi-Vector Virtual Execution (MVX) engine
    and multiple dynamic machine learning, AI, and correlation engines to analyze submitted files. Designed for integration
    into security operations workflows, SIEM systems, and custom web applications.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://www.trellix.com/products/detection-as-a-service/
  baseURL: https://feapi.marketplace.apps.fireeye.com
  tags:
  - Cloud Security
  - File Analysis
  - Malware Detection
  - Threat Detection
  properties:
  - type: Documentation
    url: https://developer.manage.trellix.com/mvision/docs/uma
- name: Trellix API Explorer
  description: Interactive API documentation and testing tool for Trellix security products formerly under the FireEye brand.
    Provides a web-based interface for exploring and testing API endpoints across multiple Trellix product lines with regional
    endpoint support for US, EU, and AP data centers.
  image: https://www.trellix.com/favicon.ico
  humanURL: https://api-docs.us.fireeye.com/
  baseURL: https://api-docs.us.fireeye.com
  tags:
  - API Explorer
  - Developer Tools
  - Documentation
  - Testing
  properties:
  - type: Documentation
    url: https://api-docs.us.fireeye.com/
- aid: trellix:trellix-action-history-api
  name: Trellix Action History API
  description: Retrieve the history of response actions executed on managed endpoints through the EDR platform.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Action History
  properties:
  - type: OpenAPI
    url: openapi/trellix-action-history-api-openapi.yml
- aid: trellix:trellix-affected-hosts-api
  name: Trellix Affected Hosts API
  description: Query detection counts, severity rankings, and first detection timestamps for systems affected by threats.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Affected Hosts
  properties:
  - type: OpenAPI
    url: openapi/trellix-affected-hosts-api-openapi.yml
- aid: trellix:trellix-alerts-api
  name: Trellix Alerts API
  description: Access discrete detection alerts containing process, user, and host context with trace identifiers and severity
    scores.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Alerts
  properties:
  - type: OpenAPI
    url: openapi/trellix-alerts-api-openapi.yml
- aid: trellix:trellix-detections-api
  name: Trellix Detections API
  description: Retrieve individual detection events with process names, command lines, hash identifiers, and domain information.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Detections
  properties:
  - type: OpenAPI
    url: openapi/trellix-detections-api-openapi.yml
- aid: trellix:trellix-devices-api
  name: Trellix Devices API
  description: Manage and query endpoint devices registered in ePO SaaS, including device attributes, agent status, and system
    information.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Devices
  properties:
  - type: OpenAPI
    url: openapi/trellix-devices-api-openapi.yml
- aid: trellix:trellix-epo-api
  name: Trellix Epo API
  description: The Epo API from Trellix — 2 operation(s) for epo.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Epo
  properties:
  - type: OpenAPI
    url: openapi/trellix-epo-api-openapi.yml
- aid: trellix:trellix-events-api
  name: Trellix Events API
  description: Retrieve threat events and security incidents detected across managed endpoints. Events have a 3-day retention
    period.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Events
  properties:
  - type: OpenAPI
    url: openapi/trellix-events-api-openapi.yml
- aid: trellix:trellix-groups-api
  name: Trellix Groups API
  description: Manage device groups and organizational hierarchy within the ePO SaaS console.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Groups
  properties:
  - type: OpenAPI
    url: openapi/trellix-groups-api-openapi.yml
- aid: trellix:trellix-queries-api
  name: Trellix Queries API
  description: Execute and manage saved queries against the ePO SaaS data store for reporting and analysis.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Queries
  properties:
  - type: OpenAPI
    url: openapi/trellix-queries-api-openapi.yml
- aid: trellix:trellix-reactions-api
  name: Trellix Reactions API
  description: Execute response actions on endpoints such as killing processes, quarantining files, or isolating hosts.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Reactions
  properties:
  - type: OpenAPI
    url: openapi/trellix-reactions-api-openapi.yml
- aid: trellix:trellix-response-actions-api
  name: Trellix Response Actions API
  description: Trigger automated response actions on managed endpoints, including policy enforcement and remediation tasks.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Response Actions
  properties:
  - type: OpenAPI
    url: openapi/trellix-response-actions-api-openapi.yml
- aid: trellix:trellix-searches-api
  name: Trellix Searches API
  description: Execute real-time searches across managed endpoints to hunt for indicators of compromise and suspicious activity.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Searches
  properties:
  - type: OpenAPI
    url: openapi/trellix-searches-api-openapi.yml
- aid: trellix:trellix-threats-api
  name: Trellix Threats API
  description: Query aggregated threat intelligence including threat names, severity rankings, SHA256 hashes, and MITRE ATT&CK
    mappings.
  humanURL: https://docs.trellix.com/bundle/epolicy-orchestrator
  baseURL: https://your-epo-server:8443/remote
  tags:
  - Threats
  properties:
  - type: OpenAPI
    url: openapi/trellix-threats-api-openapi.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
  url: https://apievangelist.com
common:
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/trellix/overview
- type: AgenticAccess
  url: agentic-access/trellix-agentic-access.yml
- type: DomainSecurity
  url: security/trellix-domain-security.yml
- type: Authentication
  url: authentication/trellix-authentication.yml
- type: LinkedIn
  url: https://www.linkedin.com/company/trellixsecurity
- type: Portal
  url: https://www.trellix.com/
- type: DeveloperPortal
  url: https://developer.manage.trellix.com/
- type: Documentation
  url: https://docs.trellix.com/
- type: Authentication
  url: https://developer.manage.trellix.com/mvision/docs/umam
- type: GettingStarted
  url: https://developer.manage.trellix.com/mvision/docs/uma
- type: Support
  url: https://www.trellix.com/support/
- type: Login
  url: https://sso.trellix.com/
- type: Signup
  url: https://developer.manage.trellix.com/
- type: Community
  url: https://communitym.trellix.com/
- type: StatusPage
  url: https://status.trellix.com/
- type: Blog
  url: https://www.trellix.com/blogs/
- type: PrivacyPolicy
  url: https://www.trellix.com/en-us/about/legal/privacy.html
- type: TermsOfService
  url: https://www.trellix.com/en-us/about/legal/terms-of-use.html
- type: GitHubOrganization
  url: https://github.com/trellix-enterprise
- type: GitHubOrganization
  url: https://github.com/opendxl
- type: GitHubOrganization
  url: https://github.com/trellix-opensource
- type: GitHubOrganization
  url: https://github.com/advanced-threat-research
- type: Website
  url: https://www.trellix.com/
- type: Knowledge Base
  url: https://kcm.trellix.com/
- type: PostmanCollection
  url: https://www.postman.com/bmarandel/trellix-api-gateway/documentation/d3e3gan/trellix-api-gateway
- type: ReleaseNotes
  url: https://docs.trellix.com/bundle/trellix-developer-portal-and-marketplace-release-notes
- type: OpenAPI
  url: openapi/trellix-edr-openapi.yml
- type: OpenAPI
  url: openapi/trellix-epo-saas-openapi.yml
- type: JSONSchema
  url: json-schema/trellix-threat-schema.json
- type: JSONSchema
  url: json-schema/trellix-device-schema.json
- type: JSONStructure
  url: json-structure/trellix-threat-structure.json
- type: JSONLD
  url: json-ld/trellix-context.jsonld
- type: SpectralRules
  url: rules/trellix-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/trellix-vocabulary.yml