# Trellix

**Canonical:** https://apis.io/providers/trellix/  
**Website:** https://www.trellix.com/  
**APIs profiled:** 27

Trellix is a cybersecurity company that delivers comprehensive, open, and native extended detection and response (XDR) platform. The company provides threat detection, investigation, and response capabilities across endpoints, networks, data, and cloud environments.

## Kin Score — 43.5 / 100 (developing)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 43.5).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 62.6 |
| Governance | 17.4 |
| Contract Governance | 17.4 |
| Operational Transparency | 39.5 |
| Developer Ergonomics | 21.4 |
| Commercial Clarity | 40.8 |
| Access Clarity | 40.8 |

## Agent readiness — 19.8 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Enterprise · Self-serve signup — onboarding: self-serve, pricing: enterprise, trial: no (confidence: high).

## APIs (27)

- **Trellix ePO API** — McAfee ePolicy Orchestrator (ePO) REST API for centralized security management, policy enforcement, and reporting across the enterprise.
- **Trellix ePO SaaS API** — The Trellix ePO SaaS API provides cloud-based access to ePolicy Orchestrator management capabilities. It enables programmatic control of devices, events, tags, queries, and resp...
- **Trellix Insights API** — API for accessing threat intelligence, security analytics, and insights from the Trellix threat research platform. Provides investigation of indicators of compromise, campaign t...
- **Trellix EDR API** — Endpoint Detection and Response API for advanced threat hunting, investigation, and automated response capabilities. The EDR API supports querying threat data, searching devices...
- **Trellix Data Exchange Layer (DXL) API** — Messaging fabric API that enables real-time communication between security tools and data sharing across the security ecosystem. OpenDXL provides client libraries in Python, Jav...
- **Trellix Endpoint Security (HX) API** — REST API for the Trellix Endpoint Security (HX) platform, formerly FireEye HX. Provides programmatic access to endpoint information, acquisitions, alerts, indicators, conditions...
- **Trellix Data Loss Prevention (DLP) API** — REST API for Trellix Data Loss Prevention Endpoint that enables programmatic management of DLP policies, retrieval and analysis of data loss incidents, and integration with clou...
- **Trellix Email Security Cloud API** — RESTful API for Trellix Email Security Cloud (formerly FireEye ETP) providing custom integration capabilities for advanced threat detection in email. Supports APIs for querying ...
- **Trellix Helix API** — API for the Trellix Helix security operations platform that integrates security controls from Trellix and over 500 third-party sources to create multi-vector threat detections a...
- **Trellix Intelligent Sandbox API** — REST API for Trellix Intelligent Sandbox (formerly Advanced Threat Defense) that enables automated submission and analysis of files and URLs in a sandboxed environment. Supports...
- **Trellix Threat Intelligence Exchange (TIE) API** — API for Trellix Threat Intelligence Exchange which acts as a reputation broker enabling real-time sharing of threat intelligence from global and local sources across the securit...
- **Trellix IOC (Indicators of Compromise) API** — REST API interface for managing indicators of compromise within the Trellix security platform. Enables uploading, querying, and managing IOCs including file hashes, IP addresses...
- **Trellix Detection as a Service API** — API-driven malware detection service that leverages the Trellix Multi-Vector Virtual Execution (MVX) engine and multiple dynamic machine learning, AI, and correlation engines to...
- **Trellix API Explorer** — Interactive API documentation and testing tool for Trellix security products formerly under the FireEye brand. Provides a web-based interface for exploring and testing API endpo...
- **Trellix Action History API** — Retrieve the history of response actions executed on managed endpoints through the EDR platform.
- **Trellix Affected Hosts API** — Query detection counts, severity rankings, and first detection timestamps for systems affected by threats.
- **Trellix Alerts API** — Access discrete detection alerts containing process, user, and host context with trace identifiers and severity scores.
- **Trellix Detections API** — Retrieve individual detection events with process names, command lines, hash identifiers, and domain information.
- **Trellix Devices API** — Manage and query endpoint devices registered in ePO SaaS, including device attributes, agent status, and system information.
- **Trellix Epo API** — The Epo API from Trellix — 2 operation(s) for epo.
- **Trellix Events API** — Retrieve threat events and security incidents detected across managed endpoints. Events have a 3-day retention period.
- **Trellix Groups API** — Manage device groups and organizational hierarchy within the ePO SaaS console.
- **Trellix Queries API** — Execute and manage saved queries against the ePO SaaS data store for reporting and analysis.
- **Trellix Reactions API** — Execute response actions on endpoints such as killing processes, quarantining files, or isolating hosts.
- **Trellix Response Actions API** — Trigger automated response actions on managed endpoints, including policy enforcement and remediation tasks.
- **Trellix Searches API** — Execute real-time searches across managed endpoints to hunt for indicators of compromise and suspicious activity.
- **Trellix Threats API** — Query aggregated threat intelligence including threat names, severity rankings, SHA256 hashes, and MITRE ATT&CK mappings.

## Agentic access (1)

- **Trellix Agentic Access** — 21 operations · 6 acting

## Security (2)

- **Trellix Authentication** — http · 1 scheme
- **Trellix Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Trellix Plans Pricing**

## Tags

Cloud Security, Cybersecurity, Endpoint Security, Threat Detection, Threat Intelligence, XDR

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/trellix/). Scores are computed from the provider's own public artifacts under a published rubric.
