McAfee (Trellix) · Schema
ThreatEvent
AntivirusCybersecurityEndpoint ProtectionSecurityThreat Intelligence
Properties
| Name | Type | Description |
|---|---|---|
| AutoID | integer | Auto-incremented event ID |
| DetectedUTC | string | Detection time in UTC |
| ReceivedUTC | string | Time the event was received by ePO |
| ThreatName | string | Name of the detected threat |
| ThreatType | string | Type of threat (e.g., virus, trojan, PUP) |
| ThreatSeverity | integer | Severity level of the threat |
| ThreatActionTaken | string | Action taken on the threat (e.g., cleaned, deleted, quarantined) |
| SourceHostName | string | Hostname of the system where the threat was detected |
| SourceIPV4 | string | IPv4 address of the source system |
| TargetFileName | string | File path of the affected file |
| AnalyzerName | string | Name of the product that detected the threat |
| AnalyzerVersion | string | Version of the detecting product |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "#/components/schemas/ThreatEvent",
"title": "ThreatEvent",
"type": "object",
"properties": {
"AutoID": {
"type": "integer",
"description": "Auto-incremented event ID"
},
"DetectedUTC": {
"type": "string",
"format": "date-time",
"description": "Detection time in UTC"
},
"ReceivedUTC": {
"type": "string",
"format": "date-time",
"description": "Time the event was received by ePO"
},
"ThreatName": {
"type": "string",
"description": "Name of the detected threat"
},
"ThreatType": {
"type": "string",
"description": "Type of threat (e.g., virus, trojan, PUP)"
},
"ThreatSeverity": {
"type": "integer",
"description": "Severity level of the threat"
},
"ThreatActionTaken": {
"type": "string",
"description": "Action taken on the threat (e.g., cleaned, deleted, quarantined)"
},
"SourceHostName": {
"type": "string",
"description": "Hostname of the system where the threat was detected"
},
"SourceIPV4": {
"type": "string",
"description": "IPv4 address of the source system"
},
"TargetFileName": {
"type": "string",
"description": "File path of the affected file"
},
"AnalyzerName": {
"type": "string",
"description": "Name of the product that detected the threat"
},
"AnalyzerVersion": {
"type": "string",
"description": "Version of the detecting product"
}
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/mcafee-threatevent"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.