aid: malwarebytes name: Malwarebytes description: 'Malwarebytes is an American anti-malware and endpoint security company founded in 2008 and headquartered in Santa Clara, California. It sells consumer protection under the Malwarebytes brand (Premium Security, Mobile Security, Browser Guard, Privacy VPN, Identity Theft Protection, Personal Data Remover, AdwCleaner) and business endpoint security under the ThreatDown brand, powered by Malwarebytes. The programmable surface is ThreatDown: two large OAuth2-protected REST APIs — the Nebula API for direct-tenant endpoint security management and the OneView API for multi-tenant MSP management of sites and subscriptions — both served from api.threatdown.com and documented with public OpenAPI 3.0 definitions covering endpoints, detections, jobs, policies, quarantine, vulnerability and patch management, EDR/XDR, DNS filtering, device control, email protection and webhooks.' url: https://raw.githubusercontent.com/api-evangelist/malwarebytes/refs/heads/main/apis.yml image: https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/01/Malwarebytes-wordmark-horiz-Brand-Blue.png?w=810 x-type: company x-source: harvest:secondary-market specificationVersion: '0.20' created: '2026-08-04' modified: '2026-08-04' tags: - Company - Security - Cybersecurity - Endpoint Security - Anti-Malware - Endpoint Detection and Response - Threat Detection - Vulnerability Management - Patch Management - Managed Service Providers - DNS Filtering - Webhooks maintainers: - FN: Kin Lane email: kin@apievangelist.com - FN: APIs.json email: info@apis.io apis: - aid: malwarebytes:malwarebytes-account-api name: Malwarebytes Account API description: The Account API from Malwarebytes — 2 operation(s) for account. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Account properties: - type: OpenAPI url: openapi/malwarebytes-account-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-ai-detection-response-api name: Malwarebytes AI Detection & Response API description: >- Manage governance rules and settings for AI Detection & Response (AIDR). Use these APIs to create per-tool authorization rules that determine whether specific AI tools are authorized, unauthorized, or pending review. Configure account-level defaults as a fallback when no matching rule exists. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - AI Detection & Response properties: - type: OpenAPI url: openapi/malwarebytes-ai-detection-response-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-app-block-api name: Malwarebytes App Block API description: The App Block API from Malwarebytes — 20 operation(s) for app block. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - App Block properties: - type: OpenAPI url: openapi/malwarebytes-app-block-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-assets-api name: Malwarebytes Assets API description: The Assets API from Malwarebytes — 8 operation(s) for assets. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Assets properties: - type: OpenAPI url: openapi/malwarebytes-assets-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-authentication-api name: Malwarebytes Authentication API description: The Authentication API from Malwarebytes — 2 operation(s) for authentication. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Authentication properties: - type: OpenAPI url: openapi/malwarebytes-authentication-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-case-management-api name: Malwarebytes Case Management API description: >- The Case Management APIs are for managing Managed Detection and Response (MDR) and Managed Threat Hunting (MTH) cases. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Case Management properties: - type: OpenAPI url: openapi/malwarebytes-case-management-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-content-filtering-api name: Malwarebytes Content Filtering API description: >- The Content Filtering APIs are for managing content filtering rules used by the DNS module. These rules control what domains or categories of domains your endpoints have access to. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Content Filtering properties: - type: OpenAPI url: openapi/malwarebytes-content-filtering-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-copilot-api name: Malwarebytes Copilot API description: The Copilot API from Malwarebytes — 10 operation(s) for copilot. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Copilot properties: - type: OpenAPI url: openapi/malwarebytes-copilot-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-detections-api name: Malwarebytes Detections API description: "Detections contain information on threats such as malware, ransomware, and malicious URLs\ \ found across your account. \n\nUse the detection APIs to export detection data and retrieve details\ \ about a specific detection." humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Detections properties: - type: OpenAPI url: openapi/malwarebytes-detections-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-device-control-api name: Malwarebytes Device Control API description: >- The Device Control feature manages access to USB storage drives. Activity is logged every time a USB device is blocked or restricted to read-only. Use the Device Control APIs to export device control activity, obtain information about a specific device control event, search for device control events, and view device control activity grouped by a selected parameter. If your endpoints are running Endpoint Agent version 2.0.0.81 or newer, you can utilize the APIs that manage the Allowlist, or exclusions, for Device Control. The Allowlist provides the ability to override policy controls and prevent certain USB devices from being blocked by Device Control. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Device Control properties: - type: OpenAPI url: openapi/malwarebytes-device-control-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-dns-api name: Malwarebytes DNS API description: The DNS API from Malwarebytes — 4 operation(s) for dns. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - DNS properties: - type: OpenAPI url: openapi/malwarebytes-dns-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-dns-logs-api name: Malwarebytes DNS Logs API description: >- The DNS Filtering module limits the number of domain-based threats in your environment by allowing and blocking access across the network. Each time this occurs, a record is generated. Use these APIs to export the DNS activity and search through the logs. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - DNS Logs properties: - type: OpenAPI url: openapi/malwarebytes-dns-logs-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-drive-encryption-api name: Malwarebytes Drive Encryption API description: The Drive Encryption API from Malwarebytes — 5 operation(s) for drive encryption. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Drive Encryption properties: - type: OpenAPI url: openapi/malwarebytes-drive-encryption-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-email-protection-api name: Malwarebytes Email Protection API description: The Email Protection API from Malwarebytes — 79 operation(s) for email protection. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Email Protection properties: - type: OpenAPI url: openapi/malwarebytes-email-protection-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-endpoints-api name: Malwarebytes Endpoints API description: >- ## Endpoints Introduction An Endpoint is a device which has the ThreatDown Endpoint Agent installed. Currently, there are available Endpoint Agents for Windows, macOS, and Linux. Refer to the installation guide for more information on registering a new Endpoint. Using the Endpoint API, you can search your registered endpoints and retrieve their last known status. The API allows you to perform advanced queries and offers grouping capabilities so that you can perform deep analysis of your company's devices and the found threats, such as Detections or Suspicious Activities. You can scan, isolate, remediate, and reboot your endpoints remotely through the Job APIs. ## How to deploy an endpoint agent **Endpoint software can be installed in the following ways**: - Active Directory (AD) Group Policy - System Center Configuration Manager (SCCM) - Third-party deployment tools - Manually on the endpoints - Discovery & Deployment Tool Once the installation is complete, the endpoints will be displayed in the console. You can retrieve installers for your account through the `Installers` APIs. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Endpoints properties: - type: OpenAPI url: openapi/malwarebytes-endpoints-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-events-api name: Malwarebytes Events API description: >- An event is a general term for a threat that has occurred, remediation or other action taken on a threat, and other endpoint-related activity. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Events properties: - type: OpenAPI url: openapi/malwarebytes-events-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-exclusions-api name: Malwarebytes Exclusions API description: >- Exclusions allow you to prevent trusted applications, websites, and services from being detected by our security engine. This means they won't be scanned or blocked. Use these APIs to manage the exclusions across your account. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Exclusions properties: - type: OpenAPI url: openapi/malwarebytes-exclusions-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-firewall-management-api name: Malwarebytes Firewall Management API description: The Firewall Management API from Malwarebytes — 20 operation(s) for firewall management. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Firewall Management properties: - type: OpenAPI url: openapi/malwarebytes-firewall-management-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-flight-recorder-api name: Malwarebytes Flight Recorder API description: "EDR customers can use Flight Recorder to search event data captured on endpoints that\ \ have suspicious activity monitoring enabled. \n\nUse these APIs to search through files, registry,\ \ processes, networking activity, and suspicious activities. This information can be used to investigate\ \ or identify indicators of compromise." humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Flight-recorder properties: - type: OpenAPI url: openapi/malwarebytes-flight-recorder-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-grid-api name: Malwarebytes Grid API description: >- # Grid Introduction Using the following API, you can search endpoints, detections, software inventory, vulnerabilities, rid rules, os-patches, device control events and dns logs. This API allows to perform filtering, sorting, grouping and aggregating of data by specifying constraints based on the field type. Available constraints for searching based on value type | Value Type | Constraints | | --- |----| | Simple String | equals, not_equals, contains, not_contains | | String (with enum) | equals, not_equals | | String/UUID (entity reference) | equals, not_equals | | Version | equals, not_equals | | Number | gt, lt, gte, lte | | Timestamp | start, end | | IP | ip | | Boolean | equals, not_equals | Grid API also supports compound constraints that can be constructed with the keywords **allOf**, **anyOf**, **noneOf** Example of compound constraint: ```json { "constraints": [ { "allOf": [ { "field": "agent.host_name", "operator": "contains", "value": "a" }, { "field": "machine.is_deleted", "operator": "equals", "value": false }, { "anyOf": [ { "field": "agent.os_info.os_platform", "operator": "equals", "value": "Linux" }, { "field": "agent.os_info.os_platform", "operator": "equals", "value": "MacOS" } ] } ] } ] } ``` In this example all the records that contain **a** in the ***agent.host_name***, have ***machine.is_deleted*** set to false and whose ***os_platform*** is equal to **either** ***Linux*** or ***MacOS*** will be returned. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Grid properties: - type: OpenAPI url: openapi/malwarebytes-grid-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-groups-api name: Malwarebytes Groups API description: >- Groups are used to contain and organize endpoints. Policies, which determine the software settings, and endpoints, are assigned to groups. Endpoints use the policies in the groups they are assigned to determine which software settings are enabled. Use these APIs to create, manage, and move endpoints into groups. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Groups properties: - type: OpenAPI url: openapi/malwarebytes-groups-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-ignore-rules-api name: Malwarebytes Ignore Rules API description: The Ignore Rules API from Malwarebytes — 4 operation(s) for ignore rules. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Ignore Rules properties: - type: OpenAPI url: openapi/malwarebytes-ignore-rules-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-info-api name: Malwarebytes Info API description: The Info API from Malwarebytes — 1 operation(s) for info. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Info properties: - type: OpenAPI url: openapi/malwarebytes-info-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-installation-tokens-api name: Malwarebytes Installation Tokens API description: >- Use these APIs to generate, send, and revoke installation tokens used to activate Mobile Security for Business. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Installation Tokens properties: - type: OpenAPI url: openapi/malwarebytes-installation-tokens-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-installers-api name: Malwarebytes Installers API description: The Installers APIs allow you to deploy the endpoint agent to Windows and macOS devices. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Installers properties: - type: OpenAPI url: openapi/malwarebytes-installers-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-itdr-api name: Malwarebytes ITDR API description: The ITDR API from Malwarebytes — 29 operation(s) for itdr. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - ITDR properties: - type: OpenAPI url: openapi/malwarebytes-itdr-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-jobs-api name: Malwarebytes Jobs API description: >- Jobs are tasks that are issued to endpoints. Use these APIs to manage, search, and export jobs. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Jobs properties: - type: OpenAPI url: openapi/malwarebytes-jobs-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-licensing-api name: Malwarebytes Licensing API description: The Licensing API from Malwarebytes — 1 operation(s) for licensing. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Licensing properties: - type: OpenAPI url: openapi/malwarebytes-licensing-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-mdr-api name: Malwarebytes MDR API description: The MDR API from Malwarebytes — 2 operation(s) for mdr. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - MDR properties: - type: OpenAPI url: openapi/malwarebytes-mdr-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-mxdr-api name: Malwarebytes MXDR API description: The MXDR API from Malwarebytes — 4 operation(s) for mxdr. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - MXDR properties: - type: OpenAPI url: openapi/malwarebytes-mxdr-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-notifications-api name: Malwarebytes Notifications API description: >- This API offers a powerful tool to create notification subscriptions. There are different categories of notifications, for each category different constraints and output fields can be specified. Please see the documentation below for the category descriptions. Notifications can be delivered by email or webhooks. In both cases, it's possible to choose the output fields, but the value could be different for the two methods. In the email, some values are mapped to friendly names, as in the Nebula Console. For webhooks the values are the raw level ones. Here's a list of the mapped values. | Output field | Email values | Webhook values | |--------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | role | Super Admin
Admin
Read Only User | SuperAdmin
Admin
ReadOnlyUser | | os_platform | Windows
MacOS
Linux | 1
2
3 | | category | Malware
PUP
PUM
Exploit
Ransomware
Remote
Website
Vulnerable Driver | MALWARE
PUP
PUM
AE
ARW
RID
MWAC
VULNERABLE_DRIVER | | status | Blocked
Found
Quarantined
Deleted
Restored | blocked
found
quarantined
deleted
restored | | threat_name | Malicious Website | web | | command | Scan
Restart
Restart
Remediate
Isolate
Remove isolation
Refresh Endpoint & Software Info
Check for protection updates
Check for software updates
Install software updates
Generate diagnostic logs
Delete active block rule
Upload file for analysis
Remove endpoint isolation
Isolate
Remediated endpoint
Endpoint logging level changed
Delete from quarantine
Restore from quarantine
Refresh policy
Apply OS Patch
Update Installed Software
Uninstall Software | command.threat.scan
command.service.restart
command.asset.reboot
command.threat.scan.remediate
command.edr.isolation
command.edr.unlock
command.asset.refresh
command.protection.update.now
command.machine.update.now
command.machine.plugin.updateparts
command.service.diag
command.bfp.rules.delete
command.edr.fileupload
command.edr.unlock.force
command.edr.lock
command.sequence.remediate
command.logging.level.set
command.threat.quarantine.remove
command.threat.quarantine.restore
command.policy.refresh
command.asset.patch
command.asset.updatesoftware
command.asset.uninstallsoftware | humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Notifications properties: - type: OpenAPI url: openapi/malwarebytes-notifications-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-os-patches-api name: Malwarebytes OS Patches API description: The OS Patches API from Malwarebytes — 8 operation(s) for os patches. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - OS Patches properties: - type: OpenAPI url: openapi/malwarebytes-os-patches-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-policies-api name: Malwarebytes Policies API description: >- A policy is a set of configurations that determine how the endpoint agent monitors your endpoints, such as protection and scan settings. Once a policy has been created, it needs to be assigned to a group in order to take affect. Endpoints will use the policy assigned to the group they belong to. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Policies properties: - type: OpenAPI url: openapi/malwarebytes-policies-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-preferences-api name: Malwarebytes Preferences API description: >- The Preferences APIs allow you to enable or disable all notifications of a specific type (email, webhook, slack, teams, admin app), without needing to modify or delete multiple notifications. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Preferences properties: - type: OpenAPI url: openapi/malwarebytes-preferences-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-products-api name: Malwarebytes Products API description: The Products API from Malwarebytes — 3 operation(s) for products. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Products properties: - type: OpenAPI url: openapi/malwarebytes-products-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-quarantine-api name: Malwarebytes Quarantine API description: >- When a harmful file is found on a device, it can be neutralized and placed in quarantine, preventing it from posing a threat. You can utilize the Quarantine APIs to export or check data for the existence of quarantined threats across your environments. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Quarantine properties: - type: OpenAPI url: openapi/malwarebytes-quarantine-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-remediation-api name: Malwarebytes Remediation API description: The Remediation API from Malwarebytes — 3 operation(s) for remediation. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Remediation properties: - type: OpenAPI url: openapi/malwarebytes-remediation-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-remote-intrusion-detection-api name: Malwarebytes Remote Intrusion Detection API description: >- A remote intrusion detection (RID) occurs when a brute force protection rule is triggered according to policy settings. Use these APIs to export and search for RID rules by specific parameters. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Remote Intrusion Detection properties: - type: OpenAPI url: openapi/malwarebytes-remote-intrusion-detection-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-reports-api name: Malwarebytes Reports API description: The Reports API from Malwarebytes — 8 operation(s) for reports. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Reports properties: - type: OpenAPI url: openapi/malwarebytes-reports-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-sandbox-api name: Malwarebytes Sandbox API description: The Sandbox API from Malwarebytes — 2 operation(s) for sandbox. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Sandbox properties: - type: OpenAPI url: openapi/malwarebytes-sandbox-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-schedules-api name: Malwarebytes Schedules API description: "Scheduled scans allow you to automate scans to run based on a certain schedule, rather\ \ than manually triggering a scan. \n\nUse these APIs to create and manage your scan schedules." humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Schedules properties: - type: OpenAPI url: openapi/malwarebytes-schedules-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-security-advisor-api name: Malwarebytes Security Advisor API description: The Security Advisor API from Malwarebytes — 8 operation(s) for security advisor. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Security Advisor properties: - type: OpenAPI url: openapi/malwarebytes-security-advisor-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-sites-api name: Malwarebytes Sites API description: >- Create and manage sites through APIs. Using sites APIs you can easily segment the usage and the subscriptions for your customers. In order to obtain an `account_id` for one of your sites to use for security APIs, for example [Endpoints](#tag/Endpoints) and [Installers](#tag/Installers), you need to create first a valid [Subscription](#tag/Subscriptions) for your customer. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Sites properties: - type: OpenAPI url: openapi/malwarebytes-sites-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-subscriptions-api name: Malwarebytes Subscriptions API description: >- Subscriptions allow you to enable and manage ThreatDown security services for your customers by setting terms, volume and duration. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Subscriptions properties: - type: OpenAPI url: openapi/malwarebytes-subscriptions-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-suspicious-activity-api name: Malwarebytes Suspicious Activity API description: "Suspicious Activities are found using Endpoint Detection and Response (EDR). When Suspicious\ \ Activity Monitoring is enabled via the policy, EDR watches for potentially malicious behavior on\ \ your endpoints by monitoring the processes, registry, file system, and network activity. \n\nUse\ \ these APIs to retrieve the suspicious activity records and details." humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Suspicious Activity properties: - type: OpenAPI url: openapi/malwarebytes-suspicious-activity-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-syslog-api name: Malwarebytes Syslog API description: The Syslog API from Malwarebytes — 5 operation(s) for syslog. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Syslog properties: - type: OpenAPI url: openapi/malwarebytes-syslog-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-usage-api name: Malwarebytes Usage API description: The Usage API from Malwarebytes — 9 operation(s) for usage. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Usage properties: - type: OpenAPI url: openapi/malwarebytes-usage-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-users-api name: Malwarebytes Users API description: The Users API from Malwarebytes — 5 operation(s) for users. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Users properties: - type: OpenAPI url: openapi/malwarebytes-users-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-vulnerability-assessment-api name: Malwarebytes Vulnerability Assessment API description: >- The Vulnerability Assessment API from Malwarebytes — 5 operation(s) for vulnerability assessment. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Vulnerability Assessment properties: - type: OpenAPI url: openapi/malwarebytes-vulnerability-assessment-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-vulnerability-management-api name: Malwarebytes Vulnerability Management API description: >- The Vulnerability Management API from Malwarebytes — 14 operation(s) for vulnerability management. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Vulnerability Management properties: - type: OpenAPI url: openapi/malwarebytes-vulnerability-management-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-webhooks-api name: Malwarebytes Webhooks API description: >- ## Using Webhooks ThreatDown can send webhook events that notify your application any time an event happens on your account. This is useful for transactions which are not reported synchronously to your code when performing an API call, or for security events happening in your endpoints. You can register multiple webhook handlers for any event. Any time an event occurs, we will send a `POST` request to any endpoint URLs you have registered for that event. ## When to use Webhooks For most requests, you don't need Webhooks. However, for all requests that involve asynchronous transactions, such as getting the report after a machine scan, you will need to register webhooks to get real-time notifications. The alternative to registering webhooks is performing polling, but this is deeply discouraged: besides involving more complicated code on your side, you may exceed your quota and consequently your API plan. ## How to configure Webhooks ThreatDown provides you with REST APIs for creating, retrieving, and deleting subscriptions. Currently, subscriptions can be registered only through APIs. ## Handling Webhook notifications and responding Creating a webhook handler on your server is no different from creating an API endpoint. Webhook data is sent as `JSON` data in the `POST` requests body. You can handle these requests and process data to fit your needs. To acknowledge receipt of a webhook notification, your server must return a `2xx` `HTTP` status code. All response codes outside this range, including `3xx`, will be threatened as failures and we will try sending these notifications again using exponential backoff for calculating the delay between requests. The default maximum number of retries is `5`. You can configure the `max_retries` parameter when registering a new subscription to customize this behavior. If your endpoint keeps responding with a status code outside the `2xx` range, after the default number of `maxAttempts`, we will stop sending the webhook notification. You will be responsible for reconciling your data by querying our API endpoints for potentially missed events. We recommend you design idempotent event processing because you might receive the same event more than once. ## How to verify Webhooks origin ThreatDown will sign the webhook events it sends to your server. We do so by including a signature in each event’s `X-MWB-Signature` header. This allows you to validate that the events were sent by ThreatDown and not by a third party. To protect your server from bad senders: - When you create a webhook subscription, you can supply an additional `secret_token` parameter. We will use that parameter as the signing key to generate an `HMAC` of the payload. - When you receive a webhook event, extract the request's body and compute: ``` HMAC_SHA256(secret_token, webhookPayload) ``` `secret_token` is the shared secret you configured when creating a subscription. - compare your result with the value of `X-MWB-Signature`. If those match, you can assume the notification was sent by ThreatDown. ## Supported events The supported events are: - job_status_change - detection - machine_events - threat_events - agent_events - quarantine_events - edr_events - syslog_events - exclusion_events - scheduled_events - policy_events - user_events - drive_events - cve_events - dns_events - license_events - appblock_events - endpoint_events ## Events model When ThreatDown sends a webhook notification, it wraps the notification in an envelope in order to supply additional metadata. When you receive a webhook notification, expect the following data posted in the request body: | Name | Description | Type | |------|-------------|-------| | event| The event type. | string, one of supported events type listed above | | subscription_id | Unique identifier of the subscription that matched this event | string | | account_id | Nebula account id (site) generating this event | string | | payload | An object containing the event-specific data | object | **When you receive a webhook notification, you usually switch your processing logic depending on the value of the `event` property, which represents the event type. Depending on the value, the `payload` sent will have a different model. Refer to specific models below:** ### job_status_change The `job_status_change` event is sent when a job you issue through the `Jobs` APIs, change its status. This allow you to track, for example, completed or failed scans. The payload includes the following parameters: | Name | Description | Type | |------|-------------|-------| | id | Unique identifier of the job | string | | machine_id | Unique identifier of the endpoint | string | | command | Type of command. See the `Job` API for more info | string | | issued_by | User issuing the job. This is of your interest only if you use Nebula through cloud console UI as well | string | | status | Status of the job. It can be one of `PENDING`, `STARTED`, `TIMED_OUT`, `COMPLETED`, `EXPIRED`, `FAILED`. | string | | relay_state | The relay state if you supplied one when issuing the job | string | | data | Job's settings. See the `Job` API for more info | object | | created_at | Timestamp indicating when the job was created | string | | updated_at | Timestamp indicating when the job was last updated | string | | expires_at | Timestamp indicating when the job expires | string | Example: ```json { "event":"job_status_change", "id":"cdf5f8e6-a3d0-4c33-a506-3c6cbce7bf0b", "payload":{ "machine_id":"cf1ed661-812c-4342-9dc7-c806b90072c3", "issued_by":"86d6c44f-2d0d-4225-b1f7-23f47b5d1a7b", "expires_at":"2020-08-31T11:22:31.624139429Z", "command":"command.asset.refresh", "data":"{}", "status":"CREATED", "id":"2c74da91-6e73-4867-8736-ca4b1f8effda", "updated_at":"2020-08-28T11:22:31.625274922Z", "created_at":"2020-08-28T11:22:31.624138004Z" }, "account_id":"550a20b8-6d36-4222-afbc-54d100f2e894", "subscription_id":"f43dc73b-2709-4d6f-9c79-08abc815114b" } ``` ### Detection The `detection` event is sent when ThreatDown finds one or more threats in your endpoints. The payload includes the following parameters: | Name | Description | Type | |------|-------------|-------| | id | Unique identifier of the detection | string | | machine_id | Unique identifier of the endpoint where the detection happened | string | | machine_name | Name of the endpoint where the detection happened | string | | scan_id | Unique identifier of the scan triggering the detection | string | | group_id | Unique identifier of the group to which the endpoint belongs | string | | group_name | Name of the group to which the endpoint belongs | string | | policy_id | Unique identifier of the policy assigned to the endpoint | string | | policy_name | Name of the policy assigned to the endpoint | string | | detection_id | Unique identifier of the detection as reported by the endpoint agent | string | | scanned_at | Timestamp of the scan (as received by the server) | string | | scanned_at_local | Timestamp of the scan (as reported by the endpoint agent) | string | | reported_at | Timestamp of when the detection was reported | string | | status | The status of the detection (i.e. `blocked`, `quarantined`) | string | | threat_name | Name of the threat | string | | type | Type of the threat | string | | path | Path where the threat was found | string | | category | Category of the threat | string | | ip_address | IP address of the detection, when applicable | string | | url | URL of the detection, when applicable | string | | port | Port of the detection, when applicable | string | | affected_application | Affected application, when applicable | string | | md5 | Hash of the file, when applicable | string | | process_name | Name of the process, when applicable | string | ### Policy Events #### Policy Updated ```json { "event":"policy_events", "id":"a8accc52-9f8c-4319-a2fd-975641f0ba7d", "payload":{ "severity":"AUDIT", "type":"POLICY_UPDATED", "account_id":"550a20b8-6d36-4222-afbc-54d100f2e894", "details":{ "message":"Policy Updated", "user_id":"86d6c44f-2d0d-4225-b1f7-23f47b5d1a7b", "user_email":"example@example.com", "user_name":"Mister User", "user_role":"Super Admin", "policy_id":"870de3fa-073e-468f-8d3a-a7edddeae594", "policy_name":"Aggressive Policy", "ip_address":"37.157.101.160" }, "user_id":"86d6c44f-2d0d-4225-b1f7-23f47b5d1a7b", "id":"579b0361-3e3f-4ab0-8453-84fc0f36f4e6", "created_at":"2020-08-28T10:35:32.637936426Z" }, "account_id":"550a20b8-6d36-4222-afbc-54d100f2e894", "subscription_id":"f43dc73b-2709-4d6f-9c79-08abc815114b" } ``` #### Policy Created ```json { "event":"policy_events", "id":"40662e4a-60c7-4920-b788-59af13c2c23d", "payload":{ "severity":"AUDIT", "type":"POLICY_CREATED", "account_id":"550a20b8-6d36-4222-afbc-54d100f2e894", "details":{ "message":"Policy Created", "user_id":"86d6c44f-2d0d-4225-b1f7-23f47b5d1a7b", "user_email":"example@example.com", "user_name":"Mister User", "user_role":"Super Admin", "policy_id":"b3bdce6e-a055-4246-b3a3-08237db82c9d", "policy_name":"My new Policy", "ip_address":"37.157.101.160" }, "user_id":"86d6c44f-2d0d-4225-b1f7-23f47b5d1a7b", "id":"c8e4d487-8167-4a46-8bf2-c6ee331abd1b", "created_at":"2020-08-28T11:01:49.015472172Z" }, "account_id":"550a20b8-6d36-4222-afbc-54d100f2e894", "subscription_id":"f43dc73b-2709-4d6f-9c79-08abc815114b" } ``` #### Policy Deleted ```json { "event":"policy_events", "id":"4a88d17d-3f48-452e-a871-32584d9b26cf", "payload":{ "severity":"AUDIT", "type":"POLICY_DELETED", "account_id":"550a20b8-6d36-4222-afbc-54d100f2e894", "details":{ "message":"Policy Deleted", "user_id":"86d6c44f-2d0d-4225-b1f7-23f47b5d1a7b", "user_email":"example@example.com", "user_name":"Mister User", "user_role":"Super Admin", "policy_id":"b3bdce6e-a055-4246-b3a3-08237db82c9d", "policy_name":"My new Policy", "ip_address":"37.157.101.160" }, "user_id":"86d6c44f-2d0d-4225-b1f7-23f47b5d1a7b", "id":"ef09a4a9-5c9f-481c-beb6-4757ede35dc3", "created_at":"2020-08-28T11:03:15.655679621Z" }, "account_id":"550a20b8-6d36-4222-afbc-54d100f2e894", "subscription_id":"f43dc73b-2709-4d6f-9c79-08abc815114b" } ``` ### Machine Events #### Machine registered ```json { "event":"machine_events", "id":"43c1fbfd-788a-4839-86b6-b765dfdc59d5", "payload":{ "severity":"AUDIT", "type":"MACHINE_REGISTERED", "machine_id":"0eed4a65-81a9-4cae-91e6-d8cd8dbd775a", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"My PC", "details":{ "message":"New machine registered" }, "id":"ccb84b33-2d8e-4dcb-94a0-922fc669ce4a", "created_at":"2020-08-28T11:28:05.083699037Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"5032842b-0dd1-44f4-a59e-feadc22c142d" } ``` #### Machine unregistered ```json { "event": "machine_events", "id": "3883b459-b3c8-40d5-999a-18514f1a3db0", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "payload": { "severity": "AUDIT", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "machine_id": "d5536936-941a-4e12-9e62-b11cda0f39a6", "id": "d7653c62-eb23-4163-8cfc-43ef69aea9ad", "created_at": "2022-03-30T13:11:52.925005454Z", "machine_name": "LeBlanc", "details": { "message": "machine unregistered", "timeout": false }, "type": "MACHINE_UNREGISTERED" }, "subscription_id": "3dc2a8d9-eb83-4127-afff-8fefa04f58e1" } ``` #### Machine asset info ```json { "event":"machine_events", "id":"9ecdd1c2-eb50-4baa-be81-823897ebd55e", "payload":{ "severity":"INFO", "type":"MACHINE_ASSET_INFO", "machine_id":"cf406788-edea-4938-b0db-757379d21e11", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"Asset information received" }, "id":"93ba7d7c-fcf4-43fd-9df8-8d857d6d3cd0", "created_at":"2020-08-28T11:29:08.290089258Z" } } ``` #### Machine group changed ```json { "event":"machine_events", "id":"7541515f-95f7-49d3-8913-9cb31c0aa927", "payload":{ "severity":"AUDIT", "type":"MACHINE_GROUP_CHANGED", "machine_id":"36b53eb8-45f0-46c7-a395-1aa361f09021", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"NewEndpoint moved from Default Group to New Test Group ihg21jhkee5mhmr", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "machine_id":"36b53eb8-45f0-46c7-a395-1aa361f09021", "machine_name":"NewEndpoint" }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"d9613bf2-e5c5-4bce-9bf8-e138c792bc6b", "created_at":"2020-08-28T11:30:09.249131849Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"5032842b-0dd1-44f4-a59e-feadc22c142d" } ``` #### Machine alias created ```json { "event": "machine_events", "id": "50be8bed-d2e9-4a85-9bfa-6ccecd98137e", "payload": { "severity": "INFO", "type": "MACHINE_ALIAS_CREATED", "account_id": "08496dca-fc09-4757-9573-c033ce078985", "user_id": "ea1b004e-5fd2-4fbc-bf09-5a00023704d0", "id": "659dc314-a9a0-41c5-bde4-26f293947ede", "created_at": "2021-03-01T10:19:31.732122237Z", "details": { "machine_id": "dc190e62-5424-4975-9913-1d84aec39300", "new_alias": "Endpoint name" } }, "account_id": "08496dca-fc09-4757-9573-c033ce078985", "subscription_id": "95dbb4e0-3cf2-4d81-a312-2ea6b6e7202c" } ``` #### Machine alias changed ```json { "event": "machine_events", "id": "5563e7f9-3d04-48f0-b276-531fdff0b637", "payload": { "severity": "INFO", "type": "MACHINE_ALIAS_CHANGED", "account_id": "08496dca-fc09-4757-9573-c033ce078985", "user_id": "ea1b004e-5fd2-4fbc-bf09-5a00023704d0", "id": "e38e8b75-a0e5-4794-bb05-f3ee4d5deed8", "created_at": "2021-03-01T10:19:32.14157065Z", "details": { "machine_id": "dc190e62-5424-4975-9913-1d84aec39300", "old_alias": "Endpoint name", "new_alias": "Changed endpoint name" } }, "account_id": "08496dca-fc09-4757-9573-c033ce078985", "subscription_id": "95dbb4e0-3cf2-4d81-a312-2ea6b6e7202c" } ``` #### Machine alias deleted ```json { "event": "machine_events", "id": "6b30f551-2f7a-4170-bf7b-0a1175ad10df", "payload": { "severity": "INFO", "type": "MACHINE_ALIAS_DELETED", "account_id": "08496dca-fc09-4757-9573-c033ce078985", "user_id": "ea1b004e-5fd2-4fbc-bf09-5a00023704d0", "id": "6b84564f-503d-4c60-bae7-c54f8092911b", "created_at": "2021-03-01T10:19:59.212023675Z", "details": { "machine_id": "8b18023a-d108-420d-b435-c4b0132c1a6e", "old_alias": "New endpoint name" } }, "account_id": "08496dca-fc09-4757-9573-c033ce078985", "subscription_id": "95dbb4e0-3cf2-4d81-a312-2ea6b6e7202c" } ``` ### Exclusion events #### Exclusion created ```json { "event":"exclusion_events", "id":"3a1ff38c-0246-42e6-a859-06cfa4a3d4db", "payload":{ "severity":"AUDIT", "type":"EXCLUSION_CREATED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"An Exclusion was Added", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "user_role":"Super Admin", "exclusion_type":1, "exclusion_value":"C:/testCreateExclusion/happypathihg21jhkee5l5na.txt", "global_exclusion":true }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"cfe2c8ae-6803-4c24-9f35-dfea16e902d9", "created_at":"2020-08-28T11:29:06.745315507Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"cf65f446-e88f-409e-accf-de7f371013a2" } ``` #### Exclusion updated ```json { "event":"exclusion_events", "id":"f6080c78-4d52-4593-935d-c33a85c7cd44", "payload":{ "severity":"AUDIT", "type":"EXCLUSION_UPDATED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"An Exclusion was Edited", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "user_role":"Super Admin", "exclusion_type":6, "exclusion_value":"https://www.malwarebytesihg21jhkee5lbib.com/", "global_exclusion":true }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"31243b63-9b24-4dc9-b7f3-d5e2eb210496", "created_at":"2020-08-28T11:29:14.236333504Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"cf65f446-e88f-409e-accf-de7f371013a2" } ``` #### Exclusion enabled ```json { "event":"exclusion_events", "id":"f1277c42-8fb6-4615-ba3d-b4cdb00b1e78", "payload":{ "severity":"AUDIT", "type":"EXCLUSION_ENABLED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"An Exclusion was Enabled", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "user_role":"Super Admin", "exclusion_type":6, "exclusion_value":"https://www.malwarebytesihg21jhkee5lh9c.com/", "global_exclusion":true }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"2833e903-955a-48a3-8a5d-8e05c1e8f75f", "created_at":"2020-08-28T11:29:21.690971637Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"cf65f446-e88f-409e-accf-de7f371013a2" } ``` #### Exclusion deleted ```json { "event":"exclusion_events", "id":"7ba0355e-44d9-4f5c-a5a0-2884b783c465", "payload":{ "severity":"AUDIT", "type":"EXCLUSION_DELETED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"An Exclusion was Deleted", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "user_role":"Super Admin", "exclusion_type":1, "exclusion_value":"C:/testCreateExclusion/happypathihg21jhkee5ls7x.txt", "global_exclusion":true }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"03fc92e0-4e17-4ab8-9b85-cd74fa521660", "created_at":"2020-08-28T11:29:36.655423399Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"cf65f446-e88f-409e-accf-de7f371013a2" } ``` #### Exclusion disabled ```json { "event":"exclusion_events", "id":"f54f8b33-95ba-4591-96f8-d3dbfce7264d", "payload":{ "severity":"AUDIT", "type":"EXCLUSION_DISABLED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"An Exclusion was Disabled", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "user_role":"Super Admin", "exclusion_type":6, "exclusion_value":"https://www.malwarebytesihg21jhkee5ln0w.com/", "global_exclusion":true }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"126430b1-8d09-4356-8533-524231a7aee9", "created_at":"2020-08-28T11:29:29.158586114Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"cf65f446-e88f-409e-accf-de7f371013a2" } ``` #### Exclusion bulk delete ```json { "event":"exclusion_events", "id":"1bf018a2-d93e-48a5-be17-579f1f4c8bac", "payload":{ "severity":"AUDIT", "type":"EXCLUSION_BULK_DELETED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"Bulk Exclusions were Deleted", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "user_role":"Super Admin", "exclusion_count":2 }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"a0d18178-f772-48bd-bc12-8c421b4dacc1", "created_at":"2020-08-28T11:29:45.054762536Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"cf65f446-e88f-409e-accf-de7f371013a2" } ``` ### Threat events #### Threat found ```json { "event":"threat_events", "id":"ebaef39a-40fd-4575-9fe7-2e07fd04d76f", "payload":{ "severity":"SEVERE", "type":"THREAT_FOUND", "machine_id":"b11220d5-60f5-4f25-adf1-03bebd14f2f2", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"Webhook validator", "details":{ "message":"Scan event notification" }, "id":"5984e884-8f7b-407a-892e-51bea5fa86e2", "created_at":"2020-08-28T11:29:08.496072781Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"820e96cd-0fd4-4ed7-af74-8d1896322a3a" } ``` #### Threat scan success ```json { "event":"threat_events", "id":"8eb6aabb-9a70-44d8-b767-5ceedf80893b", "payload":{ "severity":"INFO", "type":"THREAT_SCAN_SUCCESS", "machine_id":"b11220d5-60f5-4f25-adf1-03bebd14f2f2", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"Webhook validator", "details":{ "message":"Threat scan result received" }, "id":"10032184-9bfb-42b0-aab1-678b5cef859f", "created_at":"2020-08-28T11:29:08.46647437Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"820e96cd-0fd4-4ed7-af74-8d1896322a3a" } ``` #### Threat cleaned ```json { "event":"threat_events", "id":"a01f1de7-a072-4a98-b728-425706318cf8", "payload":{ "severity":"WARNING", "type":"THREAT_CLEANED", "machine_id":"06667ced-ed77-4cb5-bf17-ab45a6457ec6", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"Scan event notification", "scan_id":"4169c48d-2c03-40fd-8965-240e6d6b94f9", "scan_type":"ThreatScan", "group_name":"Default Group", "group_id":"513cf384-d53d-44b9-9813-db69a0e12d16", "policy_id":"138d00b0-05d0-4370-bd0e-d8b9db66dd0f", "policy_name":"Default Policy", "detections_found":0, "detections_cleaned":1, "scan_date":"2020-08-28T11:29:25Z", "scan_date_offset_seconds":0, "domain":"corp.mb-test.com", "ip_addresses":[ "10.100.136.53" ], "detections":[ { "id":"544064a5-b1bb-439b-b4df-2536d5949cfe", "trace_id":"4169c48d-2c03-40fd-8965-240e6d6b94f9_7fccf164-95bd-4035-a9bc-48a6dcf510c8", "scan_id":"4169c48d-2c03-40fd-8965-240e6d6b94f9", "machine_id":"06667ced-ed77-4cb5-bf17-ab45a6457ec6", "machine_name":"NewEndpoint", "group_id":"513cf384-d53d-44b9-9813-db69a0e12d16", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "detection_id":"7fccf164-95bd-4035-a9bc-48a6dcf510c8", "parent_detection_id":"", "correlation_hash":"", "scanned_at":"2020-08-28T11:29:25Z", "scanned_at_offset_seconds":0, "reported_at":"2020-08-28T11:29:26.138544Z", "cleaned_at":"0001-01-01T00:00:00Z", "status":"quarantined", "threat_name":"PUP.Optional.FooBar", "type":"WyJmaWxlIl0=", "path":"C:\\\\USERS\\\\ADMIN\\\\DESKTOP\\\\c8e09e6a-6619-44f3-9b5c-f7a15d258aeb.EXE", "category":"PUP", "is_rtp_stream_event":false, "affected_application":"", "md5":"", "process_name":"", "GroupName":"", "PolicyID":"", "PolicyName":"", "CurrentGroupID":"00000000-0000-0000-0000-000000000000" } ] }, "id":"26c47666-02a2-452c-b382-07942372d0df", "created_at":"2020-08-28T11:29:26.191675412Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"820e96cd-0fd4-4ed7-af74-8d1896322a3a" } ``` #### Threat remediate success ```json { "event":"threat_events", "id":"2cc1807e-9b33-4de0-9d50-c240839bc79a", "payload":{ "severity":"INFO", "type":"THREAT_REMEDIATE_SUCCESS", "machine_id":"a0f29eef-257a-4101-a814-074ee462c949", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"" }, "id":"155f60f3-8128-446c-b409-580fad9b247f", "created_at":"2020-08-28T11:30:31.264848509Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"820e96cd-0fd4-4ed7-af74-8d1896322a3a" } ``` #### Threat remediate failure ```json { "event":"threat_events", "id":"99def8df-e1c7-4558-9287-009d3d87949e", "payload":{ "severity":"INFO", "type":"THREAT_REMEDIATE_FAILURE", "machine_id":"40919ac8-a2cd-458d-ba49-8af92c19ca54", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"" }, "id":"22f8269a-8e1f-4b22-a29a-b7d16b6bc376", "created_at":"2020-08-28T11:30:57.669921894Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"820e96cd-0fd4-4ed7-af74-8d1896322a3a" } ``` #### Threat found ```json { "event":"threat_events", "id":"d9cd9bc7-b5c2-49b3-88ca-9682ffe015ca", "payload":{ "severity":"SEVERE", "type":"THREAT_FOUND", "machine_id":"58e326bc-de1f-49a6-926f-def0065275b3", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"Scan event notification", "scan_id":"1dad28d1-7a34-40df-96dc-4ee9781e9363", "scan_type":"ThreatScan", "group_name":"Default Group", "group_id":"513cf384-d53d-44b9-9813-db69a0e12d16", "policy_id":"138d00b0-05d0-4370-bd0e-d8b9db66dd0f", "policy_name":"Default Policy", "detections_found":1, "detections_cleaned":0, "scan_date":"2020-08-28T11:29:25Z", "scan_date_offset_seconds":0, "domain":"corp.mb-test.com", "ip_addresses":[ "10.100.136.53" ], "detections":[ { "id":"e659d7d7-7bc3-49e2-b3e7-7a44bf37753e", "trace_id":"1dad28d1-7a34-40df-96dc-4ee9781e9363_f596c2bf-f55c-4fa9-8dfa-17861ca8e84b", "scan_id":"1dad28d1-7a34-40df-96dc-4ee9781e9363", "machine_id":"58e326bc-de1f-49a6-926f-def0065275b3", "machine_name":"NewEndpoint", "group_id":"513cf384-d53d-44b9-9813-db69a0e12d16", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "detection_id":"f596c2bf-f55c-4fa9-8dfa-17861ca8e84b", "parent_detection_id":"", "correlation_hash":"", "scanned_at":"2020-08-28T11:29:25Z", "scanned_at_offset_seconds":0, "reported_at":"2020-08-28T11:29:25.763388Z", "cleaned_at":"0001-01-01T00:00:00Z", "status":"found", "threat_name":"PUP.Optional.FooBar", "type":"WyJmaWxlIl0=", "path":"C:\\\\USERS\\\\ADMIN\\\\DESKTOP\\\\80febe47-44fe-4b5e-9549-4677b5d8dc8d.EXE", "category":"PUP", "is_rtp_stream_event":false, "affected_application":"", "md5":"", "process_name":"", "GroupName":"", "PolicyID":"", "PolicyName":"", "CurrentGroupID":"00000000-0000-0000-0000-000000000000" } ] }, "id":"41668db4-af52-4547-84eb-f68a4ed55cb2", "created_at":"2020-08-28T11:29:25.818909871Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"820e96cd-0fd4-4ed7-af74-8d1896322a3a" } ``` ### EDR events #### Suspicious activity detection ```json { "event": "edr_events", "id": "48d1658e-87d8-4df4-87a8-27cecded2174", "payload": { "severity": "WARNING", "type": "EDR_SUSPICIOUS_ACTIVITY", "account_id": "683645cb-edf4-4a81-aa1f-efd87c53851d", "machine_id": "3a89e0b2-47db-4fe2-b6ba-8cd520bc5833", "id": "31cc7f69-4def-4291-89b8-6f7defb5b702", "created_at": "2021-03-10T15:09:45.055891846Z", "details": { "message": "C:\\REG-DISABLE-CMD359B71O4LKM3KQO3G.EXE" }, "machine_name": "NewEndpoint" }, "account_id": "683645cb-edf4-4a81-aa1f-efd87c53851d", "subscription_id": "c817dbda-95f5-4956-a6db-cc070ff0bd6d" } ``` #### Restore success ```json { "event":"edr_events", "id":"ae69d649-bd12-4948-9c98-342ba890f9a3", "payload": { "severity":"INFO", "type":"EDR_RESTORE_SUCCESS", "machine_id":"7f0d7483-92a8-4da5-9754-f7c16e4c3105", "account_id":"caef93d6-92bc-4731-a51f-f61685cca765", "details":{"message":""}, "id":"64a6fdef-31f1-4ec8-8c2a-a3d2c2f1f290", "machine_name":"NewEndpoint", "created_at":"2020-08-31T10:51:50.396082575Z" }, "account_id":"caef93d6-92bc-4731-a51f-f61685cca765", "subscription_id":"ea725d97-11c2-4a34-9022-221b347c731d" } ``` #### Restore failure ```json { "event":"edr_events", "id":"9abec3e1-99ec-4af6-9ef1-e56453b402e8", "payload": { "severity":"INFO", "type":"EDR_RESTORE_FAILURE", "machine_id":"a207f475-7e6d-4c0d-8664-f8ddb6c1bb8a", "account_id":"caef93d6-92bc-4731-a51f-f61685cca765", "details":{"message":""}, "id":"1ae86c7a-9b45-4f8d-800b-cc5885964737", "machine_name":"NewEndpoint", "created_at":"2020-08-31T10:52:16.910215996Z" }, "account_id":"caef93d6-92bc-4731-a51f-f61685cca765", "subscription_id":"ea725d97-11c2-4a34-9022-221b347c731d" } ``` #### Isolation success ```json { "event":"edr_events", "id":"7866c914-b4f9-4e99-8002-501079b2ca86", "payload": { "severity":"INFO", "type":"EDR_ISOLATION_SUCCESS", "machine_id":"f468073b-8715-49e4-a51f-903b86d8a57e", "account_id":"caef93d6-92bc-4731-a51f-f61685cca765", "details":{ "message":"Endpoint isolation succeeded" }, "id":"1c2b8b90-56d5-4bfd-97c1-073b0a4ea184", "machine_name":"NewEndpoint", "created_at":"2020-08-31T10:52:43.345700926Z" }, "account_id":"caef93d6-92bc-4731-a51f-f61685cca765", "subscription_id":"ea725d97-11c2-4a34-9022-221b347c731d" } ``` #### Isolation failure ```json { "event":"edr_events", "id":"b7265e89-c05f-4c9f-bc1b-d5ef1cbf2439", "payload":{ "severity":"INFO", "type":"EDR_ISOLATION_FAILURE", "machine_id":"0361f318-4f01-4cef-8c5b-580f721eae8f", "account_id":"caef93d6-92bc-4731-a51f-f61685cca765", "details":{ "message":"Endpoint isolation failed" }, "id":"c64d1c74-8cf5-4afa-91ec-23e87c735b05", "machine_name":"NewEndpoint", "created_at":"2020-08-31T10:53:09.878218526Z" }, "account_id":"caef93d6-92bc-4731-a51f-f61685cca765", "subscription_id":"ea725d97-11c2-4a34-9022-221b347c731d" } ``` #### Unisolation success ```json { "event": "edr_events", "id": "002e4f0a-2911-4ccb-aeb6-08d4ee5696de", "payload": { "severity": "INFO", "type": "EDR_UNISOLATION_SUCCESS", "machine_id": "f1e3a297-0039-4fb6-b736-e14e10a7b3c7", "account_id": "caef93d6-92bc-4731-a51f-f61685cca765", "details": { "message": "Endpoint un-isolation succeeded" }, "id": "5d8f7034-1d4c-4551-a4f7-d54d85de4dcd", "machine_name": "NewEndpoint", "created_at": "2020-08-31T10:53:36.517826109Z" }, "account_id": "caef93d6-92bc-4731-a51f-f61685cca765", "subscription_id": "ea725d97-11c2-4a34-9022-221b347c731d" } ``` #### Unisolation failure ```json { "event": "edr_events", "id": "0c3b07b2-4a3f-4b88-9d60-314d0fdf8314", "payload": { "severity": "INFO", "type": "EDR_UNISOLATION_FAILURE", "machine_id": "0f92d8e2-c9a1-4666-9e05-deb63a139ca7", "account_id": "caef93d6-92bc-4731-a51f-f61685cca765", "details": { "message": "Endpoint un-isolation failed" }, "id": "60ed3071-19d3-4d56-8818-842666d356e6", "machine_name": "NewEndpoint", "created_at": "2020-08-31T10:54:03.055317564Z" }, "account_id": "caef93d6-92bc-4731-a51f-f61685cca765", "subscription_id": "ea725d97-11c2-4a34-9022-221b347c731d" } ``` ### Syslog events #### Communication endpoint added ```json { "event":"syslog_events", "id":"59936c65-d1ad-4fb9-8e6f-191a7dc94d4c", "payload":{ "severity":"AUDIT", "type":"SYSLOG_COMMUNICATION_ENDPOINT_ADDED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com Added Syslog Communication Endpoint", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "machine_id":"e21c1572-cbf5-4f41-a8f2-f520b752b244", "machine_name":"NewEndpoint" }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"4663c1b1-86ba-4ae8-aab9-bbb33892bdc0", "created_at":"2020-08-28T11:29:26.553694088Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"d5d7d7aa-43f0-483a-913a-49f3e282b964" } ``` #### Communication endpoint removed ```json { "event":"syslog_events", "id":"5e3a440b-b6b3-4c17-a6af-1593419ceecc", "payload":{ "severity":"AUDIT", "type":"SYSLOG_COMMUNICATION_ENDPOINT_REMOVED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com Removed Syslog Communication Endpoint", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "machine_id":"e21c1572-cbf5-4f41-a8f2-f520b752b244", "machine_name":"NewEndpoint" }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"dd6ccb44-0cfb-4c92-8080-2b77637e809a", "created_at":"2020-08-28T11:29:33.371490102Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"d5d7d7aa-43f0-483a-913a-49f3e282b964" } ``` #### Communication endpoint disabled ```json { "event":"syslog_events", "id":"22c64b19-2a10-429f-b785-4db3ea0876bb", "payload":{ "severity":"AUDIT", "type":"SYSLOG_COMMUNICATION_ENDPOINT_DISABLED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com Disabled Syslog Communication Endpoint", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "machine_id":"e21c1572-cbf5-4f41-a8f2-f520b752b244", "machine_name":"NewEndpoint" }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"e4856d8e-c00f-4e96-a1e2-58d89bed0813", "created_at":"2020-08-28T11:29:40.182107484Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"d5d7d7aa-43f0-483a-913a-49f3e282b964" } ``` #### Communication endpoint enabled ```json { "event":"syslog_events", "id":"552c6be3-fdf2-4350-9a2e-1f90fa5feb39", "payload":{ "severity":"AUDIT", "type":"SYSLOG_COMMUNICATION_ENDPOINT_ENABLED", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "details":{ "message":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com Enabled Syslog Communication Endpoint", "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "user_email":"tagalileogalilei+ihg21jbkee5i0f0@gmail.com", "user_name":"Webhooks Tests", "machine_id":"e21c1572-cbf5-4f41-a8f2-f520b752b244", "machine_name":"NewEndpoint" }, "user_id":"d10235ef-e177-4c31-a2b7-ea40a80e6824", "id":"08bc431c-0e68-47e7-848d-56ed5ae54952", "created_at":"2020-08-28T11:29:46.987196405Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"d5d7d7aa-43f0-483a-913a-49f3e282b964" } ``` ### Scheduled events #### Scheduled threat scan success ```json { "event":"scheduled_events", "id":"2bfccc7d-0706-4fda-a32f-24016d19dc94", "payload":{ "severity":"INFO", "type":"SCHEDULED_THREAT_SCAN_SUCCESS", "machine_id":"cf406788-edea-4938-b0db-757379d21e11", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "scan_id":"86412100-2b43-4c44-af9e-fb1697b2f019", "schedule_id":"047cb2f2-2bb9-43e7-974e-625c451bf21e", "schedule_name":"Daily Scan", "schedule_command_data":"{\"schedule_for_chromeos\":true,\"schedule_for_mac\":true,\"schedule_for_windows\":true,\"scan_settings\":{\"type\":\"ThreatScan\",\"remove\":true},\"mac_scan_settings\":{\"remove\":true,\"pup_detection\":\"Detect\"},\"chromeos_scan_settings\":{}}" }, "id":"f2816da1-5244-4338-a85e-0809da72d77c", "created_at":"2020-08-28T11:29:26.403277042Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"cf5031f5-e0cb-4bf9-a581-fdf5c6289906" } ``` #### Scheduled threat scan failure ```json { "event":"scheduled_events", "id":"fac11237-7602-427f-ad6f-c230c138d774", "payload":{ "severity":"WARNING", "type":"SCHEDULED_THREAT_SCAN_FAILURE", "machine_id":"fc2b39dc-d49a-4a62-b1db-f1c9239e4f13", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "scan_id":"00000000-0000-0000-0000-000000000000", "schedule_id":"047cb2f2-2bb9-43e7-974e-625c451bf21e", "schedule_name":"Daily Scan", "schedule_command_data":"{\"schedule_for_chromeos\":true,\"schedule_for_mac\":true,\"schedule_for_windows\":true,\"scan_settings\":{\"type\":\"ThreatScan\",\"remove\":true},\"mac_scan_settings\":{\"remove\":true,\"pup_detection\":\"Detect\"},\"chromeos_scan_settings\":{}}" }, "id":"6f8b5e95-382e-44ef-9621-1921cad7b952", "created_at":"2020-08-28T11:29:52.346309401Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"cf5031f5-e0cb-4bf9-a581-fdf5c6289906" } ``` ### Quarantine events #### Quarantine deleted ```json { "event":"quarantine_events", "id":"38fadc7a-c7e6-4562-a29e-c411cdc2d85e", "payload":{ "severity":"INFO", "type":"QUARANTINE_DELETED", "machine_id":"06667ced-ed77-4cb5-bf17-ab45a6457ec6", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"C:\\\\USERS\\\\ADMIN\\\\DESKTOP\\\\c8e09e6a-6619-44f3-9b5c-f7a15d258aeb.EXE", "detection_id": "b271af4a-8967-4916-9045-c27cbe1c8f36" }, "id":"1534989f-f720-40d3-b4a8-d2640c8127c4", "created_at":"2020-08-28T11:29:26.992510864Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"3471740f-aaa8-4e2c-8695-2bfb3e378d61" } ``` #### Quarantine restored ```json { "event":"quarantine_events", "id":"56098088-35ce-44e2-ad1e-1d394580d7b2", "payload":{ "severity":"INFO", "type":"QUARANTINE_RESTORED", "machine_id":"23f22e64-d7d0-4134-9e0a-df2d4372d42f", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"C:\\\\USERS\\\\ADMIN\\\\DESKTOP\\\\895705b2-4924-4a58-9f57-38bf17190f0e.EXE", "detection_id": "b271af4a-8967-4916-9045-c27cbe1c8f36" }, "id":"851d94de-38f9-4f13-983c-1240e5847bac", "created_at":"2020-08-28T11:30:22.246451515Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"3471740f-aaa8-4e2c-8695-2bfb3e378d61" } ``` #### Restore quarantine fail ```json { "event":"quarantine_events", "id":"23e86e5f-41ba-4227-9b99-d4d0f6aaf0bb", "payload":{ "severity":"WARNING", "type":"QUARANTINE_RESTORE_FAIL", "machine_id":"f5271fe1-1d4b-462f-97a3-c1c610e6ba80", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"C:\\\\USERS\\\\ADMIN\\\\DESKTOP\\\\5d2c45f2-a076-4bdb-8cf0-060fa6bb486f.EXE", "detection_id": "b271af4a-8967-4916-9045-c27cbe1c8f36" }, "id":"844d1e23-0e34-4237-bc2d-972758d67a90", "created_at":"2020-08-28T11:30:48.946977118Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"3471740f-aaa8-4e2c-8695-2bfb3e378d61" } ``` #### Delete quarantine fail ```json { "event":"quarantine_events", "id":"308c0fcf-90e9-4036-a572-82de8aeb5075", "payload":{ "severity":"WARNING", "type":"QUARANTINE_DELETE_FAIL", "machine_id":"4d59b887-34ad-49a2-a103-1ba24dd790f1", "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "machine_name":"NewEndpoint", "details":{ "message":"C:\\\\USERS\\\\ADMIN\\\\DESKTOP\\\\3e7e7a17-969a-4d07-8126-fe62f3b26e82.EXE", "detection_id": "b271af4a-8967-4916-9045-c27cbe1c8f36" }, "id":"eabbd68e-ca6e-4ec9-aa9a-2e448e9983d5", "created_at":"2020-08-28T11:29:55.416828312Z" }, "account_id":"47632e8c-f125-4875-8d5b-ab24275c90a8", "subscription_id":"3471740f-aaa8-4e2c-8695-2bfb3e378d61" } ``` ### Users Events #### User invited ```json { "event": "user_events", "id": "d3f25ec6-e943-495a-b251-f73dca979c1e", "payload": { "severity": "AUDIT", "type": "USER_INVITED", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "user_id": "c79a9d0b-7fc5-413c-8161-182873f7870f", "id": "d38df30e-5601-40fb-92d1-c6cc55086fce", "created_at": "2021-03-10T12:56:26.316135667Z", "details": { "message": "Email: tifiy10802@566dh.com, Role: Super Admin", "ip_address": "90.191.127.234", "invited_by": "avitella@malwarebytes.com", "invitee_role": "SuperAdmin", "invitee_groupIDs": null, "invitee_email": "tifiy10802@566dh.com", "invitee_allGroupsAccess": true } }, "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "subscription_id": "f43dc73b-2709-4d6f-9c79-08abc815114b" } ``` #### User verified ```json { "event": "user_events", "id": "81ca10e2-73fa-4008-b391-f0efe63e3ca5", "payload": { "severity": "AUDIT", "type": "USER_VERIFIED", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "user_id": "a1b739d8-ad84-4730-bb92-252d372ebee4", "id": "878c484f-73d0-4482-8e38-7a8953059074", "created_at": "2021-03-10T12:57:46.961165627Z", "details": { "message": "tifiy10802@566dh.com" } }, "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "subscription_id": "f43dc73b-2709-4d6f-9c79-08abc815114b" } ``` #### User role updated ```json { "event": "user_events", "id": "a5696568-490b-44cb-83d3-b97c27b5c272", "payload": { "severity": "AUDIT", "type": "USER_ROLE_UPDATED", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "user_id": "c79a9d0b-7fc5-413c-8161-182873f7870f", "id": "b6eaceeb-b66a-4f3c-b2d3-1928f959a04d", "created_at": "2021-03-10T12:59:19.612242246Z", "details": { "message": "Changed the role for user test (tifiy10802@566dh.com) from Super Admin to Admin", "user_id": "c79a9d0b-7fc5-413c-8161-182873f7870f", "user_email": "avitella@malwarebytes.com", "user_name": "Alessio Vitella" } }, "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "subscription_id": "f43dc73b-2709-4d6f-9c79-08abc815114b" } ``` #### User group role updated ```json { "event": "user_events", "id": "700e2e19-7dd5-4dc9-aa75-436bc4ce4449", "payload": { "severity": "AUDIT", "type": "USER_GROUP_ACCESS_UPDATED", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "user_id": "c79a9d0b-7fc5-413c-8161-182873f7870f", "id": "9e3b48c9-3fee-46dd-807a-3f567205feeb", "created_at": "2021-03-10T12:59:34.6325247Z", "details": { "message": "Group access updated for user test (tifiy10802@566dh.com)", "user_id": "c79a9d0b-7fc5-413c-8161-182873f7870f", "user_email": "avitella@malwarebytes.com", "user_name": "Alessio Vitella" } }, "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "subscription_id": "f43dc73b-2709-4d6f-9c79-08abc815114b" } ``` #### User deleted ```json { "event": "user_events", "id": "acd4187a-df1e-45bf-8ef7-ef8e666c8ad1", "payload": { "severity": "AUDIT", "type": "USER_DELETED", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "user_id": "c79a9d0b-7fc5-413c-8161-182873f7870f", "id": "f60d1cb0-ed06-4de9-bedd-ea3081df9c0d", "created_at": "2021-03-10T13:01:08.21154784Z", "details": { "message": "tifiy10802@566dh.com was deleted by user avitella@malwarebytes.com", "deleted_by": "avitella@malwarebytes.com", "ip_address": "90.191.127.234" } }, "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "subscription_id": "f43dc73b-2709-4d6f-9c79-08abc815114b" } ``` ### Device control events #### Drive blocked ```json { "event": "drive_events", "id": "60de6386-56d9-4b18-b0dd-8cf75e53665e", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "9278ff33-9989-47d1-ac1f-fc40381f3b39", "id": "83418205-78d2-453b-b15e-b8ac3e6efc21", "created_at": "2022-02-09T15:36:57.7484112Z", "action": "blocked", "type": "DRIVE_BLOCKED", "details": { "group_id": "39a36fde-49ae-416b-9e68-112d9bfa1945", "group_name": "PMP DNS Lite", "policy_id": "833bd822-e2a6-44e8-a7b6-92ca1edae4c0", "policy_name": "DNS Lite", "metadata": { "timestamp": "2022-02-09T15:36:57.7484112Z", "physical_disk_name": "Walgreen Infinitive USB Device", "pnp_device_id": "USBSTOR\\DISK&VEN_WALGREEN&PROD_INFINITIVE&REV_1.00\\4C530001030323105095&0", "device_id": "\\\\.\\PHYSICALDRIVE1", "disk_interface": "USB", "manufacturer": "Zia Caterina", "serial_number": "4C530001030323105095", "drive_compressed": false, "file_system": "NTFS", "volume_name": "E:", "volume_serial": "44D9870F", "volume_device_path": "\\Device\\HarddiskVolume8", "block_status": "blocked", "driver_metadata": { "DevicePath": "\\DEVICE\\HARDDISKVOLUME8", "FileSystemFlags": 65472255, "FileSystemName": "NTFS", "MaximumComponentLength": 255, "VolumeMountPoints": [ "E:\\" ], "VolumeName": "USB", "VolumePath": "\\\\?\\Volume{0d619cc3-7d50-11ec-9bca-000c2972f401}\\", "VolumeSerialNumber": "1155106575", "schemaVersion": 1 } } }, "machine_name": "pmp-win10x64-00" }, "subscription_id": "f8b2a2f5-1e11-4709-8256-9c17609b05d3" } ``` ### Vulnerability & Patch events #### Vulnerability found ```json { "event": "cve_events", "id": "e2ebad01-faaf-40c7-8b32-00c10ef6dc85", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "9278ff33-9989-47d1-ac1f-fc40381f3b39", "id": "fb839c2e-ae9a-48c0-9233-ed278ee06b30", "created_at": "2022-05-06T13:49:51.227357Z", "type": "CVE_ADDED", "details": { "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "account_name": "Test Account1", "parent_account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "9278ff33-9989-47d1-ac1f-fc40381f3b39", "group_id": "39a36fde-49ae-416b-9e68-112d9bfa1945", "root_group_id": "39a36fde-49ae-416b-9e68-112d9bfa1945", "host_name": "TA-Win81x32-001", "fully_qualified_host_name": "TA-Win81x32-001", "display_name": "TA-Win81x32-001", "vendor": "Adobe Systems Inc.", "normalized_vendor": "adobe", "product": "Adobe Flash Player", "installed_version": "32.0.0.207", "created_at": "2022-05-06T13:49:49.893680453Z", "os_info": { "os_type": "Workstation", "os_version": "6.3.9600", "os_platform": "Windows", "os_architecture": "x86", "os_release_name": "Microsoft Windows 8.1 Enterprise" }, "sort_id": 1651844991145, "cve_id": "CVE-2019-8075", "cisa_exploitable": true, "severity": "medium", "severity_score": 58, "published_at": "2019-09-27T16:15:00Z", "cvss30_score": 7.5, "cvss20_score": 5, "description": "Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.", "resolution": { "text": "Product is defunct, please uninstall it." }, "document_id": "9278ff33-9989-47d1-ac1f-fc40381f3b39c6ba419679d8950eabad5c0385703f78CVE-2019-8075", "display_vendor": "adobe", "display_product": "Adobe Flash Player", "display_installed_version": "32.0.0.207", "version": 0 } }, "subscription_id": "f8b2a2f5-1e11-4709-8256-9c17609b05d3" } ``` #### Patch available ```json { "event": "cve_events", "id": "dea7139e-5589-4d7a-b30c-3b8ed827c4fa", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "9278ff33-9989-47d1-ac1f-fc40381f3b39", "id": "9a608078-7192-4a68-bfce-ec35121a79f1", "created_at": "2022-05-06T13:49:51.22989Z", "type": "CVE_PATCH_AVAILABLE", "details": { "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "account_name": "Test Account1", "parent_account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "9278ff33-9989-47d1-ac1f-fc40381f3b39", "group_id": "39a36fde-49ae-416b-9e68-112d9bfa1945", "root_group_id": "39a36fde-49ae-416b-9e68-112d9bfa1945", "host_name": "TA-Win81x32-001", "fully_qualified_host_name": "TA-Win81x32-001", "display_name": "TA-Win81x32-001", "created_at": "2022-05-06T13:49:49.893680453Z", "sort_id": 1651844991166, "os_info": { "os_type": "Workstation", "os_version": "6.3.9600", "os_platform": "Windows", "os_architecture": "x86", "os_release_name": "Microsoft Windows 8.1 Enterprise" }, "title": "Microsoft .NET Framework 4.8 for Windows 8.1 (KB4486105)", "description": "The Microsoft .NET Framework 4.8 is a highly compatible, in-place update for all the previous versions of .NET Framework 4.X. After you install this update, you may have to restart your computer.", "product": "Windows 8.1", "severity": "important", "category": "feature_pack", "security_update_id": "", "patch_id": "4486105", "released_at": "2020-01-14T05:00:00Z", "size": 44044135, "reboot_required": true, "document_id": "9278ff33-9989-47d1-ac1f-fc40381f3b394486105", "version": 0 } }, "subscription_id": "f8b2a2f5-1e11-4709-8256-9c17609b05d3" } ``` #### Software updated ```json { "event": "cve_events", "id": "5168387e-41a7-47cd-b554-f5d49308c464", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "payload": { "severity": "INFO", "machine_name": "Avarosa", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "machine_id": "07386bfa-d493-41b3-bff1-db6dfe64e17f", "action": "COMPLETED", // enum: ["FAILED","COMPLETED"] "details": { "application_name": "Microsoft Visual C++ Redistributable 2013", "current_version": "12.0.30501.0", "new_version": "12.0.40664.0", "product": 3092, "vendor": "microsoft" }, "created_at": "2022-05-09T10:39:59.14429501Z", "id": "1f79149f-d38f-4c20-a09e-75f2debf812a", "type": "CVE_SOFTWARE_UPDATED" }, "subscription_id": "a469cd25-4c0b-4e35-98cd-b2a01f09945d" } ``` #### Patch applied ```json { "event": "cve_events", "id": "ff0edfda-6cae-4adc-9b4b-1b5f23002d4d", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "payload": { "severity": "INFO", "machine_name": "Avarosa", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "machine_id": "07386bfa-d493-41b3-bff1-db6dfe64e17f", "action": "COMPLETED", // enum: ["FAILED","COMPLETED","REBOOT_REQUIRED"] "details": { "category": "critical_update", "product": ".NET Core 3.1", "severity": "important", "title": "2021-10 .NET Core 3.1.20 Update for Windows 11 for x64 Client (KB5007050)", "vendor": "Armut Corp", "reboot_required": false, "description": "2021-10 .NET Core 3.1.20 Update for Windows 11 for x64 Client (KB5007050)", "date": 1634277600, "size": 189019608, "kb_id": "5007050", "security_update_id": "" }, "created_at": "2022-05-09T10:40:31.848869068Z", "type": "CVE_PATCH_APPLIED" }, "subscription_id": "a469cd25-4c0b-4e35-98cd-b2a01f09945d" } ``` ### DNS Content Filtering events #### DNS blocked ```json { "event": "dns_events", "id": "4974972d-36f6-4c0f-a687-626d33a98609", "account_id": "f9c1e231-891e-40a2-93a8-7666a527c67d", "payload": { "severity": "INFO", "account_id": "f9c1e231-891e-40a2-93a8-7666a527c67d", "machine_id": "675c4b7a-335b-47c1-b71f-868f03ccf263", "created_at": "2022-09-01T15:32:12.706971938Z", "id": "0dcdf1c6-16fc-4bb7-b94f-ba1db2d5d4fb", "details": { "id": "bef4894f-d4e7-4cee-b52e-f15998c6ab49", "machine_id": "675c4b7a-335b-47c1-b71f-868f03ccf263", "group_id": "faafbf27-e166-45ce-bb16-f01f3a5b7ae1", "group_name": "Default Group", "account_id": "f9c1e231-891e-40a2-93a8-7666a527c67d", "parent_account_id": "f9c1e231-891e-40a2-93a8-7666a527c67d", "policy_id": "fa4331e7-989b-47b3-8f40-efff592d573c", "rule_id": "d25c4ec1-bb72-4d5a-8f4b-20cd131634d6", "rule_name": "no msnbc", "policy_name": "Default Policy", "action": "block", "log": { "colo_id": 465, "datetime": "2022-09-01T15:31:45Z", "device_id": "5f166267-2a09-11ed-99f4-7a63bd6fb789", "user_id": "721ab000-8a6c-4b54-858c-1b67f6d4a630", "dst_ip": "162.159.36.5", "src_ip": "98.207.10.35", "email": "non_identity@mwb-nebula-7bde22be1cb528441ad14380f02a8411.cloudflareaccess.com", "location": "d25c4ec1-bb72-4d5a-8f4b-20cd131634d6", "policy": "", "policy_id": "ccb7fe0d52fb493dbfdc2cf4de0764ee", "protocol": "https", "query_name": "msnbc.com", "query_name_reversed": "com.msnbc", "resolver_decision": "blockedRule", "query_category_ids": [7,122,164], "query_size": 38, "query_type": 28, "src_port": 0, "dst_port": 0 }, "document_id": "bef4894f-d4e7-4cee-b52e-f15998c6ab49", "version": 0, "@timestamp": "2022-09-01T15:32:12.706971938Z" }, "type": "DNS_BLOCKED" }, "subscription_id": "f01dc32c-76a6-4629-8efa-5afe861f32b7" } ``` ### License events #### License Entitlement Added ```json { "event": "license_events", "id": "5db19165-9078-408d-be55-38b540fb8527", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "payload": { "severity": "INFO", "type": "LICENSE_ENTITLEMENT_CHANGED", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "id": "1e659a56-5b03-493a-baf8-bb3ecd628c59", "details": { "id": "5944a421-9f33-4471-9382-72525fae1427", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "license_key": "CBFCK-XRRG2-67ZDJ-CGHUS", "licensed_product": "MBDNS-B,NCCA-B", "catalog_code": "", "combo_product": "NEBULA-DNS-COMBO", "licensed_seats": 10, "license_expires_at": "2023-11-17T23:59:59Z", "license_key_status": "active", "license_term_type": "subscription", "license_status": "active", "licensed_remediations": 0, "licensed_remediation_factor": 0, "remediation_count": 0, "created_at": "2022-11-17T14:01:07.426394557Z", "updated_at": "2022-11-17T14:01:07.426394557Z", "active": true, "machine_counts": null, "auto_renew": "no", "can_be_paid": false, "keystone_id": 35093303 }, "action": "added", "created_at": "2022-11-17T14:01:07.556054636Z" }, "subscription_id": "1fa8e9ee-7a16-4197-987f-4362ddfbd5ac" } ``` #### License Entitlement Updated ```json { "event": "license_events", "id": "599e8be4-ae4b-4066-b31c-ea223e900179", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "payload": { "severity": "INFO", "type": "LICENSE_ENTITLEMENT_CHANGED", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "id": "a13fdaca-13a1-4e4e-88f8-ac66309ef11b", "details": { "old_entitlement": { "id": "5944a421-9f33-4471-9382-72525fae1427", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "license_key": "CBFCK-XRRG2-67ZDJ-CGHUS", "licensed_product": "MBDNS-B,NCCA-B", "catalog_code": "", "combo_product": "NEBULA-DNS-COMBO", "licensed_seats": 10, "license_expires_at": "2023-11-17T23:59:59Z", "license_key_status": "active", "license_term_type": "subscription", "license_status": "active", "licensed_remediations": 0, "licensed_remediation_factor": 0, "remediation_count": 0, "created_at": "2022-11-17T14:01:07.426395Z", "updated_at": "2022-11-17T14:01:07.426395Z", "active": true, "machine_counts": null, "auto_renew": "no", "can_be_paid": false, "keystone_id": 35093303 }, "new_entitlement": { "id": "5944a421-9f33-4471-9382-72525fae1427", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "license_key": "CBFCK-XRRG2-67ZDJ-CGHUS", "licensed_product": "MBDNS-B,NCCA-B", "catalog_code": "", "combo_product": "NEBULA-DNS-COMBO", "licensed_seats": 20, "license_expires_at": "2023-11-17T23:59:59Z", "license_key_status": "active", "license_term_type": "subscription", "license_status": "active", "licensed_remediations": 0, "licensed_remediation_factor": 0, "remediation_count": 0, "created_at": "0001-01-01T00:00:00Z", "active": true, "machine_counts": null, "auto_renew": "no", "can_be_paid": false, "keystone_id": 35093303 } }, "action": "updated", "created_at": "2022-11-17T14:02:38.006653379Z" }, "subscription_id": "1fa8e9ee-7a16-4197-987f-4362ddfbd5ac" } ``` #### License Entitlement Removed ```json { "event": "license_events", "id": "29d6f063-fd95-4b6a-bcdb-1ecaaa15eb87", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "payload": { "severity": "INFO", "type": "LICENSE_ENTITLEMENT_CHANGED", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "id": "038304ca-4fa8-4926-a3d6-fca29c6b1e71", "details": { "id": "5944a421-9f33-4471-9382-72525fae1427", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "license_key": "CBFCK-XRRG2-67ZDJ-CGHUS", "licensed_product": "MBDNS-B,NCCA-B", "catalog_code": "", "combo_product": "NEBULA-DNS-COMBO", "licensed_seats": 20, "license_expires_at": "2023-11-17T23:59:59Z", "license_key_status": "active", "license_term_type": "subscription", "license_status": "active", "licensed_remediations": 0, "licensed_remediation_factor": 0, "remediation_count": 0, "created_at": "2022-11-17T14:01:07.426395Z", "updated_at": "2022-11-17T14:02:37.95501Z", "active": true, "machine_counts": null, "auto_renew": "no", "can_be_paid": false, "keystone_id": 35093303 }, "action": "removed", "created_at": "2022-11-17T14:03:06.077892882Z" }, "subscription_id": "1fa8e9ee-7a16-4197-987f-4362ddfbd5ac" } ``` #### License Entitlement Usage changed ```json { "event": "license_events", "id": "a79b4fbb-90f2-408c-a3d5-e4b37cdaa9d1", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "payload": { "severity": "INFO", "type": "LICENSE_ENTITLEMENT_USAGE_CHANGED", "created_at": "2022-11-17T15:57:59.921931957Z", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "details": { "license_key": "CBFCK-XRRG2-67ZDJ-CGHUS", "licensed_product": "MBAE-B,MBAM-B,MBBR-B,MBCM-B,MBFT-B,MBRX-B,NCCA-B,NCEP-B,NCRM-B", "catalog_code": "BUS-CLOUD-EPP-01", "combo_product": "NEBULA-EP-COMBO", "licensed_seats": 10, "license_expires_at": "2023-11-17T23:59:59Z", "license_key_status": "active", "license_term_type": "subscription", "license_status": "active", "auto_renew": "no", "used_seats": 5 } }, "subscription_id": "1fa8e9ee-7a16-4197-987f-4362ddfbd5ac" } ``` #### License Over deployment ```json { "event": "license_events", "id": "c39ce0df-ed3d-4f31-bea4-b2926b36f49a", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "payload": { "severity": "INFO", "type": "LICENSE_OVER_DEPLOYMENT", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "details": { "message": "Over deployment", "license_key": "CBFCK-XRRG2-67ZDJ-CGHUS", "licensed_product": "MBAE-B,MBAM-B,MBBR-B,MBCM-B,MBFT-B,MBRX-B,NCCA-B,NCEP-B,NCRM-B", "catalog_code": "BUS-CLOUD-EPP-01", "combo_product": "NEBULA-EP-COMBO", "licensed_seats": 3, "license_expires_at": "2023-11-17T23:59:59Z", "license_key_status": "active", "license_term_type": "subscription", "license_status": "active", "auto_renew": "no", "used_seats": 4 }, "created_at": "2022-11-17T14:49:59.333193431Z" }, "subscription_id": "1fa8e9ee-7a16-4197-987f-4362ddfbd5ac" } ``` #### License Expiring ```json { "event": "license_events", "id": "533605a0-6cce-4b9a-8292-101f0b9583c2", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "payload": { "severity": "INFO", "type": "LICENSE_EXPIRING", "account_id": "00017df6-13c5-4cac-8967-40f85b054e4e", "details": { "license_key": "CBFCK-XRRG2-67ZDJ-CGHUS", "licensed_product": "MBAE-B,MBAM-B,MBBR-B,MBCM-B,MBFT-B,MBRX-B,NCCA-B,NCEP-B,NCRM-B", "catalog_code": "BUS-CLOUD-EPP-01", "combo_product": "NEBULA-EP-COMBO", "licensed_seats": 3, "license_expires_at": "2022-11-30T23:59:59Z", "license_key_status": "active", "license_term_type": "subscription", "license_status": "active", "auto_renew": "no", "used_seats": 4, "message": "Expiring license", "days_left": 14 // enum: [0, 1, 7, 14 ,30] }, "created_at": "2022-11-17T14:56:26.743834259Z" }, "subscription_id": "1fa8e9ee-7a16-4197-987f-4362ddfbd5ac" } ``` ### Application Block events #### Application blocked ```json { "event": "appblock_events", "id": "b3e1f103-c490-445f-9136-d45450e1a961", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "payload": { "type": "APPBLOCK_BLOCKED", "document_id": "e8c540c7-fe43-511d-b6df-805656440afd", "severity": "INFO", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "machine_id": "f2750e61-a41c-47ed-8d12-fca857fe8453", "group_id": "f4b15520-3153-4956-be41-185c4a523cfc", "action": "blocked", "id": "e8c540c7-fe43-511d-b6df-805656440afd", "created_at": "2023-03-15T13:34:02.80344Z", "root_group_id": "f4b15520-3153-4956-be41-185c4a523cfc", "account_name": "Test-Account3", "parent_account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "group_name": "Default Group", "policy_id": "4ab40443-dea1-4c76-8713-ef5141307b98", "policy_name": "!!!!_!_!!!_!!_!_!NEW POLICY12345", "details": { "file_path": "C:\\burla2.exe", "matching_rule_ids": [ "33741ecc-6775-4f13-b7d9-4f462a59fc2a" ], "app_block_rules": [ { "id": "33741ecc-6775-4f13-b7d9-4f462a59fc2a", "account_id": "550a20b8-6d36-4222-afbc-54d100f2e894", "name": "Rule test 34", "rule": { "action": "block", "files": [ "C:\\burla2.exe" ] }, "type": "files" } ], "group_id": "f4b15520-3153-4956-be41-185c4a523cfc", "group_name": "Default Group", "policy_id": "4ab40443-dea1-4c76-8713-ef5141307b98", "policy_name": "!!!!_!_!!!_!!_!_!NEW POLICY12345", "last_user": "ben-fake-endpoint\\Testuser" } }, "subscription_id": "a22a2b59-4897-45de-b055-cfa1eabb9d1e" } ``` ### Endpoint status events #### Endpoint reboot required ```json { "event": "endpoint_events", "id": "a8f76811-fa21-48b3-8bba-6b6e800ecc6e", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "type": "ENDPOINT_REBOOT_REQUIRED", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "350eff78-1061-4357-b992-3121d22288ab", "created_at": "2023-01-17T15:06:02.410951Z", "id": "3e52d13e-ac67-109b-b0a9-9443f785f5d1", "machine_name": "test_machine387" }, "subscription_id": "289ffcf2-3168-45c4-89fb-378d59031d12" } ``` #### Endpoint reboot cleared ```json { "event": "endpoint_events", "id": "a8f76811-fa21-48b3-6bba-1b6e800ecc6e", "account_id": "f29c5663-10a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "type": "ENDPOINT_REBOOT_REQUIRED_CLEARED", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "350eff78-1061-4357-b992-3121d22288ab", "created_at": "2023-01-17T15:06:02.410951Z", "id": "3e52d13e-ac67-409b-b0a9-9443f785f5d1", "machine_name": "test_machine387" }, "subscription_id": "289ffcf2-1168-55c4-89fb-378d59031d12" } ``` #### Endpoint remediation required This event is emitted when at least one detection is detected while the endpoint had no detection before ```json { "event": "endpoint_events", "id": "f98f4ee7-1a32-4840-8d5d-9d4ab0adac93", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "type": "ENDPOINT_INFECTED", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "350eff78-1061-4357-b992-3121d22288ab", "created_at": "2023-01-17T15:52:42.6652Z", "id": "d288002d-806e-4b2b-a0d4-f8f80ae801e8", "machine_name": "test_machine387" }, "subscription_id": "289ffcf2-1168-45c4-89fb-378d59031d12" } ``` #### Endpoint remediated This event is emitted when all the detections are remediated for an endpoint ```json { "event": "endpoint_events", "id": "f98f4ee7-1232-4840-8d5d-9ddab0adac93", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "type": "ENDPOINT_REMEDIATED", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "350eff78-1061-4357-b992-3121d22288ab", "created_at": "2023-01-17T15:52:42.6652Z", "id": "d288040d-806e-4b2b-a0d4-f8f80ae801e8", "machine_name": "test_machine387" }, "subscription_id": "289ffcf2-1168-45c4-89fb-378d59031d12" } ``` #### Endpoint isolated ```json { "event": "endpoint_events", "id": "f98f4ee7-1a32-4840-8d5d-9ddab0adac95", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "type": "ENDPOINT_ISOLATED", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "350eff78-1061-4357-b992-3121d22288ab", "created_at": "2023-01-17T15:52:42.6652Z", "id": "d288000d-806e-4b2b-a0d4-f8f80ae831e8", "machine_name": "test_machine387" }, "subscription_id": "289ffcf2-1168-45c4-89fb-378d59031d12" } ``` #### Endpoint un-isolated ```json { "event": "endpoint_events", "id": "f98f4ee7-1a32-4840-8d5d-9ddab0adac93", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "type": "ENDPOINT_UNISOLATED", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "350eff78-1061-4357-b992-3121d22288ab", "created_at": "2023-01-17T15:52:42.6652Z", "id": "d288000d-806e-4b2b-a0d4-f8f80ae801e8", "machine_name": "test_machine387" }, "subscription_id": "289ffcf2-1168-45c4-89fb-378d59031d12" } ``` #### Suspicious activity detected This event is emitted when at least one suspicious activity is detected while the endpoint had no suspicious activities before ```json { "event": "endpoint_events", "id": "f98f4ee7-1a32-4840-8d5d-9ddab0ad3c93", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "type": "ENDPOINT_SUSPICIOUS_ACTIVITY_FOUND", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "350eff78-1061-4357-b992-3121d22288ab", "created_at": "2023-01-17T15:52:42.6652Z", "id": "d288000d-806e-2b2b-a0d4-f8f80ae801e8", "machine_name": "test_machine387" }, "subscription_id": "289ffcf2-1168-45c4-89fb-378d59031d12" } ``` #### Suspicious activity cleared This event is emitted when all the suspicious activities are cleared for an endpoint ```json { "event": "endpoint_events", "id": "f98f4ee7-1a32-4840-8d5d-9ddab0ad3c93", "account_id": "f29c5663-180a-4cd5-a5c3-b9a45e67ad21", "payload": { "severity": "INFO", "type": "ENDPOINT_SUSPICIOUS_ACTIVITY_CLEARED", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "350eff78-1061-4357-b992-3121d22288ab", "created_at": "2023-01-17T15:52:42.6652Z", "id": "d288200d-806e-2b2b-a0d4-f8f80ae801e8", "machine_name": "test_machine387" }, "subscription_id": "289ffcf2-1168-45c4-89fb-378d59031d12" } ``` ### Agent Events #### Endpoint needs attention This event is emitted when the list of alerts form the endpoint is changed ```json { "event": "agent_events", "id": "3be75bf1-0926-41b5-9c6f-ad4a70123293", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "payload": { "type": "AGENT_ALERTS_CHANGED", "severity": "INFO", "account_id": "f29c5663-100a-4cd5-a5c3-b9a45e67ad21", "machine_id": "350eff78-1061-4357-b992-3121d22288ab", "created_at": "2023-01-18T10:59:40.3162Z", "id": "4ec6595c-e8c4-4a85-b1e1-2ceff1086c59", "details": { "added_codes": ["FULL_DISK_ACCESS_DISABLED"], "cleared_codes": [], "current_codes": ["FULL_DISK_ACCESS_DISABLED"] }, "machine_name": "dummy-host.corp.mb-test.com" }, "subscription_id": "289ffcf2-1168-45c4-89fb-378d59031d12" } ``` humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - Webhooks properties: - type: OpenAPI url: openapi/malwarebytes-webhooks-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs - aid: malwarebytes:malwarebytes-xdr-api name: Malwarebytes XDR API description: The XDR API from Malwarebytes — 4 operation(s) for xdr. humanURL: https://api.threatdown.com/nebula/v1/docs baseURL: https://api.threatdown.com tags: - XDR properties: - type: OpenAPI url: openapi/malwarebytes-xdr-api-openapi.yml - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://cloud.malwarebytes.com/api/v2/oneview/docs common: - type: MCPServer url: mcp/malwarebytes-mcp.yml - type: Overlay url: overlays/malwarebytes-threatdown-nebula-overlay.yaml - type: Website url: https://www.malwarebytes.com/ - type: DeveloperPortal url: https://api.threatdown.com/nebula/v1/docs - type: Documentation url: https://api.threatdown.com/nebula/v1/docs - type: APIReference url: https://api.threatdown.com/nebula/v1/docs - type: GettingStarted url: https://support.threatdown.com/hc/en-us/articles/5808694795539-Nebula-API-example-using-Ruby - type: Support url: https://support.threatdown.com/hc/en-us/ - type: HelpCenter url: https://help.malwarebytes.com/hc/en-us - type: Community url: https://forums.malwarebytes.com/ - type: Blog url: https://www.malwarebytes.com/blog - type: GitHubOrganization url: https://github.com/malwarebytes - type: Pricing url: https://www.threatdown.com/pricing/ - type: SignUp url: https://cloud.threatdown.com/auth/login - type: TermsOfService url: https://www.threatdown.com/legal/terms-of-service/ - type: PrivacyPolicy url: https://www.threatdown.com/legal/privacy-policy/ - type: StatusPage url: https://status.threatdown.com/ - type: Lifecycle url: lifecycle/malwarebytes-lifecycle.yml - type: Deprecation url: lifecycle/malwarebytes-lifecycle.yml - type: ChangeLog url: changelog/malwarebytes-changelog.yml - type: Security url: security/malwarebytes-vulnerability-disclosure.yml - type: VulnerabilityDisclosure url: security/malwarebytes-vulnerability-disclosure.yml - type: TrustCenter url: security/malwarebytes-trust-center.yml - type: Compliance url: https://www.threatdown.com/legal/trust-and-compliance/ - type: DomainSecurity url: security/malwarebytes-domain-security.yml - type: Conformance url: conformance/malwarebytes-conformance.yml - type: Authentication url: authentication/malwarebytes-authentication.yml - type: OAuthScopes url: scopes/malwarebytes-scopes.yml - type: ErrorCatalog url: errors/malwarebytes-problem-types.yml - type: Conventions url: conventions/malwarebytes-conventions.yml - type: RateLimits url: rate-limits/malwarebytes-rate-limits.yml - type: DataModel url: data-model/malwarebytes-data-model.yml - type: Webhooks url: asyncapi/malwarebytes-threatdown-webhooks.yml - type: Packages url: packages/malwarebytes-packages.yml - type: WellKnown url: well-known/malwarebytes-well-known.yml - type: SecurityTxt url: well-known/malwarebytes-security.txt - type: LLMsTxt url: llms/malwarebytes-llms.txt - type: AgentSkill url: skills/_index.yml x-enrichment: date: '2026-08-04' status: enriched artifacts_added: 27 pass: local-v1