slug: malwarebytes provider: Malwarebytes generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Software & Technology min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 24 edges: - tag: Vulnerability Assessment spec_file: malwarebytes-vulnerability-assessment-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.94 evidence: '"Get vulnerability assessment CVE statistics", "Get vulnerability assessment report"' reason: Operations report CVE statistics, software statistics and assessment details across endpoints — plainly vulnerability scanning and remediation reporting. - tag: Vulnerability Management spec_file: malwarebytes-vulnerability-management-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.94 evidence: '"Get CVE details by id", "Ignore CVEs", "Search CVE"' reason: CVE search, detail retrieval, bulk export and suppression are the core workflow of vulnerability identification and remediation triage. - tag: Detections spec_file: malwarebytes-detections-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.92 evidence: '''Get detection by ID'', ''Search detections'', ''Submit false positive request'' — advanced analysis on `Detections` of `Malware`, `Ransomware`, `Exploits`' reason: Operations manage malware/threat detections raised by the endpoint agent, including triage of false positives — squarely threat detection and response. - tag: Firewall Management spec_file: malwarebytes-firewall-management-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.88 evidence: '''Create a new firewall policy'', ''Create a new firewall rule'', ''Get firewall rulesets''' reason: Full lifecycle management of host firewall policies, rules and rulesets — clearly a cybersecurity control administration surface; no single listed L2 covers network/host firewall policy, so L1. - tag: Suspicious Activity spec_file: malwarebytes-suspicious-activity-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.88 evidence: '''Suspicious activity of the account'', ''Suspicious activity process graph'', ''/sa/remediate'', ''/sa/open'', ''/sa/close''' reason: 'EDR-style detection triage: listing suspicious activity, inspecting the process graph, and opening/closing/remediating cases is threat detection and response, not observability or generic alerting.' - tag: XDR spec_file: malwarebytes-xdr-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.88 evidence: '"Get alert details", "Set alert status", "Set alert action taken in bulk"' reason: XDR alert triage — retrieving alert detail and recording status/action taken — is security threat detection and response workflow, not financial-crime alerting. - tag: Flight-recorder spec_file: malwarebytes-flight-recorder-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.85 evidence: '''Search suspicious activity'', ''Search the process graph'', ''Search a list of raw events'', ''Search the flight recorder with advanced queries''' reason: EDR telemetry hunting — process graphs, raw events and suspicious activity queries used for detection and investigation, matching threat detection & response. - tag: ITDR spec_file: malwarebytes-itdr-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.82 evidence: '"Get ITDR Darkweb Monitoring Identities", "Post ITDR Login Restriction Group", "Create ITDR Identity Posture Exclusions"' reason: 'Identity Threat Detection and Response surface: dark-web monitoring of identities, login restriction groups, identity posture exclusions. Clearly cybersecurity; sits astride identity access control (620.20) and threat detection/response (620.30), so only the L1 is asserted.' - tag: Quarantine spec_file: malwarebytes-quarantine-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.82 evidence: '''Get all quarantined items'', ''Bulk quarantine action'', ''Search quarantines'' — within an API to ''perform advanced analysis on `Detections` of `Malware`, `Ransomware`, `Exploits`''' reason: Quarantine of detected malware artefacts on endpoints is threat response handling, part of endpoint detection and response operations rather than generic IT ops. - tag: Remediation spec_file: malwarebytes-remediation-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.82 evidence: '''Bulk remediation action'', ''Mark remediation items as safe'', ''Search remediation Items''' reason: Remediating detected threats on endpoints is response action management within threat detection and response; the vendor description frames it as issuing jobs like 'Isolate', 'Remediate'. - tag: Drive Encryption spec_file: malwarebytes-drive-encryption-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '''Export drive encryption CSV'' at /drive-encryption/export/recovery-keys, ''Get drive encryption summary''' reason: Manages full-disk encryption status and recovery keys across endpoints — an information security control; no listed L2 specifically covers endpoint encryption, so L1 only. - tag: Policies spec_file: malwarebytes-policies-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"Create policy", "Set policy auto-isolation", "Get policy tamper protection password", "Add isolation image"' reason: CRUD over endpoint protection policies including auto-isolation and tamper-protection settings — configuration of security controls on managed devices. Which security sub-capability (governance vs. detection config) is ambiguous, so L1 only. - tag: Remote Intrusion Detection spec_file: malwarebytes-remote-intrusion-detection-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.8 evidence: '''Search RID rules'', ''Search grouped RID'', ''Export RID rules'' under /nebula/v1/rid/rules' reason: Remote Intrusion Detection rules and their hit records are intrusion detection telemetry, squarely threat detection and response for the protected estate. - tag: AI Detection & Response spec_file: malwarebytes-ai-detection-response-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.78 evidence: POST /nebula/v1/aidr/rules Create AIDR rule; POST /nebula/v1/aidr/tools/search Search AI tools reason: AIDR (AI Detection & Response) rule management and AI-tool discovery within ThreatDown endpoint security console — a detection/response control surface, so Cybersecurity Management, threat detection & response. Some ambiguity on the exact sub-capability (preventive control vs detection), hence 0.78. - tag: Device Control spec_file: malwarebytes-device-control-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.78 evidence: '''Create a device exclusion'', ''Search device control events'', ''Get excludable devices''' reason: Device control policy and event surface of an endpoint security product — a security control administered on endpoints. Maps to Cybersecurity Management at L1; no candidate L2 cleanly covers removable-device control. - tag: Email Protection spec_file: malwarebytes-email-protection-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.78 evidence: '''Create allow list entry'' at /email-protection/configurations/allow-list, ''Get 911 mailbox'', ''Add domains'' for email-protection integrations' reason: Configures email security filtering (allow lists, protected domains, reporting mailbox) — a security control administered for the tenant. L1 Cybersecurity Management; no L2 fits email gateway protection precisely. - tag: Case Management spec_file: malwarebytes-case-management-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.75 evidence: GET /nebula/v1/casemgmt/multiplexer/cases/events Get Case events; POST /nebula/v1/casemgmt/cases/search reason: Security operations case handling inside the ThreatDown console (cases, comments, events, actions, metrics) supporting 'advanced analysis on Detections of Malware, Ransomware, Exploits' — i.e. SOC/incident response workflow. Mapped to Threat Detection & Response Management; slight chance it is intended as customer-support ticketing, hence 0.75. - tag: Content Filtering spec_file: malwarebytes-content-filtering-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: POST /nebula/v1/content-filtering Create content filtering rule; GET /nebula/v1/content-filtering/blockpage Get DNS BlockPage Settings reason: DNS/web content filtering rules, categories, block pages and global exclusions — a preventive endpoint/network security control, so Cybersecurity Management at L1. No candidate L2 matches web filtering specifically, so L2 left null. - tag: Sandbox spec_file: malwarebytes-sandbox-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.75 evidence: '''Upload file to the sandbox'', ''Search the sandbox submission results''' reason: Detonation of suspect files in a sandbox and retrieval of analysis verdicts is malware analysis supporting detection and incident response. - tag: App Block spec_file: malwarebytes-app-block-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.72 evidence: POST /nebula/v1/app-block/rules Create App Block Rule; POST /nebula/v1/app-block/activity Search app block activity reason: Application blocking rules, rulesets, settings and blocked-activity search on managed endpoints — an endpoint security preventive control. Clearly Cybersecurity Management at L1; no candidate L2 cleanly covers application control, so L2 left null. - tag: Endpoints spec_file: malwarebytes-endpoints-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.72 evidence: '''All suspicious activity of an endpoint'' (GET /nebula/v1/endpoints/{id}/sa), ''Get endpoint agent info'', ''Search endpoints''' reason: Manages the fleet of security-agent-protected endpoints including their suspicious activity — endpoint security administration. Some overlap with IT operations/asset management keeps confidence moderate. - tag: MDR spec_file: malwarebytes-mdr-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.72 evidence: '"Configure managed settings", "Get site MDR settings", POST /nebula/v1/mdr/config' reason: MDR = Managed Detection and Response for the endpoint estate; these operations configure that managed detection/response service per site. Operations are configuration-only, so confidence is moderate. - tag: OS Patches spec_file: malwarebytes-os-patches-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.7 evidence: '"Search OS Patches", "Export OS Patches", POST /nebula/v1/os-patches/search-groupby' reason: Visibility and reporting over operating-system patch state across managed endpoints — patch/vulnerability remediation tracking within an endpoint security product. Read/export only, so not maximal confidence. - tag: Subscriptions spec_file: malwarebytes-subscriptions-api-openapi.yml capability_id: BC-4240 capability_id_l1: BC-4240 capability_name: Subscription Lifecycle Management confidence: 0.7 evidence: '''Create a new subscription for a site'', ''Get entitlements'', ''Get usage'', ''Get account available subscriptions'', ''[v2 - À la carte] Update a site''s current subscription''' reason: The bulk of the surface manages commercial subscriptions and entitlements per customer site across create/modify/delete, i.e. subscription lifecycle. Confidence held back because the tag also mixes in outbound webhook subscription operations ('Update webhook subscription'), so no single L2 is safe.