generated: '2026-08-04' method: searched source: >- npm registry search, PyPI, pkg.go.dev, RubyGems, NuGet, crates.io, Packagist, github.com/malwarebytes, github.com/ThreatDown, and the ThreatDown support portal summary: >- Malwarebytes ships NO first-party client SDK for the ThreatDown Nebula or OneView APIs in any language. The support portal teaches the API through copy-paste code examples (Ruby, PowerShell, Python, JavaScript) rather than a library. The packages Malwarebytes does publish are internal-tooling open source unrelated to the ThreatDown API surface. Every ThreatDown API client on a public registry is third-party. first_party_sdk_for_api: false sdk_gap: >- 440 Nebula operations and 401 OneView operations, OAuth2 client-credentials token exchange, cursor pagination and HMAC webhook verification are all left for each integrator to hand-roll. A single official client library in one language would be the highest-leverage developer-experience investment on this API. packages: - name: ghas-cli language: python registry: PyPI url: https://pypi.org/project/ghas-cli/ repository: https://github.com/Malwarebytes/ghas-cli official: true description: CLI utility to deploy at scale and interact with GitHub Advanced Security. license: MIT relates_to_threatdown_api: false note: >- Genuinely first-party (published from a malwarebytes.com maintainer address) but it is internal security-engineering tooling for GitHub Advanced Security, not a client for the ThreatDown API. - name: mbvpn-linux language: go registry: github url: https://github.com/malwarebytes/mbvpn-linux official: true description: Linux client for Malwarebytes VPN. license: Apache-2.0 relates_to_threatdown_api: false - name: purl-license-checker language: python registry: github url: https://github.com/malwarebytes/purl-license-checker official: true description: Retrieve licenses for purl documented dependencies. license: MIT relates_to_threatdown_api: false - name: homebrew-tap language: ruby registry: homebrew url: https://github.com/malwarebytes/homebrew-tap official: true description: Malwarebytes Homebrew tap for their open-source tooling. relates_to_threatdown_api: false third_party: - name: n8n-nodes-threatdown language: javascript registry: npm url: https://www.npmjs.com/package/n8n-nodes-threatdown official: false description: n8n community node for the ThreatDown Nebula API by Malwarebytes. version_seen: 0.1.1 note: community-maintained workflow node, not published by Malwarebytes - name: threatdownnebula language: python registry: github url: https://github.com/splunk-soar-connectors/threatdownnebula official: false description: >- Splunk SOAR connector integrating with the ThreatDown Nebula API for prevention, detection, remediation and forensics endpoint management. note: published by Splunk, not by Malwarebytes registries_checked: - registry: npm query: threatdown, malwarebytes, nebula first_party_api_client: false - registry: PyPI query: threatdown, malwarebytes, nebula first_party_api_client: false note: >- PyPI "nebula-client" and "NebulaPythonSDK" are unrelated projects (the Nebula container orchestrator / NebulaGraph), NOT ThreatDown Nebula. Name collision only. - registry: RubyGems first_party_api_client: false note: >- The archived malwarebytes/FuelSDK-Ruby and malwarebytes/restforce repositories are forks of third-party SDKs (Salesforce Marketing Cloud, Salesforce REST), not ThreatDown API clients. - registry: NuGet first_party_api_client: false - registry: pkg.go.dev first_party_api_client: false - registry: crates.io first_party_api_client: false - registry: Packagist first_party_api_client: false code_examples_in_lieu_of_sdk: - language: ruby url: https://support.threatdown.com/hc/en-us/articles/5808694795539-Nebula-API-example-using-Ruby api: nebula - language: ruby url: https://support.threatdown.com/hc/en-us/articles/29181441075475-OneView-API-example-using-Ruby api: oneview - language: powershell url: https://support.threatdown.com/hc/en-us/articles/30352080226579-Nebula-API-examples-using-PowerShell api: nebula - language: powershell url: https://support.threatdown.com/hc/en-us/articles/30353265633939-OneView-API-examples-using-PowerShell api: oneview