generated: '2026-08-04' method: probed source: live GET probes of /.well-known/* on every Malwarebytes / ThreatDown host summary: >- Malwarebytes publishes exactly one well-known document: an RFC 9116 security.txt, served identically from www.malwarebytes.com and the ThreatDown console host. No OpenID Connect discovery document, no RFC 8414 OAuth authorization-server metadata, no RFC 9727 api-catalog, no ai-plugin.json and no A2A agent card is published on any host. The OAuth2 client-credentials token endpoints (/oauth2/token and /oneview/oauth2/token on api.threatdown.com) are documented only in the OpenAPI definitions — there is no discovery metadata pointing at them. caution: >- cloud.malwarebytes.com (which redirects to cloud.threatdown.com) is an Angular single-page app whose catch-all route answers HTTP 200 with the same 3,184-byte HTML shell for EVERY /.well-known/* path. Those 200s are NOT documents and are recorded below as html_spa_catchall. Only text/plain and application/json bodies that parse are treated as hits. hosts_probed: - www.malwarebytes.com - malwarebytes.com - cloud.malwarebytes.com - api.threatdown.com - threatdown.com - www.threatdown.com - support.threatdown.com paths: - path: /.well-known/security.txt host: www.malwarebytes.com url: https://www.malwarebytes.com/.well-known/security.txt status: 200 content_type: text/plain; charset=utf-8 bytes: 198 result: hit file: well-known/malwarebytes-security.txt - path: /.well-known/security.txt host: cloud.malwarebytes.com url: https://cloud.malwarebytes.com/.well-known/security.txt status: 200 content_type: text/plain bytes: 198 result: hit note: byte-identical to the www.malwarebytes.com copy - path: /.well-known/security.txt host: threatdown.com status: 404 result: miss - path: /.well-known/security.txt host: support.threatdown.com status: 404 result: miss - path: /.well-known/openid-configuration hosts: - www.malwarebytes.com - api.threatdown.com - threatdown.com status: 404 result: miss - path: /.well-known/oauth-authorization-server host: cloud.malwarebytes.com status: 200 content_type: text/html bytes: 3184 result: html_spa_catchall note: not a document; Angular index.html returned for every unmatched route - path: /.well-known/oauth-protected-resource host: cloud.malwarebytes.com status: 200 content_type: text/html bytes: 3184 result: html_spa_catchall - path: /.well-known/api-catalog host: cloud.malwarebytes.com status: 200 content_type: text/html bytes: 3184 result: html_spa_catchall - path: /.well-known/ai-plugin.json hosts: - www.malwarebytes.com - threatdown.com - api.threatdown.com status: 404 result: miss - path: /.well-known/agent-card.json hosts: - www.malwarebytes.com - threatdown.com - www.threatdown.com - support.threatdown.com - api.threatdown.com status: 404 result: miss - path: /.well-known/agent.json hosts: - www.malwarebytes.com - threatdown.com - api.threatdown.com status: 404 result: miss - path: /llms.txt host: www.malwarebytes.com url: https://www.malwarebytes.com/llms.txt status: 200 content_type: text/plain; charset=utf-8 bytes: 7532 result: hit file: llms/malwarebytes-llms.txt - path: /llms.txt hosts: - threatdown.com - www.threatdown.com - support.threatdown.com status: 404 result: miss note: >- The published llms.txt covers only the CONSUMER malwarebytes.com estate and says so explicitly in its Scope Notes. The ThreatDown business properties that actually carry the API — threatdown.com, support.threatdown.com, api.threatdown.com — publish none. x-evidence: fetched: '2026-08-04' probe_method: GET, follow redirects, browser user-agent