openapi: 3.1.0 info: title: McAfee ePO Alarms Threat Events API description: McAfee ePolicy Orchestrator (ePO) REST API for centralized security management, including system management, policy assignment, task scheduling, query execution, and threat event retrieval across managed endpoints. version: '5.10' contact: name: McAfee Support url: https://www.mcafee.com/enterprise/en-us/support.html termsOfService: https://www.mcafee.com/enterprise/en-us/about/legal/terms-of-use.html servers: - url: https://{epo-server}:8443/remote description: McAfee ePO Server variables: epo-server: default: your-epo-server description: Hostname or IP of the ePO server security: - basicAuth: [] tags: - name: Threat Events description: Retrieve threat event data from managed endpoints paths: /detectedsystem.find: get: operationId: detectedsystemFind summary: McAfee Find threat events description: Search for detected threat events across managed systems, returning details about malware detections, intrusion attempts, and other security events. tags: - Threat Events parameters: - name: searchText in: query required: false description: Search text to filter threat events schema: type: string - $ref: '#/components/parameters/outputType' responses: '200': description: List of threat events content: application/json: schema: type: array items: $ref: '#/components/schemas/ThreatEvent' '401': description: Authentication failed components: parameters: outputType: name: :output in: query required: false description: Output format for the response. Defaults to JSON when not specified. schema: type: string enum: - json - xml - terse - verbose default: json schemas: ThreatEvent: type: object properties: AutoID: type: integer description: Auto-incremented event ID DetectedUTC: type: string format: date-time description: Detection time in UTC ReceivedUTC: type: string format: date-time description: Time the event was received by ePO ThreatName: type: string description: Name of the detected threat ThreatType: type: string description: Type of threat (e.g., virus, trojan, PUP) ThreatSeverity: type: integer description: Severity level of the threat ThreatActionTaken: type: string description: Action taken on the threat (e.g., cleaned, deleted, quarantined) SourceHostName: type: string description: Hostname of the system where the threat was detected SourceIPV4: type: string description: IPv4 address of the source system TargetFileName: type: string description: File path of the affected file AnalyzerName: type: string description: Name of the product that detected the threat AnalyzerVersion: type: string description: Version of the detecting product securitySchemes: basicAuth: type: http scheme: basic description: HTTP Basic authentication using ePO administrator credentials. Credentials are transmitted as a Base64-encoded username:password pair. externalDocs: description: McAfee ePO Web API Reference Guide url: https://docs.mcafee.com/bundle/epolicy-orchestrator-web-api-reference-guide