ThreatDown by Malwarebytes
Identity & securityClient credentials
Monitor and respond to threats on endpoints managed in Malwarebytes ThreatDown Nebula: endpoints, detections, quarantine, events and scan or isolation jobs.
12 actions
| Action | Effect | Data handled | Scope |
|---|---|---|---|
| threatdown_get_accountReturns the Nebula account's id, name, license and subscription options | read | General | |
| threatdown_search_endpointsSearches managed endpoints by name, group, isolation or alert state, one page at a time | read | Personal data | |
| threatdown_get_endpointReturns one endpoint's details: host names, operating system, agent, group, policy, network addresses and alerts | read | Personal data | |
| threatdown_get_endpoint_statusReturns an endpoint's protection and connection status | read | General | |
| threatdown_list_suspicious_activityLists EDR suspicious activity found on one endpoint, newest first unless sorted otherwise | read | Personal data | |
| threatdown_search_detectionsSearches threat detections across endpoints by machine, status, category, threat name or scan time, one page at a time | read | Personal data | |
| threatdown_get_detectionReturns one detection with its threat, file path, endpoint and action taken | read | Personal data | |
| threatdown_list_quarantineLists quarantined items across endpoints, filtered by name, category, type or date | read | Personal data | |
| threatdown_list_eventsLists account events, such as detections, scans and agent changes, filtered by text, endpoint, time or severity | read | Personal data | |
| threatdown_list_groupsLists endpoint groups with their policy, optionally by name or parent group | read | General | |
| threatdown_issue_jobSends a job to one or more endpoints, such as a threat scan, isolation, release from isolation, reboot or protection update | write | General | |
| threatdown_get_jobReturns a job's command, target endpoint, state and result | read | General |