ThreatDown by Malwarebytes

Identity & securityClient credentials

Monitor and respond to threats on endpoints managed in Malwarebytes ThreatDown Nebula: endpoints, detections, quarantine, events and scan or isolation jobs.

12 actions

ActionEffectData handledScope
threatdown_get_accountReturns the Nebula account's id, name, license and subscription optionsreadGeneral
threatdown_search_endpointsSearches managed endpoints by name, group, isolation or alert state, one page at a timereadPersonal data
threatdown_get_endpointReturns one endpoint's details: host names, operating system, agent, group, policy, network addresses and alertsreadPersonal data
threatdown_get_endpoint_statusReturns an endpoint's protection and connection statusreadGeneral
threatdown_list_suspicious_activityLists EDR suspicious activity found on one endpoint, newest first unless sorted otherwisereadPersonal data
threatdown_search_detectionsSearches threat detections across endpoints by machine, status, category, threat name or scan time, one page at a timereadPersonal data
threatdown_get_detectionReturns one detection with its threat, file path, endpoint and action takenreadPersonal data
threatdown_list_quarantineLists quarantined items across endpoints, filtered by name, category, type or datereadPersonal data
threatdown_list_eventsLists account events, such as detections, scans and agent changes, filtered by text, endpoint, time or severityreadPersonal data
threatdown_list_groupsLists endpoint groups with their policy, optionally by name or parent groupreadGeneral
threatdown_issue_jobSends a job to one or more endpoints, such as a threat scan, isolation, release from isolation, reboot or protection updatewriteGeneral
threatdown_get_jobReturns a job's command, target endpoint, state and resultreadGeneral