How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Malwarebytes ITDR API

The ITDR API from Malwarebytes — 29 operation(s) for itdr.

Malwarebytes ITDR API is one of 52 APIs that Malwarebytes publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include ITDR. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 39 operations across 29 paths. It is described by OpenAPI 3.2.0, at version 1.0.0.

Requests are made against a single base URL, https://api.threatdown.com.

39 operations 29 paths 0 schemas 5 DELETE10 GET19 POST5 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0.0
Base URL
https://api.threatdown.com
Authentication
OAuth 2.0, HTTP Bearer
Resource Areas
1

Authentication & Security 2

Malwarebytes ITDR API declares 2 security schemes for authenticating requests. It supports OAuth 2.0 (client_credentials) using the clientCredentials flow, exposing 3 scopes. It accepts HTTP bearer tokens (user_permissions).

Paths & Operations 39

Across 29 paths, the API surfaces 39 operations — 5 DELETE, 10 GET, 19 POST, 5 PUT. Each is listed below with its method, path, parameters, and response codes.

ITDR 39
POST
/nebula/v1/itdr/config
Post ITDR Config
api.nebula.itdr.config.post 2 params body → 200
DELETE
/nebula/v1/itdr/darkweb-monitoring/identities
Remove ITDR Darkweb Monitoring Identities
api.nebula.itdr.darkweb.monitoring.identities.delete 2 params body → 200
GET
/nebula/v1/itdr/darkweb-monitoring/identities
Get ITDR Darkweb Monitoring Identities
api.nebula.itdr.darkweb.monitoring.identities.get 2 params → 200
POST
/nebula/v1/itdr/darkweb-monitoring/identities
Add ITDR Darkweb Monitoring Identities
api.nebula.itdr.darkweb.monitoring.identities.post 2 params body → 200
DELETE
/nebula/v1/itdr/login-restrictions/groups
Delete ITDR Login Restriction Group
api.nebula.itdr.login.restrictions.group.delete 2 params body → 200
GET
/nebula/v1/itdr/login-restrictions/groups
Get ITDR Login Restriction Groups
api.nebula.itdr.login.restrictions.groups.get 2 params → 200
POST
/nebula/v1/itdr/login-restrictions/groups
Post ITDR Login Restriction Group
api.nebula.itdr.login.restrictions.groups.post 2 params body → 200
DELETE
/nebula/v1/itdr/identities/posture-exclusions
Remove ITDR Identity Posture Exclusions
api.nebula.itdr.identities.posture-exclusions.delete 2 params body → 200
POST
/nebula/v1/itdr/identities/posture-exclusions
Create ITDR Identity Posture Exclusions
api.nebula.itdr.identities.posture-exclusions.post 2 params body → 200
DELETE
/nebula/v1/itdr/config/{type}
Delete ITDR Config
api.nebula.itdr.config.delete 3 params → 200
DELETE
/nebula/v1/itdr/tags
Delete ITDR Predefined Identity Tag
api.nebula.itdr.tags.delete 2 params body → 200
GET
/nebula/v1/itdr/tags
Get ITDR Predefined Identity Tags
api.nebula.itdr.tags.get 2 params → 200
POST
/nebula/v1/itdr/tags
Create ITDR Predefined Identity Tag
api.nebula.itdr.tags.post 2 params body → 200
GET
/nebula/v1/itdr/config/status
Get all ITDR Config Status
api.nebula.itdr.config.status.get 2 params → 200
GET
/nebula/v1/itdr/login-restrictions/countries
Get ITDR Countries
api.nebula.itdr.countries.get 2 params → 200
GET
/nebula/v1/itdr/config/identity-protection-setting
Get ITDR Identity Protection Setting
api.nebula.itdr.identity.protection.setting.get 2 params → 200
PUT
/nebula/v1/itdr/config/identity-protection-setting
Set ITDR Identity Protection Setting
api.nebula.itdr.identity.protection.setting.put 2 params body → 200
GET
/nebula/v1/itdr/licensing/config
Get ITDR Licensing Details
api.nebula.itdr.licensing.config.get 2 params → 200
GET
/nebula/v1/itdr/login-restrictions/groups/{group_id}
Get ITDR Login Restriction Group
api.nebula.itdr.login.restrictions.group.get 3 params → 200
PUT
/nebula/v1/itdr/login-restrictions/groups/{group_id}
Put ITDR Login Restriction Group
api.nebula.itdr.login.restrictions.group.put 3 params body → 200
GET
/nebula/v1/itdr/login-restrictions/groups/{group_id}/members
Get ITDR Login Restriction Group Members
api.nebula.itdr.login.restrictions.group.members.get 3 params → 200
PUT
/nebula/v1/itdr/login-restrictions/groups/{group_id}/members
Put ITDR Login Restriction Group Members
api.nebula.itdr.login.restrictions.group.members.put 3 params body → 200
GET
/nebula/v1/itdr/config/all
Get all ITDR Configs
api.nebula.itdr.config.all.get 2 params → 200
POST
/nebula/v1/itdr/identities/export
Export ITDR Identities
api.nebula.itdr.identities.export.post 2 params body → 200
POST
/nebula/v1/itdr/graphapi/respond-action
Post ITDR Entra Respond Action
api.nebula.itdr.graphapi.respond.action.post 2 params body → 200
POST
/nebula/v1/itdr/graphapi/respond-actions
Post ITDR Entra Respond Actions
api.nebula.itdr.graphapi.respond.actions.post 2 params body → 200
POST
/nebula/v1/itdr/graphapi/respond-service-actions
Post ITDR Entra Service Respond Actions
api.nebula.itdr.graphapi.respond.service.actions.post 2 params body → 200
POST
/nebula/v1/itdr/okta/respond-action
Post ITDR Okta Respond Action
api.nebula.itdr.okta.respond.action.post 2 params body → 200
POST
/nebula/v1/itdr/okta/respond-actions
Post ITDR Okta Respond Actions
api.nebula.itdr.okta.respond.actions.post 2 params body → 200
POST
/nebula/v1/itdr/okta/respond-service-actions
Post ITDR Okta Service Respond Actions
api.nebula.itdr.okta.respond.service.actions.post 2 params body → 200
POST
/nebula/v1/itdr/posture/summary
Get ITDR Posture Summary
api.nebula.itdr.posture.summary.post 2 params body → 200
POST
/nebula/v1/itdr/{provider}/respond-service-action
Post ITDR Service Respond Action
api.nebula.itdr.provider.respond.service.action.post 3 params body → 200
POST
/nebula/v1/itdr/identities/search
Search ITDR Identities
api.nebula.itdr.identities.search.post 2 params body → 200
POST
/nebula/v1/itdr/identities/search-groupby
Search ITDR Identities GroupBy
api.nebula.itdr.identities.search.groupby.post 2 params body → 200
POST
/nebula/v1/itdr/login-restrictions/groups/search
Search ITDR Login Restriction Groups
api.nebula.itdr.login.restrictions.groups.search.post 2 params body → 200
POST
/nebula/v1/itdr/identities/search-serviceinfo
Search ITDR Service Info
api.nebula.itdr.identities.search.serviceinfo.post 2 params body → 200
POST
/nebula/v1/itdr/identities/search-userinfo
Search ITDR User Info
api.nebula.itdr.identities.search.userinfo.post 2 params body → 200
PUT
/nebula/v1/itdr/identities/tags
Update ITDR Identity Analyst Tags
api.nebula.itdr.identities.tags.put 2 params body → 200
PUT
/nebula/v1/itdr/identities/protection-enabled
Put ITDR Identities Protection Status
api.nebula.itdr.identities.protection.enabled.put 2 params body → 200

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

malwarebytes-itdr-api-openapi.yml Raw ↑

Other APIs Malwarebytes publishes across the network.

Malwarebytes Account API
Malwarebytes AI Detection & Response API
Malwarebytes App Block API
Malwarebytes Assets API
Malwarebytes Authentication API
Malwarebytes Case Management API
Malwarebytes Content Filtering API
Malwarebytes Copilot API
Malwarebytes Detections API
Malwarebytes Device Control API
Malwarebytes DNS API
Malwarebytes DNS Logs API
Where this information came from

This is an independent, third-party profile of Malwarebytes ITDR API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.