Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
minLevel2
maxLevel2
typeflat

Overview

Malwarebytes Nebula is a cloud-hosted security operations platform that allows you to manage control of any malware or ransomware incident

Devo collector features

Feature

Details

Allow parallel downloading (multipod)

Not allowed

Running environments

Collector server

On-premise

Populated Devo events

Table

Flattening preprocessing

No

Minimum configuration required for basic pulling

...

Setting

Details

client_id

Credential client ID.

client_secret

Credential client secret.

account_id

Credential account ID.

api_base_url

Credential API base url.

Info

See the Accepted authentication methods section to verify what settings are required based on the desired authentication method.

Overview

Malwarebytes Nebula is a cloud-hosted security operations platform that allows you to manage control of any malware or ransomware incident

Devo collector features

...

Feature

...

Details

...

Allow parallel downloading (multipod)

...

Not allowed

Allowed

...

Running environments

...

Collector server

On-premise

...

Populated Devo events

...

Table

...

Flattening preprocessing

...

No

Data sources

Data Source

Description

API Endpoint

Collector service name

Devo Table

Available from release

Notifications

Malwarebytes Nebula can notify you when certain events occur, such as when real-time protection or scheduled scans detect threats, or if a new endpoint registers to your console.

<base_url>/notifications/subscriptions

notifications

my.app.nebula.notifications

v1.0.0

Detection

The Detections section in Malwarebytes Nebula displays information on all threats, and potential threats, with the action taken for each item found on endpoints in your environment

<base_url>/detections

detections

my.app.nebula.detections

v1.0.0

Events

Event is a general term for a threat that has occurred, remediation or other action taken on a threat, and other endpoint-related activity. 

<base_url>/events

events

my.app.nebula.events

v1.0.0

Vulnerability Management

shows vulnerabilities for installed software and operating systems on managed endpoints. 

<base_url>/cve/export

<base_url>/cve/{id}

vulnerability_management

my.app.nebula.vulnerabilitymanagement

v1.0.0

Suspicious activity 

Suspicious Activity Monitoring is a feature included in Malwarebytes Endpoint Detection and Response

<base_url>/sa

suspicious_activity

my.app.nebula.suspiciousactivity

v1.0.0

DNS Logs Data

Logs of Dns data

<base_url>/dns

dns_log_data

my.app.nebula.dnslogdata

v1.0.0

...

Rw ui steps macro
Rw step

Use your email and password to login into Malware Nebula Cloud.

Image RemovedImage Added
Rw step

Go to Settings → API & Integrations → Add.

Rw step

Provide necessary access to the credentials.

Note

Credential only shows once

Please, note down your credentials as they only show once.

Rw step

A new web client will be created.

Image RemovedImage Added

Anchor
Accepted-authentication-methods
Accepted-authentication-methods

...

Release

Released on

Release type

Details

Recommendations

v1.0.0

12 May 2023

New collector

-

-