Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Setting

Details

client_id

Credential client ID.

client_secret

Credential client secret.

account_id

Credential account ID.

api_base_url

Credential API base url.

Info

See the Accepted authentication methods section to verify what settings are required based on the desired authentication method.

...

Data Source

Description

API Endpoint

Collector service name

Devo Table

Available from release

Notifications

Malwarebytes Nebula can notify you when certain events occur, such as when real-time protection or scheduled scans detect threats, or if a new endpoint registers to your console.

<base_url>/notifications/subscriptions

notifications

my.app.nebula.notifications

v1.0.0

Detection

The Detections section in Malwarebytes Nebula displays information on all threats, and potential threats, with the action taken for each item found on endpoints in your environment

<base_url>/detections

detections

my.app.nebula.detections

v1.0.0

Events

Event is a general term for a threat that has occurred, remediation or other action taken on a threat, and other endpoint-related activity. 

<base_url>/events

events

my.app.nebula.events

v1.0.0

Vulnerability Management

shows vulnerabilities for installed software and operating systems on managed endpoints. 

<base_url>/cve/export

<base_url>/cve/{id}

vulnerability_management

my.app.nebula.vulnerabilitymanagement

v1.0.0

Suspicious activity 

Suspicious Activity Monitoring is a feature included in Malwarebytes Endpoint Detection and Response

<base_url>/sa

suspicious_activity

my.app.nebula.suspiciousactivity

v1.0.0

DNS Logs Data

Logs of Dns data

<base_url>/dns

dns_log_data

my.app.nebula.dnslogdata

v1.0.0

For more information on how the events are parsed, visit our page.

Vendor setup

There are some steps you need to follow to run the collector.

Rw ui steps macro
Rw step

Use your email and password to login into Malware Nebula Cloud.

Image RemovedImage Added
Rw step

Go to Settings → API & Integrations → Add.

Rw step

Provide necessary access to the credentials.

Note

Credential only shows once

Please, note down your credentials as they only show once.

Rw step

A new web client will be created.

Image RemovedImage Added

Anchor
Accepted-authentication-methods
Accepted-authentication-methods

...