Malwarebytes
Scan and Remediate threats on endpoints in the Malwarebytes cloud.
- Category
- Endpoint
- Pack
- Malwarebytes
Configuration parameters
- accountid — Account ID (required)
- clientid — Client ID (required)
- clientsecret — Client Secret (required)
- region — Region (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- Fetch_Event_List — Fetch Event List
- rtp_threat_category — RTP Detections Threat Category
- suspicious_activity_severity — Suspicious Activity Severity
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- email — E-Mail
- company_name — Company Name
Commands (15)
- malwarebytes-close-sa-incident — Close Suspicious Activity Incident in Malwarebytes Cloud. Use malwarebytes-get-sa-activities command to get machine and detection ID.
- malwarebytes-deisolate-endpoint — Initiate Deisolation action on an endpoint based on IP or Hostname. This action deisolate an endpoint by Process, Network and Desktop.
- malwarebytes-get-job-status — Lists scan/isolation/deisolation status of the endpoint for the scan/isolation/deisolation initated from Demisto.
- malwarebytes-get-sa-activities — Lists all suspicious activities from hostname value and list all the hostnames from path of file.
- malwarebytes-get-scan-detections — Lists detections from an endpoint for the scans initiated from Demisto.
- malwarebytes-isolate-desktop — Initiate Desktop Isolation action on an endpoint based on IP or Hostname.
- malwarebytes-isolate-endpoint — Initiate Isolation action on an endpoint based on IP or Hostname. This action isolate an endpoint by Process, Network and Desktop.
- malwarebytes-isolate-network — Initiate Network Isolation action on an endpoint based on IP or Hostname.
- malwarebytes-isolate-process — Initiate Process Isolation action on an endpoint based on IP or Hostname.
- malwarebytes-list-endpoint-info — Lists more granular information about an endpoint.
- malwarebytes-list-endpoints — List all/online/offline endpoints available in the Malwarebytes Cloud.
- malwarebytes-open-sa-incident — Open Suspicious Activity for investigation in Malwarebytes Cloud. Use malwarebytes-get-sa-activities command to get machine and detection ID.
- malwarebytes-remediate-sa-incident — Remediate Suspicious Activity from Malwarebytes Cloud. Use malwarebytes-get-sa-activities command to get machine and detection ID.
- malwarebytes-scan-and-remediate — Initiate Scan and Remediate action on an endpoint based on IP or Hostname.
- malwarebytes-scan-and-report — Initiate Scan and report action on an endpoint based on IP or Hostname.