Overview
This endpoint performs a global action on a threat record itself, rather than on an endpoint. Provide an action (e.g., "DismissThreat") and a threatId to create a job that applies the change system-wide. Use this API to manage the lifecycle of a threat detection. It is primarily used to globally dismiss a threat that has been investigated and confirmed as a false positive. This API helps reduce alert fatigue by providing a programmatic way to close out irrelevant or benign detections, keeping analyst queues focused on active threats.
Authentication
Authentication type: Bearer Token, API Key.
You can create a token using client credentials obtained through the developer portal. The API Key (x-api-key) is provided in your onboarding email or on the API Access Management page.
Path (or URL)
POST https://{Trellix EDR_gateway_URL}/edr/v2/remediation/global-threat
Request
Request headers
Authorization: Bearer <your_bearer_token> Content-Type: application/vnd.api+json x-api-key: <your_api_key> X-MVEDR-Source: <source_region> X-Trace-Id: <trace_id_value>
Authorization: This header is used to authenticate your request. You need to replace
<your_bearer_token>with the actual token you generate.Content-Type: This header tells the server that the request body format is
json:api. Even though this specific call has no request body, the API requires this header.x-api-key: This is a custom header required by the Trellix API for authentication. You'll need to replace
<your_api_key>with the key from your onboarding email or the API Access Management page.X-MVEDR-Source (Optional): Indicates the region or source of the event data using the format
xdrsoar:<region>. For example,xdrsoar:us-west.X-Trace-Id (Optional): Supports tracking headers trace using the format
workflow-id:task/step-id. For example,execution-id:task/step-id.
Request body
Example:
{
"data": {
"type": "globalThreatRemediation",
"attributes": {
"action": "DismissThreat",
"threatActionArguments": {
"threatId": "string"
}
}
}
}Request parameters
There are no request parameters.
Response
Response example
{
"data": {
"type": "globalThreatRemediation",
"id": "gtr-36267",
"attributes": {
"status": "COMPLETED"
},
"links": {
"self": "/edr/v2/remediation/queue-jobs/gtr-36267"
}
}
}Response codes
Status | Response | Description |
|---|---|---|
201 | Created | Your request was successful, and a new resource was created as a result. Your request was successful, and a new resource was created. The response includes details such as the resource ID, which you can use to track or manage the resource. |
400 | Bad request | The server couldn't understand your request, likely due to a syntax error or an invalid parameter. |
401 | Access denied request | Your request was rejected because it lacks valid authentication credentials. Check your API key and token. |
403 | Forbidden | You are not authorized to access this resource. While your credentials may be valid, you don't have the necessary permissions. |
404 | Not Found | The specific resource or endpoint you requested does not exist. |
415 | Unsupported Media Type | The server rejected your request because the data format |
429 | Too Many Requests | You've exceeded the rate limit by sending too many requests in a short period. The |
500 | Internal Server Error | Something went wrong on the server's end. This is not an issue with your request. |