Overview
This endpoint initiates a remediation action against a specified threat on one or more endpoints. By defining an action, threatId, and a list of affectedHostIds, you can trigger a response like stopping and removing a malicious process. The API creates an asynchronous job and returns an ID for tracking its progress and final status. Use this API as the action component in a SOAR playbook to automatically contain threats upon detection, or to apply a remediation action across many endpoints for a scaled response. This API closes the loop from detection to response, enabling automated containment at scale to dramatically reduce threat impact.
Authentication
Authentication type: Bearer Token, API Key.
You can create a token using client credentials obtained through the developer portal. The API Key (x-api-key) is provided in your onboarding email or on the API Access Management page.
Path (or URL)
POST https://{Trellix EDR_gateway_URL}/edr/v2/remediation/threat
Request
Request headers
Authorization: Bearer <your_bearer_token> Content-Type: application/vnd.api+json x-api-key: <your_api_key> X-MVEDR-Source: <source_region> X-Trace-Id: <trace_id_value>
Authorization: This header is used to authenticate your request. You need to replace
<your_bearer_token>with the actual token you generate.Content-Type: This header tells the server that the request body format is
json:api. Even though this specific call has no request body, the API requires this header.x-api-key: This is a custom header required by the Trellix API for authentication. You'll need to replace
<your_api_key>with the key from your onboarding email or the API Access Management page.X-MVEDR-Source (Optional): Indicates the region or source of the event data using the format
xdrsoar:<region>. For example,xdrsoar:us-west.X-Trace-Id (Optional): Supports tracking headers trace using the format
workflow-id:task/step-id. For example,execution-id:task/step-id.
Request body
Example:
{
"data": {
"type": "threatRemediation",
"attributes": {
"action": "StopAndRemove",
"threatId": "3500",
"processName": "Keep-Running.exe",
"affectedHostIds": [
"99848",
"99849"
]
}
}
}Request parameters
There are no request parameters.
Response
Response example
{
"data": {
"type": "threatRemediation",
"id": "tr-5432",
"attributes": {
"success": [
{
"status": "200",
"message": "in-progress",
"affectedHostIds": [
"99848"
]
}
],
"failed": [
{
"status": "404",
"message": "Not Found",
"affectedHostIds": [
"99849"
]
}
]
},
"links": {
"self": "/edr/v2/remediation/queue-jobs/tr-5432"
}
}
}
Response codes
Status | Response | Description |
|---|---|---|
207 | Created | Your request to create a remediation job was accepted and is being processed. The response body will detail which parts of the submission succeeded or failed. |
400 | Bad request | The server couldn't understand your request, likely due to a syntax error or an invalid parameter. |
401 | Access denied request | Your request was rejected because it lacks valid authentication credentials. Check your API key and token. |
403 | Forbidden | You are not authorized to access this resource. While your credentials may be valid, you don't have the necessary permissions. |
404 | Not Found | The specific resource or endpoint you requested does not exist. |
415 | Unsupported Media Type | The server rejected your request because the data format |
429 | Too Many Requests | You've exceeded the rate limit by sending too many requests in a short period. The |
500 | Internal Server Error | Something went wrong on the server's end. This is not an issue with your request. |