POST - Threat Remediation

Prev Next

Overview

This endpoint initiates a remediation action against a specified threat on one or more endpoints. By defining an action, threatId, and a list of affectedHostIds, you can trigger a response like stopping and removing a malicious process. The API creates an asynchronous job and returns an ID for tracking its progress and final status. Use this API as the action component in a SOAR playbook to automatically contain threats upon detection, or to apply a remediation action across many endpoints for a scaled response. This API closes the loop from detection to response, enabling automated containment at scale to dramatically reduce threat impact.

Authentication

Authentication type: Bearer Token, API Key.

You can create a token using client credentials obtained through the developer portal. The API Key (x-api-key) is provided in your onboarding email or on the API Access Management page.

Path (or URL)

POST https://{Trellix EDR_gateway_URL}/edr/v2/remediation/threat

Request

Request headers
Authorization: Bearer <your_bearer_token>
Content-Type: application/vnd.api+json
x-api-key: <your_api_key>
X-MVEDR-Source: <source_region>
X-Trace-Id: <trace_id_value>
  • Authorization: This header is used to authenticate your request. You need to replace <your_bearer_token> with the actual token you generate.

  • Content-Type: This header tells the server that the request body format is json:api. Even though this specific call has no request body, the API requires this header.

  • x-api-key: This is a custom header required by the Trellix API for authentication. You'll need to replace <your_api_key> with the key from your onboarding email or the API Access Management page.

  • X-MVEDR-Source (Optional): Indicates the region or source of the event data using the format xdrsoar:<region>. For example, xdrsoar:us-west.

  • X-Trace-Id (Optional): Supports tracking headers trace using the format workflow-id:task/step-id. For example, execution-id:task/step-id.

Request body

Example:

{
  "data": {
    "type": "threatRemediation",
    "attributes": {
      "action": "StopAndRemove",
      "threatId": "3500",
      "processName": "Keep-Running.exe",
      "affectedHostIds": [
        "99848",
        "99849"
      ]
    }
  }
}
Request parameters

There are no request parameters.

Response

Response example
{
  "data": {
    "type": "threatRemediation",
    "id": "tr-5432",
    "attributes": {
      "success": [
        {
          "status": "200",
          "message": "in-progress",
          "affectedHostIds": [
            "99848"
          ]
        }
      ],
      "failed": [
        {
          "status": "404",
          "message": "Not Found",
          "affectedHostIds": [
            "99849"
          ]
        }
      ]
    },
    "links": {
      "self": "/edr/v2/remediation/queue-jobs/tr-5432"
    }
  }
}

Response codes

Status

Response

Description

207

Created

Your request to create a remediation job was accepted and is being processed. The response body will detail which parts of the submission succeeded or failed.

400

Bad request

The server couldn't understand your request, likely due to a syntax error or an invalid parameter.

401

Access denied request

Your request was rejected because it lacks valid authentication credentials. Check your API key and token.

403

Forbidden

You are not authorized to access this resource. While your credentials may be valid, you don't have the necessary permissions.

404

Not Found

The specific resource or endpoint you requested does not exist.

415

Unsupported Media Type

The server rejected your request because the data format (Content-Type) is not supported.

429

Too Many Requests

You've exceeded the rate limit by sending too many requests in a short period. The Retry-After header in the response will tell you how long to wait before trying again.

500

Internal Server Error

Something went wrong on the server's end. This is not an issue with your request.