The following endpoints are available in the current release:
Authentication—Sends POST requests to authenticate API calls. For more information, see Authentication.
Alerts—Queries your appliance for alert information. Also acknowledges alerts that have been reviewed. For more information, see Alerts.
Alerts—Queries the Central Management System appliance for alert information. For more information, see Alerts.
Events—Retrieves Multi-Vector Virtual Execution (MVX) correlated Intrusion Prevention System (IPS) event data from the Network Security appliance managed by your Central Management System appliance. For more information, see Events.
Email Quarantine—Lists, downloads, releases, or deletes quarantined emails. For more information, see Email quarantine management.
Emails Allowed and Blocked—Creates, updates, and deletes allowed and blocked lists for email analysis. For more information, see Emails allowed and blocked .
Reports and Statistics—Retrieves reports from the Trellix appliances. For more information, see Reports and statistics.
Submission—Submits files and URLs for detailed analysis to a Malware Analysis (AX) or Intelligent Virtual Execution (IVX) appliance, which returns a detailed report. For more information, see Submitting malware objects or IVX API Endpoints.
ATI—Retrieves Advanced Threat Intelligence details for any alert. For more information, see Retrieving ATI details.
Network Security Management Interface—The Network Security management interface allows you to configure DNS server addresses, domain names, hostnames, and IPv6 attributes. For more information, see Management interface .
Network Security Inline Operational Modes—The Network Security inline operational modes can be configured for a number of possible types of user input and validation. For more information, see Network security inline operational modes .
Port Mirroring—The Port Mirroring API allows you to read and update the port mirror configurations. For more information, see Port mirroring .
Custom IOCs—Adds, lists, updates, deletes, or downloads files with custom indicators of compromise (IOCs). For more information, see Custom IOCs .
Certificate Management—Adds, lists, updates, deletes, or downloads files with custom indicators of compromise (IOCs). For more information, see Certificate management.
Cluster Management—The MVX Cluster Management API provides a highly available and scalable MVX cluster management service. See Cluster management.
Logging Out—Ends the authenticated session between the remote server and your appliance. For more information, see Logging out.