This reference documents version 2.0 of the Web Services API. The following changes have been made since version 1.2:
When using the Alert Acknowledgment API, you must use the alert's UUID. The v1.2.0 version of this endpoint is unchanged and accepts either the alert infection ID or UUID.
The YARA rules endpoints are now supported on VX Series appliances.
The new
schema_compatibilityparameter for the Alert Acknowledgment API specifies XML and JSON content compatible with the upgraded schema. Omit this option if you are using an older schema and do not want schema compatibility.The Alert and Result response body of the Alert Request API has a new flag,
malicious, that indicates if a sample is malicious or not.
Changes in 2019.01:
The new Alert Details request gets details for a single alert.
The new System Current Health request returns the current system health status.
The new System Health History request returns the system health status for a given time period.
Changes in 2019.02:
The Statistics request has a new optional parameter
include_submission_stats.The v2.0.0 version of the Alerts Updated with ATI Details request is deprecated.
Admin users can now access Web service API.
The Events request has a new option to indicate whether to include all IPS events or MVX-correlated events only.
There are three new custom IOC endpoints:
List a YARA Rule
Download a YARA Rule File
Download a Custom Snort Rule File
Changes in 2019.03:
Added Email Quarantine endpoints.
Added a note to the Reports by Time request about using the
limitparameter with IPS report types.
Changes in 2019.03, revision 2:
The section on Submission Limits has been removed as it no longer applies.
Changes in 2020.1, revision 1:
Added Network Security IPS API endpoints.
Added Central Management System IPS API endpoints.
Changes in 2020.2, revision 1:
Added new URL argument options to
malware_typein the Filters table.Added cURL example for new
include_riskwareargument.
Changes in 2020.3, revision 1:
In the "Artifacts" section, password protection is now supported for the artifact zip archive. The default password is infected. This feature is disabled by default.
Changes in 2020.3, revision 2:
Added Emails Allowed and Blocked endpoints.
Added an
operation_typeparameter to the Request body of the "Add an Event Filter Request" page.Added default values for the
operation_typeparameter, on the "Add an Event Filter Request" page.
Changes in 2020.3, revision 3:
Removed outdated "timeout" option for VX Series on the "Submit Malware Object Request" page.
Changed
Submission_KeytoSubmission_uuidfor VX Series on the "Submission Results Request" and "Submission Status Request" pages.
Changes in 2021.1, revision 1:
Added Alert Notification Settings endpoints.
Added Network Security Management Interface endpoints.
Added Network Security Inline Operational Modes endpoints.
Added Port Mirroring endpoints.
Added Certificate Management endpoints.
Changes in 2021.1, revision 5:
Added Read Group Information endpoints.
Added Read Managed Appliance Details endpoints.
Changes in 2023, revision 6:
Added Submission Status by Time Range endpoints.
Added Submission Status by SHA List endpoints.
Added Submission Status by UUID endpoints.
Added Submission Status by UUID Result endpoints.
Added password field to VX API submission endpoints.
Added MVX Cluster Management endpoints.
Changes in 2023.1 revision 1:
Added a section specific to Intelligent Virtual Execution - Server endpoints.
Added new Submission API endpoints for Intelligent Virtual Execution - Server.
Added new attributes for some Submission endpoints.
Added "Download specific artifacts data by artifact type" endpoint.
Added an option to "add a YARA rule" endpoint that enables a Central Management System appliance to add a YARA rule to specific appliances or groups managed by the Central Management System appliance.