The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Download alert malware files as ZIP request

Prev Next

Downloads available malware files of the alert specified by alert ID, in a zip file.

GET https://<etp_instance_addr>/api/v2/public/alerts/<alert_id>/malware

Use the alert ID from the alert search response (this is a part of the API endpoint URL).

Required header

x-fireeye-api-key: <key>—Specifies your personal API key. (For FireEye IAM users)

Authorization: Bearer xxxx - Specifies your API access token (For Trellix IAM users)

Example of an alert request

GET https://<etp_instance_addr>/api/v2/public/alerts/3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8/malware

Download alert malware files as ZIP response

The downloaded zip is password protected, and the password is "infected".

Zip File (Binary)
<num>-malware.zip

cURL code sample: download alert malware files as ZIP

curl - X GET --location '<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de/malware' -o file.zip --header 'x-fireeye-api-key: xxxxx'

This cURL sample includes the following options:

  • --header 'x-fireeye-api-key: xxxxxxxxxxxxxxx'—This header specifies your personal API key. Use the access token if you are a Trellix IAM user.

  • https://<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de/malware - The request URL

Results

This example downloads all malware files of the specified alert in a zip file.