The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Endpoint Intelligence

Prev Next

This URL gets the list of executables running on your internal endpoints.

Resource URL

GET /<nbaid>/endpointintelligence?search=<search_string>&&confidencetype=<confidencetype>&&classificationtype=<classificationtype>&&duration=<duration>

Request Parameters

Field Name Description Data Type Mandatory
nbaId NTBA monitors id String Yes
Search Search string String No
confidencetype Confidence type
  • any
  • block
  • allow
  • unclassified
Default: any
String No
classificationtype Classification type
  • high
  • any
Default: any
String No
duration Duration
  • LAST_5_MINUTES
  • LAST_1_HOUR
  • LAST_6_HOURS
  • LAST-12_HOURS
  • LAST_24_HOURS
  • LAST_48_HOURS
  • LAST_7_DAYS
  • LAST_14_DAYS
String No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
EndpointExecutableList List of endpoint executables Array

Details of EndpointExecutableList:

Field Name Description Data Type
executableHash Executable hash String
executableName Executable name String
executableVersions Executable versions String
classification Classification String
fileSize File size String
firstseen First seen String
lastseen Last seen String
endpointsCount Endpoints count Int
connectionsCount Connections count Int
eventsCount Events count Int
comment Comment String

Example

Request

GET https://%3CNSM_IP%3E/sdkapi/1001/endpointintelligence/%20endpointintelligence?duration=LAST_14_DAYS&&confidencetype=any&&classificationtype=any

Response

{
"endpointExecutableList":[
{"executableHash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaa23",
"executableName":"abc.exe",
"executableVersions":"file_version",
"malwareConfidence":"Medium",
"classification":"unclassified",
"fileSize":2566795,
"firstSeen":"2013-09-10 00:00:00",
"lastSeen":"2013-09-10 12:45:00",
"endpointsCount":1,
"connectionsCount":4,
"eventsCount":12}]
} 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 3601 Invalid duration
3 400 3603 Invalid confidence type
4 400 3604 Invalid classification type
4 400 4904 Failed to retrieve data