The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Endpoint Intelligence

Prev Next

This URL gets the list of executables running on your internal endpoints.

Resource URL

GET /<nbaid>/endpointintelligence?search=<search_string>&&confidencetype=<confidencetype>&&classificationtype=<classificationtype>&&duration=<duration>

Request Parameters

Field Name

Description

Data Type

Mandatory

nbaId

NTBA monitors id

String

Yes

Search

Search string

String

No

confidencetype

Confidence type

  • any

  • block

  • allow

  • unclassified

Default: any

String

No

classificationtype

Classification type

  • high

  • any

Default: any

String

No

duration

Duration

  • LAST_5_MINUTES

  • LAST_1_HOUR

  • LAST_6_HOURS

  • LAST-12_HOURS

  • LAST_24_HOURS

  • LAST_48_HOURS

  • LAST_7_DAYS

  • LAST_14_DAYS

String

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

EndpointExecutableList

List of endpoint executables

Array

Details of EndpointExecutableList:

Field Name

Description

Data Type

executableHash

Executable hash

String

executableName

Executable name

String

executableVersions

Executable versions

String

classification

Classification

String

fileSize

File size

String

firstseen

First seen

String

lastseen

Last seen

String

endpointsCount

Endpoints count

Int

connectionsCount

Connections count

Int

eventsCount

Events count

Int

comment

Comment

String

Example

Request

GET https://<NSM_IP>/sdkapi/1001/endpointintelligence/ endpointintelligence?duration=LAST_14_DAYS&&confidencetype=any&&classificationtype=any

Response

{
"endpointExecutableList":[
{"executableHash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaa23",
"executableName":"abc.exe",
"executableVersions":"file_version",
"malwareConfidence":"Medium",
"classification":"unclassified",
"fileSize":2566795,
"firstSeen":"2013-09-10 00:00:00",
"lastSeen":"2013-09-10 12:45:00",
"endpointsCount":1,
"connectionsCount":4,
"eventsCount":12}]
}

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

400

3601

Invalid duration

3

400

3603

Invalid confidence type

4

400

3604

Invalid classification type

4

400

4904

Failed to retrieve data