The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Executable Information

Prev Next

This URL gets the executable information for given hash value.

Resource URL

GET /<nbaid>/endpointintelligence/<hash>/executableinformation? duration=<duration>

Request Parameters

Field Name Description Data Type Mandatory
duration Duration
  • LAST_5_MINUTES
  • LAST_1_HOUR
  • LAST_6_HOURS
  • LAST-12_HOURS
  • LAST_24_HOURS
  • LAST_48_HOURS
  • LAST_7_DAYS
  • LAST_14_DAYS
String No
hash Hash String Yes
nbaId NTBA monitors id String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
EndpointExecutableList List of endpoint executables Array

Details of EndpointExecutableList:

Field Name Description Data Type
properties Executable properties Object
heuristics Heuristics data Object
libraryProcesses Process using this library Object
parentProcesses Parent process Object
suspiciousLibraries Suspicious libraries Object

Details of properties:

Field Name Description Data Type
hash Executable hash String
binaryType Binary type String
binaryName Binary name String
productName Product name String
productVersion Product version String
overallMalwareConfidence Overall malware confidence String
eiaAgentMalwareConfidence EIA agent malware confidence String
classification Classification String
classifier Classifier String
classified Classified String
filesize File size Long

Details of heuristics:

Field Name Description Data Type
digitallySigned Digitally signed String
certificateStatus Certificate status String
packed Packed String
resourceSection Resource section String
smallerThan500KB Smaller than 500 KB String
embeddedUI Embedded UI String
obfuscatedFileExtention Obfuscated file extension String
recentlyModified Recently modified String
gtiReputation GTI reputation String

Details of parentProcesses:

Field Name Description Data Type
hash Hash value String
name Name String

Details of suspiciousLibraries and libraryProcesses:

Field Name Description Data Type
hash Hash value String
name Name String
malwareConfidence Malware confidence String

Example

Request

GET https://%3CNSM_IP%3E/sdkapi/1001/endpointintelligence/aaaaaaaa16/%20executableinformation?duration=LAST_14_DAYS

Response

{
"properties":
{"hash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaa23",
"binaryType":"Process",
"binaryName":"abc.exe",
"productName":"",
"productVersion":"file_version",
"overallMalwareConfidence":"Medium",
"eiaAgentMalwareConfidence":"Medium",
"classification":"unclassified",
"classifier":"---","filesize":2566795},
"heuristics":{},
"suspiciousLibraries":[{
"hash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaab1",
"name":"abc_dll.dll",
"malwareConfidence":"High"}]
} 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 3601 Invalid duration
2 400 4901 Invalid hash/failed retrieve