The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Executable Information

Prev Next

This URL gets the executable information for given hash value.

Resource URL

GET /<nbaid>/endpointintelligence/<hash>/executableinformation? duration=<duration>

Request Parameters

Field Name

Description

Data Type

Mandatory

duration

Duration

  • LAST_5_MINUTES

  • LAST_1_HOUR

  • LAST_6_HOURS

  • LAST-12_HOURS

  • LAST_24_HOURS

  • LAST_48_HOURS

  • LAST_7_DAYS

  • LAST_14_DAYS

String

No

hash

Hash

String

Yes

nbaId

NTBA monitors id

String

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

EndpointExecutableList

List of endpoint executables

Array

Details of EndpointExecutableList:

Field Name

Description

Data Type

properties

Executable properties

Object

heuristics

Heuristics data

Object

libraryProcesses

Process using this library

Object

parentProcesses

Parent process

Object

suspiciousLibraries

Suspicious libraries

Object

Details of properties:

Field Name

Description

Data Type

hash

Executable hash

String

binaryType

Binary type

String

binaryName

Binary name

String

productName

Product name

String

productVersion

Product version

String

overallMalwareConfidence

Overall malware confidence

String

eiaAgentMalwareConfidence

EIA agent malware confidence

String

classification

Classification

String

classifier

Classifier

String

classified

Classified

String

filesize

File size

Long

Details of heuristics:

Field Name

Description

Data Type

digitallySigned

Digitally signed

String

certificateStatus

Certificate status

String

packed

Packed

String

resourceSection

Resource section

String

smallerThan500KB

Smaller than 500 KB

String

embeddedUI

Embedded UI

String

obfuscatedFileExtention

Obfuscated file extension

String

recentlyModified

Recently modified

String

gtiReputation

GTI reputation

String

Details of parentProcesses:

Field Name

Description

Data Type

hash

Hash value

String

name

Name

String

Details of suspiciousLibraries and libraryProcesses:

Field Name

Description

Data Type

hash

Hash value

String

name

Name

String

malwareConfidence

Malware confidence

String

Example

Request

GET https://<NSM_IP>/sdkapi/1001/endpointintelligence/aaaaaaaa16/ executableinformation?duration=LAST_14_DAYS

Response

{
"properties":
{"hash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaa23",
"binaryType":"Process",
"binaryName":"abc.exe",
"productName":"",
"productVersion":"file_version",
"overallMalwareConfidence":"Medium",
"eiaAgentMalwareConfidence":"Medium",
"classification":"unclassified",
"classifier":"---","filesize":2566795},
"heuristics":{},
"suspiciousLibraries":[{
"hash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaab1",
"name":"abc_dll.dll",
"malwareConfidence":"High"}]
} 

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

400

3601

Invalid duration

2

400

4901

Invalid hash/failed retrieve