Overview
The Malwarebytes integration enables ThreatAware to collect endpoint protection and threat detection data from your Malwarebytes Nebula console, providing visibility into endpoint security status and detected threats across your organisation.Connection Method: API
Setup Time: 15 minutes
Access Required: Malwarebytes Nebula Administrator account
Data collected
The Malwarebytes integration provides:- Endpoint threat detection data
- Malware detection and remediation status
- Endpoint protection status
- Security compliance information
Use cases
Threat Detection
Monitor detected threats and malware across endpoints
Remediation Tracking
Track threat remediation and quarantine status
Endpoint Protection
Verify all endpoints have active protection
Security Reporting
Generate reports on threats and protection status
Setup instructions
1
Log in to Malwarebytes Nebula Console
Access your Malwarebytes Nebula Console with an administrator account.
2
Create Dedicated Admin Account
- It is recommended to create a new administrator account specifically for API integration
- Navigate to Settings > User Management or Administrators
- Create a new admin account for ThreatAware
- Ensure the account has administrator role with access to the group(s) you want to monitor
- Assign appropriate permissions to view all necessary data
- Note the account credentials for later use
3
Generate API Credentials
- Navigate to Settings > APIs & Integrations
- Click Add to generate new API credentials
- Provide a descriptive name for the API credentials (e.g., “ThreatAware Integration”)
- Select the following access options:
- Read - to retrieve endpoint and threat data
- Write - if you want to enable threat remediation actions
- Execute - if you want to enable threat remediation actions
- Click Save
- Copy the Client ID and Client Secret that are displayed
4
Retrieve Account ID
- Log in to your Malwarebytes Nebula console
- Look at the URL in your browser (e.g.,
https://console.malwarebytes.com/?account=12345) - Copy the Account ID from the URL
- This is typically a numeric identifier after the “account=” parameter
5
Configure in ThreatAware
Complete the integration setup in ThreatAware:
- Open ThreatAware and navigate to Settings > Integrations
- Search for and select Malwarebytes
- Enter the required information:
- Account ID: The ID from the Malwarebytes console URL
- Client ID: The API Client ID generated in the previous step
- Client Secret: The API Client Secret generated in the previous step
- Click Authorize to establish the integration
6
Verify Connection
After connecting, verify the integration is working:
- Check that the Integration Status shows as Active
- Wait up to 5 minutes for the initial endpoint and threat data sync
- Verify threat and endpoint protection data appears in ThreatAware
Required credentials
Account ID
Account ID
Field Name: Malwarebytes Account ID
Type: String
Description: Your unique Malwarebytes Nebula account identifierFound in the URL of your Malwarebytes console (e.g.,
https://console.malwarebytes.com/?account=12345). Copy the numeric ID only.Example: 12345Client ID
Client ID
Field Name: Malwarebytes Client ID
Type: String
Description: API Client ID for authenticationGenerated in Settings > APIs & Integrations of the Malwarebytes console.Example:
client_a1b2c3d4e5f6g7h8Client Secret
Client Secret
Field Name: Malwarebytes Client Secret
Type: Password (encrypted)
Description: API Client Secret for authentication to MalwarebytesGenerated alongside the Client ID in APIs & Integrations. This credential is sensitive and should be stored securely.
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings > Integrations in ThreatAware
- Confirm the Malwarebytes integration shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait up to 5 minutes for initial endpoint and threat data collection
- Search for a known endpoint in ThreatAware
- Verify Malwarebytes protection status and threat data appears
-
Test Queries
- Create a test query to filter endpoints by Malwarebytes threat detection status
- Verify the results match your Malwarebytes console
Troubleshooting
Invalid Credentials Error
Invalid Credentials Error
Symptoms: Integration fails to authenticateSolutions:
- Verify the Account ID is correct (from the Malwarebytes console URL)
- Confirm the Client ID and Client Secret are correct
- Ensure no extra spaces were copied with the credentials
- Check if the API credentials have expired or been revoked
- Regenerate new API credentials if necessary
- Verify the admin account has not been disabled
Permission Issues
Permission Issues
Symptoms: Integration connects but no endpoint data appearsSolutions:
- Verify the admin account has access to the appropriate groups in Malwarebytes
- Confirm the API credentials have Read permission enabled
- Check that the account has not been restricted to specific scopes
- Review Malwarebytes account permissions for the admin account
- Ensure endpoints are properly registered in Malwarebytes Nebula
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify the Malwarebytes Nebula console is accessible and responsive
- Check firewall rules allow outbound HTTPS (443) to Malwarebytes
- Confirm your internet connection is stable
- Test accessing the Malwarebytes console directly in a browser
- Check Malwarebytes service status for any outages
No Data After 5 Minutes
No Data After 5 Minutes
Symptoms: Integration shows active but no endpoint or threat data appearsSolutions:
- Verify you have endpoints enrolled in Malwarebytes Nebula
- Confirm the API credentials have proper permissions
- Wait up to 10 minutes for the initial data sync
- Check Malwarebytes console to ensure data exists
- Verify the admin account has access to the monitoring group
- Review ThreatAware integration logs for specific errors
- Review Malwarebytes Documentation for additional help
API Credential Issues
API Credential Issues
Symptoms: Client Secret not visible or credentials not workingSolutions:
- Regenerate new API credentials in Malwarebytes if the secret was lost
- Ensure you copied the Client Secret immediately after generation
- Verify the API credentials have not been revoked
- Check that the API credentials have the required permissions (Read, Write, Execute)
Additional resources
Malwarebytes Documentation
Official Malwarebytes documentation and support portal
Malwarebytes Support
Malwarebytes support for technical assistance and account issues