Skip to main content

Overview

The Malwarebytes integration enables ThreatAware to collect endpoint protection and threat detection data from your Malwarebytes Nebula console, providing visibility into endpoint security status and detected threats across your organisation.
Connection Method: API Setup Time: 15 minutes Access Required: Malwarebytes Nebula Administrator account

Data collected

The Malwarebytes integration provides:
  • Endpoint threat detection data
  • Malware detection and remediation status
  • Endpoint protection status
  • Security compliance information

Use cases

Threat Detection

Monitor detected threats and malware across endpoints

Remediation Tracking

Track threat remediation and quarantine status

Endpoint Protection

Verify all endpoints have active protection

Security Reporting

Generate reports on threats and protection status

Setup instructions

1

Log in to Malwarebytes Nebula Console

Access your Malwarebytes Nebula Console with an administrator account.
2

Create Dedicated Admin Account

  • It is recommended to create a new administrator account specifically for API integration
  • Navigate to Settings > User Management or Administrators
  • Create a new admin account for ThreatAware
  • Ensure the account has administrator role with access to the group(s) you want to monitor
  • Assign appropriate permissions to view all necessary data
  • Note the account credentials for later use
Creating a dedicated service account makes it easier to track API usage and manage access permissions.
3

Generate API Credentials

  • Navigate to Settings > APIs & Integrations
  • Click Add to generate new API credentials
  • Provide a descriptive name for the API credentials (e.g., “ThreatAware Integration”)
  • Select the following access options:
    • Read - to retrieve endpoint and threat data
    • Write - if you want to enable threat remediation actions
    • Execute - if you want to enable threat remediation actions
  • Click Save
  • Copy the Client ID and Client Secret that are displayed
The Client Secret will only be displayed once. Copy and store it securely in your password manager before closing this screen.
4

Retrieve Account ID

  • Log in to your Malwarebytes Nebula console
  • Look at the URL in your browser (e.g., https://console.malwarebytes.com/?account=12345)
  • Copy the Account ID from the URL
  • This is typically a numeric identifier after the “account=” parameter
5

Configure in ThreatAware

Complete the integration setup in ThreatAware:
  • Open ThreatAware and navigate to Settings > Integrations
  • Search for and select Malwarebytes
  • Enter the required information:
    • Account ID: The ID from the Malwarebytes console URL
    • Client ID: The API Client ID generated in the previous step
    • Client Secret: The API Client Secret generated in the previous step
  • Click Authorize to establish the integration
6

Verify Connection

After connecting, verify the integration is working:
  • Check that the Integration Status shows as Active
  • Wait up to 5 minutes for the initial endpoint and threat data sync
  • Verify threat and endpoint protection data appears in ThreatAware

Required credentials

Field Name: Malwarebytes Account ID Type: String Description: Your unique Malwarebytes Nebula account identifierFound in the URL of your Malwarebytes console (e.g., https://console.malwarebytes.com/?account=12345). Copy the numeric ID only.Example: 12345
Field Name: Malwarebytes Client ID Type: String Description: API Client ID for authenticationGenerated in Settings > APIs & Integrations of the Malwarebytes console.Example: client_a1b2c3d4e5f6g7h8
Field Name: Malwarebytes Client Secret Type: Password (encrypted) Description: API Client Secret for authentication to MalwarebytesGenerated alongside the Client ID in APIs & Integrations. This credential is sensitive and should be stored securely.
Store this credential securely in your organisation’s password manager. It will only be displayed once during generation.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Integrations in ThreatAware
    • Confirm the Malwarebytes integration shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait up to 5 minutes for initial endpoint and threat data collection
    • Search for a known endpoint in ThreatAware
    • Verify Malwarebytes protection status and threat data appears
  3. Test Queries
    • Create a test query to filter endpoints by Malwarebytes threat detection status
    • Verify the results match your Malwarebytes console

Troubleshooting

Symptoms: Integration fails to authenticateSolutions:
  • Verify the Account ID is correct (from the Malwarebytes console URL)
  • Confirm the Client ID and Client Secret are correct
  • Ensure no extra spaces were copied with the credentials
  • Check if the API credentials have expired or been revoked
  • Regenerate new API credentials if necessary
  • Verify the admin account has not been disabled
Symptoms: Integration connects but no endpoint data appearsSolutions:
  • Verify the admin account has access to the appropriate groups in Malwarebytes
  • Confirm the API credentials have Read permission enabled
  • Check that the account has not been restricted to specific scopes
  • Review Malwarebytes account permissions for the admin account
  • Ensure endpoints are properly registered in Malwarebytes Nebula
Symptoms: Integration fails to connect or times outSolutions:
  • Verify the Malwarebytes Nebula console is accessible and responsive
  • Check firewall rules allow outbound HTTPS (443) to Malwarebytes
  • Confirm your internet connection is stable
  • Test accessing the Malwarebytes console directly in a browser
  • Check Malwarebytes service status for any outages
Symptoms: Integration shows active but no endpoint or threat data appearsSolutions:
  • Verify you have endpoints enrolled in Malwarebytes Nebula
  • Confirm the API credentials have proper permissions
  • Wait up to 10 minutes for the initial data sync
  • Check Malwarebytes console to ensure data exists
  • Verify the admin account has access to the monitoring group
  • Review ThreatAware integration logs for specific errors
  • Review Malwarebytes Documentation for additional help
Symptoms: Client Secret not visible or credentials not workingSolutions:
  • Regenerate new API credentials in Malwarebytes if the secret was lost
  • Ensure you copied the Client Secret immediately after generation
  • Verify the API credentials have not been revoked
  • Check that the API credentials have the required permissions (Read, Write, Execute)

Additional resources

Malwarebytes Documentation

Official Malwarebytes documentation and support portal

Malwarebytes Support

Malwarebytes support for technical assistance and account issues

Best practices

Credential Management
  • Create a dedicated admin account specifically for ThreatAware
  • Store API credentials securely in your organisation’s password manager
  • Rotate API credentials regularly (annually or per security policy)
  • Monitor integration status to detect authentication failures early
  • Document the integration setup for future reference
Security Considerations
  • Only grant necessary API permissions (typically Read is sufficient)
  • Limit the admin account to the minimum required groups and scopes
  • Monitor Malwarebytes audit logs for API account activity
  • Review endpoint protection status regularly
  • Keep integration status monitoring in place for continuity