McAfee (Trellix)
APIs for McAfee Enterprise security products and services. McAfee Enterprise rebranded as Trellix in 2022, but its on-premises and SaaS platforms (ePO, MVISION, ESM, Web Gateway, TIE, DXL) continue to expose REST APIs documented here for centralized security management, threat intelligence, EDR, messaging, and SIEM integration.
APIs
McAfee ePO API
McAfee ePolicy Orchestrator (ePO) REST API for centralized security management, including system management, policy assignment, task scheduling, query execution, and threat even...
McAfee MVISION API
Cloud-native security platform API for endpoint detection and response (EDR), threat prevention, device management, and incident investigation.
McAfee Threat Intelligence Exchange (TIE) API
Real-time threat intelligence sharing and reputation services API.
McAfee Data Exchange Layer (DXL) API
Messaging fabric for real-time security data exchange and integration.
McAfee Web Gateway API
Web security gateway REST API for managing rule sets, URL filtering lists, SSL inspection settings, and monitoring proxy traffic and appliance health.
McAfee ESM API
Enterprise Security Manager SIEM REST API for managing security events, alarms, watchlists, data sources, cases, and executing queries against the event database.