APIs are available to all Carbon Black Cloud customers. Platform level APIs are augmented by product specific APIs.

The Carbon Black Cloud APIs enable scenarios such as interactive access from scripts during an incident investigation and persistent integration to a SIEM or SOAR tool. They also allow you to automate repetitive tasks, freeing up your resources for the things that matter most. The most common use cases are:

The most common API use cases are:

  • I would like to automate a task I usually complete in the Carbon Black Cloud console.
  • I would like to integrate the Carbon Black Cloud console with my other security products.

Most Commonly Used APIs

Carbon Black Cloud Console API Links on Dev Network
Alerts Alerts

Alert Bulk Export Guide

Investigate > Processes Processes Search
Live Query Live Query

Differential Analysis

Enforce > Managing Watchlists Watchlist

Complete Console-->API Cross-reference

Carbon Black Cloud Console and User Guide Link API Links on Dev Network
Settings > Setting Up API Access Access Profiles and Grants
Multi-tenancy > Managing Users in a Multi-tenancy Environment Access Profiles and Grants
Alerts Alerts

Alert Bulk Export Guide

Investigate > Auth Events Auth Events
Settings > Data Forwarders Data Forwarder
Inventory > Endpoints Devices

Sensor Update Services

Live Query Live Query | Differential Analysis
Inventory > Endpoints > Use Live Response Live Response
Investigate > Observations Observations
Investigate > Processes Processes Search
Enforce > Managing Policies Policy Service
Enforce > Recommendations Recommendations
Enforce > Manage Reputations Reputation Override
Settings > Managing Users User Management
Settings > Managing Roles User Management
Harden > Managing Vulnerabilities Vulnerability Assessment
Enforce > Managing Watchlists Watchlist