Skip to main content
Tools Reference

Bitdefender GravityZone Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Bitdefender GravityZone Tools

gravityzone_ · 138 tools · Free 56 · Pro 82 Endpoint protection with EDR and XDR, patch management, hardening and quarantine, reached through the MSP partner Control Center. Authentication is HTTP Basic where the API key is the user name and the password is empty; there is no token endpoint and no expiry. The Control Center access address is per tenant and is required, because a key minted on one GravityZone instance is meaningless on another. Every call is a JSON-RPC POST, so whether a tool reads or writes is a recorded judgment rather than something the transport reveals, and a failure arrives at HTTP 200 carrying an error member. A key's API groups are fixed when it is minted and cannot be widened, so a group refusal is a configuration fact rather than a bad key, while an HTTP 401 or 403 is definitive. The connection test calls the General group, so a key minted without General can never verify. Page caps are per method rather than one number.

All connector tools · Bitdefender GravityZone setup guide

Bitdefender GravityZone tool groups

Accounts

ToolPlanAccessSummary
gravityzone_configure_notifications_settingsProWritePartial-merge write of notification preferences.
gravityzone_create_accountProDestructiveCreates a console user with a role/rights grant; if password is omitted a generated password is EMAILED to the user (documented).
gravityzone_delete_accountProDestructiveDeletes a Control Center user account.
gravityzone_get_account_detailsFreeRead-onlySingle account by id/email.
gravityzone_get_accounts_listFreeRead-onlyPaged list of Control Center user accounts.
gravityzone_get_notifications_settingsFreeRead-onlyReads notification preferences.
gravityzone_update_accountProDestructiveWholesale account update; takes role (5 = Custom) and a rights object - privilege-widening.

[Bitdefender GravityZone] Partial-merge write of notification preferences. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: configureNotificationsSettings on the accounts namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
accountIdstringnonullThe ID of the account for which the notification settings are configured. If no value is provided, the settings will be applied to the account which generated the API key.
deleteAfterintegernonullThe number of days after which generated notifications will be automatically deleted. Valid values are between 1 and 365. The default value is 30 days.
emailAddressesJsonstringnonullA list of additional email addresses to be used when sending notifications. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
includeDeviceFQDNbooleannonullThis option specifies whether the FQDN will be included in the notification sent by email, when it is available, or not. The value should be True to include the FQDN respectively False to not include it. The default value is False.
includeDeviceNamebooleannonullThis option specifies whether the device name will be included in the notification sent by email, when it is available, or not. The value should be True to include the device name respectively False to not include it. The default value is False.
notificationsSettingsJsonstringnonullA list of objects containing the notification settings to be configured. Only the specified notifications will be updated. Existing values are preserved for omitted settings. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array).
sendOnlyPlainTextEmailbooleannonullThis option specifies whether notification emails should be sent in plain text only. The value should be True to send emails in plain text, or False if you want to use HTML format.

[Bitdefender GravityZone] Creates a console user with a role/rights grant; if password is omitted a generated password is EMAILED to the user (documented). DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createAccount on the accounts namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe company ID of the company you want to create the user under. If not specified, the account will be linked to the company that holds the API key used to send the request. Example: companyId": "58541613aaed7090058b4567
emailstringyesThe email address for the new account. Example: "email": "client@bitdefender.com"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
passwordstringnonullThe password for the new account. Abridged; the vendor documentation for this method carries the full text. Example: "password": "P@s4w0rd"
phoneNumberJsonstringnonullAn object containing phone number information. Refer to phoneNumber. Supply this as raw JSON (a JSON object). Example: "phoneNumber": { "countryCode": "+40", "subscriberNumber": "0000000000" },
profileJsonstringyesAn object containing profile information. Refer to profile. Supply this as raw JSON (a JSON object). Example: "profile": { "fullName": "Bitdefender User", "language": "en_US", "timezone": "Europe/Bucharest" },
rightsJsonstringnonullAn object containing the rights of a user account. Only use this parameter if the role parameter is included in your request and is assigned the value 5. In any other situation, the values assigned to the rights parameter are ignored. Refer to rights. Supply this as raw JSON (a JSON object).
roleintegernonullThe role of the new account. For more information regarding user roles and the associated rights, refer to User roles Possible values: 1 - Company Administrator 2 - Network Administrator 3 - Reporter 4 - Partner 5 - Custom. Abridged; the vendor documentation for this method carries the full text. Example: "role": 5
targetIdsJsonstringnonullA list of IDs representing the targets to be managed by the user account. Supply this as raw JSON (a JSON array). Example: "targetIds": [ "585d2dc9aaed70820e8b45b4", "585d2dd5aaed70b8048b45ca" ]

[Bitdefender GravityZone] Deletes a Control Center user account. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteAccount on the accounts namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
accountIdstringyesThe ID of the user account to be deleted.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Single account by id/email. Cloud + partner consoles only. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getAccountDetails on the accounts namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
accountIdstringnonullThe ID of the account you want to display information for. Default value: The ID of the GravityZone account used to generate the API key. Example: "accountId": "6718732309e2be32df0550c2"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Paged list of Control Center user accounts. perPage 1-100, default 30. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getAccountsList on the accounts namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of company for which you want to display the accounts for. Default value: the company the API key used to make the request belongs to.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
pageintegerno1Results page number, 1-based. Default 1. The results page number. Default value: 1.
perPageintegerno30Items per page. Default 30. Bitdefender documents a maximum of 100 for this method. Values outside the range are clamped rather than refused.

[Bitdefender GravityZone] Reads notification preferences. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getNotificationsSettings on the accounts namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
accountIdstringnonullThe ID of the account for which the notifications settings are retrieved. If not provided, the method will retrieve the notifications settings for the account which has generated the API key.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Wholesale account update; takes role (5 = Custom) and a rights object - privilege-widening. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: updateAccount on the accounts namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
accountIdstringyesThe ID of the target user account. Example: "accountId" : "585d3d3faaed70970e8b45ed"
authenticationMethodintegernonullThe method of authentication required for the user to log in. Possible values: 0 - GravityZone Credentials 1 - Identity Provider 2 - GravityZone Identity Provider Example: "email": "client@bitdefender.com"
emailstringnonullThe email address for the account. Must have a valid email format. Example: "email": "client@bitdefender.com"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
passwordstringnonullThe password for the account. The password must be at least twelve characters in length, and must contain at least one upper case character, one lower case character, one digit, one special character, and needs to be different from previously used passwords. Example: "password": "P@s4w0rd"
phoneNumberJsonstringnonullAn object containing phone number information For more information, refer to phoneNumber. Supply this as raw JSON (a JSON object). Example: "phoneNumber": { "countryCode": "+40", "subscriberNumber": "0000000000" }
profileJsonstringnonullAn object containing profile information: fullName, timezone and language. For more information, refer to profile. Supply this as raw JSON (a JSON object). Example: "profile": { "fullName": "Bitdefender User", "language": "en_US", "timezone": "Europe/Bucharest" }
rightsJsonstringnonullAn object containing the rights of a user account. This object should be set only when role parameter has the value 5 - Custom. When set for other roles, the values will be ignored and replaced with the rights specific to that role. For more information, refer to rights. Supply this as raw JSON (a JSON object).
roleintegernonullThe new role of the user. These are the available roles: 1 - Company Administrator. 2 - Network Administrator. 3 - Reporter. 4 - Partner 5 - Custom. For this role, rights must be specified. Example: "role": 5
targetIdsJsonstringnonullA list of IDs representing the targets to be managed by the user account. Supply this as raw JSON (a JSON array). Example: "targetIds": [ "585d2dc9aaed70820e8b45b4", "585d2dd5aaed70b8048b45ca" ]

Companies

ToolPlanAccessSummary
gravityzone_activate_companyProWriteReactivates a suspended company (restorative).
gravityzone_create_companyProDestructiveCreates a managed customer company and assigns a license subscription - creates a billable contract.
gravityzone_create_custom_field_definitionProWriteAdditive: new company custom-field definition.
gravityzone_delete_companyProDestructiveDeletes a managed company and everything under it.
gravityzone_delete_custom_field_definitionProDestructiveDeletes a custom-field definition and its stored values.
gravityzone_find_companies_by_nameFreeRead-onlyName search over managed companies.
gravityzone_get_company_detailsFreeRead-onlyCompany record by id.
gravityzone_get_company_details_by_userFreeRead-onlyCompany record for a given user.
gravityzone_get_custom_fields_definitionsFreeRead-onlyLists company custom-field definitions.
gravityzone_suspend_companyProDestructiveSuspends a customer company - stops protection management.
gravityzone_update_company_detailsProWritePartial-merge update of company name/address/contact.
gravityzone_update_custom_field_definitionProWritePartial update of a custom-field definition.

[Bitdefender GravityZone] Reactivates a suspended company (restorative). GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: activateCompany on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringyesThe ID of the company to be activated.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
recursivebooleanyesrue if sub-companies should be activated as well

[Bitdefender GravityZone] Creates a managed customer company and assigns a license subscription - creates a billable contract. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createCompany on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
accountEmailstringnonullThe email for the new user account to be linked to the new company. If the parameter canBeManagedByAbove is set to false, this parameter is mandatory.
accountFullNamestringnonullThe full name of the new user account to be linked to the new company. This parameter is required when canBeManagedByAbove is set to false.
accountLanguagestringnonullThe user interface language for the new user account to be linked to the new company. The default value is en_US.
accountTimezonestringnonullThe timezone of the new user account to be linked to the new company. The default value is Europe/Bucharest.
addressstringnonullThe company's physical address. The company address must not exceed 128 characters and must not contain HTML tags.
canBeManagedByAbovebooleannonullAn option defining whether the security of the new company can be managed by its Partner company. Available values: true or false. The default value is true. Important For companies using MDR, this parameter must have the true value.
contactPersonJsonstringnonullContains information regarding the company's designated contact person. The object contains the following fields: fullName - the person's first and last name. email - their business email address. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
countrystringnonullThe company's country of operation. The value must be in ISO 3166 format. No value is set for this parameter by default.
enforce2FAbooleannonullA parameter that defines Two Factor Authentication (2FA) enforcement for all GravityZone user accounts in the company. The value is always true.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
industryintegernonullThe industry the company operates in. Abridged; the vendor documentation for this method carries the full text.
licenseSubscriptionJsonstringnonullAn object containing the license details: type, an integer representing the license or subscription type. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
namestringyesThe company name. Must be unique. The company name must not exceed 64 characters.
parentIdstringnonullThe ID of the Partner company directly managing the newly created company.
phonestringnonullThe company's phone number. The phone number must not exceed 32 characters.
skip2FAPeriodintegernonullThe period, defined in days, for which the users of the company can have their devices exempted from providing a two-factor code at authentication. Available values: 0 1 3 7 14 30 90
statestringnonullThe company’s state or primary administrative subdivision of operation. The value must be in ISO 3166 format. No value is set for this parameter by default.
typeintegeryesThe company type. Available values: 0 for Partner companies 1 for Customer companies

[Bitdefender GravityZone] Additive: new company custom-field definition. Vendor JSON-RPC method: createCustomFieldDefinition on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
namestringyesThe name of the custom field.

[Bitdefender GravityZone] Deletes a managed company and everything under it. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteCompany on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringyesThe ID of the company to be deleted.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Deletes a custom-field definition and its stored values. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteCustomFieldDefinition on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idstringyesThe ID of the custom field to be deleted

[Bitdefender GravityZone] Name search over managed companies. Partner console only. Vendor JSON-RPC method: findCompaniesByName on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
maxResultsintegernonullDetermines the maximum number of entries returned by the request. Possible values: 1 - 100. Default value: 25.
nameFilterstringyesThe string to be searched in the company name. Use the asterisk symbol (*) in front of the keyword to search its appearance anywhere in the name. If omitted, only results where the name starts with the keyword will be returned.

[Bitdefender GravityZone] Company record by id. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getCompanyDetails on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe company's ID. The default value is the ID of the company linked to the user who generated the API key.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Company record for a given user. Partner console only. Vendor JSON-RPC method: getCompanyDetailsByUser on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
passwordstringnonullThe password of the specified username. This parameter is required only when the searched company is not in the target companies of the user who makes the API call.
usernamestringyesThe username linked to the searched company.

[Bitdefender GravityZone] Lists company custom-field definitions. Vendor JSON-RPC method: getCustomFieldsDefinitions on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Suspends a customer company - stops protection management. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: suspendCompany on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringyesThe ID of the company to be suspended.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
recursivebooleanyesTrue if sub-companies should be suspended as well.

[Bitdefender GravityZone] Partial-merge update of company name/address/contact. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: updateCompanyDetails on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
addressstringnonullThe company's address. It must not exceed 128 characters and must not contain HTML tags. If not set, the company's address will not be changed.
contactPersonJsonstringnonullInformation regarding the company's designated contact person. The object contains the following fields: fullName (String) - the person's first and last name. email (String) - their business email address. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
countrystringnonullThe company's new country of operation. The value must be in ISO 3166 format. If not set, the company's country will not be changed.
customFieldsJsonstringnonullAn object containing the custom fields' values for the company. To delete the custom fields, set it as an empty array. Important You cannot change custom field values for your own company (the company linked to the API key that generated the request). Supply this as raw JSON (a JSON object).
duplicateClosedIncidentsOnUpdatebooleannonullWhen set to: true: Updates found on a closed incident trigger the creation of a new incident. false: If updates are detected on a closed incident, the incident is reopened. If not configured, it retains the value set prior to the update. Abridged; the vendor documentation for this method carries the full text.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idstringnonullThe ID of the company to be updated. The default value is the ID of the company linked to the user who generated the API key. The value must be a 24-character hexadecimal string.
industryintegernonullThe industry the company operates in. Abridged; the vendor documentation for this method carries the full text.
mdrContactInformationJsonstringnonullThe company's designated emergency contact details, intended for use by the MDR team during security events or incidents. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
namestringnonullThe company's new name. It must be unique. It must not exceed 64 characters. If not set, the company's name will not be changed.
phonestringnonullThe company's new phone number. It must not exceed 32 characters. If not set, the company's phone number will not be changed.
skip2FAPeriodintegernonullThe period, defined in days, for which the users of the company can have their devices exempted from providing a two-factor code at authentication. Available values: 0 1 3 7 14 30 90
statestringnonullThe company's state or primary administrative subdivision of operation. The value must be in ISO 3166 format. If not set, the company's state will not be changed.
typeintegernonullThe company type. Available values: 0 for Partner companies, 1 for Customer companies. If not set, the company type will not be changed. Important You cannot change the type of your own company (the company linked to the API key that generated the request).

[Bitdefender GravityZone] Partial update of a custom-field definition. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: updateCustomFieldDefinition on the companies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idstringyesThe ID of the custom field
namestringyesCustom field name

General

ToolPlanAccessSummary
gravityzone_get_api_key_detailsFreeRead-onlyZero params.

[Bitdefender GravityZone] Zero params. Returns enabledApis[] (the namespaces this key may call) + createdAt. Vendor JSON-RPC method: getApiKeyDetails on the general namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

Incidents

ToolPlanAccessSummary
gravityzone_add_to_blocklistProDestructiveAdds a hash/path to the estate-wide blocklist - live enforcement.
gravityzone_change_incident_statusProWriteWorkflow status field update (open/closed).
gravityzone_create_custom_ruleProDestructiveCreates an EDR detection/exclusion rule; an exclusion can silence detection.
gravityzone_create_isolate_endpoint_taskProDestructiveNetwork-isolates a live endpoint.
gravityzone_create_response_actionProDestructiveDispatches an EDR response action against live endpoints.
gravityzone_create_restore_endpoint_from_isolation_taskProDestructiveLifts isolation on a live endpoint (dispatch + control removal).
gravityzone_delete_custom_ruleProDestructiveDeletes a custom rule.
gravityzone_get_blocklist_itemsFreeRead-onlyPaged blocklist read.
gravityzone_get_custom_rules_listFreeRead-onlyPaged custom-rule list.
gravityzone_get_incidentFreeRead-onlySingle incident by id.
gravityzone_get_incidents_by_idsFreeRead-onlyBulk incident fetch by id array.
gravityzone_get_incidents_listFreeRead-onlyPaged incident search.
gravityzone_get_response_action_statusFreeRead-onlyPolls a response action.
gravityzone_get_similar_emailsFreeRead-onlyCorrelated email search for an email incident.
gravityzone_remove_from_blocklistProDestructiveRemoves a security control (revoke).
gravityzone_start_yara_scanProDestructiveDispatches a YARA scan to live endpoints.
gravityzone_update_custom_ruleProDestructiveWholesale replace of a custom rule.
gravityzone_update_incident_noteProWritePartial write of a free-text note field.

[Bitdefender GravityZone] Adds a hash/path to the estate-wide blocklist - live enforcement. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: addToBlocklist on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company to which the Blocklist item belongs. Must be the valid ID of a managed company with a license that includes the Blocklist feature. For details on eligible licenses, refer to Security features. Default value: the ID of the company associated with the API key used to make the request.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
recursivebooleannonullIndicates whether the rules should be applied recursively to all companies managed by the company specified through companyId. When set to false, the rules are applied only to the company specified by companyId. Default value: true. Example: "recursive": false
rulesJsonstringyesContains the list of rules you want to create and their assigned settings. You can only add rules that match the type specified in the type parameter. Refer to rules. Supply this as raw JSON (a JSON array).
typestringyesIndicates the type of rules you want to create. Possible values: hash path connection Example: "type": "hash"

[Bitdefender GravityZone] Workflow status field update (open/closed). GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: changeIncidentStatus on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
incidentIdstringyesThe ID of the incident, obtained from the Event Push details. The value corresponds to the incident_id parameter from New Incident and New extended incident event types. Abridged; the vendor documentation for this method carries the full text.
statusintegeryesThe status to be assigned to the incident. Possible values: 1: Open 2: Investigating 3: Closed: Confirmed incident 4: Closed: False positive
typestringyesThe type of the target incident. Possible values: incidents: Endpoint incident from GravityZone Control Center. extendedIncidents: Organization incident from GravityZone Control Center.

[Bitdefender GravityZone] Creates an EDR detection/exclusion rule; an exclusion can silence detection. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createCustomRule on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company the custom rule will belong to. Must be the valid ID of a company that you manage. Default value: The ID of the company the API key used to make the request. Example: "companyId": "58541613aaed7090058b4567"
descriptionstringnonullThe description of the rule. This parameter cannot begin with a whitespace character, cannot include the characters <, >, ', or ", and must be no longer than 1024 characters. Example: "description": "Detection Rule via API Description"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
namestringyesThe name of the rule to be created. This parameter cannot begin with a whitespace character, cannot include the characters <, >, ', or ", and must be no longer than 128 characters. Also, it cannot be duplicated within the same company. Example: "name": "Detection Rule via API"
returnRuleIdbooleannonullIndicates if the request will return the ID of the new rule. Possible values: true, will return the ID of the newly created rule, if the request is successful. false, will not return the ID of the newly created rule. Instead, it will return a Boolean value. Default value: false. Example: "returnRuleId": true
settingsJsonstringyesThe settings associated with the rule. Refer to settings. Supply this as raw JSON (a JSON object).
subtypeintegernonullSpecifies whether the rule is YARA-based or Basic. Possible values: 0 - Basic 1 - YARA Default value: 0. Important If type is 2, the subtype parameter must be set to 0. Example: "subtype": 1
tagsJsonstringnonullThe list of associated rule tags. Each string must: Not contain <, >, ', or " Be at least 2 characters long and no longer than 128 characters Not start with a whitespace character Be unique in the array Supply this as raw JSON (a JSON array). Example: "tags": [ "api", "detection" ]
targetsJsonstringnonullContains either: companiesIds, which lists the IDs of the companies to which the custom rule applies, or endpointTags, which lists the tags, of which each endpoint targeted by the custom rule must have at least one assigned. Refer to targets. Supply this as raw JSON (a JSON object).
typeintegernonullThe type of the rule to be created: detection or exclusion. Possible values: 1 - Detection 2 - Exclusion Default value: 2. Important If type is 2, the subtype parameter must be set to 0. Example: "type": 1

[Bitdefender GravityZone] Network-isolates a live endpoint. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_response_action_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createIsolateEndpointTask on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
endpointIdsJsonstringyesThe IDs of the endpoints to be isolated. Each string in the array should consist of exactly 24 hexadecimal characters. The array is limited to a maximum of 1000 items. If any endpoint ID in the array is invalid, no endpoints will be isolated. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Dispatches an EDR response action against live endpoints. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_response_action_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createResponseAction on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
actionTypeintegeryesThe type of action to be taken and the type of environment it will be applied to. Possible values: 1 - Reset credentials for a Microsoft 365 (Office 365) or Entra ID (Azure AD) user. 2 - Reset credentials for an Active Directory user. Abridged; the vendor documentation for this method carries the full text.
emailIdstringnonullThe email ID associated with the user node. For actionType 11, this is the ID of the reference email used to identify similar emails. Abridged; the vendor documentation for this method carries the full text.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
fileUrlstringnonullThe URL of the file to be deleted. Important Supported exclusively for actionType 10. Mandatory if actionType is 10. Example: "fileUrl": "https://example-my.sharepoint.com/personal/xDocuments/x.txt.exe"
incidentIdstringnonullThe ID of the incident to which the user nodes belong. Either incidentId or integrationIdentifiers must be included in the request. Important If both incidentId and integrationIdentifiers are provided, the request is processed based solely on incidentId. In this case, the integrationIdentifiers parameter is ignored.
integrationIdentifiersstringnonullThe information required to identify the integration used for importing the user. Refer to integrationIdentifiers. Example: { "companyId": "66b08ace2f15a991ca079343", "officeTenantId": "123e4567-e89b-12d3-a456-426614174000" }
targetsJsonstringnonullSupported exclusively for actionType 11. Indicates which similar Microsoft 365 (Office 365) emails should be deleted. Each email can be identified by user and email ID or by a similarity hash. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
usernamestringnonullThe username involved in the event. This parameter must be a valid email for actionType 1, 3, 5, 6, 8, or 9. For actionType 2 or 4, this parameter must follow the domain\username format. Abridged; the vendor documentation for this method carries the full text. Example: "username": "user@bitdefender.com"

[Bitdefender GravityZone] Lifts isolation on a live endpoint (dispatch + control removal). DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_response_action_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createRestoreEndpointFromIsolationTask on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
endpointIdsJsonstringyesThe IDs of the endpoints to be restored from isolation. Each string in the array should consist of exactly 24 hexadecimal characters. The array is limited to a maximum of 1000 items. If any endpoint ID in the array is invalid, no endpoints will be restored from isolation. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Deletes a custom rule. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteCustomRule on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
ruleIdstringyesThe ID of the rule to be deleted. The value must be a 24-character hexadecimal string.
typeintegernonullThe type of the rule to be deleted. Possible values: 1 - Detection 2 - Exclusion Default value: 2.

[Bitdefender GravityZone] Paged blocklist read. perPage 1-100. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getBlocklistItems on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company to which the Blocklist item belongs. Must be the valid ID of a managed company. Default value: the company the API key used to make the request belongs to. Example: "companyId": "58541613aaed7090058b4567"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
pageintegerno1Results page number, 1-based. Default 1. The number of the results page currently displayed. Default value: 1
perPageintegerno30Items per page. Default 30. Bitdefender documents a maximum of 100 for this method. Values outside the range are clamped rather than refused.

[Bitdefender GravityZone] Paged custom-rule list. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getCustomRulesList on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company for which to retrieve the list of custom rules. Must be the valid ID of a company that you manage. Defaults to the ID of the company associated with the user making the API request. Example: "companyId": "61827b8036492c2fc0718722"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
subtypesJsonstringnonullIndicates if the retrieved rules should be YARA-based, Basic, or both. Can be used only when type is 1. Possible values: [0] - Only Basic rules will be retrieved. [1] - Only YARA rules will be retrieved. [0, 1] - Both Basic and YARA rules will be retrieved. Default value: [0, 1]. Supply this as raw JSON (a JSON array).
typeintegernonullSpecifies the type of custom rules to retrieve: detection or exclusion. Possible values: 1 - Detection 2 - Exclusion Default value: 2. Example: "type": 1

[Bitdefender GravityZone] Single incident by id. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getIncident on the incidents namespace (v1.2). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idstringyesThe ID of the incident you want to retrieve information for. This ID is included in the URL of the incident details page from GravityZone Control Center. The value must be the ID of an incident accessible to you. It should contain exactly 24 hexadecimal characters. Example: "id": "67dd30dd4a842ebbbb0b6af3"

[Bitdefender GravityZone] Bulk incident fetch by id array. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getIncidentsByIds on the incidents namespace (v1.2). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idsJsonstringyesThe IDs of the incidents you want to retrieve information for. The list must be non-empty and can contain up to 10 IDs. Each string must be the valid ID of an incident you have access to. Each string should consist of exactly 24 hexadecimal characters. Supply this as raw JSON (a JSON array).

[Bitdefender GravityZone] Paged incident search. perPage 10-10000, default 30. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. Filters are nested JSON objects, not query strings. Two traps: filters.details.name matches by PREFIX unless you lead the value with * (which switches it to contains), and a filter whose GravityZone license is not active is SILENTLY IGNORED rather than refused — which returns a confidently wrong result set. Confirm the license before trusting a filtered count. Vendor JSON-RPC method: getIncidentsList on the incidents namespace (v1.2). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
filtersJsonstringnonullThe criteria used to filter the returned incidents. For more information, refer to filters. Supply this as raw JSON (a JSON object).
optionsJsonstringnonullAdditional criteria used to filter the returned incidents. For more information, refer to options. Supply this as raw JSON (a JSON object). Example: "options": { "includeChildCompanies": true, "sortBy": "lastIncidentChange" }
pageintegerno1Results page number, 1-based. Default 1. The page number to return from the complete set of result pages. Default value: 1. This value must be minimum 1.
perPageintegerno30Items per page. Default 30. StackJack caps this at 1000; Bitdefender publishes no maximum for this method. The vendor's documented MINIMUM is 10. Values outside the range are clamped rather than refused.

[Bitdefender GravityZone] Polls a response action. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getResponseActionStatus on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
actionIdstringyesThe action ID returned by the createResponseAction method. The value must be a 24-character hexadecimal string. Example: "actionId": "6912758f88df334ddbfb7e1a"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Correlated email search for an email incident. Default perPage 1000. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getSimilarEmails on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
emailIdstringyesThe external ID of the reference email used to identify similar emails. Note In the response returned by this method, the external email ID appears as mailId for each identified email. The value of this parameter cannot be an empty string or "0".
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Removes a security control (revoke). DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: removeFromBlocklist on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company to which the Blocklist items belong. Must be the valid ID of a company that the user has access to. Default value: the company the API key used to make the request belongs to. Example: "companyId": "58541613aaed7090058b4567"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idsJsonstringyesThe IDs of the items you want to remove from the Blocklist. Must be the valid IDs of Blocklist items that you have access to. Supply this as raw JSON (a JSON array). Example: "ids": [ "6605882651f1f25d2708d2d7", "6605882651f1f25d2708d2d8" ]

[Bitdefender GravityZone] Dispatches a YARA scan to live endpoints. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_response_action_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: startYaraScan on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
pathsJsonstringnonullThe local directories that will be scanned. Each string in the array should be a valid absolute path on at least one of the endpoints that the YARA rule targets. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array).
ruleIdstringyesThe ID of the YARA rule used to define the scan detection conditions. This parameter should consist of exactly 24 hexadecimal characters.

[Bitdefender GravityZone] Wholesale replace of a custom rule. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: updateCustomRule on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
descriptionstringnonullThe new description of the rule. This parameter cannot begin with a whitespace character, cannot include the characters <, >, ', or ", and must be no longer than 1024 characters. Example: "description": "Detection Rule via API - Description"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
namestringyesThe rule’s new name This parameter cannot begin with a whitespace character, cannot include the characters <, >, ', or ", and must be no longer than 128 characters. Also, it cannot be duplicated within the same company. Example: "name": "Detection Rule via API"
ruleIdstringyesThe ID of the rule to be updated. This parameter should consist of exactly 24 hexadecimal characters. Example: "ruleId": "6182a7e26f59d3072a1e8fc5"
settingsJsonstringyesThe settings associated with the rule. Refer to settings. Supply this as raw JSON (a JSON object).
tagsJsonstringnonullThe new list of associated rule tags. Each string must: Not contain <, >, ', or " Be at least 2 characters long and no longer than 128 characters Not start with a whitespace character Be unique in the array Supply this as raw JSON (a JSON array). Example: "tags": [ "TAG 1", "TAG 2" ]
targetsJsonstringnonullContains either: companiesIds, which lists the IDs of the companies to which the custom rule applies, or endpointTags, which lists the tags, of which each endpoint targeted by the custom rule must have at least one assigned. Refer to targets. Supply this as raw JSON (a JSON object).
typeintegernonullThe type of the rule to be updated. Possible values: 1 - Detection 2 - Exclusion Default value: 2. Mandatory for detection rules Optional for exclusion rules. Example: "type": 1

[Bitdefender GravityZone] Partial write of a free-text note field. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: updateIncidentNote on the incidents namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
incidentIdstringyesThe ID of the incident, obtained from the Event Push details. The value corresponds to the incident_id parameter from New incident and New extended incident event types. Abridged; the vendor documentation for this method carries the full text.
notestringyesThe text to be included in the note. A maximum of 50,000 characters is allowed for the note. All whitespace or empty note values are not supported. Note If the incident already has a note assigned to it, it will be overwritten.
typestringyesThe type of the target incident. Possible values: incidents: Endpoint incident from GravityZone Control Center extendedIncidents: Organization incident from GravityZone Control Center

Integrations

ToolPlanAccessSummary
gravityzone_configure_amazon_ec2_integration_cross_account_roleProDestructiveGrants cross-account AWS role access - privilege-widening.
gravityzone_create_integrationProDestructiveCreates a third-party integration incl.
gravityzone_delete_integrationProDestructiveDeletes an integration.
gravityzone_disable_amazon_ec2_integrationProDestructiveDisables the EC2 integration.
gravityzone_generate_amazon_ec2_external_id_cross_account_roleProDestructiveMints an AWS external id (credential minting).
gravityzone_get_amazon_ec2_external_id_for_cross_account_roleFreeRead-onlyReads the existing external id.
gravityzone_get_company_details_by_aws_account_idFreeRead-onlyCompany lookup by AWS account id.
gravityzone_get_configured_integrationsFreeRead-onlyPaged list of configured integrations.
gravityzone_get_hourly_usage_for_amazon_ec2_instancesFreeRead-onlyEC2 hourly usage read (billing input).
gravityzone_get_integration_detailsFreeRead-onlyReads one integration.
gravityzone_manage_integrationProDestructiveEnables/disables an integration.
gravityzone_update_integrationProDestructiveWholesale replace of an integration config incl.

[Bitdefender GravityZone] Grants cross-account AWS role access - privilege-widening. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: configureAmazonEC2IntegrationUsingCrossAccountRole on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the target company. Default value: the ID of the company that the API key used to make the request belongs to.
crossAccountRoleArnstringyesThe Amazon Resource Name of a valid AWS Cross-Account Role.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
integrationNamestringnonullEnter a name to identify this specific integration. Default value: the ID of the AWS account (awsAccountId).

[Bitdefender GravityZone] Creates a third-party integration incl. credentials. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createIntegration on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company you want to configure the integration for. Default value: The ID of the company the API key used to make the request belongs to. Example: "companyId": "677e745dd121e7cec70444fe"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
namestringyesThe name of the integration. The value must be between 1 and 128 characters Example: "name": "integrationjDAAdvXoYt77FP6Eu4O3"
specificsJsonstringyesThe configuration settings for the integration. Refer to specifics. Supply this as raw JSON (a JSON object).
typeintegeryesThe type of the integration. Possible values: 1 - VMware Integration Example: "type": 1

[Bitdefender GravityZone] Deletes an integration. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteIntegration on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
integrationIdstringyesThe ID of the integration you want to delete. The user making the request must have Network administrator rights for the company the ID belongs to. Example: "integrationId": "67a09cb42639eb963f016972"

[Bitdefender GravityZone] Disables the EC2 integration. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: disableAmazonEC2Integration on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company. Default value: the ID of the company that the API key used to make the request belongs to.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
integrationNamestringnonullThe name of the integration to be deleted. Warning If this parameter is not included in the request, all the integrations on the selected company will be deleted.

[Bitdefender GravityZone] Mints an AWS external id (credential minting). DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: generateAmazonEC2ExternalIdForCrossAccountRole on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the target company. The default value is the ID of the company linked to the user who generated the API key.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Reads the existing external id. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getAmazonEC2ExternalIdForCrossAccountRole on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the target company. The default value is the ID of the company linked to the user who generated the API key.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Company lookup by AWS account id. Partner console only. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getCompanyDetailsByAWSAccountId on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
accountIdstringyesThe ID of the AWS account
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Paged list of configured integrations. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getConfiguredIntegrations on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIDstringnonullThe ID of the company that you want to retrieve configurations for. The user making the request must have Network administrator rights for The company the ID belongs to. Default value: The ID of the company associated with the API key used for the request.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] EC2 hourly usage read (billing input). GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getHourlyUsageForAmazonEC2Instances on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company. The default value is the ID of the company linked to the user who generated the API key.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
targetMonthstringnonullThe month for which the usage is returned. The month will be provided in the following format: mm/yyyy. The default value is the current month.

[Bitdefender GravityZone] Reads one integration. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getIntegrationDetails on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
integrationIdstringyesThe ID of the integration you want to get information for. Example: "integrationId": "678f89ef8fe5bb14010b3242"

[Bitdefender GravityZone] Enables/disables an integration. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: manageIntegration on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
integrationIdstringyesThe ID of the integration you want to enable or disable. Example: "id": "b675cb3d-c884-444f-b339-b427bd82340b"

[Bitdefender GravityZone] Wholesale replace of an integration config incl. credentials. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: updateIntegration on the integrations namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
integrationIdstringyesThe ID of the integration you want to update. Example: "integrationId": "6788dd3aae9178700406b8ca"
namestringnonullThe new name for the integration. Example: "name": "edited05M353Nwh9Dn9BbCkSoD"
specificsJsonstringnonullThe configuration settings for the integration. Refer to speficics. Supply this as raw JSON (a JSON object).

Investigation

ToolPlanAccessSummary
gravityzone_collect_investigation_packageProDestructiveDispatches forensic collection on a live endpoint.
gravityzone_get_investigation_file_urlFreeRead-onlyReturns a signed download URL for a collected artifact.
gravityzone_kill_process_investigationProDestructiveTerminates a running process on a live endpoint.
gravityzone_start_command_execution_on_endpointProDestructiveARBITRARY COMMAND EXECUTION on a live endpoint.
gravityzone_start_retrieve_investigation_file_from_endpointProDestructivePulls an arbitrary file off a live endpoint.

[Bitdefender GravityZone] Dispatches forensic collection on a live endpoint. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status_network for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: collectInvestigationPackage on the investigation namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
targetIdstringyesThe ID of the managed endpoint targeted by the investigation package collection task. The string should be a valid managed endpoint ID containing exactly 24 hexadecimal characters.

[Bitdefender GravityZone] Returns a signed download URL for a collected artifact. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getInvestigationFileUrl on the investigation namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
activityIdstringyesThe investigation activity ID returned by collectInvestigationPackage. Must be the valid ID of a collectInvestigationPackage task previously initiated for the endpoint specified through targetId. The string should contain exactly 24 hexadecimal characters.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
targetIdstringyesThe ID of the endpoint for which the package retrieval was previously initiated using collectInvestigationPackage. The string should be a valid managed endpoint ID containing exactly 24 hexadecimal characters.

[Bitdefender GravityZone] Terminates a running process on a live endpoint. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: killProcess on the investigation namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
pathstringnonullThe file system path to the process to kill. Must be a valid file system path. If processId is set, this parameter must correspond to the executable path of the process whose PID matches the value of processId. Mandatory if processId is not provided Optional if processId is provided.
processIdintegernonullThe unique process identifier (PID) of the process to terminate. Must be non-negative. If path is set, this parameter must correspond to the PID of the process whose executable path matches the value of path. Mandatory if path is not provided Optional if path is provided.
targetIdstringyesThe ID of the managed endpoint where the target process is running. Must be the valid ID of an endpoint in your network that is protected by BEST. The string should contain exactly 24 hexadecimal characters.

[Bitdefender GravityZone] ARBITRARY COMMAND EXECUTION on a live endpoint. Cloud doc set only. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status_network for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: startCommandExecutionOnEndpoint on the investigation namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
commandstringyesThe shell command to execute on the endpoint. Maximum length: 10,000 characters.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
targetIdstringyesThe ID of the endpoint on which you want to execute a command. The string should be the valid ID of an endpoint protected by BEST within your company. It should contain exactly 24 hexadecimal characters.

[Bitdefender GravityZone] Pulls an arbitrary file off a live endpoint. Cloud doc set only. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status_network for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: startRetrieveInvestigationFileFromEndpoint on the investigation namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
pathstringyesThe full path to the file to collect. Must be a valid file path.
targetIdstringyesThe unique identifier of the managed endpoint from which the investigation file will be retrieved. The string should be the valid ID of an endpoint within your company. It should contain exactly 24 hexadecimal characters.

Licensing

ToolPlanAccessSummary
gravityzone_add_product_keyProDestructiveAdds a product key - spends money / changes entitlement.
gravityzone_get_license_infoFreeRead-onlyLicense/subscription read.
gravityzone_get_monthly_usageFreeRead-onlyMonthly usage read (billing input).
gravityzone_get_monthly_usage_per_product_typeFreeRead-onlyMonthly usage by product type.
gravityzone_remove_product_keyProDestructiveRemoves a product key.
gravityzone_set_license_keyProDestructiveReplaces the license key - can cut protection.
gravityzone_set_monthly_subscriptionProDestructiveSets a customer monthly subscription - billable.

[Bitdefender GravityZone] Adds a product key - spends money / changes entitlement. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: addProductKey on the licensing namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company whose license will be set. If no value is passed, the user's company will be selected.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
licenseKeystringyesThe license key to be set. It can be an add-on or a base license.
mdrContactInformationJsonstringnonullAn object containing the company's designated emergency contact details, intended for use by the MDR team during security events or incidents. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
replaceIncompatibleKeysbooleannonullIf true, all existing base licenses or add-ons that are not compatible with the current license key will be removed and the new license will be added to the existing base licenses or add-on keys. The default value is true.

[Bitdefender GravityZone] License/subscription read. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getLicenseInfo on the licensing namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company for which the license information is retrieved. The default value is the ID of the company linked to the user who generated the API key.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
returnAllProductsbooleannonullIf true, information about all the products of the given company will be included in the response. The default value is false.

[Bitdefender GravityZone] Monthly usage read (billing input). GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getMonthlyUsage on the licensing namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company. The default value is the ID of the company linked to the user who generated the API key.
companyRegistrationEndDatestringnonullOnly return monthly usage for companies that were created before this date. Note The time used in the request is considered as UTC.
companyRegistrationStartDatestringnonullOnly return monthly usage for companies that were created after this date. Note The time used in the request is counted as UTC.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
productTypeintegernonullReturn monthly usage for a specific product type. Possible values: 0 for Endpoint Security 3 for Bitdefender EDR 5 for Bitdefender PHASR
targetMonthstringyesThe month for which the usage is returned. It should have the following format: mm/yyyy. The default value is the current month.
usageCoverageTypeintegernonullOnly return monthly usage for companies created in a specific time interval. Use the companyRegistrationStartDate and companyRegistrationEndDate parameters to specify the time period you want to query. Possible values: 3. Abridged; the vendor documentation for this method carries the full text.

[Bitdefender GravityZone] Monthly usage by product type. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getMonthlyUsagePerProductType on the licensing namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company. The default value is the ID of the company linked to the user who generated the API key.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
targetMonthstringnonullThe month for which the usage is returned. It should have the following format: mm/yyyy. The default value is the current month.

[Bitdefender GravityZone] Removes a product key. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: removeProductKey on the licensing namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company. The default value is the ID of the company linked to the user who generated the API key.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
licenseKeystringyesThe key of the license to be removed

[Bitdefender GravityZone] Replaces the license key - can cut protection. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: setLicenseKey on the licensing namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company whose license will be set. If no value is passed, the user's company will be selected.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
licenseKeystringyesThe license key to be set.
mdrContactInformationJsonstringnonullAn object containing the company's designated emergency contact details, intended for use by the MDR team during security events or incidents. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).

[Bitdefender GravityZone] Sets a customer monthly subscription - billable. Partner console only. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: setMonthlySubscription on the licensing namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
additionalProductTypesJsonstringnonullThis parameter applies only to Partner companies. It is an array of integers representing the product types that the Partner can assign to its clients. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array).
assignedProductTypeintegernonullThe product type assigned to the target company. Possible values: 0, for Endpoint Security 3, for Bitdefender EDR 5, for Bitdefender PHASR The default value is 0.
assignedProtectionModelstringnonullassignedProtectionModel, a string representing the type of the protection model that the company will use. Abridged; the vendor documentation for this method carries the full text.
autoRenewPeriodintegernonullThe license validity in months, after auto renewal. This parameter can be set when license subscription type has the value 3 (monthly subscription). The default value is 12, provided endSubscription is set. For no auto-renewal use 0.
companyIdstringyesThe ID of the company that will inherit license seats from the parent company.
edrDataRetentionintegeryesAn integer indicating how long EDR data retention is stored. It is only returned if manageEventCorrelator is set to true. Possible values: 0 - Data retention is not enabled. 1 - Data retention is enabled for 90 days. 2 - Data retention is enabled for 180 days. 3 - Data retention is enabled for 1 year.
endSubscriptionstringnonullThe UTC end date for the product subscription. This parameter can be set when license subscription type has the value 3 (monthly subscription). To unset endSubscription use empty string: ''.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
imDataRetentionintegeryesThe number of days the events will be stored for. It is only returned if manageIntegrityMonitoring is true. Possible values: 0 (7 days retention), 1 (90 days retention), 2 (180 days retention), 3 (365 days retention). The default value is 0 (7 days retention).
licensedServicesJsonstringnonullAn object containing service settings for the company. This parameter makes sense only when creating a company with license of type 3. If omitted, the service will be unavailable. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
manageComplianceManagerbooleannonullTrue for allowing the company to use the Compliance Manager service, False otherwise. If the property is not present, the current value is not changed. Abridged; the vendor documentation for this method carries the full text.
manageContainerProtectionbooleannonullTrue for allowing the company to use the Container Protection service, False otherwise. If the property is not present, the current value is not changed. Abridged; the vendor documentation for this method carries the full text.
manageEASMbooleannonullTrue for allowing the company to use the EASM service, False otherwise. If the property is not present, the current value is not changed. Abridged; the vendor documentation for this method carries the full text.
manageEncryptionbooleannonullTrue for allowing the company to use the Full Disk Encryption service, False otherwise. If the property is not present, the current value is not changed.
manageEventCorrelatorbooleannonullTrue for allowing the company to use the Endpoint Detection and Response (EDR) service, False otherwise. If the property is not present, the current value is not changed. EDR requires Sandbox Analyzer and HyperDetect to be enabled. Abridged; the vendor documentation for this method carries the full text.
manageExchangebooleannonullTrue for allowing the company to use the Security for Exchange service, False otherwise. If the property is not present, the current value is not changed.
manageExtendedEmailSecuritybooleannonullTrue for allowing the company to use the Extended Email Security service, False otherwise. If the property is not present, the current value is not changed. Abridged; the vendor documentation for this method carries the full text.
manageHyperDetectbooleannonullTrue for allowing the company to use the HyperDetect service, False otherwise. If the property is not present, the current value is not changed. Note This parameter can not be used if any of the manageHtperDetect and manageHyperDetectResell settings under the ownUse and resell object parameters exist.
manageIntegrityMonitoringbooleannonullTrue for allowing the company to use the Integrity Monitoring service, False otherwise. If the property is not present, the current value is not changed.
manageMobileSecuritybooleannonullTrue for allowing the company to use the Mobile Security service, False otherwise. If the property is not present, the current value is not changed.
managePHASRbooleannonullTrue for allowing the company to use the PHASR service, False otherwise. If the property is not present, the current value is not changed. Note This parameter can not be used if any of the managePHASR and managePHASRResell settings under the ownUse and resell object parameters exist.
managePatchManagementbooleannonullTrue for allowing the company to use the Patch Management service, False otherwise. If the property is not present, the current value is not changed. Abridged; the vendor documentation for this method carries the full text.
manageRemoteEnginesScanningbooleannonullTrue for allowing the company to use the Security for Virtualized Environments service, False otherwise. If the property is not present, the current value is not changed. Abridged; the vendor documentation for this method carries the full text.
manageSandboxAnalyzerbooleannonullTrue for allowing the company to use the Sandbox Analyzer service, False otherwise. If the property is not present, the current value is not changed.
removeReservedSlotsbooleannonullTrue for allowing dynamic provisioning of license seats to this company and its clients, False otherwise. Default value is False.
reservedSlotsintegernonullThe number of seats ensured for the target company from the parent's company total amount of seats. The default value is 0, meaning that no seats will be reserved. If no value is passed, the parameter preserves its previous value.

Maintenance Windows

ToolPlanAccessSummary
gravityzone_assign_maintenance_windowsProDestructiveAssigns windows to targets - schedules patch installs/reboots.
gravityzone_create_patch_management_maintenance_windowProWriteAdditive: creates a maintenance window definition.
gravityzone_delete_maintenance_windowProDestructiveDeletes a maintenance window.
gravityzone_get_maintenance_window_detailsFreeRead-onlyOne maintenance window.
gravityzone_get_maintenance_windows_listFreeRead-onlyPaged maintenance-window list.
gravityzone_get_manually_approved_patchesFreeRead-onlyReads manually approved patches.
gravityzone_unassign_maintenance_windowsProDestructiveRemoves windows from targets (revoke).
gravityzone_update_patch_management_maintenance_windowProDestructiveWholesale replace; schedules patching and reboots.

[Bitdefender GravityZone] Assigns windows to targets - schedules patch installs/reboots. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: assignMaintenanceWindows on the maintenanceWindows namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
maintenanceWindowIdsJsonstringyesThe list of maintenance windows identified by ID to assign to the policy. Note The maintenance window must be from the same company as the policy. maintenanceWindowIds array can contain only 1 maintenance window of each type. Supply this as raw JSON (a JSON array).
policyIdstringyesThe ID of the policy to assign the maintenance windows to.

[Bitdefender GravityZone] Additive: creates a maintenance window definition. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createPatchManagementMaintenanceWindow on the maintenanceWindows namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
allowChangeByOtherUsersbooleanyesIndicates if the target is a Customer company. Example: "allowChangeByOtherUsers": "1"
companyIdstringnonullThe ID of the company where you want the maintenance window created. Default value: The ID of the company linked to the user who generated the API key. Requirements: The user must have Manage Company rights for the selected company. Abridged; the vendor documentation for this method carries the full text.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
namestringyesThe name you want to assign to the Patch Management window. Possible values: Must be between 1 and 80 characters. Must be unique. Example: "name": "QXPzQWvgtqtI4FlCRSU9z"
settingsJsonstringyesUse this array to configure Patch Management settings for the maintenance window you are creating. Refer to Objects Supply this as raw JSON (a JSON array). Example: "settings": { "downloadSettings": , "installPatchesSettings": , "scanPatchesSettings": },

[Bitdefender GravityZone] Deletes a maintenance window. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteMaintenanceWindow on the maintenanceWindows namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idstringyesThe ID of the maintenance window to be deleted.

[Bitdefender GravityZone] One maintenance window. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getMaintenanceWindowDetails on the maintenanceWindows namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idstringyesThe ID of the queried maintenance window

[Bitdefender GravityZone] Paged maintenance-window list. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getMaintenanceWindowsList on the maintenanceWindows namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullCompany identifier
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
pageintegerno1Results page number, 1-based. Default 1. The results page number. The default value is 1.
perPageintegerno30Items per page. Default 30. StackJack caps this at 1000; Bitdefender publishes no maximum for this method. Values outside the range are clamped rather than refused.
typeintegernonullThe type of maintenance windows to retrieve. If not provided, all windows will be retrieved. The only available value is 0 - Patch Management.

[Bitdefender GravityZone] Reads manually approved patches. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getManuallyApprovedPatches on the maintenanceWindows namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringyesThe ID of the company you want to retrieve the patches for. Default value: the company the API key used to make the request belongs to.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Removes windows from targets (revoke). DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: unassignMaintenanceWindows on the maintenanceWindows namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
maintenanceWindowIdsJsonstringyesThe list of IDs belonging to the maintenance windows that will be unassigned from the policy. Note maintenanceWindowIds array can contain only 1 maintenance window of each type. Supply this as raw JSON (a JSON array).
policyIdstringyesThe ID of the policy to unassign the maintenance windows from. Note The policyId must belong to a company where the user has visibility. If the policy does not belong your company, and uiSettings.general.allowChangeByOtherUsers is set to False an error will be received and the request will not be processed.

[Bitdefender GravityZone] Wholesale replace; schedules patching and reboots. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: updatePatchManagementMaintenanceWindow on the maintenanceWindows namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
allowChangeByOtherUsersbooleanyesIndicates if the target is a Customer company. Example: "allowChangeByOtherUsers": "1"
companyIdstringnonullThe ID of the company where you want the maintenance window created. Default value: The ID of the company linked to the user who generated the API key. Requirements: The user must have Manage Company rights for the selected company. Abridged; the vendor documentation for this method carries the full text.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idstringyesThe ID of the maintenance window (inside params, alongside settings) Example: "id": "61974ab63bdfe97a6c34fe4d"
namestringyesThe name you want to assign to the Patch Management window. Possible values: Must be between 1 and 80 characters. Must be unique. Example: "name": "QXPzQWvgtqtI4FlCRSU9z"
settingsJsonstringyesUse this array to configure Patch Management settings for the maintenance window you are creating. Refer to Objects Supply this as raw JSON (a JSON array). Example: "settings": { "downloadSettings": , "installPatchesSettings": , "scanPatchesSettings": },

Network

ToolPlanAccessSummary
gravityzone_add_integratorsProDestructiveGrants an integrator access to a company - privilege-widening.
gravityzone_assign_policyProDestructiveReplaces the security policy on targets - can disable protection modules.
gravityzone_create_company_folderProWriteAdditive: creates a company folder.
gravityzone_create_custom_groupProWriteAdditive: creates an inventory group.
gravityzone_create_reconfigure_client_taskProDestructiveInstalls/removes protection modules on live endpoints.
gravityzone_create_scan_taskProDestructiveDispatches a scan to live endpoints.
gravityzone_create_scan_task_by_macProDestructiveDispatches a scan by MAC address.
gravityzone_create_submit_to_sandbox_analyzer_taskProDestructiveUploads a sample for detonation - live dispatch.
gravityzone_delete_company_folderProDestructiveDeletes a company folder.
gravityzone_delete_custom_groupProDestructiveDeletes an inventory group.
gravityzone_delete_endpointProDestructiveDeletes an endpoint from inventory.
gravityzone_delete_taskProDestructiveDeletes a task.
gravityzone_get_companies_listFreeRead-onlyManaged companies list.
gravityzone_get_company_folders_listFreeRead-onlyCompany folder list.
gravityzone_get_custom_groups_listFreeRead-onlyLists custom groups.
gravityzone_get_endpoint_tagsFreeRead-onlyEndpoint tag list.
gravityzone_get_endpoints_listFreeRead-onlyPaged endpoint list.
gravityzone_get_integratorsFreeRead-onlyLists integrators on a company.
gravityzone_get_managed_endpoint_detailsFreeRead-onlyFull endpoint record incl.
gravityzone_get_network_inventory_itemsFreeRead-onlyPaged inventory across all item types.
gravityzone_get_root_containersFreeRead-onlyTop-level containers.
gravityzone_get_scan_tasks_listFreeRead-onlyPaged task list.
gravityzone_get_task_statusFreeRead-onlyTask status read.
gravityzone_kill_process_networkProDestructiveTerminates a running process on a live endpoint.
gravityzone_move_company_or_company_folderProDestructiveRelocates a customer/folder in the partner hierarchy.
gravityzone_move_custom_groupProDestructiveMoves a group - changes inherited policy.
gravityzone_move_endpointsProDestructiveMoves endpoints between groups - changes inherited policy.
gravityzone_move_endpoints_between_companiesProDestructiveCross-tenant endpoint move - licensing/billing impact.
gravityzone_remove_integratorsProDestructiveRevokes integrator access.
gravityzone_run_gather_logs_taskProDestructiveDispatches log collection to a live endpoint.
gravityzone_run_live_search_queryProDestructiveRead in intent, but dispatches a live query to endpoints (Live Search / AWS-backed).
gravityzone_set_endpoint_labelProWritePartial write of one label field.

[Bitdefender GravityZone] Grants an integrator access to a company - privilege-widening. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: addIntegrators on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
integrationIdJsonstringyesThe ID of the integration you want to assign the endpoint as an integrator for. Supply this as raw JSON (a JSON array). Example: "id": "b675cb3d-c884-444f-b339-b427bd82340b"
targetIdsJsonstringyesThe ID of the endpoints you want to set as integrators. The endpoint must belong to the same company where the integration is configured. Supply this as raw JSON (a JSON array). Example: "targetIds": [ "67fcfc57f021e56c3b9a0ee2" ]

[Bitdefender GravityZone] Replaces the security policy on targets - can disable protection modules. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: assignPolicy on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
forcePolicyInheritancebooleannonullIf true, the policy is also assigned to all the child endpoints of the selected targets. To use this parameter, policyId must be included in the request. Default value: false. Example: "forcePolicyInheritance": true
inheritFromAbovebooleannonullIf true, the target endpoints will inherit the policy of the parent containers. If a specific endpoint does not have a parent or the parent does not have any specific policy assigned, it will receive the default policy. Abridged; the vendor documentation for this method carries the full text.
policyIdstringnonullThe ID of the policy you want to assign. If not included in the request, the inheritFromAbove must be present in the request and set to true. Example: "policyId": "55828d66b1a43de92c71****"
targetIdsJsonstringyesThe IDs of the endpoints you want to assign the policy to. Supply this as raw JSON (a JSON array). Example: "targetIds": [ "56728d66b1a43de92c7****", "69738d66b1a43de92c71****" ]

[Bitdefender GravityZone] Additive: creates a company folder. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createCompanyFolder on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
folderNamestringyesThe name for the new folder.
parentIdstringnonullThe ID of the parent company or folder (if the case). The default value is the ID of the parent company.

[Bitdefender GravityZone] Additive: creates an inventory group. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createCustomGroup on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
groupNamestringyesThe name for the new group
parentIdstringnonullThe ID of the parent container. If the parentId refers to a company, the new group is created under the 'Computers and Groups' group of that company. The user's company is automatically selected if no value is passed for this parameter.

[Bitdefender GravityZone] Installs/removes protection modules on live endpoints. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createReconfigureClientTask on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
modulesJsonstringnonullThe modules to be enabled or disabled. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
productTypeintegernonullThis parameter determines the operation mode of the security agent. Possible values: 0 - for Detection and prevention mode, default for full endpoint security agents. 3 - for EDR (Report only) mode, default for Bitdefender EDR agents. For additional information, refer to Parameter info.
rolesJsonstringnonullThe roles to be enabled or disabled on the agent: relay with the following possible values: 1 for enabled 0 for disabled (default) exchange with the following possible values: 1 for enabled 0 for disabled... Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
scanModeJsonstringnonullThe settings for the scanning engines. The object contains the following fields: type, an Integer with one of the following values: 1 for automatic configuration (default) 2 for custom settings. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
schedulerJsonstringnonullThe task scheduler settings. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
targetIdsJsonstringyesThe endpoint or container IDs, for which you want to reconfigure the agents. Supply this as raw JSON (a JSON array).

[Bitdefender GravityZone] Dispatches a scan to live endpoints. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createScanTask on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
customScanSettingsJsonstringnonullObject containing information such as scan depth and scan path(s). This object should be set only when type parameter has the value 4 - Custom scan. When set for other types, the values will be ignored. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
namestringnonullThe name of the task. If the parameter is not passed, the name will be automatically generated.
returnAllTaskIdsbooleannonullIndicates if the response will contain the IDs for all the tasks created as a result of the request. Possible values: true - will return an array of strings with the IDs of all the tasks created as a result of the request. false - will not return any task IDs. Default value: false.
returnTaskIdbooleannonullWarning We recommend using the returnAllTaskIds parameter instead, to make sure all task IDs generated by the request are made available to you in the response. Abridged; the vendor documentation for this method carries the full text.
targetIdsJsonstringyesA list with the IDs of the targets to scan. The target ID can designate an endpoint or a container. Supply this as raw JSON (a JSON array).
typeintegeryesThe type of scan. Available options are: 1 - quick scan; 2 - full scan; 3 - memory scan; 4 - custom scan

[Bitdefender GravityZone] Dispatches a scan by MAC address. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createScanTaskByMac on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
customScanSettingsJsonstringnonullObject containing information such as scan depth and scan path(s). This object should be set only when type parameter has the value 4 - Custom scan. When set for other types, the values will be ignored. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
macAddressesJsonstringyesThe list of mac addresses of the endpoints to be scanned. You can specify at most 100 MAC addresses at once. Supply this as raw JSON (a JSON array).
namestringnonullThe name of the task. If the parameter is not passed, the name will be generated automatically.
returnTaskIdbooleannonullIndicates if the request will return the ID of the new task. Possible values: true, will return the ID of the newly created task, if the request is successful. false, will not return the ID of the newly created task. Instead, it will return a Boolean value. Default value: False.
typeintegeryesThe type of scan. Available options: 1 - quick scan; 2 - full scan; 3 - memory scan; 4 - custom scan

[Bitdefender GravityZone] Uploads a sample for detonation - live dispatch. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createSubmitToSandboxAnalyzerTask on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
commandLinesJsonstringnonullThis array contains multiple Strings that allow you customize how each file is processed in Sandbox Analyzer. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
samplePathsJsonstringyesThe paths to the files you want to submit for analysis. The Array can contain between 1 and 5 Strings. The values must have a valid path format and can have up to 1024 characters. Supply this as raw JSON (a JSON array). Example: "samplePaths": [ "C:\first-script.ps1", "C:\executable.exe", "C:\text-file.txt" ]
targetIdstringyesThe endpoint id from which the task will be launched and where the files to be submitted are located. Example: "targetId": "5d7244b10ea1de153817c072"
taskNamestringnonullThe name you want to apply to the task. The string can have up to 512 characters. Default value: Submit to Sandbox Analyzer YYYY-MM-DD. Example: "taskName": "Submit to Sandbox Task Example"

[Bitdefender GravityZone] Deletes a company folder. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteCompanyFolder on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
folderIdstringyesThe ID of the company folder to be deleted.

[Bitdefender GravityZone] Deletes an inventory group. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteCustomGroup on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
forcebooleannonullForce delete when group is not empty. By default, the parameter is set to False.
groupIdstringyesThe ID of the custom group to be deleted

[Bitdefender GravityZone] Deletes an endpoint from inventory. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteEndpoint on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
endpointIdstringyesThe ID of the endpoint
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Deletes a task. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteTask on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
taskIdstringyesThe ID of the task you want to retrieve the status of. Example: "taskId": "21a295eeb1a43d8b497b23b7",

[Bitdefender GravityZone] Managed companies list. Partner console only. Filters are nested JSON objects, not query strings. Two traps: filters.details.name matches by PREFIX unless you lead the value with * (which switches it to contains), and a filter whose GravityZone license is not active is SILENTLY IGNORED rather than refused — which returns a confidently wrong result set. Confirm the license before trusting a filtered count. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getCompaniesList on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
filtersJsonstringnonullThe filters to apply on the returned list. The filtering criteria are: companyType: 0 - partner companies, 1 - customer companies licenseType: 1 - companies with trial license key, 2 - companies with yearly license key, 3 - companies with monthly license key Supply this as raw JSON (a JSON object).
parentIdstringnonullThe parent company's ID or the company folder's ID. The default value is the ID of the parent company.

[Bitdefender GravityZone] Company folder list. Partner console only. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getCompanyFoldersList on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
parentIdstringnonullThe parent company's ID or the parent folder's ID. The default value is the ID of the parent company.

[Bitdefender GravityZone] Lists custom groups. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getCustomGroupsList on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
parentIdstringnonullThe ID of the parent group for which the child groups will be listed. 'Computers and Groups' and 'Deleted' groups are returned if the passed parameter is null or a company ID.

[Bitdefender GravityZone] Endpoint tag list. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getEndpointTags on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdsJsonstringnonullThe IDs of the companies for which the endpoint tags will be returned. Each string in the array should consist of exactly 24 hexadecimal characters. By default, this parameter is an array with the ID of the company associated with the API request. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
orderstringnonullThe sort order. Possible values: ASC: Endpoint tags are returned in ascending order depending on the selected criterion: created: From oldest to newest. name: Alphabetical order from A to Z. type: Custom tags before Automatic tags. Abridged; the vendor documentation for this method carries the full text.
orderBystringnonullThe criterion used to sort the returned endpoint tags. Possible values: name: Endpoint tags will be sorted by tag name. type: Endpoint tags will be sorted by type: Custom or Automatic. created: Endpoint tags will be sorted by their creation date. Default value: created. Example: "orderBy": "name"

[Bitdefender GravityZone] Paged endpoint list. perPage 1-1000. THE core read. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. Filters are nested JSON objects, not query strings. Two traps: filters.details.name matches by PREFIX unless you lead the value with * (which switches it to contains), and a filter whose GravityZone license is not active is SILENTLY IGNORED rather than refused — which returns a confidently wrong result set. Confirm the license before trusting a filtered count. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getEndpointsList on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
filtersJsonstringnonullThe parameters used to customize the type of endpoints you want to retrieve. For information regarding the available filters and how to use them, refer to Available Filters. Supply this as raw JSON (a JSON object).
isManagedbooleannonullThe flag to list managed or unmanaged endpoints. By default, the parameter is not set and the method returns all the managed and unmanaged endpoints. If set on True, the method returns only managed endpoints.
optionsJsonstringnonullA set of options that control what information is present in the response. Supply this as raw JSON (a JSON object).
pageintegerno1Results page number, 1-based. Default 1. The results page number.. Default value: 1.
parentIdstringnonullThe ID of the target company or group. If not specified, the method returns items that are in the targets of the company linked to the API key. Note To retrieve information on Active Directory endpoints, use the getNetworkInventoryItems method.
perPageintegerno30Items per page. Default 30. Bitdefender documents a maximum of 1000 for this method. Values outside the range are clamped rather than refused.

[Bitdefender GravityZone] Lists integrators on a company. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getIntegrators on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
integrationIdJsonstringyesThe ID of the integration you want to retrieve the list of integrators for. Supply this as raw JSON (a JSON array). Example: "id": "b675cb3d-c884-444f-b339-b427bd82340b"

[Bitdefender GravityZone] Full endpoint record incl. agent/module state. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getManagedEndpointDetails on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
endpointIdstringyesThe ID of the endpoint for which the details will be returned. Must be a valid ID, belonging to a managed endpoint. Tip You can use the getEndpointsList method to get a list of managed endpoints by including the isManaged parameter and setting it to true. Example: "endpointId" : "54a28b41b1a43d89367b23fd"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
optionsJsonstringnonullA set of options that control what information is present in the response. For more information on this object, refer to options. Supply this as raw JSON (a JSON object). Example: "options": { "includeScanLogs": true, "includeLastLoggedUsers": true }

[Bitdefender GravityZone] Paged inventory across all item types. perPage 1-1000. Rate-limited to 5 rps. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. Filters are nested JSON objects, not query strings. Two traps: filters.details.name matches by PREFIX unless you lead the value with * (which switches it to contains), and a filter whose GravityZone license is not active is SILENTLY IGNORED rather than refused — which returns a confidently wrong result set. Confirm the license before trusting a filtered count. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getNetworkInventoryItems on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
filtersJsonstringnonullThe filters you want to use when querying the endpoints list. You can find a full list of available filters and instructions on how to use them, under Available Filters. Supply this as raw JSON (a JSON object).
optionsJsonstringnonullUse this set of options that to control what information is included in the request. For more information, refer to Available Options. Supply this as raw JSON (a JSON object).
pageintegerno1Results page number, 1-based. Default 1. The results page number. Default page number is 1.
parentIdstringnonullThe ID of the target company or group. If not specified, the default value applies. Default value: the ID of the company that the API key used to make the request belongs to.
perPageintegerno30Items per page. Default 30. Bitdefender documents a maximum of 1000 for this method. Values outside the range are clamped rather than refused.

[Bitdefender GravityZone] Top-level containers. Partner console only. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getRootContainers on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company for which the method will return the root containers. If null, the id of company linked to the API access key will be considered.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Paged task list. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. Vendor JSON-RPC method: getScanTasksList on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
namestringnonullThe name of the task. Filter the list of tasks by task name. Use the asterisk symbol (*) in front of the keyword to search its appearance anywhere in the name. If omitted, only results where the name starts with the keyword will be returned.
pageintegerno1Results page number, 1-based. Default 1. The results page number. Default page number is 1.
perPageintegerno30Items per page. Default 30. StackJack caps this at 1000; Bitdefender publishes no maximum for this method. Values outside the range are clamped rather than refused.
statusintegernonullThe status of the task. Available options are: 1 - Pending; 2 - In progress; 3 - Finished.

[Bitdefender GravityZone] Task status read. perPage 1-1000. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getTaskStatus on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
endedAfterstringnonullWhen used, the response only includes information on tasks that have ended after a specific date and time.
endedBeforestringnonullWhen used, the response only includes information on tasks that have ended before a specific date and time.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
optionsJsonstringnonullUse this set of options that to control what information is included in the request. To use this parameter, returnSubtasks must be included in the request and must have the true value assigned. Supply this as raw JSON (a JSON object).
pageintegerno1Results page number, 1-based. Default 1. The results page number. Default value: 1.
perPageintegerno30Items per page. Default 30. Bitdefender documents a maximum of 1000 for this method. Values outside the range are clamped rather than refused.
returnSubtasksbooleannonullDetermines if the response also includes information on individual subtasks. Tip When a task is created for multiple endpoints, a subtask is created for each individual endpoint.
statusintegernonullWhen included in the request, this field determines what subtasks are included in the request, based on their current status. Possible values: 1 - Pending 2 - In progress 3 - Finished
subtaskFiltersJsonstringnonullDetermines information on which subtasks is included in the response. To use this parameter, returnSubtasks must be included in the request and must have the true value assigned. Supply this as raw JSON (a JSON object).
taskIdstringyesThe ID of the task you want to retrieve the status of.

[Bitdefender GravityZone] Terminates a running process on a live endpoint. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: killProcess on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
endpointIdstringyesThe endpoint (or node) where the process is running. Example: "endpointId": "66a0fe708d3a52774522b442"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
incidentIdstringnonullThe ID of the incident generated as a result of this process. Example: "incidentId": "66a251423506b508d2fefb05
pathstringyesThe location of the file that starts the process on the endpoint where it is stored. Must be in the proper path format and lead to an existing file. Example: Windows "path": "C:\Windows\explorer.exe" Linux "path": "/usr/bin/rhythmbox" Mac "path": "/System/Applications/Calendar.app/Contents/MacOS/Calendar"
processIdstringyesThe ID of the process you want to terminate. Example: "processId": 12228

[Bitdefender GravityZone] Relocates a customer/folder in the partner hierarchy. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: moveCompanyOrCompanyFolder on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
idstringyesThe ID of the company or company folder to be moved.
newParentIdstringyesThe ID of the new parent company of company folder.

[Bitdefender GravityZone] Moves a group - changes inherited policy. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: moveCustomGroup on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
groupIdstringyesThe ID of the custom group to be moved
parentIdstringyesThe ID of the destination custom group

[Bitdefender GravityZone] Moves endpoints between groups - changes inherited policy. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: moveEndpoints on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
endpointIdsJsonstringyesThe list of endpoints IDs Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
groupIdstringyesThe ID of the destination group

[Bitdefender GravityZone] Cross-tenant endpoint move - licensing/billing impact. Partner console only. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: moveEndpointsBetweenCompanies on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
destinationGroupIdstringyesThe ID of the destination group
endpointIdsJsonstringyesThe list of endpoints IDs Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Revokes integrator access. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: removeIntegrators on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
targetIdsJsonstringyesThe ID of the endpoint that you want to unassigned as an integrator. Supply this as raw JSON (a JSON array). Example: "targetIds": [ "67fcffe8bf190f9d03b3487e" ]

[Bitdefender GravityZone] Dispatches log collection to a live endpoint. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. Vendor JSON-RPC method: runGatherLogsTask on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
paramsJsonstringnonullThe full JSON-RPC params object for this method, as raw JSON. Bitdefender's documentation page for this method did not publish a machine-readable parameter table, so StackJack passes your object through unchanged rather than guessing a signature. Consult the vendor documentation for the exact fields.

[Bitdefender GravityZone] Read in intent, but dispatches a live query to endpoints (Live Search / AWS-backed). Classified W+Destructive under the live-dispatch rule; owner may downgrade to a Free-tier read. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: runLiveSearchQuery on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringyesThe ID of the company that the target endpoints belong to. Example: "companyId": "669659908c2fa1ace601****"
endpointsJsonstringnonullA list of endpoint IDs. Determines where the query is ran. The ID must belong to an endpoint managed by the target company. Default value: all endpoints in the target company. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
operatingSystemsJsonstringnonullThe operating system of the target endpoints. Tip This parameter is best suited to run a query on all the endpoints of the target company that use a specific operating system. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array).
querystringyesThe query that will run on all endpoints. Refer to this KB article for more information on queries. Example: "query": "select * from time;"
s3UploadConfigJsonstringyesThe S3 bucket where the returned data is stored. Refer to s3UploadConfig Supply this as raw JSON (a JSON object). Example: "s3UploadConfig": { "bucket": "test-bucket-name", "region": "eu-north-1", "roleArn": "arn:aws:iam::000000000000:role/role-name", "externalId": "000000000000000000000" }

[Bitdefender GravityZone] Partial write of one label field. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: setEndpointLabel on the network namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
endpointIdstringyesThe endpoint ID
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
labelstringyesA string representing the label. The maximum allowed length is 64 characters. Enter an empty string to reset a previously set label.

Packages

ToolPlanAccessSummary
gravityzone_create_packageProWriteAdditive: creates an installer package definition.
gravityzone_delete_packageProDestructiveDeletes an installer package.
gravityzone_get_installation_linksFreeRead-onlyReturns installer download links for a package.
gravityzone_get_package_detailsFreeRead-onlyOne package definition.
gravityzone_get_packages_listFreeRead-onlyPaged package list.
gravityzone_update_packageProDestructiveWholesale replace of an installer package definition.

[Bitdefender GravityZone] Additive: creates an installer package definition. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createPackage on the packages namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company. The default value is the ID of the company linked to the user who generated the API key.
deploymentOptionsJsonstringnonullAn object containing installation options: type, an integer indicating the entity to which the endpoint will connect to. This entity will deliver the installation kit and updates. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
descriptionstringnonullThe description of the package. If no value is passed, the description will be an empty string.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
languagestringnonullThe language of the package in the LL_CC format, where LL is the language and CC is the country. The supported languages are: en_US, es_ES, de_DE, fr_FR, ro_RO, pl_PL, pt_BR, it_IT, ru_RU. If not specified, the default value is en_US.
modulesJsonstringnonullAn object with the modules to be enabled/disabled. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
packageNamestringyesThe name of the package.
productTypeintegernonullThis parameter determines the operation mode of the security agent. Possible values: 0 - for Detection and prevention mode, default for full endpoint security agents. 3 - for EDR (Report only) mode, default for Bitdefender EDR agents. 5 - for PHASR Standalone mode. For additional information, refer to Parameter Info.
rolesJsonstringnonullAn object containing the roles to be enabled or disabled: relay with the following possible values: 1 for enabling the Relay role, and 0 to disable it. By default, the Relay role is disabled. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
scanModeJsonstringnonullAn object with the scan mode settings. Object description: The accepted keys are: type, vms, computers, and ec2 if the AWS integration is set up. The type value can be 1 (automatic) or 2 (for custom mode). Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
settingsJsonstringnonullAn object with other settings of the package. The values can be: removeCompetitors, uninstallPassword, customInstallationPath, customGroupId. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).

[Bitdefender GravityZone] Deletes an installer package. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deletePackage on the packages namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
packageIdstringyesThe ID of the package to be deleted.

[Bitdefender GravityZone] One package definition. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getPackageDetails on the packages namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
packageIdstringyesThe ID of the package for which details should be retrieved.

[Bitdefender GravityZone] Paged package list. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getPackagesList on the packages namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company for which the packages list is retrieved. The default value is the company of the user who has generated the API key. If not passed, the packages available to the company are returned.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
pageintegerno1Results page number, 1-based. Default 1. The page number of results. Default page number is 1.
perPageintegerno30Items per page. Default 30. StackJack caps this at 1000; Bitdefender publishes no maximum for this method. Values outside the range are clamped rather than refused.

[Bitdefender GravityZone] Wholesale replace of an installer package definition. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: updatePackage on the packages namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company. The default value is the ID of the company linked to the user who generated the API key.
deploymentOptionsJsonstringnonullAn object containing installation options: type, an integer indicating the entity to which the endpoint will connect to. This entity will deliver the installation kit and updates. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
descriptionstringnonullThe description of the package. If no value is passed, the description will be an empty string.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
languagestringnonullThe language of the package in the LL_CC format, where LL is the language and CC is the country. The supported languages are: en_US, es_ES, de_DE, fr_FR, ro_RO, pl_PL, pt_BR, it_IT, ru_RU. If not specified, the default value is en_US.
modulesJsonstringnonullAn object with the modules to be enabled/disabled. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
packageIdstringyesThe ID of the package.
packageNamestringyesThe name of the package.
productTypeintegernonullThis parameter determines the operation mode of the security agent. Possible values: 0 - for Detection and prevention mode, default for full endpoint security agents. 3 - for EDR (Report only) mode, default for Bitdefender EDR agents. Abridged; the vendor documentation for this method carries the full text.
rolesJsonstringnonullAn object containing the roles to be enabled or disabled: relay with the following possible values: 1 for enabling the Relay role, and 0 to disable it. By default, the Relay role is disabled. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
scanModeJsonstringnonullAn object with the scan mode settings. Object description: The accepted keys are: type, vms, computers, and ec2 if the AWS integration is set up. The type value can be 1 (automatic) or 2 (for custom mode). Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
settingsJsonstringnonullAn object with other settings of the package. The values can be: removeCompetitors, uninstallPassword, customInstallationPath, customGroupId. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).

Patch Management

ToolPlanAccessSummary
gravityzone_get_installed_patchesFreeRead-onlyPaged installed-patch inventory.
gravityzone_get_missing_patchesFreeRead-onlyPaged missing-patch inventory - high MSP value.

[Bitdefender GravityZone] Paged installed-patch inventory. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. Filters are nested JSON objects, not query strings. Two traps: filters.details.name matches by PREFIX unless you lead the value with * (which switches it to contains), and a filter whose GravityZone license is not active is SILENTLY IGNORED rather than refused — which returns a confidently wrong result set. Confirm the license before trusting a filtered count. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getInstalledPatches on the patchManagement namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company for which you want to retrieve patch information for. Example: "companyId": "63c6bb02e3cb799758020c99"
endpointsIdsJsonstringnonullThe ID of the endpoint for which you want to retrieve patch information for. Mandatory Note Either the endpointId or the companyId parameter must be included in the request. The two are mutually exclusive. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
filtersJsonstringnonullDetermines the type of patches should be included in the response. Default value: If this parameter is not included in the request, all filters will be returned, regardless of type of severity level. Supply this as raw JSON (a JSON object). Example: "filters":{ "type": 0, "severity": 1 },
pageintegerno1Results page number, 1-based. Default 1. The results page number. Default value: 1.
perPageintegerno30Items per page. Default 30. StackJack caps this at 1000; Bitdefender publishes no maximum for this method. Values outside the range are clamped rather than refused.

[Bitdefender GravityZone] Paged missing-patch inventory - high MSP value. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. Filters are nested JSON objects, not query strings. Two traps: filters.details.name matches by PREFIX unless you lead the value with * (which switches it to contains), and a filter whose GravityZone license is not active is SILENTLY IGNORED rather than refused — which returns a confidently wrong result set. Confirm the license before trusting a filtered count. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getMissingPatches on the patchManagement namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company for which you want to retrieve patch information for. Example: "companyId": "63c6bb02e3cb799758020c99"
endpointsIdsJsonstringnonullThe ID of the endpoint for which you want to retrieve patch information for. Mandatory Note Either the endpointId or the companyId parameter must be included in the request. The two are mutually exclusive. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
filtersJsonstringnonullDetermines the type of patches should be included in the response. Default value: If this parameter is not included in the request, all filters will be returned, regardless of type of severity level. Supply this as raw JSON (a JSON object). Example: "filters":{ "type": 0, "severity": 1 },
pageintegerno1Results page number, 1-based. Default 1. The results page number. Default value: 1.
perPageintegerno30Items per page. Default 30. StackJack caps this at 1000; Bitdefender publishes no maximum for this method. Values outside the range are clamped rather than refused.

PHASR

ToolPlanAccessSummary
gravityzone_apply_recommendationsProDestructiveApplies PHASR hardening recommendations across endpoints.
gravityzone_edit_monitored_rules_accessProDestructiveChanges PHASR access enforcement on identities/resources.
gravityzone_get_all_company_identitiesFreeRead-onlyPHASR identities list.
gravityzone_get_all_company_resourcesFreeRead-onlyPHASR resources list.
gravityzone_get_monitored_rule_dataFreeRead-onlyPHASR rule data read.
gravityzone_get_monitored_rulesFreeRead-onlyPHASR monitored rules list.
gravityzone_get_phasr_recommendationsFreeRead-onlyPHASR recommendation list.
gravityzone_get_recommendation_profilesFreeRead-onlyPHASR recommendation profiles.
gravityzone_take_request_access_actionProDestructiveApproves/denies a PHASR access request - privilege grant.

[Bitdefender GravityZone] Applies PHASR hardening recommendations across endpoints. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: applyRecommendations on the phasr namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company the recommendations you want to apply belong to. Must be a valid company ID for which you have management rights to. Default value: The ID of the company associated with the API key used for the request. Optional Note Mandatory when applying recommendations from another company.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
recommendationIdsJsonstringyesThe IDs of the recommendations you want to apply. Must be valid recommendation IDs and must belong to the same company. Supply this as raw JSON (a JSON array). Example: "recommendationIds": [ "68480f4e11e8dc005bb0f9e7", "6853e32b4783f7a2f15582c4", "6853e32b4783f7a2f15582cf" ]

[Bitdefender GravityZone] Changes PHASR access enforcement on identities/resources. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: editMonitoredRulesAccess on the phasr namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
actionintegeryesThe action that is to be taken on the specified behavioral profiles. Possible values: 0 - Allow access - Grants access for the specified behavioral profiles to the assets identified in the recommendation generated by the specified rule. Abridged; the vendor documentation for this method carries the full text.
companyIdstringnonullThe ID of the company the rule belongs to. Default value: The ID of the company associated with the API key used for the request. Example: "companyId": "68306c15c9b5cb3e920ffe22"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
ruleIdintegeryesThe ID of the rule on which the recommendation is based. Example: "ruleId": 1
targetTypeintegernonullThe type of the specified behavioral profiles. Possible values: 0 - Profile
targetsJsonstringyesA list of the IDs of the behavioral profiles to which you want to apply the recommendation generated by the specified rule. A behavioral profile ID is constructed by combining the identityId of a user with the resourceId of a device they are paired with. Supply this as raw JSON (a JSON array).

[Bitdefender GravityZone] PHASR identities list. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getAllCompanyIdentities on the phasr namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company you want to retrieve identity information for. Must be a valid company ID for which you have management rights to. Default value: The ID of the company associated with the API key used for the request. Example: "companyId": "67fe8595d4db0d536908ec92"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
searchStringstringnonullA text value used to search and return only the identities whose names match the specified string. If not included, the response will include all identities. Example: "searchString": "BDAdmin"

[Bitdefender GravityZone] PHASR resources list. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getAllCompanyResources on the phasr namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company you want to retrieve resource information for. Must be a valid company ID for which you have management rights to. Default value: The ID of the company associated with the API key used for the request. Example: "companyId": "67fe8595d4db0d536908ec92"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
searchStringstringnonullA text value used to search and return only the resources whose names match the specified string. If not included, the response will include all resources. Example: "searchString": "AUTHORITY"

[Bitdefender GravityZone] PHASR rule data read. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getMonitoredRuleData on the phasr namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company to which the specified rule belongs. Default value: The ID of the company associated with the API key used for the request. Example: "companyId": "68306c15c9b5cb3e920ffe22"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
profileTypeintegernonullDetermines the types of behavioral profiles that are included in the response. Abridged; the vendor documentation for this method carries the full text. Example: "profileType": 61
ruleIdintegeryesThe ID of the rule you want to retrieve information for. Example: "ruleId": 61

[Bitdefender GravityZone] PHASR monitored rules list. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getMonitoredRules on the phasr namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
categoriesJsonstringnonullDetermines what type of rules are returned by the method. Possible values: 1 - Tampering tool 2 - Hack tool 3 - Remote tool 4 - Miner 5 - Lolbin Supply this as raw JSON (a JSON array). Example: "categories": [1, 3, 5]
companyIdstringyesThe ID of the company you want to retrieve the monitored rules for. Default value: The ID of the company associated with the API key used for the request. Example: "companyId": "68306c15c9b5cb3e920ffe22"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] PHASR recommendation list. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getPhasrRecommendations on the phasr namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
actionTakenJsonstringnonullWhen included, the response will only returns recommendations where a specific action was taken as a result of the recommendation. Possible values: 0 - Action needed. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array). Example: "actionTaken": [0, 1]
behavioralProfileIdentitiesJsonstringnonullOnly include recommendations for the identities associated with the specified identifiers. Values must be in a valid behavioral profile identities format. Supply this as raw JSON (a JSON array).
behavioralProfileResourcesJsonstringnonullOnly include recommendations for the resources associated with the specified identifiers. Values must be in a valid behavioral profile resource format. Supply this as raw JSON (a JSON array).
categoryIdsJsonstringnonullWhen included, the response will only returns recommendations of the specified type. Possible values: 1 - tampering tool 2 - hack tool 3 - remote tool 4 - miner 5 - lol bin Supply this as raw JSON (a JSON array). Example: "categoryIds": [4, 3, 2]
companyIdstringnonullThe ID of the company you want to retrieve PHASR recommendations for. Must be a valid company ID for which you have management rights to. Default value: The ID of the company associated with the API key used for the request. Example: "companyId": "1234567890abcdef"
createdOnMaxstringnonullOnly include recommendations created before this specific date and time. The value must be in ISO 8601 date format. Example: "createdOnMax": "2025-06-06T13:21:00.704Z"
createdOnMinstringnonullOnly include recommendations created after this specific date and time. The value must be in ISO 8601 date format. Example: "createdOnMin": "2025-05-07T13:21:00.704Z"
dirstringnonullDetermines the direction in which the results are sorted: ascending or descending. Possible values: ASC DESC Example: "dir": "ASC"
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
objectIdstringnonullThe ID of the specific recommendation you want to retrieve. Must be a valid recommendation ID. Example: "objectId": "68480f4e11e8dc005bb0f9e7",
ruleIdsJsonstringnonullThe IDs of the rules for which you want to retrieve recommendations. The IDs must be in the - format. Supply this as raw JSON (a JSON array). Example: "ruleIds": ["696-0", "596-1"]
sortstringnonullDetermines the basis on which the recommendations will be ordered in the response. Possible values: attackSurfaceReduction createdOn Example: "sort": "attackSurfaceReduction"
typeJsonstringnonullThe type of the specific recommendation you want to retrieve. Possible values: 0 - Allow access. This retrieves allow recommendations. 1 - Restrict access. This retrieves restrict recommendations. 2 - Allow access request. This retrieves allow access requests. Supply this as raw JSON (a JSON array).

[Bitdefender GravityZone] PHASR recommendation profiles. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getRecommendationProfiles on the phasr namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company the targeted recommendation belongs to. Must be a valid company ID for which you have management rights to. Default value: The ID of the company associated with the API key used for the request. Optional Note Mandatory when targetting recommendations from another company.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
objectIdstringyesThe ID of the recommendation you want to retrieve the behavioral profiles for. Must be a valid recommendation ID. Example: "objectId": "123abc123abc123abc123abc"

[Bitdefender GravityZone] Approves/denies a PHASR access request - privilege grant. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: takeRequestAccessAction on the phasr namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
actionstringyesThe available action for the recommendations. Must represent one of the allowed values: "allow" or "deny"
companyIdstringnonullThe ID of the company the recommendations you want to apply belong to. Must be a valid company ID for which you have management rights to. Default value: The ID of the company associated with the API key used for the request. Optional Note Mandatory when applying recommendations from another company.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
recommendationIdsJsonstringyesThe IDs of the recommendations you want to apply. Must be valid recommendation IDs and must belong to the same company. Supply this as raw JSON (a JSON array). Example: "recommendationIds": [ "68480f4e11e8dc005bb0f9e7", "6853e32b4783f7a2f15582c4", "6853e32b4783f7a2f15582cf" ]

Policies

ToolPlanAccessSummary
gravityzone_get_policies_listFreeRead-onlyPaged policy list.
gravityzone_get_policy_detailsFreeRead-onlyFull policy document.
gravityzone_set_policy_modules_stateProDestructiveTurns protection modules on/off inside a policy.

[Bitdefender GravityZone] Paged policy list. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getPoliciesList on the policies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company for which the policies are retrieved.The default value is the company of the user who has generated the API key. If not passed, the policies available to the company are returned.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
pageintegerno1Results page number, 1-based. Default 1. The page of results. The default value is 1.
perPageintegerno30Items per page. Default 30. StackJack caps this at 1000; Bitdefender publishes no maximum for this method. Values outside the range are clamped rather than refused.

[Bitdefender GravityZone] Full policy document. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getPolicyDetails on the policies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
policyIdstringyesThe ID of the policy you want to get details for. Must be a valid policy ID that the user has access to managing. Example: "policyId" : "55828d66b1a43de92c712345"

[Bitdefender GravityZone] Turns protection modules on/off inside a policy. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: setPolicyModulesState on the policies namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
policyIdstringyesThe ID of the policy you want to modify. The user making the request must have the managePoliciesRead and managePoliciesWrite user rights for the company the target policy belongs to. Example: "policyId": "683ee75b6c9598ab03098f92",
settingsJsonstringyesThe setting you want to modify. This object contains the settings that will be changed as a result of this request and their new values. Supply this as raw JSON (a JSON object).

Event Push Service

ToolPlanAccessSummary
gravityzone_get_push_event_settingsFreeRead-onlyReads the event-push config.
gravityzone_get_push_event_statsFreeRead-onlyPush delivery stats and errors.
gravityzone_reset_push_event_statsProDestructivePurges push statistics/error counters.
gravityzone_send_test_push_eventProDestructiveEmits an event to the customer-configured external endpoint.
gravityzone_set_push_event_settingsProDestructiveWholesale replace of the event-push config; a bad write silences the SIEM feed.

[Bitdefender GravityZone] Reads the event-push config. Vendor JSON-RPC method: getPushEventSettings on the push namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Push delivery stats and errors. Vendor JSON-RPC method: getPushEventStats on the push namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Purges push statistics/error counters. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. Vendor JSON-RPC method: resetPushEventStats on the push namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Emits an event to the customer-configured external endpoint. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. Vendor JSON-RPC method: sendTestPushEvent on the push namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
dataJsonstringnonullTest events are created from templates. This parameter can be used to overwrite data in the returned event example. Supply this as raw JSON (a JSON object).
eventTypestringyesThe type of the event you want tot send a test for. Possible values: hwid-change - Hardware ID Change. This event is generated when the hardware ID of an endpoint from your network is changed. adcloud - Cloud AD Integration. Abridged; the vendor documentation for this method carries the full text.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.

[Bitdefender GravityZone] Wholesale replace of the event-push config; a bad write silences the SIEM feed. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. Vendor JSON-RPC method: setPushEventSettings on the push namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
serviceSettingsJsonstringyesSpecific settings for each service type. For information regarding the service settings, refer to Service Type Settings. Supply this as raw JSON (a JSON object).
serviceTypestringyesType of the web service. Valid values: jsonRPC, splunk, cef, qradar, azureSentinel, and azureSentinelV2.
statusintegeryes0 - disabled, 1 - enabled
subscribeToCompaniesJsonstringyesThe list of companies under your management for which you want to receive the events. You need to mention your own company as well. The list cannot be empty. If the field is missing or has the null value, you will receive events for all companies you manage. Supply this as raw JSON (a JSON array).
subscribeToEventTypesJsonstringyesList of event types to be sent to the web service. Supply this as raw JSON (a JSON array).

Quarantine

ToolPlanAccessSummary
gravityzone_create_add_file_to_quarantine_taskProDestructiveRemoves a file from a live endpoint into quarantine.
gravityzone_create_empty_quarantine_taskProDestructivePurges the whole quarantine.
gravityzone_create_release_quarantine_exchange_item_taskProDestructiveReleases a quarantined email to the recipient mailbox - reaches a human.
gravityzone_create_remove_quarantine_item_taskProDestructivePermanently deletes quarantined items.
gravityzone_create_restore_quarantine_exchange_item_taskProDestructiveRestores a quarantined Exchange item.
gravityzone_create_restore_quarantine_item_taskProDestructiveRestores a quarantined file back to the endpoint - reintroduces flagged content.
gravityzone_get_quarantine_items_listFreeRead-onlyPaged quarantine inventory.

[Bitdefender GravityZone] Removes a file from a live endpoint into quarantine. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createAddFileToQuarantineTask on the quarantine namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
endpointIdsJsonstringyesA list with the IDs of target endpoints. You can specify a maximum of 100 targets at once. Only endpoints with security agents in Detection and prevention mode and an active EDR Sensor module are valid targets. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
filePathstringyesThe absolute file path on disk. This path can be at most 4096 characters in length and should have the format suitable to the target endpoint's operating system.

[Bitdefender GravityZone] Purges the whole quarantine. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. Vendor JSON-RPC method: createEmptyQuarantineTask on the quarantine namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
includeSubCompaniesbooleannonullInclude the quarantined items for child companies. The default value for this parameter is false.
servicestringyesWhich GravityZone quarantine to address: 'computers' (Computers and Virtual Machines) or 'exchange' (Security for Exchange). Required — the vendor addresses this namespace per service.

[Bitdefender GravityZone] Releases a quarantined email to the recipient mailbox - reaches a human. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. This method is documented for the "exchange" (Security for Exchange) quarantine only. Vendor JSON-RPC method: createReleaseQuarantineExchangeItemTask on the quarantine/exchange namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
quarantineItemsIdsJsonstringyesThe list of IDs for the quarantined items. You can restore maximum 100 items once. Supply this as raw JSON (a JSON array).

[Bitdefender GravityZone] Permanently deletes quarantined items. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createRemoveQuarantineItemTask on the quarantine namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
quarantineItemsIdsJsonstringyesThe list of quarantine items IDs. The maximum number of items that can be removed once is 100. The ID must belong to a quarantine item that the user has permission to access. Supply this as raw JSON (a JSON array).
servicestringyesWhich GravityZone quarantine to address: 'computers' (Computers and Virtual Machines) or 'exchange' (Security for Exchange). Required — the vendor addresses this namespace per service.

[Bitdefender GravityZone] Restores a quarantined Exchange item. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. This method is documented for the "exchange" (Security for Exchange) quarantine only. Vendor JSON-RPC method: createRestoreQuarantineExchangeItemTask on the quarantine/exchange namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
emailstringnonullThe email address of the Exchange user. This parameter is necessary when the email address is different from the username.
ewsUrlstringnonullThe Exchange Web Services URL.The EWS URL is necessary when the Exchange Autodiscovery does not work.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
passwordstringyesThe password of an Exchange user.
quarantineItemsIdsJsonstringyesThe list of IDs for the quarantined items. You can restore maximum 100 items once. Supply this as raw JSON (a JSON array).
usernamestringyesThe username of an Microsoft Exchange user. The username must include the domain name.

[Bitdefender GravityZone] Restores a quarantined file back to the endpoint - reintroduces flagged content. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. This DISPATCHES an asynchronous GravityZone task and returns a task id — it is not a completed action. Poll gravityzone_get_task_status for progress before reporting the outcome. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. This method is documented for the "computers" (Computers and Virtual Machines) quarantine only. Vendor JSON-RPC method: createRestoreQuarantineItemTask on the quarantine/computers namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
addExclusionInPolicybooleannonullExclude the files to be restored from future scans. Exclusions do not apply to items with the Default Policy assigned. The default value for this parameter is False.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
locationToRestorestringnonullThe absolute path to the folder where the items will be restored. If the parameter is not set, the original location will be used.
quarantineItemsIdsJsonstringyesThe list of IDs for the quarantined items. You can restore maximum 100 items once. Supply this as raw JSON (a JSON array).

[Bitdefender GravityZone] Paged quarantine inventory. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. Filters are nested JSON objects, not query strings. Two traps: filters.details.name matches by PREFIX unless you lead the value with * (which switches it to contains), and a filter whose GravityZone license is not active is SILENTLY IGNORED rather than refused — which returns a confidently wrong result set. Confirm the license before trusting a filtered count. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: getQuarantineItemsList on the quarantine namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
companyIdstringnonullThe ID of the company for which the quarantine items are retrieved. Default value: the company the API key used to make the request belongs to. If this parameter is not included in the request, the response will display all the quarantined items within the company that the API key used to make the request belongs to.
endpointIdstringnonullThe ID of the computer for which you want to retrieve the quarantined items. If this parameter is not included in the request, the method returns the items quarantined in the entire network.
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
filtersJsonstringnonullThe filters to be used when querying the quarantine items list. For information regarding the available filters and how to use them, refer to Available Filters. Supply this as raw JSON (a JSON object).
pageintegerno1Results page number, 1-based. Default 1. The results page. The default value is 1.
perPageintegerno30Items per page. Default 30. StackJack caps this at 1000; Bitdefender publishes no maximum for this method. Values outside the range are clamped rather than refused.
servicestringyesWhich GravityZone quarantine to address: 'computers' (Computers and Virtual Machines) or 'exchange' (Security for Exchange). Required — the vendor addresses this namespace per service.

Reports

ToolPlanAccessSummary
gravityzone_create_reportProDestructiveCreates an instant or scheduled report; emailList delivers it to human recipients.
gravityzone_delete_reportProDestructiveDeletes a report and its history.
gravityzone_get_download_linksFreeRead-onlyReturns report download links.
gravityzone_get_reports_listFreeRead-onlyPaged scheduled-report list.

[Bitdefender GravityZone] Creates an instant or scheduled report; emailList delivers it to human recipients. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: createReport on the reports namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
emailListJsonstringnonullA list of emails where to deliver the report. emailList should not be set for an instant report. You can only use this parameter if the scheduledInfo parameter is included in the request. Supply this as raw JSON (a JSON array).
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
namestringyesThe name of the report.
optionsJsonstringnonullThe object that defines the options for creating the report. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON object).
scheduledInfoJsonstringnonullThe object that defines the schedule to run the report. If the parameter is omitted, an instant report is generated. For more information, please check the details of the scheduledInfo object. Supply this as raw JSON (a JSON object).
targetIdsJsonstringyesA list with the IDs of the targets for which to create the report. The targets depend on the report type. Abridged; the vendor documentation for this method carries the full text. Supply this as raw JSON (a JSON array).
typeintegeryesThe type of report. Abridged; the vendor documentation for this method carries the full text.

[Bitdefender GravityZone] Deletes a report and its history. DESTRUCTIVE: this changes live customer systems, security posture, billing or console access. Read the parameters carefully before calling it. GravityZone IDs are opaque strings (24-character hex in every documented example). Never parse, construct or increment one — discover IDs from the matching list tool. Vendor JSON-RPC method: deleteReport on the reports namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
reportIdstringyesThe report ID

[Bitdefender GravityZone] Paged scheduled-report list. Paged: page on the response's hasMoreRecords flag, NOT on total or pagesCount — GravityZone returns those two only on page 1, so a loop that reads total from page 3 gets nothing. Vendor JSON-RPC method: getReportsList on the reports namespace (v1.0). If GravityZone answers -32001, this API key was not granted that namespace — grants are chosen when the key is minted and cannot be widened through the API.

ParamTypeRequiredDefaultDescription
extraParamsJsonstringnonullAdditional JSON-RPC params as a raw JSON object, merged into the request after the typed arguments above. Use this only for a field the vendor documents for this method that the arguments above do not expose.
namestringnonullThe name of the report.
pageintegerno1Results page number, 1-based. Default 1. The results page number. Default page number is 1.
perPageintegerno30Items per page. Default 30. StackJack caps this at 1000; Bitdefender publishes no maximum for this method. Values outside the range are clamped rather than refused.
typeintegernonullThe report type. Abridged; the vendor documentation for this method carries the full text.