Skip to main content
Tools Reference

DefensX Tools

Written By Christopher Scaminaci

Last updated 7 days ago

DefensX Tools

dfx_ · 46 tools · Free 38 · Pro 8 Secure web gateway and browser security for MSPs. The credential is a long-lived partner API bearer token against a fixed host, with an optional instance override. Paging is page and limit, default 1000, and the vendor's pagination envelope is passed through as sent. Nearly every operation is scoped to a customer, so read the customer id from dfx_list_customers or dfx_get_self_customer first. The SIEM and external notification callbacks are push mechanisms and are not exposed as tools.

All connector tools · DefensX setup guide

DefensX tool groups

Partner Account & Usage

ToolPlanAccessSummary
dfx_create_customerProWriteCreate a new customer under the partner account.
dfx_get_current_usageFreeRead-onlyGet the current, not-yet-billed usage in the current subscription term window.
dfx_get_self_customerFreeRead-onlyGet the partner's own ('self') customer record.
dfx_get_statusFreeRead-onlyHealth/authentication check for the DefensX Partner API.
dfx_get_usageFreeRead-onlyGet calculated billing usage across customer subscriptions.
dfx_get_usage_detailsFreeRead-onlyGet per-user usage detail for a specific subscription usage record.
dfx_list_customersFreeRead-onlyList all customers under the partner account.
dfx_list_message_templatesFreeRead-onlyList the message templates available for customers.
dfx_list_policy_templatesFreeRead-onlyList the policy templates available for customers.
dfx_list_productsFreeRead-onlyList all subscription products available to the partner.

[DefensX] Create a new customer under the partner account. Provide a JSON object body. Required: name (string) and subscription_id (integer — a product id from dfx_list_products). Optional: domain (string), message_template_id (uuid from dfx_list_message_templates), policy_template_id (from dfx_list_policy_templates), and trial (boolean — when true the subscription starts in trial mode for the product's configured free days). Returns the created Customer (id, name, enabled, domains).

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body. Required: name (string), subscription_id (integer, a product id from dfx_list_products). Optional: domain, message_template_id (from dfx_list_message_templates), policy_template_id (from dfx_list_policy_templates), trial (boolean).

[DefensX] Get the current, not-yet-billed usage in the current subscription term window. Omit customerId for all customers, or pass a customerId (from dfx_list_customers) to filter to one. Paginated with page + limit (limit defaults to 1000, capped at 5000). Use dfx_get_usage for a calculated historical range and dfx_get_usage_details for per-user detail.

ParamTypeRequiredDefaultDescription
customerIdstringnonullOptional customer id (from dfx_list_customers) to filter to a single customer. Omit for all customers.
limitintegerno1000Records per page (default 1000, capped at 5000).
pageintegerno1Page number for pagination (default 1).

[DefensX] Get the partner's own ('self') customer record. Returns the same Customer shape as dfx_list_customers (id, name, enabled, domains). Use this to obtain the customerId for the partner's own tenant when running customer-scoped tools against the partner account itself.

[DefensX] Health/authentication check for the DefensX Partner API. Returns a small object with the number of customers under the partner account (). This is the lightest authed call — use it to confirm the Partner API token is valid before running other tools. A 401 means the token is invalid/revoked and a 403 means it lacks permission; regenerate the token in the DefensX Partner Dashboard > API Keys.

[DefensX] Get calculated billing usage across customer subscriptions. 'from' is REQUIRED (a date, YYYY-MM-DD or ISO 8601 e.g. 2021-03-06T00:00:00.000Z) and is passed verbatim. 'to' is optional (defaults to now). Omit customerId for all customers, or pass a customerId (from dfx_list_customers) to filter to one. The queried range may not exceed 6 months or the API returns an error. Companion to dfx_get_current_usage (unbilled current term) and dfx_get_usage_details (per-user drill-down).

ParamTypeRequiredDefaultDescription
customerIdstringnonullOptional customer id (from dfx_list_customers) to filter usage to a single customer. Omit for all customers.
fromstringyesREQUIRED start date, YYYY-MM-DD or ISO 8601 (passed verbatim). Range from 'from' to 'to' may not exceed 6 months.
tostringnonullOptional end date, YYYY-MM-DD (passed verbatim). Defaults to the current time when omitted.

[DefensX] Get per-user usage detail for a specific subscription usage record. Both subscriptionId and usageId are REQUIRED and are obtained from a prior dfx_get_usage response (each usageBySubscriptions entry carries the subscriptionId and its usage record id). Returns the term window plus a per-user breakdown (login, quantity, firstUse).

ParamTypeRequiredDefaultDescription
subscriptionIdstringyesREQUIRED subscription id (from a dfx_get_usage response).
usageIdintegeryesREQUIRED usage record id for the period within that subscription (from a dfx_get_usage response).

[DefensX] List all customers under the partner account. Each customer carries an id (UUID), name, enabled flag, and attached domains. This is the primary discovery tool: nearly every other DefensX tool takes a customerId, which you obtain here (use dfx_get_self_customer for the partner's own customer record).

[DefensX] List the message templates available for customers. Each template has a uuid id and a name. Pass a template id as message_template_id when creating a customer with dfx_create_customer to control the end-user messaging applied to that customer.

[DefensX] List the policy templates available for customers. Each template has an id and a name. Pass a template id as policy_template_id when creating a customer with dfx_create_customer to seed that customer's security policy from a partner-defined template.

[DefensX] List all subscription products available to the partner. Each product carries an integer id, sku, and name. The product id is the subscription_id you pass to dfx_create_customer when provisioning a new customer. Use this to discover the catalog before creating a customer.

Customer Inventory

ToolPlanAccessSummary
dfx_list_agentsFreeRead-onlyList the DefensX agents installed under a customer.
dfx_list_agents_with_childrenFreeRead-onlyList the DefensX agents under a customer, including each agent's child elements (the expanded agent hierarchy).
dfx_list_browser_extension_usersFreeRead-onlyList the users who have a specific browser extension installed, under a customer.
dfx_list_browser_extensionsFreeRead-onlyList the browser extensions detected across a customer's users.
dfx_list_deploymentsFreeRead-onlyList the deployments configured under a customer (the installer/deployment definitions used to roll out DefensX agents).
dfx_list_groupsFreeRead-onlyList the groups defined under a customer.
dfx_list_low_reputation_browser_extensionsFreeRead-onlyList only the low-reputation (risky) browser extensions detected across a customer's users — the security-relevant subset of dfx_list_browser_extensions.
dfx_list_usersFreeRead-onlyList the users under a customer.

[DefensX] List the DefensX agents installed under a customer. Returns the agent roster for the given customer. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer. Use dfx_list_agents_with_children to also include each agent's child elements.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer id (UUID, from dfx_list_customers or dfx_get_self_customer).

[DefensX] List the DefensX agents under a customer, including each agent's child elements (the expanded agent hierarchy). customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer. Use dfx_list_agents for the flat roster without children.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer id (UUID, from dfx_list_customers or dfx_get_self_customer).

[DefensX] List the users who have a specific browser extension installed, under a customer. Paginated with page + limit (limit capped at 5000); the response carries a Pagination envelope passed through verbatim. customerId (UUID) is required (from dfx_list_customers or dfx_get_self_customer); browserExtensionId identifies the extension (from dfx_list_browser_extensions or dfx_list_low_reputation_browser_extensions).

ParamTypeRequiredDefaultDescription
browserExtensionIdstringyesThe browser extension id (from dfx_list_browser_extensions or dfx_list_low_reputation_browser_extensions).
customerIdstringyesThe customer id (UUID, from dfx_list_customers or dfx_get_self_customer).
limitintegerno1000Records per page (default 1000, capped at 5000).
pageintegerno1Page number for pagination (default 1).

[DefensX] List the browser extensions detected across a customer's users. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer. Use dfx_list_low_reputation_browser_extensions to filter to only risky extensions, and dfx_list_browser_extension_users to see which users have a given extension installed.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer id (UUID, from dfx_list_customers or dfx_get_self_customer).

[DefensX] List the deployments configured under a customer (the installer/deployment definitions used to roll out DefensX agents). customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer id (UUID, from dfx_list_customers or dfx_get_self_customer).

[DefensX] List the groups defined under a customer. Paginated with page + limit (limit capped at 5000); the response carries a Pagination envelope (totalPages/totalCount/nitems) passed through verbatim. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer id (UUID, from dfx_list_customers or dfx_get_self_customer).
limitintegerno1000Records per page (default 1000, capped at 5000).
pageintegerno1Page number for pagination (default 1).

[DefensX] List only the low-reputation (risky) browser extensions detected across a customer's users — the security-relevant subset of dfx_list_browser_extensions. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer. Use dfx_list_browser_extension_users to see which users have a flagged extension.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer id (UUID, from dfx_list_customers or dfx_get_self_customer).

[DefensX] List the users under a customer. Paginated with page + limit (limit capped at 5000); the response carries a Pagination envelope (totalPages/totalCount/nitems) passed through verbatim. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer id (UUID, from dfx_list_customers or dfx_get_self_customer).
limitintegerno1000Records per page (default 1000, capped at 5000).
pageintegerno1Page number for pagination (default 1).

Web Filter Policies

ToolPlanAccessSummary
dfx_create_policyProWriteCreate a policy group for a customer.
dfx_delete_policyProDestructivePermanently delete a policy group by its id (from dfx_list_policies) for a customer.
dfx_get_policyFreeRead-onlyGet the full configuration of a single policy group by its id (from dfx_list_policies) for a customer.
dfx_list_policiesFreeRead-onlyList the policy groups configured for a customer.
dfx_list_webfilter_categoriesFreeRead-onlyList every web-filter category DefensX can classify (a map of category key -> display name, e.g. CAT_MALWARE -> "Malware", CAT_PHISHING_SITES -> "Phishing Sites").
dfx_update_policyProWritePartially update a policy group by its id (from dfx_list_policies) for a customer.

[DefensX] Create a policy group for a customer. Provide the full policy as a JSON object in fieldsJson (a DetailedPolicy: name plus the per-category rule configuration; use dfx_list_webfilter_categories for valid category keys). The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
fieldsJsonstringyesJSON object for the new policy group (DetailedPolicy: name + category rules).

[DefensX] Permanently delete a policy group by its id (from dfx_list_policies) for a customer. Users/devices assigned to this group fall back to the default policy. The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
policyGroupIdstringyesThe numeric policy-group id to delete (from dfx_list_policies).

[DefensX] Get the full configuration of a single policy group by its id (from dfx_list_policies) for a customer. Returns the detailed policy including its category rules and settings. The customerId is a UUID from dfx_list_customers.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
policyGroupIdstringyesThe numeric policy-group id (from dfx_list_policies).

[DefensX] List the policy groups configured for a customer. Returns each group's id, name, and summary. The customerId is a UUID from dfx_list_customers / dfx_get_self_customer. Policy-group ids feed dfx_get_policy, dfx_update_policy, and dfx_delete_policy.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).

[DefensX] List every web-filter category DefensX can classify (a map of category key -> display name, e.g. CAT_MALWARE -> "Malware", CAT_PHISHING_SITES -> "Phishing Sites"). Partner-wide, takes no customerId. Use these keys when building or reading policy-group rules (dfx_create_policy / dfx_update_policy) and to interpret category ids returned by dfx_get_top_categories / dfx_get_top_blocked_categories.

[DefensX] Partially update a policy group by its id (from dfx_list_policies) for a customer. Provide only the fields to change as a JSON object in fieldsJson (a partial DetailedPolicy). The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
fieldsJsonstringyesJSON object of the policy fields to change (partial DetailedPolicy).
policyGroupIdstringyesThe numeric policy-group id to update (from dfx_list_policies).

Custom URLs

ToolPlanAccessSummary
dfx_create_custom_url_groupProWriteCreate a custom URL group under a customer (the customer must have a valid subscription).
dfx_create_custom_urlsProWriteAdd one or more custom URLs to a custom URL group (from dfx_list_custom_url_groups) for a customer.
dfx_delete_custom_urlProDestructivePermanently delete a single custom URL entry from a custom URL group for a customer.
dfx_delete_custom_url_groupProDestructivePermanently delete a custom URL group AND ALL of its custom URLs (cascade) by the group id (from dfx_list_custom_url_groups) for a customer.
dfx_list_custom_url_groupsFreeRead-onlyList the custom URL groups for a customer.
dfx_list_custom_urlsFreeRead-onlyList the custom URL entries inside a custom URL group (from dfx_list_custom_url_groups) for a customer, optionally filtered by a search string q.
dfx_search_custom_url_groupsFreeRead-onlySearch a customer's custom URL groups for a given hostname — returns the groups that contain a matching custom-URL entry.

[DefensX] Create a custom URL group under a customer (the customer must have a valid subscription). Provide the group as a JSON object in fieldsJson — required: name; config_type (one of: any, adblocker, file_transfers, phishing, web_filters). The customerId is a UUID from dfx_list_customers. Add URL entries afterward with dfx_create_custom_urls. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
fieldsJsonstringyesJSON object for the new group: { "name": "...", "config_type": "web_filters" } (config_type is one of: any, adblocker, file_transfers, phishing, web_filters).

[DefensX] Add one or more custom URLs to a custom URL group (from dfx_list_custom_url_groups) for a customer. Provide urlsJson, a JSON array of URL/domain strings (max 1000 per request), e.g. [".abc.com", "www.xyz.com", "https://foo.com/path"]. Use the "." prefix to match a domain and all its subdomains. The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.

ParamTypeRequiredDefaultDescription
customUrlGroupIdstringyesThe numeric custom-URL-group id (from dfx_list_custom_url_groups).
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
urlsJsonstringyesJSON array of URL/domain strings to add (max 1000), e.g. ["*.abc.com", "www.xyz.com"].

[DefensX] Permanently delete a single custom URL entry from a custom URL group for a customer. Identify it by the group id (from dfx_list_custom_url_groups) and the entry id (from dfx_list_custom_urls). The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.

ParamTypeRequiredDefaultDescription
customUrlGroupIdstringyesThe numeric custom-URL-group id (from dfx_list_custom_url_groups).
customUrlIdstringyesThe numeric custom-URL entry id to delete (from dfx_list_custom_urls).
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).

[DefensX] Permanently delete a custom URL group AND ALL of its custom URLs (cascade) by the group id (from dfx_list_custom_url_groups) for a customer. The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.

ParamTypeRequiredDefaultDescription
customUrlGroupIdstringyesThe numeric custom-URL-group id to delete (from dfx_list_custom_url_groups).
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).

[DefensX] List the custom URL groups for a customer. Returns each group's id, name, and config_type (one of: any, adblocker, file_transfers, phishing, web_filters). The customerId is a UUID from dfx_list_customers. Group ids feed dfx_list_custom_urls, dfx_create_custom_urls, dfx_delete_custom_url_group, and dfx_delete_custom_url.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).

[DefensX] List the custom URL entries inside a custom URL group (from dfx_list_custom_url_groups) for a customer, optionally filtered by a search string q. Returns each entry's id and URL/pattern. Entry ids feed dfx_delete_custom_url. The customerId is a UUID from dfx_list_customers.

ParamTypeRequiredDefaultDescription
customUrlGroupIdstringyesThe numeric custom-URL-group id (from dfx_list_custom_url_groups).
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
qstringnonullOptional substring to filter the custom URLs (omit to list all).

[DefensX] Search a customer's custom URL groups for a given hostname — returns the groups that contain a matching custom-URL entry. The customerId is a UUID from dfx_list_customers; hostname is required (e.g. "facebook.com"). Use this to find which group already governs a domain before adding a new rule with dfx_create_custom_urls.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
hostnamestringyesThe hostname to search for across the customer's custom URL groups (e.g. "facebook.com").

Event Logs

ToolPlanAccessSummary
dfx_get_consent_logsFreeRead-onlyGet user-consent logs for a customer — occasions where a user acknowledged a warning and proceeded to a flagged site/action.
dfx_get_credential_logsFreeRead-onlyGet credential-submission (password-theft protection) logs for a customer from browser-extension and mobile endpoints — where users entered credentials on external sites.
dfx_get_dns_logsFreeRead-onlyGet DNS query logs for a customer produced by the DefensX agent.
dfx_get_file_transfer_logsFreeRead-onlyGet file-transfer (upload/download) logs for a customer.
dfx_get_rbi_logsFreeRead-onlyGet Remote Browser Isolation (RBI) session logs for a customer — isolated-browsing sessions where risky sites were rendered remotely.
dfx_get_url_logsFreeRead-onlyGet URL access logs for a customer from browser-extension, mobile, and RBI sessions.

[DefensX] Get credential-submission (password-theft protection) logs for a customer from browser-extension and mobile endpoints — where users entered credentials on external sites. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Page-based pagination (page + limit; default 1000, max 5000).

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
limitintegerno1000Records per page (default 1000, max 5000).
pageintegerno1Page number (default 1).
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get DNS query logs for a customer produced by the DefensX agent. Note: these exist only for agent (fat-client) deployments — extension/mobile deployments surface their activity via dfx_get_url_logs instead, and by default only non-Allow (blocked/warned) DNS queries are logged. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Page-based pagination (page + limit; default 1000, max 5000).

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
limitintegerno1000Records per page (default 1000, max 5000).
pageintegerno1Page number (default 1).
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get file-transfer (upload/download) logs for a customer. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Page-based pagination (page + limit; default 1000, max 5000); responses may be wrapped in a Pagination envelope.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
limitintegerno1000Records per page (default 1000, max 5000).
pageintegerno1Page number (default 1).
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get Remote Browser Isolation (RBI) session logs for a customer — isolated-browsing sessions where risky sites were rendered remotely. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Page-based pagination (page + limit; default 1000, max 5000).

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
limitintegerno1000Records per page (default 1000, max 5000).
pageintegerno1Page number (default 1).
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get URL access logs for a customer from browser-extension, mobile, and RBI sessions. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current calendar month. Page-based pagination (page + limit; default 1000, max 5000); responses may be wrapped in a Pagination envelope.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
limitintegerno1000Records per page (default 1000, max 5000).
pageintegerno1Page number (default 1).
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

Reporting Stats

ToolPlanAccessSummary
dfx_get_top_blocked_categoriesFreeRead-onlyGet the top 20 most-blocked web-filter categories for a customer.
dfx_get_top_blocked_credential_hostnamesFreeRead-onlyGet the top 20 hostnames or IP addresses where a customer's users attempted to submit credentials and were blocked by policy.
dfx_get_top_blocked_hostnamesFreeRead-onlyGet the top 20 most-blocked hostnames or IP addresses for a customer.
dfx_get_top_categoriesFreeRead-onlyGet the top 20 most-visited web-filter categories for a customer.
dfx_get_top_category_hostnamesFreeRead-onlyGet the top 20 most-visited hostnames within a specific web-filter category for a customer.
dfx_get_top_credential_consent_hostnamesFreeRead-onlyGet the top 20 hostnames or IP addresses where a customer's users gave consent and then submitted credentials.
dfx_get_top_credential_hostnamesFreeRead-onlyGet the top 20 hostnames or IP addresses where a customer's users submitted credentials.
dfx_get_top_uncategorized_hostnamesFreeRead-onlyGet the top 20 most-visited uncategorized hostnames or IP addresses for a customer (sites DefensX could not classify).

[DefensX] Get the top 20 most-blocked web-filter categories for a customer. The customerId is a UUID from dfx_list_customers. source selects the log source: "Browser" (default) or "DNS". start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Category keys resolve via dfx_list_webfilter_categories.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
sourcestringnonullLog source: "Browser" (default) or "DNS". Omit for Browser.
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get the top 20 hostnames or IP addresses where a customer's users attempted to submit credentials and were blocked by policy. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. (This stat has no source filter.)

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get the top 20 most-blocked hostnames or IP addresses for a customer. The customerId is a UUID from dfx_list_customers. source selects the log source: "Browser" (default) or "DNS". start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
sourcestringnonullLog source: "Browser" (default) or "DNS". Omit for Browser.
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get the top 20 most-visited web-filter categories for a customer. The customerId is a UUID from dfx_list_customers. source selects the log source: "Browser" (default; browser/extension URL logs, best visibility) or "DNS" (agent DNS requests). start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Category keys resolve via dfx_list_webfilter_categories.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
sourcestringnonullLog source: "Browser" (default) or "DNS". Omit for Browser.
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get the top 20 most-visited hostnames within a specific web-filter category for a customer. The customerId is a UUID from dfx_list_customers; categoryId is the numeric category id. source selects the log source: "Browser" (default) or "DNS". start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month.

ParamTypeRequiredDefaultDescription
categoryIdstringyesThe numeric web-filter category id.
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
sourcestringnonullLog source: "Browser" (default) or "DNS". Omit for Browser.
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get the top 20 hostnames or IP addresses where a customer's users submitted credentials. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. (This stat has no source filter.)

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

[DefensX] Get the top 20 most-visited uncategorized hostnames or IP addresses for a customer (sites DefensX could not classify). The customerId is a UUID from dfx_list_customers. source selects the log source: "Browser" (default) or "DNS". start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
sourcestringnonullLog source: "Browser" (default) or "DNS". Omit for Browser.
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.

Cyber Resilience

ToolPlanAccessSummary
dfx_get_cyber_resilienceFreeRead-onlyGet a customer's cyber-resilience score over a time range, including the top 10 riskiest users.

[DefensX] Get a customer's cyber-resilience score over a time range, including the top 10 riskiest users. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer UUID (from dfx_list_customers or dfx_get_self_customer).
endDatestringnonullWindow end (JSON datetime or Unix timestamp). Default: end of the month.
startDatestringnonullWindow start (JSON datetime or Unix timestamp). Default: beginning of the month.