DefensX Tools
Written By Christopher Scaminaci
Last updated 7 days ago
DefensX Tools
dfx_ · 46 tools · Free 38 · Pro 8
Secure web gateway and browser security for MSPs. The credential is a long-lived partner API bearer token against a fixed host, with an optional instance override. Paging is page and limit, default 1000, and the vendor's pagination envelope is passed through as sent. Nearly every operation is scoped to a customer, so read the customer id from dfx_list_customers or dfx_get_self_customer first. The SIEM and external notification callbacks are push mechanisms and are not exposed as tools.
All connector tools · DefensX setup guide
DefensX tool groups
- Partner Account & Usage — 10 tools
- Customer Inventory — 8 tools
- Web Filter Policies — 6 tools
- Custom URLs — 7 tools
- Event Logs — 6 tools
- Reporting Stats — 8 tools
- Cyber Resilience — 1 tool
Partner Account & Usage
dfx_create_customer details
dfx_create_customer details
[DefensX] Create a new customer under the partner account. Provide a JSON object body. Required: name (string) and subscription_id (integer — a product id from dfx_list_products). Optional: domain (string), message_template_id (uuid from dfx_list_message_templates), policy_template_id (from dfx_list_policy_templates), and trial (boolean — when true the subscription starts in trial mode for the product's configured free days). Returns the created Customer (id, name, enabled, domains).
dfx_get_current_usage details
dfx_get_current_usage details
[DefensX] Get the current, not-yet-billed usage in the current subscription term window. Omit customerId for all customers, or pass a customerId (from dfx_list_customers) to filter to one. Paginated with page + limit (limit defaults to 1000, capped at 5000). Use dfx_get_usage for a calculated historical range and dfx_get_usage_details for per-user detail.
dfx_get_self_customer details
dfx_get_self_customer details
[DefensX] Get the partner's own ('self') customer record. Returns the same Customer shape as dfx_list_customers (id, name, enabled, domains). Use this to obtain the customerId for the partner's own tenant when running customer-scoped tools against the partner account itself.
dfx_get_status details
dfx_get_status details
[DefensX] Health/authentication check for the DefensX Partner API. Returns a small object with the number of customers under the partner account (). This is the lightest authed call — use it to confirm the Partner API token is valid before running other tools. A 401 means the token is invalid/revoked and a 403 means it lacks permission; regenerate the token in the DefensX Partner Dashboard > API Keys.
dfx_get_usage details
dfx_get_usage details
[DefensX] Get calculated billing usage across customer subscriptions. 'from' is REQUIRED (a date, YYYY-MM-DD or ISO 8601 e.g. 2021-03-06T00:00:00.000Z) and is passed verbatim. 'to' is optional (defaults to now). Omit customerId for all customers, or pass a customerId (from dfx_list_customers) to filter to one. The queried range may not exceed 6 months or the API returns an error. Companion to dfx_get_current_usage (unbilled current term) and dfx_get_usage_details (per-user drill-down).
dfx_get_usage_details details
dfx_get_usage_details details
[DefensX] Get per-user usage detail for a specific subscription usage record. Both subscriptionId and usageId are REQUIRED and are obtained from a prior dfx_get_usage response (each usageBySubscriptions entry carries the subscriptionId and its usage record id). Returns the term window plus a per-user breakdown (login, quantity, firstUse).
dfx_list_customers details
dfx_list_customers details
[DefensX] List all customers under the partner account. Each customer carries an id (UUID), name, enabled flag, and attached domains. This is the primary discovery tool: nearly every other DefensX tool takes a customerId, which you obtain here (use dfx_get_self_customer for the partner's own customer record).
dfx_list_message_templates details
dfx_list_message_templates details
[DefensX] List the message templates available for customers. Each template has a uuid id and a name. Pass a template id as message_template_id when creating a customer with dfx_create_customer to control the end-user messaging applied to that customer.
dfx_list_policy_templates details
dfx_list_policy_templates details
[DefensX] List the policy templates available for customers. Each template has an id and a name. Pass a template id as policy_template_id when creating a customer with dfx_create_customer to seed that customer's security policy from a partner-defined template.
dfx_list_products details
dfx_list_products details
[DefensX] List all subscription products available to the partner. Each product carries an integer id, sku, and name. The product id is the subscription_id you pass to dfx_create_customer when provisioning a new customer. Use this to discover the catalog before creating a customer.
Customer Inventory
dfx_list_agents details
dfx_list_agents details
[DefensX] List the DefensX agents installed under a customer. Returns the agent roster for the given customer. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer. Use dfx_list_agents_with_children to also include each agent's child elements.
dfx_list_agents_with_children details
dfx_list_agents_with_children details
[DefensX] List the DefensX agents under a customer, including each agent's child elements (the expanded agent hierarchy). customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer. Use dfx_list_agents for the flat roster without children.
dfx_list_browser_extension_users details
dfx_list_browser_extension_users details
[DefensX] List the users who have a specific browser extension installed, under a customer. Paginated with page + limit (limit capped at 5000); the response carries a Pagination envelope passed through verbatim. customerId (UUID) is required (from dfx_list_customers or dfx_get_self_customer); browserExtensionId identifies the extension (from dfx_list_browser_extensions or dfx_list_low_reputation_browser_extensions).
dfx_list_browser_extensions details
dfx_list_browser_extensions details
[DefensX] List the browser extensions detected across a customer's users. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer. Use dfx_list_low_reputation_browser_extensions to filter to only risky extensions, and dfx_list_browser_extension_users to see which users have a given extension installed.
dfx_list_deployments details
dfx_list_deployments details
[DefensX] List the deployments configured under a customer (the installer/deployment definitions used to roll out DefensX agents). customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer.
dfx_list_groups details
dfx_list_groups details
[DefensX] List the groups defined under a customer. Paginated with page + limit (limit capped at 5000); the response carries a Pagination envelope (totalPages/totalCount/nitems) passed through verbatim. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer.
dfx_list_low_reputation_browser_extensions details
dfx_list_low_reputation_browser_extensions details
[DefensX] List only the low-reputation (risky) browser extensions detected across a customer's users — the security-relevant subset of dfx_list_browser_extensions. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer. Use dfx_list_browser_extension_users to see which users have a flagged extension.
dfx_list_users details
dfx_list_users details
[DefensX] List the users under a customer. Paginated with page + limit (limit capped at 5000); the response carries a Pagination envelope (totalPages/totalCount/nitems) passed through verbatim. customerId (UUID) is required — obtain it from dfx_list_customers or dfx_get_self_customer.
Web Filter Policies
dfx_create_policy details
dfx_create_policy details
[DefensX] Create a policy group for a customer. Provide the full policy as a JSON object in fieldsJson (a DetailedPolicy: name plus the per-category rule configuration; use dfx_list_webfilter_categories for valid category keys). The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.
dfx_delete_policy details
dfx_delete_policy details
[DefensX] Permanently delete a policy group by its id (from dfx_list_policies) for a customer. Users/devices assigned to this group fall back to the default policy. The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.
dfx_get_policy details
dfx_get_policy details
[DefensX] Get the full configuration of a single policy group by its id (from dfx_list_policies) for a customer. Returns the detailed policy including its category rules and settings. The customerId is a UUID from dfx_list_customers.
dfx_list_policies details
dfx_list_policies details
[DefensX] List the policy groups configured for a customer. Returns each group's id, name, and summary. The customerId is a UUID from dfx_list_customers / dfx_get_self_customer. Policy-group ids feed dfx_get_policy, dfx_update_policy, and dfx_delete_policy.
dfx_list_webfilter_categories details
dfx_list_webfilter_categories details
[DefensX] List every web-filter category DefensX can classify (a map of category key -> display name, e.g. CAT_MALWARE -> "Malware", CAT_PHISHING_SITES -> "Phishing Sites"). Partner-wide, takes no customerId. Use these keys when building or reading policy-group rules (dfx_create_policy / dfx_update_policy) and to interpret category ids returned by dfx_get_top_categories / dfx_get_top_blocked_categories.
dfx_update_policy details
dfx_update_policy details
[DefensX] Partially update a policy group by its id (from dfx_list_policies) for a customer. Provide only the fields to change as a JSON object in fieldsJson (a partial DetailedPolicy). The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.
Custom URLs
dfx_create_custom_url_group details
dfx_create_custom_url_group details
[DefensX] Create a custom URL group under a customer (the customer must have a valid subscription). Provide the group as a JSON object in fieldsJson — required: name; config_type (one of: any, adblocker, file_transfers, phishing, web_filters). The customerId is a UUID from dfx_list_customers. Add URL entries afterward with dfx_create_custom_urls. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.
dfx_create_custom_urls details
dfx_create_custom_urls details
[DefensX] Add one or more custom URLs to a custom URL group (from dfx_list_custom_url_groups) for a customer. Provide urlsJson, a JSON array of URL/domain strings (max 1000 per request), e.g. [".abc.com", "www.xyz.com", "https://foo.com/path"]. Use the "." prefix to match a domain and all its subdomains. The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.
dfx_delete_custom_url details
dfx_delete_custom_url details
[DefensX] Permanently delete a single custom URL entry from a custom URL group for a customer. Identify it by the group id (from dfx_list_custom_url_groups) and the entry id (from dfx_list_custom_urls). The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.
dfx_delete_custom_url_group details
dfx_delete_custom_url_group details
[DefensX] Permanently delete a custom URL group AND ALL of its custom URLs (cascade) by the group id (from dfx_list_custom_url_groups) for a customer. The customerId is a UUID from dfx_list_customers. A 403 means the Partner API token lacks write permission — regenerate it in the DefensX Partner Dashboard > API Keys.
dfx_list_custom_url_groups details
dfx_list_custom_url_groups details
[DefensX] List the custom URL groups for a customer. Returns each group's id, name, and config_type (one of: any, adblocker, file_transfers, phishing, web_filters). The customerId is a UUID from dfx_list_customers. Group ids feed dfx_list_custom_urls, dfx_create_custom_urls, dfx_delete_custom_url_group, and dfx_delete_custom_url.
dfx_list_custom_urls details
dfx_list_custom_urls details
[DefensX] List the custom URL entries inside a custom URL group (from dfx_list_custom_url_groups) for a customer, optionally filtered by a search string q. Returns each entry's id and URL/pattern. Entry ids feed dfx_delete_custom_url. The customerId is a UUID from dfx_list_customers.
dfx_search_custom_url_groups details
dfx_search_custom_url_groups details
[DefensX] Search a customer's custom URL groups for a given hostname — returns the groups that contain a matching custom-URL entry. The customerId is a UUID from dfx_list_customers; hostname is required (e.g. "facebook.com"). Use this to find which group already governs a domain before adding a new rule with dfx_create_custom_urls.
Event Logs
dfx_get_consent_logs details
dfx_get_consent_logs details
[DefensX] Get user-consent logs for a customer — occasions where a user acknowledged a warning and proceeded to a flagged site/action. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Page-based pagination (page + limit; default 1000, max 5000).
dfx_get_credential_logs details
dfx_get_credential_logs details
[DefensX] Get credential-submission (password-theft protection) logs for a customer from browser-extension and mobile endpoints — where users entered credentials on external sites. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Page-based pagination (page + limit; default 1000, max 5000).
dfx_get_dns_logs details
dfx_get_dns_logs details
[DefensX] Get DNS query logs for a customer produced by the DefensX agent. Note: these exist only for agent (fat-client) deployments — extension/mobile deployments surface their activity via dfx_get_url_logs instead, and by default only non-Allow (blocked/warned) DNS queries are logged. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Page-based pagination (page + limit; default 1000, max 5000).
dfx_get_file_transfer_logs details
dfx_get_file_transfer_logs details
[DefensX] Get file-transfer (upload/download) logs for a customer. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Page-based pagination (page + limit; default 1000, max 5000); responses may be wrapped in a Pagination envelope.
dfx_get_rbi_logs details
dfx_get_rbi_logs details
[DefensX] Get Remote Browser Isolation (RBI) session logs for a customer — isolated-browsing sessions where risky sites were rendered remotely. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Page-based pagination (page + limit; default 1000, max 5000).
dfx_get_url_logs details
dfx_get_url_logs details
[DefensX] Get URL access logs for a customer from browser-extension, mobile, and RBI sessions. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current calendar month. Page-based pagination (page + limit; default 1000, max 5000); responses may be wrapped in a Pagination envelope.
Reporting Stats
dfx_get_top_blocked_categories details
dfx_get_top_blocked_categories details
[DefensX] Get the top 20 most-blocked web-filter categories for a customer. The customerId is a UUID from dfx_list_customers. source selects the log source: "Browser" (default) or "DNS". start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Category keys resolve via dfx_list_webfilter_categories.
dfx_get_top_blocked_credential_hostnames details
dfx_get_top_blocked_credential_hostnames details
[DefensX] Get the top 20 hostnames or IP addresses where a customer's users attempted to submit credentials and were blocked by policy. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. (This stat has no source filter.)
dfx_get_top_blocked_hostnames details
dfx_get_top_blocked_hostnames details
[DefensX] Get the top 20 most-blocked hostnames or IP addresses for a customer. The customerId is a UUID from dfx_list_customers. source selects the log source: "Browser" (default) or "DNS". start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month.
dfx_get_top_categories details
dfx_get_top_categories details
[DefensX] Get the top 20 most-visited web-filter categories for a customer. The customerId is a UUID from dfx_list_customers. source selects the log source: "Browser" (default; browser/extension URL logs, best visibility) or "DNS" (agent DNS requests). start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. Category keys resolve via dfx_list_webfilter_categories.
dfx_get_top_category_hostnames details
dfx_get_top_category_hostnames details
[DefensX] Get the top 20 most-visited hostnames within a specific web-filter category for a customer. The customerId is a UUID from dfx_list_customers; categoryId is the numeric category id. source selects the log source: "Browser" (default) or "DNS". start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month.
dfx_get_top_credential_consent_hostnames details
dfx_get_top_credential_consent_hostnames details
[DefensX] Get the top 20 hostnames or IP addresses where a customer's users gave consent and then submitted credentials. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. (This stat has no source filter.)
dfx_get_top_credential_hostnames details
dfx_get_top_credential_hostnames details
[DefensX] Get the top 20 hostnames or IP addresses where a customer's users submitted credentials. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month. (This stat has no source filter.)
dfx_get_top_uncategorized_hostnames details
dfx_get_top_uncategorized_hostnames details
[DefensX] Get the top 20 most-visited uncategorized hostnames or IP addresses for a customer (sites DefensX could not classify). The customerId is a UUID from dfx_list_customers. source selects the log source: "Browser" (default) or "DNS". start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month.
Cyber Resilience
dfx_get_cyber_resilience details
dfx_get_cyber_resilience details
[DefensX] Get a customer's cyber-resilience score over a time range, including the top 10 riskiest users. The customerId is a UUID from dfx_list_customers. start_date/end_date accept JSON datetime or a Unix timestamp and default to the current month.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team