Skip to main content
Tools Reference

ESET PROTECT Tools

Written By Christopher Scaminaci

Last updated 7 days ago

ESET PROTECT Tools

eset_ · 102 tools · Free 51 · Pro 51 Endpoint protection management: devices, groups, policies, detections, tasks and quarantine. Sign-in is a user name and password against your ESET PROTECT console; the refresh token rotates and is renewed for you. There is no single host - each call targets your region and product domain, taken from the instance address. Paging is a page size capped at 1000 with an opaque page token. The two quarantine downloads return a link to the stored file rather than bytes. The quarantine and user families, and the detection list, are unavailable in the Japan region.

All connector tools · ESET PROTECT setup guide

ESET PROTECT tool groups

Executables

ToolPlanAccessSummary
eset_block_executableProWriteBlock an executable so it will not be executed on managed devices.
eset_get_executableFreeRead-onlyGet details of a specific executable.
eset_list_executablesFreeRead-onlyList all executables observed across managed devices.
eset_unblock_executableProDestructiveUnblock a previously blocked executable so it can run again.

[ESET PROTECT] Block an executable so it will not be executed on managed devices. Provide the executable UUID (from eset_list_executables). Idempotent — re-blocking an already-blocked executable is a no-op. Returns the raw ESET response JSON.

ParamTypeRequiredDefaultDescription
executableUuidstringyesReference to the executable to be blocked (from eset_list_executables).

[ESET PROTECT] Get details of a specific executable. Provide the executable UUID (from eset_list_executables). Returns the raw ESET executable JSON.

ParamTypeRequiredDefaultDescription
executableUuidstringyesReference to the executable whose details are requested (from eset_list_executables).

[ESET PROTECT] List all executables observed across managed devices. Paginated via pageToken. Returns raw ESET JSON {executables:[...], nextPageToken}. Get a single executable's detail with eset_get_executable.

ParamTypeRequiredDefaultDescription
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.

[ESET PROTECT] Unblock a previously blocked executable so it can run again. Provide the executable UUID (from eset_list_executables). Idempotent — unblocking an already-unblocked executable is a no-op. Returns the raw ESET response JSON.

ParamTypeRequiredDefaultDescription
executableUuidstringyesReference to the executable to be unblocked (from eset_list_executables).

Groups (Asset Management)

ToolPlanAccessSummary
eset_create_groupProWriteCreate a static group (folder) in the asset hierarchy and receive its assigned UUID.
eset_delete_groupProDestructiveDelete the group referenced by groupUuid AND every group and object beneath it — cascading and irreversible.
eset_move_groupProDestructiveMove a group (and its subtree) under a different parent, reorganizing the MSP company/site tree and re-evaluating policy assignments along the new hierarchy — only within the same tenant.
eset_rename_groupProWriteChange a group's display name.

[ESET PROTECT] Create a static group (folder) in the asset hierarchy and receive its assigned UUID. Body (fieldsJson) wraps a `group` object; set `group.displayName` (required) and optionally `group.parentGroupUuid` (parent group UUID from eset_list_device_groups; omit for the tree root) and `group.description`. Returns the created group JSON. The special 'All'/'Lost&Found' groups and entity-linked (CUSTOMER/MSP) groups cannot be created here.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesGroup definition JSON wrapping a `group` object. Required: group.displayName. Optional: group.parentGroupUuid, group.description, group.externalReference.

[ESET PROTECT] Delete the group referenced by groupUuid AND every group and object beneath it — cascading and irreversible. Entity-linked (CUSTOMER/MSP) groups cannot be deleted. Group UUID from eset_list_device_groups.

ParamTypeRequiredDefaultDescription
groupUuidstringyesUUID of the group to delete (root of the removed subtree). From eset_list_device_groups.
releaseConsumedUnitsbooleannonullIf true, release the units/seats consumed by deleted devices so they can be reused. Optional.

[ESET PROTECT] Move a group (and its subtree) under a different parent, reorganizing the MSP company/site tree and re-evaluating policy assignments along the new hierarchy — only within the same tenant. Body (fieldsJson): newParentUuid (the target parent group UUID). Group UUIDs from eset_list_device_groups.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with newParentUuid: the target parent group UUID.
groupUuidstringyesUUID of the group to move. From eset_list_device_groups.

[ESET PROTECT] Change a group's display name. Body (fieldsJson): displayName (the new name). Group UUID from eset_list_device_groups.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with displayName: the new group display name.
groupUuidstringyesUUID of the group to rename. From eset_list_device_groups.

Device Tasks (Automation)

ToolPlanAccessSummary
eset_create_device_taskProDestructiveCreate a device task that runs an action (scan / isolation / uninstall / power action) on target endpoints.
eset_delete_device_taskProDestructiveDelete a device task.
eset_get_device_taskFreeRead-onlyGet a single device task entity by UUID (its action, targets, and triggers).
eset_list_device_task_runsFreeRead-onlyList the run history (executions and results) of a device task, optionally scoped to one device or only the latest run per device.
eset_list_device_tasksFreeRead-onlyList all device tasks (scheduled actions run on endpoints).
eset_update_device_task_targetsProDestructiveReplace the targets (which devices / device groups the task runs on) of an existing device task — re-aiming an endpoint action.
eset_update_device_task_triggersProDestructiveReplace the trigger list (when the task runs) of an existing device task.

[ESET PROTECT] Create a device task that runs an action (scan / isolation / uninstall / power action) on target endpoints. Body (fieldsJson) wraps a `task` object requiring: task.displayName, task.action, task.targets (device or device-group UUIDs), and at least one entry in task.triggers (else the call fails). Returns the created task JSON. May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesTask definition JSON wrapping a `task` object. Required: task.displayName, task.action, task.targets, task.triggers (non-empty).

[ESET PROTECT] Delete a device task. Deleting a templated task deletes all tasks sharing its template. Irreversible. Task UUID from eset_list_device_tasks.

ParamTypeRequiredDefaultDescription
taskUuidstringyesUUID of the device task to delete. From eset_list_device_tasks.

[ESET PROTECT] Get a single device task entity by UUID (its action, targets, and triggers). For per-device execution history call eset_list_device_task_runs. Task UUID from eset_list_device_tasks.

ParamTypeRequiredDefaultDescription
taskUuidstringyesUUID of the device task. From eset_list_device_tasks.

[ESET PROTECT] List the run history (executions and results) of a device task, optionally scoped to one device or only the latest run per device. Paginated via pageToken. Task UUID from eset_list_device_tasks; device UUID from eset_list_devices.

ParamTypeRequiredDefaultDescription
deviceUuidstringnonullOptional device UUID — include only runs on this device. From eset_list_devices.
listOnlyLastRunsbooleannonullIf true, return only the latest run per device.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.
taskUuidstringyesUUID of the device task whose runs to list (required). From eset_list_device_tasks.

[ESET PROTECT] List all device tasks (scheduled actions run on endpoints). Paginated via pageToken. Returns raw ESET JSON {tasks:[...], nextPageToken}. Task UUIDs feed eset_get_device_task and eset_list_device_task_runs.

ParamTypeRequiredDefaultDescription
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.

[ESET PROTECT] Replace the targets (which devices / device groups the task runs on) of an existing device task — re-aiming an endpoint action. Body (fieldsJson): targets with devicesUuids and/or deviceGroupsUuids arrays. Task UUID from eset_list_device_tasks. May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with a `targets` object: devicesUuids and/or deviceGroupsUuids arrays.
taskUuidstringyesUUID of the device task to re-target. From eset_list_device_tasks.

[ESET PROTECT] Replace the trigger list (when the task runs) of an existing device task. The new triggers array cannot be empty. Body (fieldsJson): triggers array. Task UUID from eset_list_device_tasks. May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with a non-empty `triggers` array that replaces the current triggers.
taskUuidstringyesUUID of the device task to re-trigger. From eset_list_device_tasks.

Device Groups

ToolPlanAccessSummary
eset_list_device_group_membersFreeRead-onlyList the devices that are members of a device group.
eset_list_device_groupsFreeRead-onlyList all device groups.

[ESET PROTECT] List the devices that are members of a device group. Provide the device group UUID (from eset_list_device_groups). Set recurseSubgroups=true to also include devices from nested subgroups. Group membership is independent of the device entity itself. Paginated via pageToken. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
groupUuidstringyesReference to the device group whose members should be listed (from eset_list_device_groups).
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.
recurseSubgroupsbooleannonullIf true, also return devices from the group's subgroups, not just the requested group.

[ESET PROTECT] List all device groups. The group hierarchy can be reconstructed from the returned device_groups (each carries its parent reference). Paginated via pageToken. Returns raw ESET JSON {device_groups:[...], nextPageToken}. List the member devices of a group with eset_list_device_group_members.

ParamTypeRequiredDefaultDescription
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.

Devices

ToolPlanAccessSummary
eset_batch_get_devicesFreeRead-onlyRetrieve a specific set of devices at a consistent point in time.
eset_get_deviceFreeRead-onlyGet the full details of a single device.
eset_import_devicesProWriteImport a batch of devices into device management (max 1000 per request).
eset_list_devicesFreeRead-onlyList all managed devices, optionally filtered.
eset_move_deviceProDestructiveMove a device under a new parent group.
eset_rename_deviceProWriteUpdate a device's display name.

[ESET PROTECT] Retrieve a specific set of devices at a consistent point in time. Provide the device UUIDs (from eset_list_devices). The operation is atomic — either every requested device is returned or none. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
devicesUuidsarraynonullIdentifiers of the devices to retrieve (from eset_list_devices). If empty, the API returns INVALID_ARGUMENT.

[ESET PROTECT] Get the full details of a single device. Provide the device UUID (from eset_list_devices). Returns the raw ESET device JSON.

ParamTypeRequiredDefaultDescription
deviceUuidstringyesReference to the device (from eset_list_devices).

[ESET PROTECT] Import a batch of devices into device management (max 1000 per request). Imported devices cannot be managed until properly enrolled. Body (fieldsJson) requires a `devices` array (each with a unique `displayName`; set `isMobile`=true for MDM scenarios) and an optional `parentGroupUuid` (from eset_list_device_groups) applied to all imported devices. May return partial success (200 with per-device errors keyed by display name). May return a 202 cached-response envelope with a response-id for long-running requests. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesImport request JSON. Required: devices array (each device needs a mutually-unique displayName). Optional: parentGroupUuid applied to all imported devices.

[ESET PROTECT] List all managed devices, optionally filtered. Paginated via pageToken. Returns raw ESET JSON {devices:[...], nextPageToken}. Use eset_get_device for a single device's full detail, or eset_batch_get_devices to fetch several at once.

ParamTypeRequiredDefaultDescription
displayNamesarraynonullExact-match display names to filter on. Only devices whose display name exactly matches one of these are returned. Omit for no display-name constraint.
functionalityStatusstringnonullFilter by functionality status: DEVICE_FUNCTIONALITY_STATUS_OK, DEVICE_FUNCTIONALITY_STATUS_ATTENTION_RECOMMENDED, or DEVICE_FUNCTIONALITY_STATUS_ATTENTION_REQUIRED. Omit to return devices regardless of status.
isMutedbooleannonullIf true, only muted devices are returned; if false, only unmuted. Omit to return devices regardless of mute state.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.

[ESET PROTECT] Move a device under a new parent group. Provide the device UUID (from eset_list_devices). Body (fieldsJson) requires: newParentUuid (target group, from eset_list_device_groups). Moves are limited to the same tenant; policy assignments update to the new hierarchy. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
deviceUuidstringyesReference to the device to move (from eset_list_devices).
fieldsJsonstringyesMove request JSON. Required: newParentUuid (the target group, from eset_list_device_groups).

[ESET PROTECT] Update a device's display name. Provide the device UUID (from eset_list_devices). Body (fieldsJson) requires: displayName. The display name is objective — it changes for everyone requesting the device. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
deviceUuidstringyesReference to the device to rename (from eset_list_devices).
fieldsJsonstringyesRename request JSON. Required: displayName (the new display name).

IAM (Roles & Permissions)

ToolPlanAccessSummary
eset_assign_roleProWriteAssign a role to a subject over one or more scopes.
eset_create_roleProWriteCreate a custom role that bundles a set of permissions.
eset_delete_roleProDestructiveDelete a custom role by name.
eset_list_permissionsFreeRead-onlyList every permission the platform defines — the catalog you draw permissionNames from when creating a role with eset_create_role.
eset_list_role_assignmentsFreeRead-onlyList role assignments — which subjects (users, devices, user groups, managed identities, services) hold which roles over which scopes.
eset_revoke_roleProDestructiveRemove a role from a subject over the given scopes.

[ESET PROTECT] Assign a role to a subject over one or more scopes. Additive — existing roles are kept. Body (fieldsJson): subjectType, subjectReference, and role {roleName, scopes:[...]}. Role names from eset_list_role_assignments / eset_create_role. Returns the resulting assignment JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with subjectType, subjectReference, and role {roleName, scopes}.

[ESET PROTECT] Create a custom role that bundles a set of permissions. Body (fieldsJson) wraps a `role` object: name (URL-safe, unique within the instance; alphanumeric/-/_ only), permissionNames (from eset_list_permissions), and optional displayName/description. Returns the created role JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesRole definition JSON wrapping a `role` object. Required: role.name, role.permissionNames. Optional: role.displayName, role.description.

[ESET PROTECT] Delete a custom role by name. Irreversible; any subject currently holding it loses those permissions. Role names appear in eset_list_role_assignments.

ParamTypeRequiredDefaultDescription
roleNamestringyesName of the role to delete.

[ESET PROTECT] List every permission the platform defines — the catalog you draw permissionNames from when creating a role with eset_create_role. Paginated via pageToken.

ParamTypeRequiredDefaultDescription
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.

[ESET PROTECT] List role assignments — which subjects (users, devices, user groups, managed identities, services) hold which roles over which scopes. Filter by a single subject and/or subject type; leave filters empty to return everything visible to the caller. Paginated via pageToken.

ParamTypeRequiredDefaultDescription
includeNestedScopesbooleannonullIf true, also include roles inherited from nested scopes.
orderBystringnonullComma-separated list of fields to order by (snake_case or JSON field names).
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.
subjectReferencestringnonullReturn only roles of this subject (e.g. a User UUID / JWT `sub`). Omit to return all subjects.
subjectTypestringnonullSubject type filter: SUBJECT_TYPE_USER, SUBJECT_TYPE_DEVICE, SUBJECT_TYPE_USER_GROUP, SUBJECT_TYPE_MANAGED_IDENTITY, or SUBJECT_TYPE_SERVICE.

[ESET PROTECT] Remove a role from a subject over the given scopes. The subject keeps roles/scopes not named here. Body (fieldsJson): subjectType, subjectReference, and role {roleName, scopes:[...]}. Inspect current assignments with eset_list_role_assignments first.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with subjectType, subjectReference, and role {roleName, scopes} to remove.

Detections

ToolPlanAccessSummary
eset_batch_get_detectionsFreeRead-onlyBatch-retrieve detections by UUID in one atomic call (all-or-nothing).
eset_get_detectionFreeRead-onlyGet a single detection by UUID (v2).
eset_get_detection_v1FreeRead-onlyGet a single detection by UUID (legacy v1 surface).
eset_list_detectionsFreeRead-onlyList detections (v2) matching the criteria, across device and ESET Cloud Office Protection sources.
eset_list_detections_v1FreeRead-onlyList detections (legacy v1 surface) matching the criteria.
eset_resolve_detectionProDestructiveMark a detection as resolved.

[ESET PROTECT] Batch-retrieve detections by UUID in one atomic call (all-or-nothing). Body (fieldsJson) requires: detectionUuids (array of detection UUIDs from eset_list_detections; keep to ~100 per call, hard cap 1000). Returns raw ESET JSON. May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body. Required: detectionUuids (array of detection UUIDs from eset_list_detections). Recommended <=100 per call; hard cap 1000.

[ESET PROTECT] Get a single detection by UUID (v2). Detection UUID from eset_list_detections. Returns the raw ESET detection JSON.

ParamTypeRequiredDefaultDescription
detectionUuidstringyesDetection UUID from eset_list_detections.

[ESET PROTECT] Get a single detection by UUID (legacy v1 surface). Detection UUID from eset_list_detections_v1. Returns the raw ESET detection JSON.

ParamTypeRequiredDefaultDescription
detectionUuidstringyesDetection UUID from eset_list_detections_v1.

[ESET PROTECT] List detections (v2) matching the criteria, across device and ESET Cloud Office Protection sources. Optionally filter by cloud-office tenant and occurrence-time window. Paginated via pageToken. Returns raw ESET JSON {detections:[...], nextPageToken}. Not available in the Japan (jpn) region.

ParamTypeRequiredDefaultDescription
cloudOfficeTenantUuidstringnonullInclude only detections for this ESET Cloud Office Protection tenant (UUID). Leave null for device detections.
endTimestringnonullInclude only detections that occurred before this time (exclusive). UTC or offset timestamp, e.g. 2024-10-30T12:00Z.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.
startTimestringnonullInclude only detections that occurred at or after this time (inclusive). UTC or offset timestamp, e.g. 2024-10-30T12:00Z.

[ESET PROTECT] List detections (legacy v1 surface) matching the criteria. Optionally filter by device and occurrence-time window. Paginated via pageToken. Returns raw ESET JSON {detections:[...], nextPageToken}. Prefer eset_list_detections (v2) unless you specifically need the v1 shape.

ParamTypeRequiredDefaultDescription
deviceUuidstringnonullInclude only detections that occurred on this device (UUID from eset_list_devices).
endTimestringnonullInclude only detections that occurred before this time (exclusive). UTC or offset timestamp, e.g. 2024-10-30T12:00Z.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.
startTimestringnonullInclude only detections that occurred at or after this time (inclusive). UTC or offset timestamp, e.g. 2024-10-30T12:00Z.

[ESET PROTECT] Mark a detection as resolved. Detection UUID from eset_list_detections / eset_get_detection. Body (fieldsJson) optional: note (arbitrary text explaining the resolution); pass for none. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
detectionUuidstringyesDetection UUID from eset_list_detections.
fieldsJsonstringyesJSON body. Optional: note (text explaining the resolution). Pass for no note.

Detection Groups

ToolPlanAccessSummary
eset_get_detection_groupFreeRead-onlyGet details about a single detection group by UUID.
eset_list_detection_groupsFreeRead-onlyList detection groups (detections deduplicated/grouped by signature) matching the criteria.
eset_resolve_detection_groupProDestructiveMark ALL detections in a group as resolved in one call.
eset_search_detection_groupsFreeRead-onlySearch detection groups with a filter expression (richer than the plain list).

[ESET PROTECT] Get details about a single detection group by UUID. Detection-group UUID from eset_list_detection_groups / eset_search_detection_groups. Returns the raw ESET detection-group JSON.

ParamTypeRequiredDefaultDescription
detectionGroupUuidstringyesDetection-group UUID from eset_list_detection_groups.

[ESET PROTECT] List detection groups (detections deduplicated/grouped by signature) matching the criteria. Optionally filter by cloud-office tenant, device, and occurrence-time window. Paginated via pageToken. Returns raw ESET JSON {detectionGroups:[...], nextPageToken}.

ParamTypeRequiredDefaultDescription
cloudOfficeTenantUuidstringnonullInclude only groups for this ESET Cloud Office Protection tenant (UUID). Leave null for device detections.
deviceUuidstringnonullInclude only groups whose detections occurred on this device (UUID from eset_list_devices).
endTimestringnonullInclude only detections that occurred before this time (exclusive). UTC or offset timestamp, e.g. 2024-10-30T12:00Z.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.
startTimestringnonullInclude only detections that occurred at or after this time (inclusive). UTC or offset timestamp, e.g. 2024-10-30T12:00Z.

[ESET PROTECT] Mark ALL detections in a group as resolved in one call. Detection-group UUID from eset_list_detection_groups. Body (fieldsJson) optional: note (text explaining the resolution); pass for none. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
detectionGroupUuidstringyesDetection-group UUID from eset_list_detection_groups.
fieldsJsonstringyesJSON body. Optional: note (text explaining the resolution). Pass for no note.

[ESET PROTECT] Search detection groups with a filter expression (richer than the plain list). Body (fieldsJson) optional: filter (e.g. "resolved eq 0" for unresolved; supports eq/ne/gt/ge/lt/le/and/or/() and dot-notation nested fields), returnTotalSize (bool). Pass to return all. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body. Optional: filter (ODdata-style expression, e.g. "resolved eq 0"), returnTotalSize (bool). Pass for no filter.

EDR Rules & Exclusions

ToolPlanAccessSummary
eset_create_edr_ruleProWriteCreate an EDR (ESET Inspect) rule.
eset_create_edr_rule_exclusionProDestructiveCreate an EDR rule exclusion.
eset_delete_edr_ruleProDestructiveDelete an EDR rule permanently.
eset_delete_edr_rule_exclusionProDestructiveDelete an EDR rule exclusion permanently.
eset_disable_edr_ruleProDestructiveDisable an EDR rule (stops it matching) without deleting it.
eset_enable_edr_ruleProWriteEnable an EDR rule so it is used for matching.
eset_get_edr_ruleFreeRead-onlyGet details of a single EDR rule by UUID.
eset_get_edr_rule_exclusionFreeRead-onlyGet details of a single EDR rule exclusion by UUID.
eset_list_edr_rule_exclusionsFreeRead-onlyList EDR rule exclusions (patches that suppress one or more EDR rules' actions) matching the criteria.
eset_list_edr_rulesFreeRead-onlyList EDR (ESET Inspect) rules matching the criteria, optionally filtered by severity level.
eset_update_edr_rule_definitionProDestructiveReplace the XML definition of an existing EDR rule.
eset_update_edr_rule_exclusion_definitionProDestructiveReplace the XML definition of an existing EDR rule exclusion.

[ESET PROTECT] Create an EDR (ESET Inspect) rule. Body (fieldsJson) requires: rule object with xmlDefinition (XML in ESET Inspect rule format; a valid definition is required); optional enabled, scopes. Returns the created rule JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body. Required: rule (object with xmlDefinition; optional enabled, scopes).

[ESET PROTECT] Create an EDR rule exclusion. Body (fieldsJson) requires: exclusion object with xmlDefinition (XML in ESET Inspect rule format, actions ignored); optional ruleUuids (EDR rules the exclusion applies to, from eset_list_edr_rules), enabled, scopes, note. Returns the created exclusion JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body. Required: exclusion (object with xmlDefinition; optional ruleUuids, enabled, scopes, note).

[ESET PROTECT] Delete an EDR rule permanently. Rule UUID from eset_list_edr_rules. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
ruleUuidstringyesEDR rule UUID from eset_list_edr_rules.

[ESET PROTECT] Delete an EDR rule exclusion permanently. Exclusion UUID from eset_list_edr_rule_exclusions. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
exclusionUuidstringyesEDR rule exclusion UUID from eset_list_edr_rule_exclusions.

[ESET PROTECT] Disable an EDR rule (stops it matching) without deleting it. Rule UUID from eset_list_edr_rules. No body required. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
ruleUuidstringyesEDR rule UUID from eset_list_edr_rules.

[ESET PROTECT] Enable an EDR rule so it is used for matching. Rule UUID from eset_list_edr_rules. No body required. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
ruleUuidstringyesEDR rule UUID from eset_list_edr_rules.

[ESET PROTECT] Get details of a single EDR rule by UUID. Rule UUID from eset_list_edr_rules. Returns the raw ESET rule JSON.

ParamTypeRequiredDefaultDescription
ruleUuidstringyesEDR rule UUID from eset_list_edr_rules.

[ESET PROTECT] Get details of a single EDR rule exclusion by UUID. Exclusion UUID from eset_list_edr_rule_exclusions. Returns the raw ESET exclusion JSON.

ParamTypeRequiredDefaultDescription
exclusionUuidstringyesEDR rule exclusion UUID from eset_list_edr_rule_exclusions.

[ESET PROTECT] List EDR rule exclusions (patches that suppress one or more EDR rules' actions) matching the criteria. Paginated via pageToken. Returns raw ESET JSON {edrRuleExclusions:[...], nextPageToken}.

ParamTypeRequiredDefaultDescription
includeTotalSizebooleannonullIf true, include total_size in the response.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.

[ESET PROTECT] List EDR (ESET Inspect) rules matching the criteria, optionally filtered by severity level. Paginated via pageToken. Returns raw ESET JSON {edrRules:[...], nextPageToken}.

ParamTypeRequiredDefaultDescription
includeTotalSizebooleannonullIf true, include total_size in the response.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.
severityLevelstringnonullFilter to one severity level. One of: SEVERITY_LEVEL_UNSPECIFIED, SEVERITY_LEVEL_DIAGNOSTIC, SEVERITY_LEVEL_INFORMATIONAL, SEVERITY_LEVEL_LOW, SEVERITY_LEVEL_MEDIUM, SEVERITY_LEVEL_HIGH.

[ESET PROTECT] Replace the XML definition of an existing EDR rule. Rule UUID from eset_list_edr_rules. Body (fieldsJson) requires: xmlDefinition (XML in ESET Inspect rule format; an invalid definition returns 400). Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body. Required: xmlDefinition (new XML definition of the rule).
ruleUuidstringyesEDR rule UUID from eset_list_edr_rules.

[ESET PROTECT] Replace the XML definition of an existing EDR rule exclusion. Exclusion UUID from eset_list_edr_rule_exclusions. Body (fieldsJson) requires: xmlDefinition (XML in ESET Inspect rule format, actions ignored). Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
exclusionUuidstringyesEDR rule exclusion UUID from eset_list_edr_rule_exclusions.
fieldsJsonstringyesJSON body. Required: xmlDefinition (new XML definition of the exclusion).

Incidents

ToolPlanAccessSummary
eset_close_incidentProDestructiveClose an incident.
eset_create_incident_commentProWriteAdd a comment to an incident.
eset_delete_incident_commentProDestructiveDelete a comment from an incident permanently.
eset_get_incidentFreeRead-onlyGet details of a single incident by UUID.
eset_get_incident_commentFreeRead-onlyGet a single incident comment by UUID.
eset_list_incident_commentsFreeRead-onlyList all comments on a single incident, ordered by create time.
eset_list_incidentsFreeRead-onlyList incidents matching an optional filter, ordered by order_by.
eset_reopen_incidentProWriteReopen a non-Open incident (sets status back to Open; assignee unchanged; a prior closing comment becomes a normal comment).
eset_update_incident_attributesProWriteUpdate chosen basic attributes of an incident.
eset_update_incident_commentProWriteChange the text of an existing incident comment.

[ESET PROTECT] Close an incident. Incident UUID from eset_list_incidents. Body (fieldsJson) optional: closureReason (INCIDENT_RESOLVE_REASON_TRUE_POSITIVE / _FALSE_POSITIVE / _SUSPICIOUS / _UNSPECIFIED) and finalComment () describing how it was resolved; pass to close with no reason/comment. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body. Optional: closureReason (enum), finalComment (). Pass for none.
incidentUuidstringyesIncident UUID from eset_list_incidents.

[ESET PROTECT] Add a comment to an incident. Incident UUID from eset_list_incidents. Body (fieldsJson) requires: comment object with text. Returns the created comment JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body. Required: comment ().
incidentUuidstringyesIncident UUID from eset_list_incidents.

[ESET PROTECT] Delete a comment from an incident permanently. Incident UUID from eset_list_incidents; comment UUID from eset_list_incident_comments. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
commentUuidstringyesComment UUID from eset_list_incident_comments.
incidentUuidstringyesIncident UUID from eset_list_incidents.

[ESET PROTECT] Get details of a single incident by UUID. Incident UUID from eset_list_incidents. Returns the raw ESET incident JSON.

ParamTypeRequiredDefaultDescription
incidentUuidstringyesIncident UUID from eset_list_incidents.

[ESET PROTECT] Get a single incident comment by UUID. Incident UUID from eset_list_incidents; comment UUID from eset_list_incident_comments. Returns the raw ESET comment JSON.

ParamTypeRequiredDefaultDescription
commentUuidstringyesComment UUID from eset_list_incident_comments.
incidentUuidstringyesIncident UUID from eset_list_incidents.

[ESET PROTECT] List all comments on a single incident, ordered by create time. Incident UUID from eset_list_incidents. Returns raw ESET JSON with the incident's comments.

ParamTypeRequiredDefaultDescription
incidentUuidstringyesIncident UUID whose comments to list (from eset_list_incidents).

[ESET PROTECT] List incidents matching an optional filter, ordered by order_by. Paginated via pageToken. Returns raw ESET JSON {incidents:[...], nextPageToken}.

ParamTypeRequiredDefaultDescription
filterstringnonullOptional filter (CEL/AIP-160 syntax), e.g. incident.assignee_uuid == "uuid" or displayName.contains("abc"). Time filters use timestamp("...").
orderBystringnonullComma-separated fields to sort by (lower_case_with_underscores); append " desc" for descending, e.g. "display_name, severity desc".
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.

[ESET PROTECT] Reopen a non-Open incident (sets status back to Open; assignee unchanged; a prior closing comment becomes a normal comment). Incident UUID from eset_list_incidents. Body (fieldsJson) optional: comment (); pass for none. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body. Optional: comment (). Pass for none.
incidentUuidstringyesIncident UUID from eset_list_incidents.

[ESET PROTECT] Update chosen basic attributes of an incident. Incident UUID from eset_list_incidents. Body (fieldsJson): any of assigneeUuid (user UUID), displayName, description, severity (INCIDENT_SEVERITY_LEVEL_LOW/_MEDIUM/_HIGH/_UNSPECIFIED), plus updateMask listing the fields to change. Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body. Optional fields: assigneeUuid, displayName, description, severity (enum), updateMask (fields to update).
incidentUuidstringyesIncident UUID from eset_list_incidents.

[ESET PROTECT] Change the text of an existing incident comment. Incident UUID from eset_list_incidents; comment UUID from eset_list_incident_comments. Body (fieldsJson) requires: text (the new comment text). Returns the raw ESET JSON response.

ParamTypeRequiredDefaultDescription
commentUuidstringyesComment UUID from eset_list_incident_comments.
fieldsJsonstringyesJSON body. Required: text (new comment text).
incidentUuidstringyesIncident UUID from eset_list_incidents.

Installers

ToolPlanAccessSummary
eset_create_installerProWriteCreate a downloadable installer that drops components, activates products, and enrolls devices into a security group.
eset_delete_installerProDestructiveDelete an installer by UUID, invalidating its download URL.
eset_generate_installerProWriteGenerate an ad-hoc GPO/SCCM-compatible configuration file for deploying the security product via Group Policy or System Center Configuration Manager.
eset_get_installerFreeRead-onlyGet details of one installer by UUID (download URL, expiry, activated products, installed components).
eset_list_installersFreeRead-onlyList the installers available to the caller (each carries a download URL and expiry).

[ESET PROTECT] Create a downloadable installer that drops components, activates products, and enrolls devices into a security group. Body (fieldsJson) wraps an `installer` object: displayName, operatingSystemFamilyId (1=Windows, 3=macOS), deviceEnrollment.securityGroupUuid, plus optional flags; requestedComponentIds may pin specific components. Returns the installer JSON with downloadUrl. May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesInstaller definition JSON wrapping an `installer` object (displayName, operatingSystemFamilyId, deviceEnrollment, ...) plus optional requestedComponentIds.

[ESET PROTECT] Delete an installer by UUID, invalidating its download URL. Irreversible. Installer UUID from eset_list_installers.

ParamTypeRequiredDefaultDescription
installerUuidstringyesUUID of the installer to delete. From eset_list_installers.

[ESET PROTECT] Generate an ad-hoc GPO/SCCM-compatible configuration file for deploying the security product via Group Policy or System Center Configuration Manager. The config is returned inline and not stored. Body (fieldsJson) optional: sendAnonymousDiagnosticData, deviceEnrollmentSettings.securityGroupUuid (target group from eset_list_device_groups). May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesGeneration options JSON. Optional: sendAnonymousDiagnosticData (bool), deviceEnrollmentSettings.securityGroupUuid.

[ESET PROTECT] Get details of one installer by UUID (download URL, expiry, activated products, installed components). Installer UUID from eset_list_installers.

ParamTypeRequiredDefaultDescription
installerUuidstringyesUUID of the installer. From eset_list_installers.

[ESET PROTECT] List the installers available to the caller (each carries a download URL and expiry). Optionally filter by usability. Paginated via pageToken. Installer UUIDs feed eset_get_installer and eset_delete_installer.

ParamTypeRequiredDefaultDescription
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.
usablebooleannonullIf true, return only usable installers; if false, only unusable; omit for all.

Mobile Devices

ToolPlanAccessSummary
eset_activate_product_mobile_devicesProDestructiveCreate a product-activation task targeting a batch of mobile devices; the product is chosen automatically from each device's parent group.
eset_get_mobile_device_enrollment_linksProWriteGenerate enrollment links (valid on Android/iOS only) for a batch of up to 1000 mobile devices.

[ESET PROTECT] Create a product-activation task targeting a batch of mobile devices; the product is chosen automatically from each device's parent group. All devices must share the same parent device group and that group must have an available subscription. Body (fieldsJson): deviceUuids array (from eset_list_devices). Fails atomically (400/403/404). May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with deviceUuids: array of mobile device UUIDs sharing one parent group. From eset_list_devices.

Network Access Protection

ToolPlanAccessSummary
eset_get_network_access_ruleFreeRead-onlyGet details about a single IP set on a policy.
eset_list_network_access_rulesFreeRead-onlyList all IP sets defined on a policy.
eset_update_network_access_ruleProDestructiveUpdate an IP set on a policy.

[ESET PROTECT] Get details about a single IP set on a policy. Provide the policy UUID (from eset_list_policies) and the IP set UUID (from eset_list_network_access_rules). Returns the raw ESET IP-set JSON.

ParamTypeRequiredDefaultDescription
ipSetUuidstringyesReference to the IP set (from eset_list_network_access_rules).
policyUuidstringyesReference to the policy in which the IP set is defined (from eset_list_policies).

[ESET PROTECT] List all IP sets defined on a policy. Provide the policy UUID (from eset_list_policies). Paginated via pageToken. Returns raw ESET JSON. Get a single IP set with eset_get_network_access_rule.

ParamTypeRequiredDefaultDescription
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.
policyUuidstringyesReference to the policy whose IP sets are listed (from eset_list_policies).

[ESET PROTECT] Update an IP set on a policy. Provide the policy UUID (from eset_list_policies) and the IP set UUID (from eset_list_network_access_rules). Body (fieldsJson) wraps the changes under an `ipSet` object; updatable attributes are displayName, description, and ipAddresses (CIDR/IPv4/IPv6, no uniqueness check). Read-only IP sets cannot be updated; for built-in IP sets only ipAddresses is updatable. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesUpdate request JSON with an `ipSet` object. Updatable fields: displayName, description, ipAddresses.
ipSetUuidstringyesReference to the IP set to update (from eset_list_network_access_rules).
policyUuidstringyesReference to the policy in which the IP set is defined (from eset_list_policies).

Patch Management

ToolPlanAccessSummary
eset_get_patching_process_detailsFreeRead-onlyList device patching-process details (history of patch attempts).
eset_list_device_patch_statusFreeRead-onlyList device patches (unpatched applications, packages, and operating systems).
eset_list_recent_patching_processesFreeRead-onlyList the patching details of all application patching attempts performed recently (within the last few days).

[ESET PROTECT] List device patching-process details (history of patch attempts). History is pruned repeatedly; at least the previous 30 days are available. Filter by deviceUuid (from eset_list_devices), deviceGroupUuid (from eset_list_device_groups), and an optional time interval (timePeriodStartTime inclusive, timePeriodEndTime exclusive; RFC 3339 timestamps). Paginated via pageToken. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
deviceGroupUuidstringnonullReference to a device group to scope to (from eset_list_device_groups). Omit for all accessible devices.
deviceUuidstringnonullReference to a single device to scope to (from eset_list_devices). Omit for all accessible devices.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.
timePeriodEndTimestringnonullExclusive end of the interval (RFC 3339 timestamp). Optional.
timePeriodStartTimestringnonullInclusive start of the interval (RFC 3339 timestamp). Optional.

[ESET PROTECT] List device patches (unpatched applications, packages, and operating systems). If the same patch is missing on multiple devices, each device/patch pair is a separate entry. Filter by deviceUuid (from eset_list_devices), deviceGroupUuid (from eset_list_device_groups), or patchType. Paginated via pageToken. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
deviceGroupUuidstringnonullReference to a device group to scope to; nested groups are included recursively (from eset_list_device_groups). Omit for any accessible device.
deviceUuidstringnonullReference to a single device to scope to (from eset_list_devices). Omit for any accessible device.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.
patchTypestringnonullFilter by patch category: PATCH_TYPE_APPLICATION, PATCH_TYPE_OPERATING_SYSTEM, or PATCH_TYPE_PACKAGE. Omit for all categories.

[ESET PROTECT] List the patching details of all application patching attempts performed recently (within the last few days). The list may be empty if no patching has occurred recently; stale data is pruned over several days. Returns raw ESET JSON.

Policies

ToolPlanAccessSummary
eset_create_policyProWriteCreate a policy carrying feature configurations.
eset_create_policy_assignmentProDestructiveAssign a policy to a target (device, device group, or subscription).
eset_delete_policyProDestructiveDelete a policy by UUID.
eset_delete_policy_assignmentProDestructiveRemove a policy assignment (unassign a policy from its target); remaining assignments on that target are reordered.
eset_get_policyFreeRead-onlyGet one policy's details (its feature configurations) by UUID.
eset_get_policy_assignmentFreeRead-onlyGet one policy assignment (policy, target, and rank) by UUID.
eset_list_policiesFreeRead-onlyList all policies visible to the caller.
eset_list_policy_assignmentsFreeRead-onlyList policy assignments (which policies are applied to which targets, and at what rank).
eset_update_policy_assignment_rankingProDestructiveMove a policy assignment to a new rank on its target (rank 1 = highest priority).

[ESET PROTECT] Create a policy carrying feature configurations. All included feature policies must be valid or the call returns 400. Body (fieldsJson) wraps a `policy` object: displayName, features array, optional description. Returns the created policy JSON. Assign it to targets with eset_create_policy_assignment.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesPolicy definition JSON wrapping a `policy` object. Required: policy.displayName. Optional: policy.features, policy.description.

[ESET PROTECT] Assign a policy to a target (device, device group, or subscription). New assignments are appended at the lowest rank; rank 1 has the highest priority and policies merge from rank 1 downward. Body (fieldsJson) wraps an `assignment` object: policyUuid and target. Returns the created assignment JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesAssignment JSON wrapping an `assignment` object: policyUuid and target {deviceUuid | deviceGroupUuid | subscriptionUuid}.

[ESET PROTECT] Delete a policy by UUID. Irreversible; built-in policies cannot be deleted. Policy UUID from eset_list_policies.

ParamTypeRequiredDefaultDescription
policyUuidstringyesUUID of the policy to delete. From eset_list_policies.

[ESET PROTECT] Remove a policy assignment (unassign a policy from its target); remaining assignments on that target are reordered. Irreversible. Assignment UUID from eset_list_policy_assignments.

ParamTypeRequiredDefaultDescription
assignmentUuidstringyesUUID of the policy assignment to remove. From eset_list_policy_assignments.

[ESET PROTECT] Get one policy's details (its feature configurations) by UUID. Policy UUID from eset_list_policies.

ParamTypeRequiredDefaultDescription
policyUuidstringyesUUID of the policy. From eset_list_policies.

[ESET PROTECT] Get one policy assignment (policy, target, and rank) by UUID. Assignment UUID from eset_list_policy_assignments.

ParamTypeRequiredDefaultDescription
assignmentUuidstringyesUUID of the policy assignment. From eset_list_policy_assignments.

[ESET PROTECT] List all policies visible to the caller. Paginated via pageToken. Policy UUIDs feed eset_get_policy, eset_delete_policy, and eset_create_policy_assignment.

ParamTypeRequiredDefaultDescription
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.

[ESET PROTECT] List policy assignments (which policies are applied to which targets, and at what rank). Filter by policy or by target device / device group / subscription. Paginated via pageToken. Assignment UUIDs feed eset_get_policy_assignment and eset_delete_policy_assignment.

ParamTypeRequiredDefaultDescription
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.
policyUuidstringnonullFilter to assignments of one policy UUID. Merged with policyUuids when both are set.
policyUuidsarraynonullFilter to assignments of several policies at once: one or more policy UUIDs. For a single policy prefer the policyUuid parameter.
targetDeviceGroupUuidstringnonullFilter to assignments targeting this device group UUID. From eset_list_device_groups.
targetDeviceUuidstringnonullFilter to assignments targeting this device UUID. From eset_list_devices.
targetSubscriptionUuidstringnonullFilter to assignments targeting this subscription UUID.

[ESET PROTECT] Move a policy assignment to a new rank on its target (rank 1 = highest priority). Body (fieldsJson): rank (>= 1 and <= the target's assignment count, else 400/412). Other assignments are reordered around it. Assignment UUID from eset_list_policy_assignments.

ParamTypeRequiredDefaultDescription
assignmentUuidstringyesUUID of the policy assignment to re-rank. From eset_list_policy_assignments.
fieldsJsonstringyesJSON with rank: the new 1-based rank (cannot exceed the target's number of assignments).

Quarantine

ToolPlanAccessSummary
eset_batch_delete_quarantined_objectsProDestructivePermanently delete a batch of quarantined objects by UUID — irreversible.
eset_batch_download_quarantined_objectsProRead-onlyDownload a batch of quarantined objects (by UUID) as a ZIP archive.
eset_batch_restore_quarantined_objectsProDestructiveRestore a batch of quarantined objects (by UUID) to their original locations — re-releases potentially-malicious files onto endpoints.
eset_count_quarantined_objectsFreeRead-onlyCount quarantined objects matching the filter (same filter fields as eset_list_quarantined_objects).
eset_download_quarantined_objectsProRead-onlyDownload quarantined objects matching a filter as a ZIP archive.
eset_get_quarantined_objectFreeRead-onlyGet a single quarantined object by UUID.
eset_list_quarantined_objectsFreeRead-onlyList quarantined objects (files, email messages, email attachments) matching the filter.
eset_purge_quarantined_objectsProDestructivePermanently delete every quarantined object matching a filter (criteria-based delete) — irreversible.
eset_restore_quarantined_objects_by_filterProDestructiveRestore every quarantined object matching a filter to its original location — re-releases potentially-malicious files onto endpoints.

[ESET PROTECT] Permanently delete a batch of quarantined objects by UUID — irreversible. Body (fieldsJson): objectUuids array (from eset_list_quarantined_objects). Not available in the Japan (jpn) region. May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with objectUuids: array of quarantined-object UUIDs to permanently delete. From eset_list_quarantined_objects.

[ESET PROTECT] Download a batch of quarantined objects (by UUID) as a ZIP archive. Body (fieldsJson): objectUuids array (from eset_list_quarantined_objects). Returns a short-lived read-only SAS URL to the archive — the payload is potentially malicious and is handled out-of-band, not inline. A slow (>30s) download returns a pending marker with an opaque ContinuationToken instead; retrieve the archive later by calling eset_resume_async with that token. Not available in the Japan (jpn) region.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with objectUuids: array of quarantined-object UUIDs to download. From eset_list_quarantined_objects.

[ESET PROTECT] Restore a batch of quarantined objects (by UUID) to their original locations — re-releases potentially-malicious files onto endpoints. Body (fieldsJson): objectUuids array plus optional addToExclusions (exclude from future scanning). Not available in the Japan (jpn) region. May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with objectUuids: array of UUIDs to restore, plus optional addToExclusions (bool). From eset_list_quarantined_objects.

[ESET PROTECT] Count quarantined objects matching the filter (same filter fields as eset_list_quarantined_objects). Cheaper than listing when you only need totals. Not available in the Japan (jpn) region.

ParamTypeRequiredDefaultDescription
filterCloudOfficeTenantUuidstringnonullFilter: cloud office tenant UUID.
filterEmailInternetMessageIdstringnonullFilter: email Message-ID (exact).
filterEmailRecipientstringnonullFilter: email recipient address.
filterEmailSenderstringnonullFilter: email sender address.
filterEmailSubjectstringnonullFilter: substring in the email subject.
filterFileNamestringnonullFilter: quarantined file path suffix.
filterMsSharepointRootSiteUuidstringnonullFilter: Microsoft SharePoint root site UUID.
filterMsTeamsTeamUuidstringnonullFilter: Microsoft Teams team UUID.
filterObjectOriginstringnonullFilter object origin: OBJECT_ORIGIN_MS_OFFICE365, OBJECT_ORIGIN_GOOGLE_WORKSPACE, or OBJECT_ORIGIN_DEVICE.
filterObjectTypestringnonullFilter object type: QUARANTINED_OBJECT_TYPE_EMAIL_MESSAGE, QUARANTINED_OBJECT_TYPE_EMAIL_ATTACHMENT, or QUARANTINED_OBJECT_TYPE_FILE_ON_DRIVE.
filterQuarantineReasonstringnonullFilter quarantine reason: QUARANTINE_REASON_MALWARE, _GRAYWARE, _PHISHING, _SPAM, _SENDER_SPOOFING, or _RULE.
filterQuarantineTimeEndTimestringnonullFilter: exclusive end of the quarantine-time interval (RFC 3339 timestamp).
filterQuarantineTimeStartTimestringnonullFilter: inclusive start of the quarantine-time interval (RFC 3339 timestamp).
filterUserUuidstringnonullFilter: owning user UUID (mailbox/drive owner).

[ESET PROTECT] Download quarantined objects matching a filter as a ZIP archive. Body (fieldsJson): a `filter` object (same fields as eset_list_quarantined_objects) plus optional excludedObjectUuids. Returns a short-lived read-only SAS URL to the archive — the payload is potentially malicious and is handled out-of-band, not inline. A slow (>30s) download returns a pending marker with an opaque ContinuationToken instead; retrieve the archive later by calling eset_resume_async with that token. Not available in the Japan (jpn) region.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with a `filter` object (email/file/origin/reason/time filters) and optional excludedObjectUuids.

[ESET PROTECT] Get a single quarantined object by UUID. Object UUID from eset_list_quarantined_objects. Not available in the Japan (jpn) region.

ParamTypeRequiredDefaultDescription
objectUuidstringyesUUID of the quarantined object. From eset_list_quarantined_objects.

[ESET PROTECT] List quarantined objects (files, email messages, email attachments) matching the filter. All filters combine with AND. Paginated via pageToken. Object UUIDs feed eset_get_quarantined_object and the batch restore/delete/download tools. Not available in the Japan (jpn) region.

ParamTypeRequiredDefaultDescription
filterCloudOfficeTenantUuidstringnonullFilter: cloud office tenant UUID.
filterEmailInternetMessageIdstringnonullFilter: email Message-ID (exact).
filterEmailRecipientstringnonullFilter: email recipient address.
filterEmailSenderstringnonullFilter: email sender address.
filterEmailSubjectstringnonullFilter: substring in the email subject.
filterFileNamestringnonullFilter: quarantined file path suffix.
filterMsSharepointRootSiteUuidstringnonullFilter: Microsoft SharePoint root site UUID.
filterMsTeamsTeamUuidstringnonullFilter: Microsoft Teams team UUID.
filterObjectOriginstringnonullFilter object origin: OBJECT_ORIGIN_MS_OFFICE365, OBJECT_ORIGIN_GOOGLE_WORKSPACE, or OBJECT_ORIGIN_DEVICE.
filterObjectTypestringnonullFilter object type: QUARANTINED_OBJECT_TYPE_EMAIL_MESSAGE, QUARANTINED_OBJECT_TYPE_EMAIL_ATTACHMENT, or QUARANTINED_OBJECT_TYPE_FILE_ON_DRIVE.
filterQuarantineReasonstringnonullFilter quarantine reason: QUARANTINE_REASON_MALWARE, _GRAYWARE, _PHISHING, _SPAM, _SENDER_SPOOFING, or _RULE.
filterQuarantineTimeEndTimestringnonullFilter: exclusive end of the quarantine-time interval (RFC 3339 timestamp).
filterQuarantineTimeStartTimestringnonullFilter: inclusive start of the quarantine-time interval (RFC 3339 timestamp).
filterUserUuidstringnonullFilter: owning user UUID (mailbox/drive owner).
orderBystringnonullComma-separated list of fields to order by.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken.

[ESET PROTECT] Permanently delete every quarantined object matching a filter (criteria-based delete) — irreversible. Body (fieldsJson): a `filter` object (same fields as eset_list_quarantined_objects) plus optional excludedObjectUuids. Not available in the Japan (jpn) region. May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with a `filter` object selecting objects to permanently delete, plus optional excludedObjectUuids.

[ESET PROTECT] Restore every quarantined object matching a filter to its original location — re-releases potentially-malicious files onto endpoints. Body (fieldsJson): a `filter` object plus optional addToExclusions (exclude from future scanning) and excludedObjectUuids. Not available in the Japan (jpn) region. May return a 202 cached-response envelope with a response-id for long-running requests.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON with a `filter` object selecting objects to restore, plus optional addToExclusions (bool) and excludedObjectUuids.

Users

ToolPlanAccessSummary
eset_batch_get_usersFreeRead-onlyRetrieve a specific set of users at a point in time (max 1000 per request).
eset_get_userFreeRead-onlyGet the details of a single user by their unique identifier.
eset_list_usersFreeRead-onlyList users, optionally filtered by active-product, cloud-office, display name, email, protection status, or user group.

[ESET PROTECT] Retrieve a specific set of users at a point in time (max 1000 per request). Body (fieldsJson) requires: usersUuids (array of user UUIDs, from eset_list_users). The operation is atomic — either every requested user is returned or none. Returns raw ESET JSON. Not available in the Japan (jpn) region.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesRequest JSON. Required: usersUuids (array of user UUIDs to retrieve, from eset_list_users).

[ESET PROTECT] Get the details of a single user by their unique identifier. Provide the user UUID (from eset_list_users). Returns the raw ESET user JSON. Not available in the Japan (jpn) region.

ParamTypeRequiredDefaultDescription
userUuidstringyesReference to the user to retrieve (from eset_list_users).

[ESET PROTECT] List users, optionally filtered by active-product, cloud-office, display name, email, protection status, or user group. Paginated via pageToken. Returns raw ESET JSON {users:[...], nextPageToken}. Get a single user with eset_get_user or several with eset_batch_get_users. Not available in the Japan (jpn) region.

ParamTypeRequiredDefaultDescription
activeProductAutoActivatedbooleannonullIf true, only users whose product was auto-activated (for their group or tenant) are returned.
activeProductAutoActivationDetailsBasestringnonullAuto-activation base filter: PRODUCT_AUTO_ACTIVATION_BASE_TENANT or PRODUCT_AUTO_ACTIVATION_BASE_USER_GROUP.
activeProductAutoActivationDetailsUserGroupUuidstringnonullUser group reference for auto-activation; only meaningful when base is USER_GROUP.
activeProductIdintegernonullIdentifier (numeric value) of the governed product resource.
activeProductNamestringnonullName of the governed product item (not the display name).
activeProductSubscriptionUuidstringnonullReference to the subscription used for product activation.
activeProductUnitPoolUuidstringnonullReference to the unit pool used for product activation.
cloudOfficeTenantReferencestringnonullExact-match filter on the user's cloud office tenant reference.
displayNamestringnonullPartial-match filter on the user's display name.
emailstringnonullPartial-match filter on the user's primary or proxy email address.
hasCloudOfficeMsLicensebooleannonullIf true, only users with an associated Microsoft cloud-office license; if false, only users without one.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.
protectionStatusstringnonullFilter by protection status: PROTECTION_STATUS_UNPROTECTED, PROTECTION_STATUS_PENDING, PROTECTION_STATUS_PARTIALLY_PROTECTED, or PROTECTION_STATUS_FULLY_PROTECTED.
userGroupUuidstringnonullFilter by the user's group (from user-management). Omit for all groups.

Vulnerabilities

ToolPlanAccessSummary
eset_list_device_os_vulnerabilitiesFreeRead-onlyList operating-system vulnerabilities for devices.
eset_list_device_vulnerabilitiesFreeRead-onlyList device vulnerabilities matching the criteria.
eset_list_recent_vulnerability_scansFreeRead-onlyList the scan details of all vulnerability scans performed recently (within the last few days).
eset_list_vulnerable_devicesFreeRead-onlyList vulnerable devices matching the criteria.

[ESET PROTECT] List operating-system vulnerabilities for devices. On Linux, some core-package vulnerabilities (glibc, systemd, etc.) are reported both here and as package vulnerabilities. Filter by deviceUuid (from eset_list_devices) or deviceGroupUuid (from eset_list_device_groups). Paginated via pageToken. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
deviceGroupUuidstringnonullReference to a device group to scope to (from eset_list_device_groups). Omit for any accessible device.
deviceUuidstringnonullReference to the vulnerable device to scope to (from eset_list_devices). Omit for any accessible device.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.

[ESET PROTECT] List device vulnerabilities matching the criteria. Each vulnerability is a separate entry, so a device with multiple vulnerabilities is listed multiple times. Filter by deviceUuid (from eset_list_devices), deviceGroupUuid (from eset_list_device_groups, recursive), or vulnerabilityScope (VULNERABILITY_SCOPE_APPLICATION, VULNERABILITY_SCOPE_OPERATING_SYSTEM, VULNERABILITY_SCOPE_PACKAGE). Paginated via pageToken. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
deviceGroupUuidstringnonullReference to a device group to scope to; nested groups are included recursively (from eset_list_device_groups). Omit for any accessible device.
deviceUuidstringnonullReference to the device to scope to (from eset_list_devices). Omit for any accessible device.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.
vulnerabilityScopestringnonullFilter by vulnerability scope: VULNERABILITY_SCOPE_APPLICATION, VULNERABILITY_SCOPE_OPERATING_SYSTEM, or VULNERABILITY_SCOPE_PACKAGE. Omit for any scope.

[ESET PROTECT] List the scan details of all vulnerability scans performed recently (within the last few days). The list may be empty if no scans have occurred recently; stale data is pruned over several days. Filter by deviceUuid (from eset_list_devices) or deviceGroupUuid (from eset_list_device_groups). Paginated via pageToken. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
deviceGroupUuidstringnonullReference to a device group to scope to (from eset_list_device_groups). Omit for all accessible devices.
deviceUuidstringnonullReference to the device to scope to (from eset_list_devices). Omit for all accessible devices.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.

[ESET PROTECT] List vulnerable devices matching the criteria. Even if a device has multiple vulnerabilities, it is listed only once. Filter by deviceGroupUuid (from eset_list_device_groups). Paginated via pageToken. Returns raw ESET JSON. Use eset_list_device_vulnerabilities for per-vulnerability detail.

ParamTypeRequiredDefaultDescription
deviceGroupUuidstringnonullReference to a device group to scope to (from eset_list_device_groups). Omit for any accessible device.
pageSizeintegerno50Max results per page (1-1000, default 50).
pageTokenstringnonullOpaque cursor from a previous response's nextPageToken. Omit for the first page.

Web Access Protection

ToolPlanAccessSummary
eset_list_web_address_rulesFreeRead-onlyList the web-address rules on a policy, optionally narrowed to rules that reference a given domain.
eset_update_web_address_ruleProDestructiveReplace all domains inside a web-address rule.

[ESET PROTECT] List the web-address rules on a policy, optionally narrowed to rules that reference a given domain. Provide the policy UUID (from eset_list_policies); set includeDomain to filter to rules containing that domain. Returns raw ESET JSON. Replace a rule's domains with eset_update_web_address_rule.

ParamTypeRequiredDefaultDescription
includeDomainstringnonullDomain of interest — restricts the result to rules that contain this domain. Omit to list all rules.
policyUuidstringyesReference to the policy whose web-address rules are listed (from eset_list_policies).

[ESET PROTECT] Replace all domains inside a web-address rule. Provide the policy UUID (from eset_list_policies) and the address rule UUID (from eset_list_web_address_rules). Body (fieldsJson): urls (array of URLs or domains — only the domain part is extracted, and duplicates collapse to one) plus optional sourceName. This replaces the rule's entire domain list; adding even a single domain requires the whole policy to be validated. Returns raw ESET JSON.

ParamTypeRequiredDefaultDescription
addressRuleUuidstringyesReference to the web-address rule whose domains are replaced (from eset_list_web_address_rules).
fieldsJsonstringyesUpdate request JSON. Required: urls (array of URLs/domains to set). Optional: sourceName (e.g. the source filename).
policyUuidstringyesReference to the policy containing the rule (from eset_list_policies).

Async Continuation

ToolPlanAccessSummary
eset_resume_asyncFreeRead-onlyResume any ESET operation that returned a 202 pending marker.

[ESET PROTECT] Resume any ESET operation that returned a 202 pending marker. Pass the pending marker's ContinuationToken verbatim as continuationToken — that is the ONLY input required; do not construct or edit it. Returns the completed result (raw JSON, or a SAS URL for a quarantine download), or another pending marker if ESET is still processing (retry with the new token). The token is validated as authentic and is redeemed with the exact plan/permission/safety gates of the original tool; a forged, cross-tenant, or repointed token is refused.

ParamTypeRequiredDefaultDescription
continuationTokenstringyesThe opaque ContinuationToken copied verbatim from a prior ESET 202 pending marker. This is a tamper-proof handle to the original request — pass it unchanged; it fully determines what is resumed.