ESET PROTECT Tools
Written By Christopher Scaminaci
Last updated 7 days ago
ESET PROTECT Tools
eset_ · 102 tools · Free 51 · Pro 51
Endpoint protection management: devices, groups, policies, detections, tasks and quarantine. Sign-in is a user name and password against your ESET PROTECT console; the refresh token rotates and is renewed for you. There is no single host - each call targets your region and product domain, taken from the instance address. Paging is a page size capped at 1000 with an opaque page token. The two quarantine downloads return a link to the stored file rather than bytes. The quarantine and user families, and the detection list, are unavailable in the Japan region.
All connector tools · ESET PROTECT setup guide
ESET PROTECT tool groups
- Executables — 4 tools
- Groups (Asset Management) — 4 tools
- Device Tasks (Automation) — 7 tools
- Device Groups — 2 tools
- Devices — 6 tools
- IAM (Roles & Permissions) — 6 tools
- Detections — 6 tools
- Detection Groups — 4 tools
- EDR Rules & Exclusions — 12 tools
- Incidents — 10 tools
- Installers — 5 tools
- Mobile Devices — 2 tools
- Network Access Protection — 3 tools
- Patch Management — 3 tools
- Policies — 9 tools
- Quarantine — 9 tools
- Users — 3 tools
- Vulnerabilities — 4 tools
- Web Access Protection — 2 tools
- Async Continuation — 1 tool
Executables
eset_block_executable details
eset_block_executable details
[ESET PROTECT] Block an executable so it will not be executed on managed devices. Provide the executable UUID (from eset_list_executables). Idempotent — re-blocking an already-blocked executable is a no-op. Returns the raw ESET response JSON.
eset_get_executable details
eset_get_executable details
[ESET PROTECT] Get details of a specific executable. Provide the executable UUID (from eset_list_executables). Returns the raw ESET executable JSON.
eset_list_executables details
eset_list_executables details
[ESET PROTECT] List all executables observed across managed devices. Paginated via pageToken. Returns raw ESET JSON {executables:[...], nextPageToken}. Get a single executable's detail with eset_get_executable.
eset_unblock_executable details
eset_unblock_executable details
[ESET PROTECT] Unblock a previously blocked executable so it can run again. Provide the executable UUID (from eset_list_executables). Idempotent — unblocking an already-unblocked executable is a no-op. Returns the raw ESET response JSON.
Groups (Asset Management)
eset_create_group details
eset_create_group details
[ESET PROTECT] Create a static group (folder) in the asset hierarchy and receive its assigned UUID. Body (fieldsJson) wraps a `group` object; set `group.displayName` (required) and optionally `group.parentGroupUuid` (parent group UUID from eset_list_device_groups; omit for the tree root) and `group.description`. Returns the created group JSON. The special 'All'/'Lost&Found' groups and entity-linked (CUSTOMER/MSP) groups cannot be created here.
eset_delete_group details
eset_delete_group details
[ESET PROTECT] Delete the group referenced by groupUuid AND every group and object beneath it — cascading and irreversible. Entity-linked (CUSTOMER/MSP) groups cannot be deleted. Group UUID from eset_list_device_groups.
eset_move_group details
eset_move_group details
[ESET PROTECT] Move a group (and its subtree) under a different parent, reorganizing the MSP company/site tree and re-evaluating policy assignments along the new hierarchy — only within the same tenant. Body (fieldsJson): newParentUuid (the target parent group UUID). Group UUIDs from eset_list_device_groups.
eset_rename_group details
eset_rename_group details
[ESET PROTECT] Change a group's display name. Body (fieldsJson): displayName (the new name). Group UUID from eset_list_device_groups.
Device Tasks (Automation)
eset_create_device_task details
eset_create_device_task details
[ESET PROTECT] Create a device task that runs an action (scan / isolation / uninstall / power action) on target endpoints. Body (fieldsJson) wraps a `task` object requiring: task.displayName, task.action, task.targets (device or device-group UUIDs), and at least one entry in task.triggers (else the call fails). Returns the created task JSON. May return a 202 cached-response envelope with a response-id for long-running requests.
eset_delete_device_task details
eset_delete_device_task details
[ESET PROTECT] Delete a device task. Deleting a templated task deletes all tasks sharing its template. Irreversible. Task UUID from eset_list_device_tasks.
eset_get_device_task details
eset_get_device_task details
[ESET PROTECT] Get a single device task entity by UUID (its action, targets, and triggers). For per-device execution history call eset_list_device_task_runs. Task UUID from eset_list_device_tasks.
eset_list_device_task_runs details
eset_list_device_task_runs details
[ESET PROTECT] List the run history (executions and results) of a device task, optionally scoped to one device or only the latest run per device. Paginated via pageToken. Task UUID from eset_list_device_tasks; device UUID from eset_list_devices.
eset_list_device_tasks details
eset_list_device_tasks details
[ESET PROTECT] List all device tasks (scheduled actions run on endpoints). Paginated via pageToken. Returns raw ESET JSON {tasks:[...], nextPageToken}. Task UUIDs feed eset_get_device_task and eset_list_device_task_runs.
eset_update_device_task_targets details
eset_update_device_task_targets details
[ESET PROTECT] Replace the targets (which devices / device groups the task runs on) of an existing device task — re-aiming an endpoint action. Body (fieldsJson): targets with devicesUuids and/or deviceGroupsUuids arrays. Task UUID from eset_list_device_tasks. May return a 202 cached-response envelope with a response-id for long-running requests.
eset_update_device_task_triggers details
eset_update_device_task_triggers details
[ESET PROTECT] Replace the trigger list (when the task runs) of an existing device task. The new triggers array cannot be empty. Body (fieldsJson): triggers array. Task UUID from eset_list_device_tasks. May return a 202 cached-response envelope with a response-id for long-running requests.
Device Groups
eset_list_device_group_members details
eset_list_device_group_members details
[ESET PROTECT] List the devices that are members of a device group. Provide the device group UUID (from eset_list_device_groups). Set recurseSubgroups=true to also include devices from nested subgroups. Group membership is independent of the device entity itself. Paginated via pageToken. Returns raw ESET JSON.
eset_list_device_groups details
eset_list_device_groups details
[ESET PROTECT] List all device groups. The group hierarchy can be reconstructed from the returned device_groups (each carries its parent reference). Paginated via pageToken. Returns raw ESET JSON {device_groups:[...], nextPageToken}. List the member devices of a group with eset_list_device_group_members.
Devices
eset_batch_get_devices details
eset_batch_get_devices details
[ESET PROTECT] Retrieve a specific set of devices at a consistent point in time. Provide the device UUIDs (from eset_list_devices). The operation is atomic — either every requested device is returned or none. Returns raw ESET JSON.
eset_get_device details
eset_get_device details
[ESET PROTECT] Get the full details of a single device. Provide the device UUID (from eset_list_devices). Returns the raw ESET device JSON.
eset_import_devices details
eset_import_devices details
[ESET PROTECT] Import a batch of devices into device management (max 1000 per request). Imported devices cannot be managed until properly enrolled. Body (fieldsJson) requires a `devices` array (each with a unique `displayName`; set `isMobile`=true for MDM scenarios) and an optional `parentGroupUuid` (from eset_list_device_groups) applied to all imported devices. May return partial success (200 with per-device errors keyed by display name). May return a 202 cached-response envelope with a response-id for long-running requests. Returns raw ESET JSON.
eset_list_devices details
eset_list_devices details
[ESET PROTECT] List all managed devices, optionally filtered. Paginated via pageToken. Returns raw ESET JSON {devices:[...], nextPageToken}. Use eset_get_device for a single device's full detail, or eset_batch_get_devices to fetch several at once.
eset_move_device details
eset_move_device details
[ESET PROTECT] Move a device under a new parent group. Provide the device UUID (from eset_list_devices). Body (fieldsJson) requires: newParentUuid (target group, from eset_list_device_groups). Moves are limited to the same tenant; policy assignments update to the new hierarchy. Returns raw ESET JSON.
eset_rename_device details
eset_rename_device details
[ESET PROTECT] Update a device's display name. Provide the device UUID (from eset_list_devices). Body (fieldsJson) requires: displayName. The display name is objective — it changes for everyone requesting the device. Returns raw ESET JSON.
IAM (Roles & Permissions)
eset_assign_role details
eset_assign_role details
[ESET PROTECT] Assign a role to a subject over one or more scopes. Additive — existing roles are kept. Body (fieldsJson): subjectType, subjectReference, and role {roleName, scopes:[...]}. Role names from eset_list_role_assignments / eset_create_role. Returns the resulting assignment JSON.
eset_create_role details
eset_create_role details
[ESET PROTECT] Create a custom role that bundles a set of permissions. Body (fieldsJson) wraps a `role` object: name (URL-safe, unique within the instance; alphanumeric/-/_ only), permissionNames (from eset_list_permissions), and optional displayName/description. Returns the created role JSON.
eset_delete_role details
eset_delete_role details
[ESET PROTECT] Delete a custom role by name. Irreversible; any subject currently holding it loses those permissions. Role names appear in eset_list_role_assignments.
eset_list_permissions details
eset_list_permissions details
[ESET PROTECT] List every permission the platform defines — the catalog you draw permissionNames from when creating a role with eset_create_role. Paginated via pageToken.
eset_list_role_assignments details
eset_list_role_assignments details
[ESET PROTECT] List role assignments — which subjects (users, devices, user groups, managed identities, services) hold which roles over which scopes. Filter by a single subject and/or subject type; leave filters empty to return everything visible to the caller. Paginated via pageToken.
eset_revoke_role details
eset_revoke_role details
[ESET PROTECT] Remove a role from a subject over the given scopes. The subject keeps roles/scopes not named here. Body (fieldsJson): subjectType, subjectReference, and role {roleName, scopes:[...]}. Inspect current assignments with eset_list_role_assignments first.
Detections
eset_batch_get_detections details
eset_batch_get_detections details
[ESET PROTECT] Batch-retrieve detections by UUID in one atomic call (all-or-nothing). Body (fieldsJson) requires: detectionUuids (array of detection UUIDs from eset_list_detections; keep to ~100 per call, hard cap 1000). Returns raw ESET JSON. May return a 202 cached-response envelope with a response-id for long-running requests.
eset_get_detection details
eset_get_detection details
[ESET PROTECT] Get a single detection by UUID (v2). Detection UUID from eset_list_detections. Returns the raw ESET detection JSON.
eset_get_detection_v1 details
eset_get_detection_v1 details
[ESET PROTECT] Get a single detection by UUID (legacy v1 surface). Detection UUID from eset_list_detections_v1. Returns the raw ESET detection JSON.
eset_list_detections details
eset_list_detections details
[ESET PROTECT] List detections (v2) matching the criteria, across device and ESET Cloud Office Protection sources. Optionally filter by cloud-office tenant and occurrence-time window. Paginated via pageToken. Returns raw ESET JSON {detections:[...], nextPageToken}. Not available in the Japan (jpn) region.
eset_list_detections_v1 details
eset_list_detections_v1 details
[ESET PROTECT] List detections (legacy v1 surface) matching the criteria. Optionally filter by device and occurrence-time window. Paginated via pageToken. Returns raw ESET JSON {detections:[...], nextPageToken}. Prefer eset_list_detections (v2) unless you specifically need the v1 shape.
eset_resolve_detection details
eset_resolve_detection details
[ESET PROTECT] Mark a detection as resolved. Detection UUID from eset_list_detections / eset_get_detection. Body (fieldsJson) optional: note (arbitrary text explaining the resolution); pass for none. Returns the raw ESET JSON response.
Detection Groups
eset_get_detection_group details
eset_get_detection_group details
[ESET PROTECT] Get details about a single detection group by UUID. Detection-group UUID from eset_list_detection_groups / eset_search_detection_groups. Returns the raw ESET detection-group JSON.
eset_list_detection_groups details
eset_list_detection_groups details
[ESET PROTECT] List detection groups (detections deduplicated/grouped by signature) matching the criteria. Optionally filter by cloud-office tenant, device, and occurrence-time window. Paginated via pageToken. Returns raw ESET JSON {detectionGroups:[...], nextPageToken}.
eset_resolve_detection_group details
eset_resolve_detection_group details
[ESET PROTECT] Mark ALL detections in a group as resolved in one call. Detection-group UUID from eset_list_detection_groups. Body (fieldsJson) optional: note (text explaining the resolution); pass for none. Returns the raw ESET JSON response.
eset_search_detection_groups details
eset_search_detection_groups details
[ESET PROTECT] Search detection groups with a filter expression (richer than the plain list). Body (fieldsJson) optional: filter (e.g. "resolved eq 0" for unresolved; supports eq/ne/gt/ge/lt/le/and/or/() and dot-notation nested fields), returnTotalSize (bool). Pass to return all. Returns raw ESET JSON.
EDR Rules & Exclusions
eset_create_edr_rule details
eset_create_edr_rule details
[ESET PROTECT] Create an EDR (ESET Inspect) rule. Body (fieldsJson) requires: rule object with xmlDefinition (XML in ESET Inspect rule format; a valid definition is required); optional enabled, scopes. Returns the created rule JSON.
eset_create_edr_rule_exclusion details
eset_create_edr_rule_exclusion details
[ESET PROTECT] Create an EDR rule exclusion. Body (fieldsJson) requires: exclusion object with xmlDefinition (XML in ESET Inspect rule format, actions ignored); optional ruleUuids (EDR rules the exclusion applies to, from eset_list_edr_rules), enabled, scopes, note. Returns the created exclusion JSON.
eset_delete_edr_rule details
eset_delete_edr_rule details
[ESET PROTECT] Delete an EDR rule permanently. Rule UUID from eset_list_edr_rules. Returns the raw ESET JSON response.
eset_delete_edr_rule_exclusion details
eset_delete_edr_rule_exclusion details
[ESET PROTECT] Delete an EDR rule exclusion permanently. Exclusion UUID from eset_list_edr_rule_exclusions. Returns the raw ESET JSON response.
eset_disable_edr_rule details
eset_disable_edr_rule details
[ESET PROTECT] Disable an EDR rule (stops it matching) without deleting it. Rule UUID from eset_list_edr_rules. No body required. Returns the raw ESET JSON response.
eset_enable_edr_rule details
eset_enable_edr_rule details
[ESET PROTECT] Enable an EDR rule so it is used for matching. Rule UUID from eset_list_edr_rules. No body required. Returns the raw ESET JSON response.
eset_get_edr_rule details
eset_get_edr_rule details
[ESET PROTECT] Get details of a single EDR rule by UUID. Rule UUID from eset_list_edr_rules. Returns the raw ESET rule JSON.
eset_get_edr_rule_exclusion details
eset_get_edr_rule_exclusion details
[ESET PROTECT] Get details of a single EDR rule exclusion by UUID. Exclusion UUID from eset_list_edr_rule_exclusions. Returns the raw ESET exclusion JSON.
eset_list_edr_rule_exclusions details
eset_list_edr_rule_exclusions details
[ESET PROTECT] List EDR rule exclusions (patches that suppress one or more EDR rules' actions) matching the criteria. Paginated via pageToken. Returns raw ESET JSON {edrRuleExclusions:[...], nextPageToken}.
eset_list_edr_rules details
eset_list_edr_rules details
[ESET PROTECT] List EDR (ESET Inspect) rules matching the criteria, optionally filtered by severity level. Paginated via pageToken. Returns raw ESET JSON {edrRules:[...], nextPageToken}.
eset_update_edr_rule_definition details
eset_update_edr_rule_definition details
[ESET PROTECT] Replace the XML definition of an existing EDR rule. Rule UUID from eset_list_edr_rules. Body (fieldsJson) requires: xmlDefinition (XML in ESET Inspect rule format; an invalid definition returns 400). Returns the raw ESET JSON response.
eset_update_edr_rule_exclusion_definition details
eset_update_edr_rule_exclusion_definition details
[ESET PROTECT] Replace the XML definition of an existing EDR rule exclusion. Exclusion UUID from eset_list_edr_rule_exclusions. Body (fieldsJson) requires: xmlDefinition (XML in ESET Inspect rule format, actions ignored). Returns the raw ESET JSON response.
Incidents
eset_close_incident details
eset_close_incident details
[ESET PROTECT] Close an incident. Incident UUID from eset_list_incidents. Body (fieldsJson) optional: closureReason (INCIDENT_RESOLVE_REASON_TRUE_POSITIVE / _FALSE_POSITIVE / _SUSPICIOUS / _UNSPECIFIED) and finalComment () describing how it was resolved; pass to close with no reason/comment. Returns the raw ESET JSON response.
eset_create_incident_comment details
eset_create_incident_comment details
[ESET PROTECT] Add a comment to an incident. Incident UUID from eset_list_incidents. Body (fieldsJson) requires: comment object with text. Returns the created comment JSON.
eset_delete_incident_comment details
eset_delete_incident_comment details
[ESET PROTECT] Delete a comment from an incident permanently. Incident UUID from eset_list_incidents; comment UUID from eset_list_incident_comments. Returns the raw ESET JSON response.
eset_get_incident details
eset_get_incident details
[ESET PROTECT] Get details of a single incident by UUID. Incident UUID from eset_list_incidents. Returns the raw ESET incident JSON.
eset_get_incident_comment details
eset_get_incident_comment details
[ESET PROTECT] Get a single incident comment by UUID. Incident UUID from eset_list_incidents; comment UUID from eset_list_incident_comments. Returns the raw ESET comment JSON.
eset_list_incident_comments details
eset_list_incident_comments details
[ESET PROTECT] List all comments on a single incident, ordered by create time. Incident UUID from eset_list_incidents. Returns raw ESET JSON with the incident's comments.
eset_list_incidents details
eset_list_incidents details
[ESET PROTECT] List incidents matching an optional filter, ordered by order_by. Paginated via pageToken. Returns raw ESET JSON {incidents:[...], nextPageToken}.
eset_reopen_incident details
eset_reopen_incident details
[ESET PROTECT] Reopen a non-Open incident (sets status back to Open; assignee unchanged; a prior closing comment becomes a normal comment). Incident UUID from eset_list_incidents. Body (fieldsJson) optional: comment (); pass for none. Returns the raw ESET JSON response.
eset_update_incident_attributes details
eset_update_incident_attributes details
[ESET PROTECT] Update chosen basic attributes of an incident. Incident UUID from eset_list_incidents. Body (fieldsJson): any of assigneeUuid (user UUID), displayName, description, severity (INCIDENT_SEVERITY_LEVEL_LOW/_MEDIUM/_HIGH/_UNSPECIFIED), plus updateMask listing the fields to change. Returns the raw ESET JSON response.
eset_update_incident_comment details
eset_update_incident_comment details
[ESET PROTECT] Change the text of an existing incident comment. Incident UUID from eset_list_incidents; comment UUID from eset_list_incident_comments. Body (fieldsJson) requires: text (the new comment text). Returns the raw ESET JSON response.
Installers
eset_create_installer details
eset_create_installer details
[ESET PROTECT] Create a downloadable installer that drops components, activates products, and enrolls devices into a security group. Body (fieldsJson) wraps an `installer` object: displayName, operatingSystemFamilyId (1=Windows, 3=macOS), deviceEnrollment.securityGroupUuid, plus optional flags; requestedComponentIds may pin specific components. Returns the installer JSON with downloadUrl. May return a 202 cached-response envelope with a response-id for long-running requests.
eset_delete_installer details
eset_delete_installer details
[ESET PROTECT] Delete an installer by UUID, invalidating its download URL. Irreversible. Installer UUID from eset_list_installers.
eset_generate_installer details
eset_generate_installer details
[ESET PROTECT] Generate an ad-hoc GPO/SCCM-compatible configuration file for deploying the security product via Group Policy or System Center Configuration Manager. The config is returned inline and not stored. Body (fieldsJson) optional: sendAnonymousDiagnosticData, deviceEnrollmentSettings.securityGroupUuid (target group from eset_list_device_groups). May return a 202 cached-response envelope with a response-id for long-running requests.
eset_get_installer details
eset_get_installer details
[ESET PROTECT] Get details of one installer by UUID (download URL, expiry, activated products, installed components). Installer UUID from eset_list_installers.
eset_list_installers details
eset_list_installers details
[ESET PROTECT] List the installers available to the caller (each carries a download URL and expiry). Optionally filter by usability. Paginated via pageToken. Installer UUIDs feed eset_get_installer and eset_delete_installer.
Mobile Devices
eset_activate_product_mobile_devices details
eset_activate_product_mobile_devices details
[ESET PROTECT] Create a product-activation task targeting a batch of mobile devices; the product is chosen automatically from each device's parent group. All devices must share the same parent device group and that group must have an available subscription. Body (fieldsJson): deviceUuids array (from eset_list_devices). Fails atomically (400/403/404). May return a 202 cached-response envelope with a response-id for long-running requests.
eset_get_mobile_device_enrollment_links details
eset_get_mobile_device_enrollment_links details
[ESET PROTECT] Generate enrollment links (valid on Android/iOS only) for a batch of up to 1000 mobile devices. Each device must be flagged mobile and not already enrolled, else the whole batch fails atomically (400/404). Body (fieldsJson): deviceUuids array (from eset_list_devices). Returns the generated links.
Network Access Protection
eset_get_network_access_rule details
eset_get_network_access_rule details
[ESET PROTECT] Get details about a single IP set on a policy. Provide the policy UUID (from eset_list_policies) and the IP set UUID (from eset_list_network_access_rules). Returns the raw ESET IP-set JSON.
eset_list_network_access_rules details
eset_list_network_access_rules details
[ESET PROTECT] List all IP sets defined on a policy. Provide the policy UUID (from eset_list_policies). Paginated via pageToken. Returns raw ESET JSON. Get a single IP set with eset_get_network_access_rule.
eset_update_network_access_rule details
eset_update_network_access_rule details
[ESET PROTECT] Update an IP set on a policy. Provide the policy UUID (from eset_list_policies) and the IP set UUID (from eset_list_network_access_rules). Body (fieldsJson) wraps the changes under an `ipSet` object; updatable attributes are displayName, description, and ipAddresses (CIDR/IPv4/IPv6, no uniqueness check). Read-only IP sets cannot be updated; for built-in IP sets only ipAddresses is updatable. Returns raw ESET JSON.
Patch Management
eset_get_patching_process_details details
eset_get_patching_process_details details
[ESET PROTECT] List device patching-process details (history of patch attempts). History is pruned repeatedly; at least the previous 30 days are available. Filter by deviceUuid (from eset_list_devices), deviceGroupUuid (from eset_list_device_groups), and an optional time interval (timePeriodStartTime inclusive, timePeriodEndTime exclusive; RFC 3339 timestamps). Paginated via pageToken. Returns raw ESET JSON.
eset_list_device_patch_status details
eset_list_device_patch_status details
[ESET PROTECT] List device patches (unpatched applications, packages, and operating systems). If the same patch is missing on multiple devices, each device/patch pair is a separate entry. Filter by deviceUuid (from eset_list_devices), deviceGroupUuid (from eset_list_device_groups), or patchType. Paginated via pageToken. Returns raw ESET JSON.
eset_list_recent_patching_processes details
eset_list_recent_patching_processes details
[ESET PROTECT] List the patching details of all application patching attempts performed recently (within the last few days). The list may be empty if no patching has occurred recently; stale data is pruned over several days. Returns raw ESET JSON.
Policies
eset_create_policy details
eset_create_policy details
[ESET PROTECT] Create a policy carrying feature configurations. All included feature policies must be valid or the call returns 400. Body (fieldsJson) wraps a `policy` object: displayName, features array, optional description. Returns the created policy JSON. Assign it to targets with eset_create_policy_assignment.
eset_create_policy_assignment details
eset_create_policy_assignment details
[ESET PROTECT] Assign a policy to a target (device, device group, or subscription). New assignments are appended at the lowest rank; rank 1 has the highest priority and policies merge from rank 1 downward. Body (fieldsJson) wraps an `assignment` object: policyUuid and target. Returns the created assignment JSON.
eset_delete_policy details
eset_delete_policy details
[ESET PROTECT] Delete a policy by UUID. Irreversible; built-in policies cannot be deleted. Policy UUID from eset_list_policies.
eset_delete_policy_assignment details
eset_delete_policy_assignment details
[ESET PROTECT] Remove a policy assignment (unassign a policy from its target); remaining assignments on that target are reordered. Irreversible. Assignment UUID from eset_list_policy_assignments.
eset_get_policy details
eset_get_policy details
[ESET PROTECT] Get one policy's details (its feature configurations) by UUID. Policy UUID from eset_list_policies.
eset_get_policy_assignment details
eset_get_policy_assignment details
[ESET PROTECT] Get one policy assignment (policy, target, and rank) by UUID. Assignment UUID from eset_list_policy_assignments.
eset_list_policies details
eset_list_policies details
[ESET PROTECT] List all policies visible to the caller. Paginated via pageToken. Policy UUIDs feed eset_get_policy, eset_delete_policy, and eset_create_policy_assignment.
eset_list_policy_assignments details
eset_list_policy_assignments details
[ESET PROTECT] List policy assignments (which policies are applied to which targets, and at what rank). Filter by policy or by target device / device group / subscription. Paginated via pageToken. Assignment UUIDs feed eset_get_policy_assignment and eset_delete_policy_assignment.
eset_update_policy_assignment_ranking details
eset_update_policy_assignment_ranking details
[ESET PROTECT] Move a policy assignment to a new rank on its target (rank 1 = highest priority). Body (fieldsJson): rank (>= 1 and <= the target's assignment count, else 400/412). Other assignments are reordered around it. Assignment UUID from eset_list_policy_assignments.
Quarantine
eset_batch_delete_quarantined_objects details
eset_batch_delete_quarantined_objects details
[ESET PROTECT] Permanently delete a batch of quarantined objects by UUID — irreversible. Body (fieldsJson): objectUuids array (from eset_list_quarantined_objects). Not available in the Japan (jpn) region. May return a 202 cached-response envelope with a response-id for long-running requests.
eset_batch_download_quarantined_objects details
eset_batch_download_quarantined_objects details
[ESET PROTECT] Download a batch of quarantined objects (by UUID) as a ZIP archive. Body (fieldsJson): objectUuids array (from eset_list_quarantined_objects). Returns a short-lived read-only SAS URL to the archive — the payload is potentially malicious and is handled out-of-band, not inline. A slow (>30s) download returns a pending marker with an opaque ContinuationToken instead; retrieve the archive later by calling eset_resume_async with that token. Not available in the Japan (jpn) region.
eset_batch_restore_quarantined_objects details
eset_batch_restore_quarantined_objects details
[ESET PROTECT] Restore a batch of quarantined objects (by UUID) to their original locations — re-releases potentially-malicious files onto endpoints. Body (fieldsJson): objectUuids array plus optional addToExclusions (exclude from future scanning). Not available in the Japan (jpn) region. May return a 202 cached-response envelope with a response-id for long-running requests.
eset_count_quarantined_objects details
eset_count_quarantined_objects details
[ESET PROTECT] Count quarantined objects matching the filter (same filter fields as eset_list_quarantined_objects). Cheaper than listing when you only need totals. Not available in the Japan (jpn) region.
eset_download_quarantined_objects details
eset_download_quarantined_objects details
[ESET PROTECT] Download quarantined objects matching a filter as a ZIP archive. Body (fieldsJson): a `filter` object (same fields as eset_list_quarantined_objects) plus optional excludedObjectUuids. Returns a short-lived read-only SAS URL to the archive — the payload is potentially malicious and is handled out-of-band, not inline. A slow (>30s) download returns a pending marker with an opaque ContinuationToken instead; retrieve the archive later by calling eset_resume_async with that token. Not available in the Japan (jpn) region.
eset_get_quarantined_object details
eset_get_quarantined_object details
[ESET PROTECT] Get a single quarantined object by UUID. Object UUID from eset_list_quarantined_objects. Not available in the Japan (jpn) region.
eset_list_quarantined_objects details
eset_list_quarantined_objects details
[ESET PROTECT] List quarantined objects (files, email messages, email attachments) matching the filter. All filters combine with AND. Paginated via pageToken. Object UUIDs feed eset_get_quarantined_object and the batch restore/delete/download tools. Not available in the Japan (jpn) region.
eset_purge_quarantined_objects details
eset_purge_quarantined_objects details
[ESET PROTECT] Permanently delete every quarantined object matching a filter (criteria-based delete) — irreversible. Body (fieldsJson): a `filter` object (same fields as eset_list_quarantined_objects) plus optional excludedObjectUuids. Not available in the Japan (jpn) region. May return a 202 cached-response envelope with a response-id for long-running requests.
eset_restore_quarantined_objects_by_filter details
eset_restore_quarantined_objects_by_filter details
[ESET PROTECT] Restore every quarantined object matching a filter to its original location — re-releases potentially-malicious files onto endpoints. Body (fieldsJson): a `filter` object plus optional addToExclusions (exclude from future scanning) and excludedObjectUuids. Not available in the Japan (jpn) region. May return a 202 cached-response envelope with a response-id for long-running requests.
Users
eset_batch_get_users details
eset_batch_get_users details
[ESET PROTECT] Retrieve a specific set of users at a point in time (max 1000 per request). Body (fieldsJson) requires: usersUuids (array of user UUIDs, from eset_list_users). The operation is atomic — either every requested user is returned or none. Returns raw ESET JSON. Not available in the Japan (jpn) region.
eset_get_user details
eset_get_user details
[ESET PROTECT] Get the details of a single user by their unique identifier. Provide the user UUID (from eset_list_users). Returns the raw ESET user JSON. Not available in the Japan (jpn) region.
eset_list_users details
eset_list_users details
[ESET PROTECT] List users, optionally filtered by active-product, cloud-office, display name, email, protection status, or user group. Paginated via pageToken. Returns raw ESET JSON {users:[...], nextPageToken}. Get a single user with eset_get_user or several with eset_batch_get_users. Not available in the Japan (jpn) region.
Vulnerabilities
eset_list_device_os_vulnerabilities details
eset_list_device_os_vulnerabilities details
[ESET PROTECT] List operating-system vulnerabilities for devices. On Linux, some core-package vulnerabilities (glibc, systemd, etc.) are reported both here and as package vulnerabilities. Filter by deviceUuid (from eset_list_devices) or deviceGroupUuid (from eset_list_device_groups). Paginated via pageToken. Returns raw ESET JSON.
eset_list_device_vulnerabilities details
eset_list_device_vulnerabilities details
[ESET PROTECT] List device vulnerabilities matching the criteria. Each vulnerability is a separate entry, so a device with multiple vulnerabilities is listed multiple times. Filter by deviceUuid (from eset_list_devices), deviceGroupUuid (from eset_list_device_groups, recursive), or vulnerabilityScope (VULNERABILITY_SCOPE_APPLICATION, VULNERABILITY_SCOPE_OPERATING_SYSTEM, VULNERABILITY_SCOPE_PACKAGE). Paginated via pageToken. Returns raw ESET JSON.
eset_list_recent_vulnerability_scans details
eset_list_recent_vulnerability_scans details
[ESET PROTECT] List the scan details of all vulnerability scans performed recently (within the last few days). The list may be empty if no scans have occurred recently; stale data is pruned over several days. Filter by deviceUuid (from eset_list_devices) or deviceGroupUuid (from eset_list_device_groups). Paginated via pageToken. Returns raw ESET JSON.
eset_list_vulnerable_devices details
eset_list_vulnerable_devices details
[ESET PROTECT] List vulnerable devices matching the criteria. Even if a device has multiple vulnerabilities, it is listed only once. Filter by deviceGroupUuid (from eset_list_device_groups). Paginated via pageToken. Returns raw ESET JSON. Use eset_list_device_vulnerabilities for per-vulnerability detail.
Web Access Protection
eset_list_web_address_rules details
eset_list_web_address_rules details
[ESET PROTECT] List the web-address rules on a policy, optionally narrowed to rules that reference a given domain. Provide the policy UUID (from eset_list_policies); set includeDomain to filter to rules containing that domain. Returns raw ESET JSON. Replace a rule's domains with eset_update_web_address_rule.
eset_update_web_address_rule details
eset_update_web_address_rule details
[ESET PROTECT] Replace all domains inside a web-address rule. Provide the policy UUID (from eset_list_policies) and the address rule UUID (from eset_list_web_address_rules). Body (fieldsJson): urls (array of URLs or domains — only the domain part is extracted, and duplicates collapse to one) plus optional sourceName. This replaces the rule's entire domain list; adding even a single domain requires the whole policy to be validated. Returns raw ESET JSON.
Async Continuation
eset_resume_async details
eset_resume_async details
[ESET PROTECT] Resume any ESET operation that returned a 202 pending marker. Pass the pending marker's ContinuationToken verbatim as continuationToken — that is the ONLY input required; do not construct or edit it. Returns the completed result (raw JSON, or a SAS URL for a quarantine download), or another pending marker if ESET is still processing (retry with the new token). The token is validated as authentic and is redeemed with the exact plan/permission/safety gates of the original tool; a forged, cross-tenant, or repointed token is refused.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team