Skip to main content
Connector guides

Connect Bitdefender GravityZone

Bitdefender GravityZone is the console behind Bitdefender's endpoint protection. It runs antivirus and anti-ransomware on your customers' machines, adds EDR and XDR incident detection on top, patches…

Written By Christopher Scaminaci

Last updated 6 days ago

Bitdefender GravityZone is the console behind Bitdefender's endpoint protection. It runs antivirus and anti-ransomware on your customers' machines, adds EDR and XDR incident detection on top, patches third-party software, hardens applications, and holds the quarantine that suspicious files land in. MSPs usually reach it through the partner Control Center, where each customer is a company you manage under your own account.

Connecting GravityZone to StackJack gives your AI assistant a family of gravityzone_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • See the estate — every managed endpoint with its protection status, agent version, policy and label, plus the group and company structure around it
  • Work the incident queue — endpoint and organization incidents, the evidence behind each, the blocklist, and the custom detection rules in force
  • Report on patching — which updates are installed across the fleet and which are missing, filtered to a company or a set of endpoints
  • Check the quarantine — what is being held for both endpoints and Exchange mail, and why
  • Audit licensing and companies — license status, monthly usage, company details, and the custom fields attached to each
  • Review hardening — the PHASR rules being monitored, the recommendations waiting on a decision, and who has asked for an exception
  • Respond to a threat (on Pro plans) — isolate a compromised endpoint from the network, kill a running process, collect an investigation package, run a scan, and lift isolation again
  • Change protection (on Pro plans) — assign policies, switch protection modules on or off, add and remove blocklist entries, and create or update custom detection rules
  • Manage the estate (on Pro plans) — create, suspend and delete companies, move endpoints and seats between them, build installation packages, and schedule maintenance windows

How StackJack authenticates to GravityZone

GravityZone uses a single long-lived API key. There is no client ID, no second secret, and nothing that expires on a schedule. You generate the key once in Control Center and paste it into StackJack along with your console's Access URL.

The Access URL and the key are a pair

This is the one thing worth getting right before anything else. GravityZone cloud consoles are completely separate from one another, and a key created on one console is meaningless on another. Always copy both values from the same place, in the same sitting.

You will find both in Control Center under My Account: the Access URL under Control Center API, and the key under API keys.

If you run GravityZone on-premises, enter the address of your own console instead of a Bitdefender cloud address. It must be reachable over HTTPS with a valid certificate.

Choose the API groups carefully — you cannot widen them later

When you create the key, GravityZone asks which API groups it may reach. That choice is fixed at creation. There is no way to add a group to an existing key afterward, from the console or from StackJack.

Tick General. It is the group StackJack's connection test runs on: the test asks GravityZone which groups the key holds, and that question is itself a General call. A key without General cannot be verified at all, so the connector never reports as connected no matter how many other groups you ticked.

Beyond General, pick the groups matching the work you want your AI to do. The narrower this choice, the less any later mistake can reach — and it cannot be widened afterwards, so a key that reaches only what you need is the strongest control available here. If you would rather not decide now, enabling all of them and relying on StackJack's plan tiers and your own tool selection is the simpler path.

A key that is missing one of those other groups is not broken. Tools in that group will report that GravityZone refused them, everything else keeps working, and the connection test still shows as connected.

Steps

  1. Sign in to Control Center as an administrator whose account holds the Manage Networks, Manage Users, Manage Company, and View and analyze data rights. An account without those rights can create a key that silently sees nothing.
  2. Copy your Access URL from My Account, under Control Center API.
  3. Create the API key under My Account, choosing the API groups it may reach. Include General, or the connection test in step 6 cannot run.
  4. Copy the key immediately. GravityZone shows it exactly once. It cannot be read back afterward — if you lose it, create a replacement and delete the old one.
  5. Paste both values into StackJack. Open Connectors, choose Bitdefender GravityZone, and enter the Access URL and the key.
  6. Run a Test Connection. A successful test confirms the key works — it needs the General group to do that — but it does not list your API groups back to you. To see the granted list, ask your agent for Get API Key Details (gravityzone_get_api_key_details) once the connector is saved; it is read-only and available on Free.

What to know before your AI uses this connector

Every GravityZone action is a request that looks the same

GravityZone does not distinguish a read from a change at the network level — reading the endpoint list and isolating a machine are the same shape of request. Nothing in the protocol protects you, so StackJack labels each tool by what it actually does, and that label is what your AI application reads.

Seventy of the tools are marked destructive, and every one of them requires the Pro tier. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting, and grant only what you want an AI to reach.

Some tools take a machine off the network

  • Isolating an endpoint cuts it off from everything except GravityZone itself. It is the right response to a live compromise, and it will also stop a person working. Restoring from isolation is a separate tool.
  • Running a command on an endpoint, killing a process, and collecting an investigation package all act on a live machine while someone may be using it.
  • Running a live search query reaches every endpoint in a company at once and writes its results to storage you nominate.

Some tools change protection itself

  • Switching a protection module off leaves the agent installed and reporting, so nothing looks broken, while that layer of protection stops running.
  • Assigning a policy replaces the settings on every endpoint it reaches.
  • Adding a custom rule as an exclusion tells GravityZone to stop detecting something. That is sometimes exactly right and always worth reading twice.
  • Removing a blocklist entry allows something that was previously blocked estate-wide.

Some tools affect billing and customer access

  • Creating, suspending and deleting companies changes who exists in your console. Deleting one removes its endpoints and history with it.
  • Moving endpoints between companies moves the seats that go with them, and therefore the billing.
  • Setting a license key or a monthly subscription changes what a customer is charged.

Quarantine releases put a file back

Restoring a quarantined file returns it to the machine it came from, and releasing a quarantined Exchange item delivers that message to a real person's inbox. Emptying the quarantine discards everything held in it, and there is no undo.

Anything asynchronous returns a task, not a result

Scans, isolation, package collection, log gathering and command execution all hand back a task identifier rather than a finished outcome. Ask your AI to check the task status before it reports what happened — a dispatched task is not a completed one.

Filters can be silently ignored

Two GravityZone filtering behaviors are worth knowing, because both produce a confidently wrong answer rather than an error:

  • A name filter matches by prefix unless the value starts with *, which switches it to a contains match.
  • A filter whose underlying GravityZone license is not active is ignored rather than refused, so the result set comes back looking complete.

If a filtered count looks surprising, confirm the license before trusting it.

Plans and limits

Read tools are available on the Free tier. Everything that writes, responds, isolates, or changes licensing is Pro. Business reaches the same tools as Pro and differs by monthly call quota.

See the generated Bitdefender GravityZone tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Bitdefender limits an API key to 10 requests a second by default. Some areas are slower on purpose: licensing and company changes allow 5 a second, and the blocklist, custom-rule, notification and maintenance-window changes allow only 5 a minute. StackJack paces requests and backs off automatically when GravityZone throttles, which usually makes a large sweep slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Several customers

Some MSPs need one Bitdefender GravityZone connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.

Troubleshooting

"GravityZone rejected the credentials" — the key is wrong for this console, or it has been deleted. Because the Access URL and the key are a pair, the most common cause is a key copied from a different console than the URL. Re-copy both from the same Control Center and run a Test Connection.

"This API key was not granted that group" — the key is valid and the group it needs was not enabled when it was created. Groups cannot be widened on an existing key: create a replacement key with the groups you need, paste it into StackJack, then delete the old one.

A company shows no endpoints — check that the account behind the key can actually see that company. A partner account sees the companies it manages; a company-level account sees one. A key with narrower reach than you expect returns an empty list rather than an error.

A filtered list looks too short — see the note on filters above. A prefix match and a silently-ignored filter both look like a small result rather than a mistake.

An action reported success but nothing happened — check whether the tool dispatches a task. Scans, isolation, package collection and command execution all return a task identifier first; the work happens afterward and can still fail.

Reports and packages seem to vanish — GravityZone holds generated reports and installation packages on its own schedule. If a download link no longer resolves, regenerate the report rather than retrying the old link.

Bitdefender GravityZone tools

gravityzone_ · 138 tools · Free 56 · Pro 82

Accounts

ToolWhat it does
gravityzone_configure_notifications_settings
Pro · Write
Partial-merge write of notification preferences.
gravityzone_create_account
Pro · Destructive
Creates a console user with a role/rights grant; if password is omitted a generated password is EMAILED to the user (documented).
gravityzone_delete_account
Pro · Destructive
Deletes a Control Center user account.
gravityzone_get_account_details
Free · Read-only
Single account by id/email.
gravityzone_get_accounts_list
Free · Read-only
Paged list of Control Center user accounts.
gravityzone_get_notifications_settings
Free · Read-only
Reads notification preferences.
gravityzone_update_account
Pro · Destructive
Wholesale account update; takes role (5 = Custom) and a rights object - privilege-widening.

Companies

ToolWhat it does
gravityzone_activate_company
Pro · Write
Reactivates a suspended company (restorative).
gravityzone_create_company
Pro · Destructive
Creates a managed customer company and assigns a license subscription - creates a billable contract.
gravityzone_create_custom_field_definition
Pro · Write
Additive: new company custom-field definition.
gravityzone_delete_company
Pro · Destructive
Deletes a managed company and everything under it.
gravityzone_delete_custom_field_definition
Pro · Destructive
Deletes a custom-field definition and its stored values.
gravityzone_find_companies_by_name
Free · Read-only
Name search over managed companies.
gravityzone_get_company_details
Free · Read-only
Company record by id.
gravityzone_get_company_details_by_user
Free · Read-only
Company record for a given user.
gravityzone_get_custom_fields_definitions
Free · Read-only
Lists company custom-field definitions.
gravityzone_suspend_company
Pro · Destructive
Suspends a customer company - stops protection management.
gravityzone_update_company_details
Pro · Write
Partial-merge update of company name/address/contact.
gravityzone_update_custom_field_definition
Pro · Write
Partial update of a custom-field definition.

General

ToolWhat it does
gravityzone_get_api_key_details
Free · Read-only
Zero params.

Incidents

ToolWhat it does
gravityzone_add_to_blocklist
Pro · Destructive
Adds a hash/path to the estate-wide blocklist - live enforcement.
gravityzone_change_incident_status
Pro · Write
Workflow status field update (open/closed).
gravityzone_create_custom_rule
Pro · Destructive
Creates an EDR detection/exclusion rule; an exclusion can silence detection.
gravityzone_create_isolate_endpoint_task
Pro · Destructive
Network-isolates a live endpoint.
gravityzone_create_response_action
Pro · Destructive
Dispatches an EDR response action against live endpoints.
gravityzone_create_restore_endpoint_from_isolation_task
Pro · Destructive
Lifts isolation on a live endpoint (dispatch + control removal).
gravityzone_delete_custom_rule
Pro · Destructive
Deletes a custom rule.
gravityzone_get_blocklist_items
Free · Read-only
Paged blocklist read.
gravityzone_get_custom_rules_list
Free · Read-only
Paged custom-rule list.
gravityzone_get_incident
Free · Read-only
Single incident by id.
gravityzone_get_incidents_by_ids
Free · Read-only
Bulk incident fetch by id array.
gravityzone_get_incidents_list
Free · Read-only
Paged incident search.
gravityzone_get_response_action_status
Free · Read-only
Polls a response action.
gravityzone_get_similar_emails
Free · Read-only
Correlated email search for an email incident.
gravityzone_remove_from_blocklist
Pro · Destructive
Removes a security control (revoke).
gravityzone_start_yara_scan
Pro · Destructive
Dispatches a YARA scan to live endpoints.
gravityzone_update_custom_rule
Pro · Destructive
Wholesale replace of a custom rule.
gravityzone_update_incident_note
Pro · Write
Partial write of a free-text note field.

Integrations

ToolWhat it does
gravityzone_configure_amazon_ec2_integration_cross_account_role
Pro · Destructive
Grants cross-account AWS role access - privilege-widening.
gravityzone_create_integration
Pro · Destructive
Creates a third-party integration incl.
gravityzone_delete_integration
Pro · Destructive
Deletes an integration.
gravityzone_disable_amazon_ec2_integration
Pro · Destructive
Disables the EC2 integration.
gravityzone_generate_amazon_ec2_external_id_cross_account_role
Pro · Destructive
Mints an AWS external id (credential minting).
gravityzone_get_amazon_ec2_external_id_for_cross_account_role
Free · Read-only
Reads the existing external id.
gravityzone_get_company_details_by_aws_account_id
Free · Read-only
Company lookup by AWS account id.
gravityzone_get_configured_integrations
Free · Read-only
Paged list of configured integrations.
gravityzone_get_hourly_usage_for_amazon_ec2_instances
Free · Read-only
EC2 hourly usage read (billing input).
gravityzone_get_integration_details
Free · Read-only
Reads one integration.
gravityzone_manage_integration
Pro · Destructive
Enables/disables an integration.
gravityzone_update_integration
Pro · Destructive
Wholesale replace of an integration config incl.

Investigation

ToolWhat it does
gravityzone_collect_investigation_package
Pro · Destructive
Dispatches forensic collection on a live endpoint.
gravityzone_get_investigation_file_url
Free · Read-only
Returns a signed download URL for a collected artifact.
gravityzone_kill_process_investigation
Pro · Destructive
Terminates a running process on a live endpoint.
gravityzone_start_command_execution_on_endpoint
Pro · Destructive
ARBITRARY COMMAND EXECUTION on a live endpoint.
gravityzone_start_retrieve_investigation_file_from_endpoint
Pro · Destructive
Pulls an arbitrary file off a live endpoint.

Licensing

ToolWhat it does
gravityzone_add_product_key
Pro · Destructive
Adds a product key - spends money / changes entitlement.
gravityzone_get_license_info
Free · Read-only
License/subscription read.
gravityzone_get_monthly_usage
Free · Read-only
Monthly usage read (billing input).
gravityzone_get_monthly_usage_per_product_type
Free · Read-only
Monthly usage by product type.
gravityzone_remove_product_key
Pro · Destructive
Removes a product key.
gravityzone_set_license_key
Pro · Destructive
Replaces the license key - can cut protection.
gravityzone_set_monthly_subscription
Pro · Destructive
Sets a customer monthly subscription - billable.

Maintenance Windows

ToolWhat it does
gravityzone_assign_maintenance_windows
Pro · Destructive
Assigns windows to targets - schedules patch installs/reboots.
gravityzone_create_patch_management_maintenance_window
Pro · Write
Additive: creates a maintenance window definition.
gravityzone_delete_maintenance_window
Pro · Destructive
Deletes a maintenance window.
gravityzone_get_maintenance_window_details
Free · Read-only
One maintenance window.
gravityzone_get_maintenance_windows_list
Free · Read-only
Paged maintenance-window list.
gravityzone_get_manually_approved_patches
Free · Read-only
Reads manually approved patches.
gravityzone_unassign_maintenance_windows
Pro · Destructive
Removes windows from targets (revoke).
gravityzone_update_patch_management_maintenance_window
Pro · Destructive
Wholesale replace; schedules patching and reboots.

Network

ToolWhat it does
gravityzone_add_integrators
Pro · Destructive
Grants an integrator access to a company - privilege-widening.
gravityzone_assign_policy
Pro · Destructive
Replaces the security policy on targets - can disable protection modules.
gravityzone_create_company_folder
Pro · Write
Additive: creates a company folder.
gravityzone_create_custom_group
Pro · Write
Additive: creates an inventory group.
gravityzone_create_reconfigure_client_task
Pro · Destructive
Installs/removes protection modules on live endpoints.
gravityzone_create_scan_task
Pro · Destructive
Dispatches a scan to live endpoints.
gravityzone_create_scan_task_by_mac
Pro · Destructive
Dispatches a scan by MAC address.
gravityzone_create_submit_to_sandbox_analyzer_task
Pro · Destructive
Uploads a sample for detonation - live dispatch.
gravityzone_delete_company_folder
Pro · Destructive
Deletes a company folder.
gravityzone_delete_custom_group
Pro · Destructive
Deletes an inventory group.
gravityzone_delete_endpoint
Pro · Destructive
Deletes an endpoint from inventory.
gravityzone_delete_task
Pro · Destructive
Deletes a task.
gravityzone_get_companies_list
Free · Read-only
Managed companies list.
gravityzone_get_company_folders_list
Free · Read-only
Company folder list.
gravityzone_get_custom_groups_list
Free · Read-only
Lists custom groups.
gravityzone_get_endpoint_tags
Free · Read-only
Endpoint tag list.
gravityzone_get_endpoints_list
Free · Read-only
Paged endpoint list.
gravityzone_get_integrators
Free · Read-only
Lists integrators on a company.
gravityzone_get_managed_endpoint_details
Free · Read-only
Full endpoint record incl.
gravityzone_get_network_inventory_items
Free · Read-only
Paged inventory across all item types.
gravityzone_get_root_containers
Free · Read-only
Top-level containers.
gravityzone_get_scan_tasks_list
Free · Read-only
Paged task list.
gravityzone_get_task_status
Free · Read-only
Task status read.
gravityzone_kill_process_network
Pro · Destructive
Terminates a running process on a live endpoint.
gravityzone_move_company_or_company_folder
Pro · Destructive
Relocates a customer/folder in the partner hierarchy.
gravityzone_move_custom_group
Pro · Destructive
Moves a group - changes inherited policy.
gravityzone_move_endpoints
Pro · Destructive
Moves endpoints between groups - changes inherited policy.
gravityzone_move_endpoints_between_companies
Pro · Destructive
Cross-tenant endpoint move - licensing/billing impact.
gravityzone_remove_integrators
Pro · Destructive
Revokes integrator access.
gravityzone_run_gather_logs_task
Pro · Destructive
Dispatches log collection to a live endpoint.
gravityzone_run_live_search_query
Pro · Destructive
Read in intent, but dispatches a live query to endpoints (Live Search / AWS-backed).
gravityzone_set_endpoint_label
Pro · Write
Partial write of one label field.

Packages

ToolWhat it does
gravityzone_create_package
Pro · Write
Additive: creates an installer package definition.
gravityzone_delete_package
Pro · Destructive
Deletes an installer package.
gravityzone_get_installation_links
Free · Read-only
Returns installer download links for a package.
gravityzone_get_package_details
Free · Read-only
One package definition.
gravityzone_get_packages_list
Free · Read-only
Paged package list.
gravityzone_update_package
Pro · Destructive
Wholesale replace of an installer package definition.

Patch Management

ToolWhat it does
gravityzone_get_installed_patches
Free · Read-only
Paged installed-patch inventory.
gravityzone_get_missing_patches
Free · Read-only
Paged missing-patch inventory - high MSP value.

PHASR

ToolWhat it does
gravityzone_apply_recommendations
Pro · Destructive
Applies PHASR hardening recommendations across endpoints.
gravityzone_edit_monitored_rules_access
Pro · Destructive
Changes PHASR access enforcement on identities/resources.
gravityzone_get_all_company_identities
Free · Read-only
PHASR identities list.
gravityzone_get_all_company_resources
Free · Read-only
PHASR resources list.
gravityzone_get_monitored_rule_data
Free · Read-only
PHASR rule data read.
gravityzone_get_monitored_rules
Free · Read-only
PHASR monitored rules list.
gravityzone_get_phasr_recommendations
Free · Read-only
PHASR recommendation list.
gravityzone_get_recommendation_profiles
Free · Read-only
PHASR recommendation profiles.
gravityzone_take_request_access_action
Pro · Destructive
Approves/denies a PHASR access request - privilege grant.

Policies

ToolWhat it does
gravityzone_get_policies_list
Free · Read-only
Paged policy list.
gravityzone_get_policy_details
Free · Read-only
Full policy document.
gravityzone_set_policy_modules_state
Pro · Destructive
Turns protection modules on/off inside a policy.

Event Push Service

ToolWhat it does
gravityzone_get_push_event_settings
Free · Read-only
Reads the event-push config.
gravityzone_get_push_event_stats
Free · Read-only
Push delivery stats and errors.
gravityzone_reset_push_event_stats
Pro · Destructive
Purges push statistics/error counters.
gravityzone_send_test_push_event
Pro · Destructive
Emits an event to the customer-configured external endpoint.
gravityzone_set_push_event_settings
Pro · Destructive
Wholesale replace of the event-push config; a bad write silences the SIEM feed.

Quarantine

ToolWhat it does
gravityzone_create_add_file_to_quarantine_task
Pro · Destructive
Removes a file from a live endpoint into quarantine.
gravityzone_create_empty_quarantine_task
Pro · Destructive
Purges the whole quarantine.
gravityzone_create_release_quarantine_exchange_item_task
Pro · Destructive
Releases a quarantined email to the recipient mailbox - reaches a human.
gravityzone_create_remove_quarantine_item_task
Pro · Destructive
Permanently deletes quarantined items.
gravityzone_create_restore_quarantine_exchange_item_task
Pro · Destructive
Restores a quarantined Exchange item.
gravityzone_create_restore_quarantine_item_task
Pro · Destructive
Restores a quarantined file back to the endpoint - reintroduces flagged content.
gravityzone_get_quarantine_items_list
Free · Read-only
Paged quarantine inventory.

Reports

ToolWhat it does
gravityzone_create_report
Pro · Destructive
Creates an instant or scheduled report; emailList delivers it to human recipients.
gravityzone_delete_report
Pro · Destructive
Deletes a report and its history.
gravityzone_get_download_links
Free · Read-only
Returns report download links.
gravityzone_get_reports_list
Free · Read-only
Paged scheduled-report list.