Cybereason

Download 0
Last updated Jun 15, 2026

cybereason-malops-legacy

Get a list of MalOps using the legacy API from the Cybereason server.

cybereason-malops-legacy [profile=VALUE] [duration=VALUE] [from=VALUE] [to=VALUE]
profile=VALUE
Optional. Cybereason connect profile identifier
duration=VALUE
Optional. Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=VALUE
Optional. Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=VALUE
Optional. End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.

Output Fields

FieldTypeNameDescription
profileStringConnect profileCybereason connect profile identifier
malop_guidStringMalOp GUIDUnique identifier of the MalOp
statusStringStatusMalOp status (Active, Remediated, Closed, Excluded)
display_nameStringDisplay nameDisplay name of the root cause element
createdDateCreation timeMalOp creation time
updatedDateLast update timeMalOp last update time
decision_statusesStringDecision statusesList of decision statuses
priorityStringPriorityMalOp priority level
riskStringRiskSeverity level of the MalOp
detection_enginesStringDetection enginesList of detection engines
signaturesStringSignaturesList of detection signatures
signatureStringSignaturePrimary detection signature
activity_typeStringActivity typeType of detected activity
malop_typeStringMalOp typeList of IOCs (Indicators of Compromise)
root_cause_hashStringRoot cause hashHash values of root cause elements
root_cause_typeStringRoot cause typeType of root cause element
affected_machinesStringAffected machinesList of affected machines
affected_usersStringAffected usersList of affected users
labelsStringLabelsList of labels assigned to MalOp
close_adminStringCloser nameName of the administrator who closed the MalOp
group_idStringGroup IDList of group identifiers
is_escalatedBooleanEscalatedWhether the MalOp is escalated
is_edrBooleanIs EDRWhether the MalOp is from EDR
icon_base64StringIcon Base64Base64 encoded icon image