REST API, Prometheus metrics and SIEM webhooks
MxGuard is fully scriptable and observable, which matters for MSPs and security teams that want it wired into existing tooling.
REST API. A REST API covers domain management, allow/block rules, verdict lookup and quarantine actions. Access uses API-key authentication with scoped permissions, so you can issue a key that can, say, read verdicts but not delete domains.
Prometheus metrics. A native Prometheus endpoint exports per-domain counters — verdicts broken down by type, ML latency histograms, Claude evaluation call counts and queue-depth metrics — so MxGuard drops straight into an existing Grafana dashboard.
Audit log. A searchable audit log records administrative actions and is exportable as JSON or CSV.
Webhooks for SIEM/SOAR. Optional outbound webhooks can fire per verdict, letting you stream detections into a SIEM or trigger SOAR playbooks in real time.
Between the API, metrics and webhooks, MxGuard can be operated entirely programmatically and monitored alongside the rest of your estate.

0 comments
Sign in with your TDesk account to comment.