To ensure communication between Nebula and your endpoints, you must allow specific addresses through your firewall or other security software.
This article includes two address lists. Use the list that matches your account.
- Standard external access requirements: For Nebula accounts provisioned in our standard data center. This applies to most of our customers.
- European Data Center external access requirements: For EU-based customers with Nebula accounts provisioned in our European data center. This applies to a limited set of accounts provisioned after August 3, 2026.
If you're unsure which data center your account uses, contact Support before configuring your firewall.
Standard external access requirements
Allow the following addresses through your firewall or other security software. Endpoint Agents use the sites below to reach Nebula services.
| Address | Port number | Purpose | Date Added |
|---|---|---|---|
| https://nebula-asset-discovery-v2-mb-prod.s3.amazonaws.com | 443 | Used to upload asset information to Nebula. | 8/3/2026 |
| https://nebula-isolation-images-mb-prod.s3.amazonaws.com/ | 443 | Used to download custom BMP file for Windows desktop isolation. | 8/3/2026 |
| http://nebula-helix-syslog-mb-prod.s3.us-east-1.amazonaws.com/ | 443 | Used to provide syslog functionality between the endpoint and Nebula. | 6/8/2026 |
| https://nebula-stork-prod-1.s3.us-east-1.amazonaws.com | 443 | Used to download the installation packages. | 6/3/2026 |
| https://detect-remediate.threatdown.com | 443 | Used to provide Endpoint Detection and Response capabilities. | 1/27/2026 |
| http://crl.r2m04.amazontrust.com/r2m04.crl | 80 | Used to validate the SSL certificate for threatdown.com | 10/16/2025 |
| http://crl.r2m03.amazontrust.com/r2m03.crl | 80 | Used to validate the SSL certificate for malwarebytes.com | 10/16/2025 |
| https://detect.threatdown.com | 443 | Used to send portable executables to our servers for threat telemetry. | 10/1/2025 |
| https://hubble.threatdown.com | 443 | Used to validate threats against our servers for better protection and reduce false positives. | 9/16/2025 |
| https://blitz.threatdown.com | 443 | Used to upload files for research and analysis. | 9/16/2025 |
| https://machines.threatdown.com | 443 | Used by the Endpoint Agent to communicate with Nebula. | 4/17/2025 |
| https://api.threatdown.com | 443 | Used to communicate with our Public APIs. | 9/12/2024 |
| https://ars.cloud.threatdown.com | 443 | Used to allow access for Active Response Shell. | 9/12/2024 |
| https://arsws.cloud.threatdown.com | 443 | Used to allow websocket connection for Active Response Shell. | 9/12/2024 |
| https://telemetry.threatdown.com | 443 | Used to communicate telemetry and threat information to our servers. More information on our telemetry can be found on our Privacy Policy. | 9/12/2024 |
| https://cdn.threatdown.com | 443 | Used to deliver updates to products. | 9/12/2024 |
| https://cloud.threatdown.com | 443 | Used to access the Nebula admin console. | 9/9/2024 |
| https://ark.threatdown.com | 443 | Used to deliver updates to products. | 8/29/2024 |
| https://sirius.threatdown.com | 443 | Used to check for updates for both the product version and the protection database. | 8/29/2024 |
| https://*.cloudflare-gateway.com | 443 | Used for the DNS Filtering module. | 2023 |
| https://cosmos-shuriken-samples-mb-prod.s3.amazonaws.com/ | 443 | Used to process samples sent from the endpoint agent. | 2023 |
| https://storage.gra.cloud.ovh.net | 443 | Used to upload suspicious files for sandbox analysis for Endpoint Detection and Response. | 2021 |
| https://socket.cloud.malwarebytes.com | 443 | Used to provide real-time communication between the endpoint agent and Nebula. | 2019 |
| https://downloads.malwarebytes.com | 443 | Used to download packages and unmanaged remediation utilities. | 2019 |
| https://links.malwarebytes.com | 443 | Used to access product documentation through Nebula. | 2019 |
| https://keystone.mwbsys.com | 443 | Used to validate product licensing. | 2019 |
| https://meps.mwbsys.com | 443 | Used to validate the Ransomware Extinction Prevention system in Nebula. | 2019 |
| https://repositories.mwbsys.com | 443 | Used to download the Linux installation packages. | 2019 |
| https://data-cdn.mbamupdates.com | 443 | Used to deliver updates to products. | 2019 |
| https://data-cdn-static.mbamupdates.com | 443 | Used to deliver updates to products. | 2019 |
| https://nebula-diagnostics-mb-prod.s3.amazonaws.com | 443 | Used to provide diagnostic data from the endpoint agent to Nebula. | 2019 |
European Data Center external access requirements
Allow the following addresses instead of the standard list above if your Nebula login URL contains .euc1.
| Address | Port number | Purpose | Date Added |
|---|---|---|---|
| nebula-asset-discovery-v2-mb-euc1-prod.s3.eu-central-1.amazonaws.com | 443 | Used to upload asset information to Nebula. | 8/3/2026 |
| nebula-isolation-images-mb-euc1-prod.s3.eu-central-1.amazonaws.com | 443 | Used to download custom BMP file for Windows desktop isolation. | 8/3/2026 |
| https://nebula-helix-syslog-mb-euc1-prod.s3.eu-central-1.amazonaws.com/ | 443 | Used to provide syslog functionality between the endpoint and Nebula. | 8/3/2026 |
| https://nebula-stork-euc1-prod-1.s3.eu-central-1.amazonaws.com | 443 | Used to download the installation packages. | 8/3/2026 |
| https://detect-remediate.euc1.threatdown.com | 443 | Used to provide Endpoint Detection and Response capabilities. | 8/3/2026 |
| http://crl.r2m04.amazontrust.com/r2m04.crl | 80 | Used to validate the SSL certificate for threatdown.com | 8/3/2026 |
| http://crl.r2m03.amazontrust.com/r2m03.crl | 80 | Used to validate the SSL certificate for malwarebytes.com | 8/3/2026 |
| https://detect.threatdown.com | 443 | Used to send portable executables to our servers for threat telemetry. | 8/3/2026 |
| https://hubble.threatdown.com | 443 | Used to validate threats against our servers for better protection and reduce false positives. | 8/3/2026 |
| https://blitz.threatdown.com | 443 | Used to upload files for research and analysis. | 8/3/2026 |
| https://machines.euc1.threatdown.com | 443 | Used by the Endpoint Agent to communicate with Nebula. | 8/3/2026 |
| https://api.euc1.threatdown.com | 443 | Used to communicate with our Public APIs. | 8/3/2026 |
| https://ars.euc1.cloud.threatdown.com | 443 | Used to allow access for Active Response Shell. | 8/3/2026 |
| https://arsws.euc1.cloud.threatdown.com | 443 | Used to allow websocket connection for Active Response Shell. | 8/3/2026 |
| https://telemetry.threatdown.com | 443 | Used to communicate telemetry and threat information to our servers. More information on our telemetry can be found on our Privacy Policy. | 8/3/2026 |
| https://cdn.threatdown.com | 443 | Used to deliver updates to products. | 8/3/2026 |
| https://cloud.euc1.threatdown.com | 443 | Used to access the Nebula admin console. | 8/3/2026 |
| https://ark.threatdown.com | 443 | Used to deliver updates to products. | 8/3/2026 |
| https://sirius.threatdown.com | 443 | Used to check for updates for both the product version and the protection database. | 8/3/2026 |
| https://*.cloudflare-gateway.com | 443 | Used for the DNS Filtering module. | 8/3/2026 |
| https://cosmos-shuriken-samples-mb-prod.s3.amazonaws.com/ | 443 | Used to process samples sent from the endpoint agent. | 8/3/2026 |
| https://storage.gra.cloud.ovh.net | 443 | Used to upload suspicious files for sandbox analysis for Endpoint Detection and Response. | 8/3/2026 |
| https://socket.euc1.cloud.malwarebytes.com | 443 | Used to provide real-time communication between the endpoint agent and Nebula. | 8/3/2026 |
| https://downloads.malwarebytes.com | 443 | Used to download packages and unmanaged remediation utilities. | 8/3/2026 |
| https://links.malwarebytes.com | 443 | Used to access product documentation through Nebula. | 8/3/2026 |
| https://keystone.mwbsys.com | 443 | Used to validate product licensing. | 8/3/2026 |
| https://meps.mwbsys.com | 443 | Used to validate the Ransomware Extinction Prevention system in Nebula. | 8/3/2026 |
| https://repositories.mwbsys.com | 443 | Used to download the Linux installation packages. | 8/3/2026 |
| https://data-cdn.mbamupdates.com | 443 | Used to deliver updates to products. | 8/3/2026 |
| https://data-cdn-static.mbamupdates.com | 443 | Used to deliver updates to products. | 8/3/2026 |
| https://nebula-diagnostics-mb-euc1-prod.s3.eu-central-1.amazonaws.com | 443 | Used to provide diagnostic data from the endpoint agent to Nebula. | 8/3/2026 |
Notes
- The endpoint agent does not allow packet-inspection, as this interferes with the service protocols.
- Bypass inspection is required to bypass packet-inspection on the endpoint agent.
- Proxy configurations are supported using built-in functions.
- Pass-through proxy configuration is recommended.
- Dynamic proxy configuration is not supported.
- To test the Endpoint Agent connection, see: Use the Endpoint Agent Command-line tool with Nebula.
Deprecated URLs
You can safely remove the following URLs from your network firewalls or allowlists because the Endpoint Agent no longer requires access to them. Removing these URLs will not affect the agent’s functionality or performance.
| Address | Date deprecated |
|---|---|
| https://keystone-akamai.mwbsys.com | 8/3/2026 |
| https://nebula-helix-syslog-mb-prod.s3.amazonaws.com | 6/8/2026 |
| https://sirius.mwbsys.com | 1/27/2026 |
| https://hubble.mb-cosmos.com | 1/27/2026 |
| https://cdn.mwbsys.com | 1/27/2026 |
| https://blitz.mb-cosmos.com | 1/27/2026 |
| https://ark.mwbsys.com | 1/27/2026 |
| https://telemetry.malwarebytes.com | 1/27/2026 |
| https://cloud.malwarebytes.com | 1/27/2026 |
| https://api.malwarebytes.com | 1/27/2026 |
| https://arsws.cloud.malwarebytes.com | 1/27/2026 |
| https://ars.cloud.malwarebytes.com | 1/27/2026 |
| https://detect-remediate.cloud.malwarebytes.com | 1/27/2026 |
File and Printer Sharing
We recommend using Administrator shared folders for network tasks, such as installations. To use them, you must enable File and Printer Sharing on your endpoints.
The location of the File and Printer Sharing options depends on your endpoint's operating system. Consult your operating system guide for additional information.
Exclude Nebula from other applications
We recommend adding specific software exclusions if you use additional security software with Nebula. For more information, see Exclusions for using Nebula with other security applications.