From alert to forensic insight, automatically, with the Magnet Nexus API
Key takeaways
- The Magnet Nexus API enables automated forensic collections based on SOC alerts and predefined triggers, helping teams preserve volatile data before it disappears.
- By automating collections, case creation, and other repetitive tasks, DFIR teams can spend less time managing workflows and more time analyzing evidence.
- The Nexus API connects Nexus with SIEM, SOAR, EDR/XDR, ticketing, messaging, and other tools, creating a unified workflow from alert to forensic insight.
Here’s a scenario that may be familiar to many SOCs:
An alert escalates at 11:00PM on Friday. There is lateral movement on a finance workstation and it’s enough signal that your SOC tier 1 analyst flags it, but not quite enough to page the DFIR team.
The on-call analyst does what the runbook says: documents it, escalates the alert, moves on.
Now it’s Monday morning and the DFIR team lead sees the alert. By then the machine has been rebooted, so memory is gone and some of the logs have rolled over.
The investigation is still possible, it’s just missing key evidence, takes longer, and now has a less certain answer waiting at the end because the forensic collection didn’t take place automatically on Friday evening.
To call in the DFIR analyst or not: that is the question
Forensic collection often requires someone with the proper tooling, access, and training. That’s usually a limited team of people (or one person!), and on a Friday evening they’re already logged off for the weekend.
So, when an alert comes in, the on-call SOC analyst has two options: wake someone up (which teams rightly reserve for confirmed incidents) or wait (which is usually what happens).
Neither is a lapse in judgment but thanks to a new API integration with Magnet Nexus, everyone can rest easier.
Automatically move from detection to forensic collection and insight
Integrating tooling and creating triggers for data collection via API removes dependency. Collection doesn’t wait for the DFIR analyst to execute, it automatically happens based on escalated alerts and triggers.
When the alert escalates, the playbook calls Magnet Nexus and a targeted collection runs against the endpoint. Volatile artifacts are captured while they still exist, in addition to other artifact categories, collecting critical data before it’s gone and reducing overall MTTR.
Monday morning, the DFIR lead opens a case in Nexus that already has the data collected, processed, and ready for analysis at the moment it mattered, not three (or more) days later.
Run it end to end, alert through collection through export, and you have one unified workflow instead of a chain of handoffs. It runs the same way every time, which means the same team covers more investigations and your MTTR isn’t extended waiting for someone to be available.
Automated collection doesn’t just preserve critical evidence — it shortens the entire investigative workflow. Instead of analysts spending valuable time initiating collections, they can begin analysis sooner. The result is less time spent on administrative tasks, faster case resolution, and lower overall investigation times.
Enhance your DFIR workflow by integrating Magnet Nexus
By integrating Nexus via API into your existing workflows, you can:
- Standardize investigative workflows.
- Automate repetitive tasks, such as creating cases (in addition to collections) and exporting data out of Nexus (coming soon)
- Scale your investigations by running actions across endpoints and operating systems.
- Integrate with tools and platforms, such as Magnet Automate, SIEM tools, SOAR platforms, EDR/ XDR platforms, alerting tools, corporate messaging and ticketing solutions, and internal scripts

How the Magnet Nexus API works
The Nexus API follows a REST-based design using a standard request-and-response model. Each operation is grouped by resource type (cases, endpoints, and collections) and uses standard HTTP methods, for example, GET (retrieve data) and POST (create a resource).
-
Request
- Your script or application sends an HTTP request to the Nexus API. This script can be triggered by an event from another application, such as an alerting tool.
-
Authenticate
- To verify your identity, the Nexus API must authenticate each request with a JSON Web Token (JWT), which you obtain from an API token.
-
Process
- After validating the request, the Nexus API performs the specified action.
-
Return a response
- After performing the action, the Magnet Nexus API returns a response in JSON format. This allows you to confirm the action was performed and troubleshoot any errors in the request.
More recent updates to Magnet Nexus
Additional developments to help you easily deploy and integrate Nexus with your existing tech stack include:
- Traffic allowlisting improvements – Static IP addresses can now be used to provide more flexibility in tools that do not support DNS-based traffic allowlisting
- Enhanced agent auto-updating controls – Organizations can now meet their change control and risk requirements automatically
- Additional API calls – Including automating the export of audit logs and a comprehensive list of all endpoints with Nexus collection agents
Request a free trial of Magnet Nexus
The Nexus API is available now through an Early Access program for Nexus customers and free trial users, so we can validate real workflows. Early Access is included in all tiers of Nexus, request access through the Nexus “My Organization” administration view or through your customer success or account manager.
If you want to learn more and experience Nexus for yourself, talk to your Magnet Forensics sales representative or request a demo or free trial here.