Malwarebytes Cloud Endpoint Removal tool

Document created by lwei Employee on Aug 31, 2018Last modified by lwei Employee on May 3, 2019
Version 9Show Document
  • View in full screen mode

What's This?

The Malwarebytes Cloud Endpoint Removal tool is a Windows command-line utility to bulk remove endpoints that have not been active for selected period of time.



The tool is a Windows command-line application that requires .NET Framework 4.5.2 or above.



Download and execute the program. There is no installer or configuration.



This is a user community shared utility. Please send questions, comments, and support request to the author directly. 



  • The tool logs into the Malwarebytes Cloud using the Console credentials.
  • Ability to filter endpoints based on any arbitrary number of days offline. 30 days is the default.
  • By default, the tool will display the endpoints matching the criteria, but will not automatically perform the irreversible removal step.
  • A rotating log file is kept for debugging and tracking purposes.



v1.0.1 (2019-05-03) - Added filter by group ID.

v1.0 (2018-August) - First release.



Troubleshooting information will be added as they become available.



  1. Run the program without parameters to see usage information.

  2. Preview the endpoints affected before actually removing them from the server.

  3. Successful removal execution.