Bitdefender GravityZone protects your clients. This module makes sure you can actually
see it doing that, without logging into the Control Center all day. Connect your
GravityZone API key once, and your entire multi-company endpoint fleet appears inside
your CRM: searchable, filterable, and ready to act on.
The whole fleet on one screen.
The dashboard opens with live KPI cards: total endpoints, managed, infected, outdated
agents, and companies. Below it, every endpoint across every client, with hostname,
FQDN, company, OS, IP, machine type (computer, VM, or EC2), and a status badge:
Managed, Unmanaged, Outdated, or Infected. Search by hostname, IP, or company,
filter to a single client, or flip on "Infected only" when it matters most.
Full multi-tenant sync.
The sync engine walks your entire GravityZone network tree recursively: partner
companies, sub-companies, custom groups, and all, so endpoints land in the CRM
tagged with the right client company. It enriches each one with managed-endpoint
detail: infection state, malware detection, policy name, product and engine versions,
signature status, and last-seen time.
Drill into any endpoint.
The detail page pulls live data from the GravityZone API (falling back to the last
synced snapshot if the API is unreachable) across three tabs: Overview (IP, OS,
company, group, policy, last seen, malware status), Modules (every protection module
with a clear on/off state: antimalware, firewall, EDR sensor, encryption, network
attack defense, and more), and Agent (product version, engine version, last update,
outdated and licensed flags).
Act, not just watch.
Launch a Quick, Full, or Memory scan on any endpoint with one click. Scans are
created as real GravityZone tasks through the API, and the CRM keeps its own log
of who launched what, when, on which machine.
Set-and-forget syncing.
Sync on demand with one button, or schedule it: the module generates a tokenized
cron URL you drop into a cPanel cron job at your chosen interval. No login, no
session, just a fresh fleet picture every 15 minutes (or whatever you choose).
Secure by design.
Your API key is stored AES-256-GCM encrypted, sent only as Basic auth to your own
GravityZone access URL (US and EU consoles both supported). A built-in connection
test verifies the key and shows exactly which API scopes are enabled against the
list the module needs, and a diagnostics endpoint helps troubleshoot without
guesswork.
Highlights:
Live fleet dashboard: KPIs, search, company filter, infected-only toggle
Recursive multi-company sync that follows your whole GravityZone network tree
Endpoint detail with Overview, Modules, and Agent tabs
Live API detail with automatic fallback to the last synced snapshot
One-click Quick, Full, and Memory scans with a per-endpoint scan log
Scheduled sync via tokenized cron URL, plus a manual Sync Now button
AES-256-GCM encrypted API key storage and a one-click connection test
API scope checklist so misconfigured keys are obvious immediately
Self-healing schema: installs and upgrades its own tables automatically
In your Blackhawk CRM, open the Marketplace and install Bitdefender GravityZone
(or upload the module ZIP through the Marketplace uploader).
In GravityZone Control Center, go to My Account, then API keys, and generate a
key with the Companies, Network, Packages, Policies, Incidents, and Reports APIs
enabled. Copy the Access URL shown on the same page.
In the CRM, open Bitdefender from the left navigation and go to Settings. Paste
the access URL and API key, then click Test Connection. The scope checklist
turns green for each API the key has enabled.
Click Save Settings, return to the dashboard, and click Sync Now. Your companies
and endpoints populate within moments.
For automatic syncing, copy the tokenized cron URL from Settings and add a cPanel
cron job that fetches it at your chosen interval (15 minutes is a good default).
Click any endpoint to see its detail tabs and launch scans.
Q: Which GravityZone accounts does this work with?
A: Cloud Control Center accounts with API access, including MSP partner accounts.
Both US (cloud.gravityzone) and EU (cloudgz.gravityzone) consoles are supported;
you paste whichever access URL your account shows.
Q: Will it see endpoints across all my client companies?
A: Yes. The sync walks your full network tree recursively, including sub-companies
and custom groups, and tags each endpoint with its company so you can filter
per client.
Q: Can I run scans from the CRM?
A: Yes. Quick, Full, and Memory scans launch as real GravityZone tasks from the
endpoint detail page, and the CRM logs who launched each scan and when.
Q: Is my API key safe?
A: The key is stored AES-256-GCM encrypted in your database and only ever sent as
Basic auth directly to your GravityZone access URL. It is never displayed again
after saving.
Q: What if the GravityZone API is down when I open an endpoint?
A: The detail page falls back to the last synced snapshot automatically and tells
you it is doing so, so you still have data during an outage.
Q: How current is the dashboard?
A: As current as your sync schedule. Use the tokenized cron URL for hands-off
syncing at any interval (15 minutes recommended), and the Sync Now button
whenever you want an immediate refresh.
Q: My key tests OK but sync finds nothing. What should I check?
A: The scope checklist in Settings. Sync needs the Network and Companies APIs
enabled on the key; the checklist shows exactly which scopes your key has,
and the diagnostics endpoint gives a deeper trace if needed.
v1.2.1
Recursive network tree walking via getCustomGroupsList so sub-companies and
custom groups are fully discovered
Endpoint enrichment: infection state, policy, product and engine versions,
signature status, last seen
One-click Quick, Full, and Memory scans with per-endpoint scan history
Endpoint detail tabs: Overview, Modules, Agent, with live API and
synced-snapshot fallback
Dashboard KPIs, company filter, infected-only toggle, and pagination


