Huntress Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Huntress Tools
huntress_ · 92 tools · Free 55 · Pro 37
Huntress managed-detection API; raw JSON passthrough.
All connector tools · Huntress setup guide
Huntress tool groups
- Account — 2 tools
- Agents — 6 tools
- Identities — 2 tools
- Incident Reports — 7 tools
- Escalations — 3 tools
- Platform Actions — 2 tools
- Signals — 2 tools
- Organizations — 5 tools
- Memberships — 5 tools
- Invoices — 2 tools
- External Recon — 2 tools
- Summary Reports — 2 tools
- Unwanted Access Rules — 6 tools
- Managed Accounts (Reseller) — 36 tools
- Reseller Billing — 9 tools
- SIEM — 1 tool
Account
huntress_get_account details
huntress_get_account details
[Huntress] Get the Huntress account associated with the current API credentials — name, subdomain, status, and high-level account metadata. Use this to confirm which account the key is operating against before drilling into agents, organizations, or billing with huntress_list_organizations / huntress_list_invoices.
huntress_get_actor details
huntress_get_actor details
[Huntress] Get the actor for the current API credentials — the set of entities (account, organizations, permissions) the key is authorized to act as. Use this to understand the effective scope and access of the credentials before making scoped calls.
Agents
huntress_get_agent details
huntress_get_agent details
[Huntress] Get a single Huntress agent by its numeric ID — full host detail, OS, platform, version, last-seen, and organization. Discover agent IDs via huntress_list_agents.
huntress_isolate_agent details
huntress_isolate_agent details
[Huntress] Network-isolate a Huntress agent's endpoint, cutting it off from the network except for Huntress communication. Optionally provide a reason and request strict isolation. Discover agent IDs via huntress_list_agents; reverse with huntress_release_agent_isolation.
huntress_list_agents details
huntress_list_agents details
[Huntress] List Huntress agents (deployed endpoint sensors) across the account. Returns a paginated list with host, OS, platform, version, and organization. Filter by organization, platform, hostname, OS, or version. Use huntress_get_agent for full detail on one agent, and huntress_list_organizations to discover organizationId values.
huntress_release_agent_isolation details
huntress_release_agent_isolation details
[Huntress] Release network isolation on a Huntress agent's endpoint, restoring normal network connectivity. Reverses huntress_isolate_agent. Discover agent IDs via huntress_list_agents.
huntress_uninstall_agent details
huntress_uninstall_agent details
[Huntress] Uninstall the Huntress agent from an endpoint. This is an asynchronous, IRREVERSIBLE action — the sensor is removed and monitoring stops; reinstalling requires a fresh deployment. Discover agent IDs via huntress_list_agents.
huntress_update_agent details
huntress_update_agent details
[Huntress] Update a Huntress agent — set its tags and/or tamper-protection-configured flag. Tags are supplied as a comma-separated list and replace the agent's existing tags. Discover agent IDs via huntress_list_agents.
Identities
huntress_get_identity details
huntress_get_identity details
[Huntress] Get a single ITDR identity by its numeric ID — full user detail, risk level, MFA status, and tenant. Discover identity IDs via huntress_list_identities.
huntress_list_identities details
huntress_list_identities details
[Huntress] List ITDR identities (Microsoft 365 / Google Workspace users) monitored by Huntress. Returns a paginated list with risk level, MFA status, billable/enabled/external flags, and tenant. Filter by organization, tenant type, billable, enabled, external, risk level, or MFA status. Use huntress_get_identity for full detail on one identity.
Incident Reports
huntress_approve_remediations details
huntress_approve_remediations details
[Huntress] Approve the remediations recommended for a Huntress incident report, authorizing Huntress to apply them. This is a bodyless action — the Huntress API approves all pending remediations for the report and takes no parameters beyond the report ID. Discover incident report IDs via huntress_list_incident_reports and remediations via huntress_list_remediations.
huntress_get_incident_report details
huntress_get_incident_report details
[Huntress] Get a single incident report by its numeric ID — full threat detail, indicators, severity, status, and SOC narrative. Discover report IDs via huntress_list_incident_reports; see remediation steps with huntress_list_remediations.
huntress_get_remediation details
huntress_get_remediation details
[Huntress] Get a single remediation by its ID, scoped to its parent incident report — full remediation detail, type, and status. Discover remediation IDs via huntress_list_remediations.
huntress_list_incident_reports details
huntress_list_incident_reports details
[Huntress] List incident reports — confirmed threats triaged by the Huntress SOC. Returns a paginated list with indicator type, status, severity, platform, and the affected organization/agent. Filter by indicator type, status, severity, platform, organization, or agent. Use huntress_get_incident_report for full detail, and huntress_list_remediations to see the remediation steps for a report.
huntress_list_remediations details
huntress_list_remediations details
[Huntress] List the remediations attached to a specific incident report — the recommended or applied remediation steps (assisted, manual, or containment). Filter by remediation type or status. Paginated: when more pages exist, read next_page_token from the response's pagination object and pass it as pageToken. Use huntress_get_remediation for one remediation's full detail; discover incident report IDs via huntress_list_incident_reports.
huntress_reject_remediations details
huntress_reject_remediations details
[Huntress] Reject the remediations recommended for a Huntress incident report, declining to apply them. The Huntress API REQUIRES comment and useful. Discover incident report IDs via huntress_list_incident_reports and remediations via huntress_list_remediations.
huntress_resolve_incident_report details
huntress_resolve_incident_report details
[Huntress] Resolve a Huntress incident report. This is a bodyless action — the Huntress API takes no parameters beyond the report ID. Discover incident report IDs via huntress_list_incident_reports.
Escalations
huntress_get_escalation details
huntress_get_escalation details
[Huntress] Get a single escalation by its numeric ID — full detail, severity, status, due date, and the related organization. Discover escalation IDs via huntress_list_escalations.
huntress_list_escalations details
huntress_list_escalations details
[Huntress] List escalations — items the Huntress SOC has escalated to the partner for action. Returns a paginated list with status, severity, subtype, due date, and organization. Filter by status, severity, subtype, or organization. Use huntress_get_escalation for full detail on one escalation.
huntress_resolve_escalation details
huntress_resolve_escalation details
[Huntress] Resolve a Huntress escalation by recording a determination (expected vs unauthorized) and the scope it applies to (account, organization, or identity). Discover escalation IDs via huntress_list_escalations.
Platform Actions
huntress_get_platform_action details
huntress_get_platform_action details
[Huntress] Get a single platform action by its numeric ID — full detail, severity, status, and the related organization. Discover platform action IDs via huntress_list_platform_actions.
huntress_list_platform_actions details
huntress_list_platform_actions details
[Huntress] List platform actions — actions requested or taken on the Huntress platform. Returns a paginated list with status, severity, subtype, and organization. Filter by status, severity, subtype, or organization. Use huntress_get_platform_action for full detail on one action.
Signals
huntress_get_signal details
huntress_get_signal details
[Huntress] Get a single security signal by its numeric ID — full detail, type, status, related entity, and investigation timeline. Discover signal IDs via huntress_list_signals.
huntress_list_signals details
huntress_list_signals details
[Huntress] List security signals — investigated detections tied to entities (users, mailboxes, agents, identities). Returns a paginated list with status, type, the related entity, and investigation timestamps. Filter by investigated-at window, entity, organization, type, or status. Use huntress_get_signal for full detail on one signal.
Organizations
huntress_create_organization details
huntress_create_organization details
[Huntress] Create a new organization within the Huntress account. Both name and key are REQUIRED by the Huntress API. List existing organizations via huntress_list_organizations.
huntress_delete_organization details
huntress_delete_organization details
[Huntress] Delete a Huntress organization. This is IRREVERSIBLE — the organization and its associations are removed. Discover organization IDs via huntress_list_organizations.
huntress_get_organization details
huntress_get_organization details
[Huntress] Get a single organization by its numeric ID — full detail, name, key, and metadata. Discover organization IDs via huntress_list_organizations.
huntress_list_organizations details
huntress_list_organizations details
[Huntress] List the customer organizations under the account. Returns a paginated list with name, key, and metadata. The organization `id` returned here is the `organizationId` filter used across huntress_list_agents, huntress_list_identities, huntress_list_incident_reports, huntress_list_signals, and more. Filter by name or key; use huntress_get_organization for full detail.
huntress_update_organization details
huntress_update_organization details
[Huntress] Update a Huntress organization — rename it. Discover organization IDs via huntress_list_organizations.
Memberships
huntress_create_membership details
huntress_create_membership details
[Huntress] Invite a user to the Huntress account by creating a membership. The Huntress API REQUIRES email, first name, last name, and permissions. Optionally scope the membership to an organization. List existing memberships via huntress_list_memberships.
huntress_delete_membership details
huntress_delete_membership details
[Huntress] Delete a Huntress membership, revoking the member's access to the account. This is IRREVERSIBLE — it removes the membership but does NOT delete the underlying user. Discover membership IDs via huntress_list_memberships.
huntress_get_membership details
huntress_get_membership details
[Huntress] Get a single membership by its numeric ID — full detail, the user, organization, and permission role. Discover membership IDs via huntress_list_memberships.
huntress_list_memberships details
huntress_list_memberships details
[Huntress] List memberships — the user-to-organization access grants and their permission roles. Returns a paginated list with user, organization, and permissions. Filter by organization, user, or permission role. Use huntress_get_membership for full detail on one membership.
huntress_update_membership details
huntress_update_membership details
[Huntress] Update a Huntress membership — change the member's permissions. Discover membership IDs via huntress_list_memberships.
Invoices
huntress_get_invoice details
huntress_get_invoice details
[Huntress] Get a single invoice by its numeric ID — full billing detail, status, line items, and amounts. Discover invoice IDs via huntress_list_invoices.
huntress_list_invoices details
huntress_list_invoices details
[Huntress] List billing invoices for the account. Returns a paginated list with status, amounts, and usage flags. Filter by status or whether the invoice has usage. Use huntress_get_invoice for full detail on one invoice.
External Recon
huntress_get_external_port details
huntress_get_external_port details
[Huntress] Get a single External Recon port finding by its numeric ID — full detail, protocol, port, service, and risk classification. Discover finding IDs via huntress_list_external_ports.
huntress_list_external_ports details
huntress_list_external_ports details
[Huntress] List externally-discovered open ports and exposed services found by Huntress External Recon. Returns a paginated list with protocol, port, service, and risky-service flag. Filter by organization, protocol, port, risky-service, or service name. Use huntress_get_external_port for full detail on one finding.
Summary Reports
huntress_get_report details
huntress_get_report details
[Huntress] Get a single summary report by its numeric ID — full report detail, type, period, and the related organization. Discover report IDs via huntress_list_reports.
huntress_list_reports details
huntress_list_reports details
[Huntress] List summary reports — periodic monthly/quarterly/yearly account and organization summaries. Returns a paginated list with report type, period, and organization. Filter by period window, organization, or report type. Use huntress_get_report for full detail on one report.
Unwanted Access Rules
huntress_create_unwanted_access_rule details
huntress_create_unwanted_access_rule details
[Huntress] Create an unwanted-access rule that classifies identity sign-ins as expected or unauthorized. The Huntress API REQUIRES type (expected|unauthorized). Set an optional category (country|vpn) and its match (countryCode or vpn), the matching logic, an active window (startsAt/expiresAt), and notes. List existing rules via huntress_list_unwanted_access_rules.
huntress_delete_unwanted_access_rule details
huntress_delete_unwanted_access_rule details
[Huntress] Delete an unwanted-access rule. This is IRREVERSIBLE — the rule is removed and no longer classifies sign-ins. Discover rule IDs via huntress_list_unwanted_access_rules.
huntress_get_unwanted_access_rule details
huntress_get_unwanted_access_rule details
[Huntress] Get a single unwanted access rule by its numeric ID — full detail, type, status, scope, category, and matching logic. Discover rule IDs via huntress_list_unwanted_access_rules.
huntress_list_known_vpns details
huntress_list_known_vpns details
[Huntress] List the reference catalog of known VPN providers recognized by Huntress ITDR. Returns the full list (no pagination, no parameters). Use these VPN identifiers when interpreting or building vpn-category unwanted access rules (see huntress_list_unwanted_access_rules).
huntress_list_unwanted_access_rules details
huntress_list_unwanted_access_rules details
[Huntress] List unwanted access rules — ITDR location/VPN access policies that flag expected vs. unauthorized sign-in sources. Returns a paginated list with type, status, scope, category, and matching logic. Filter by organization, identity, type, status, scope, category, country code, VPN, or logic. Use huntress_get_unwanted_access_rule for full detail, and huntress_list_known_vpns for the VPN reference list.
huntress_update_unwanted_access_rule details
huntress_update_unwanted_access_rule details
[Huntress] Update an unwanted-access rule. Only the active window (startsAt/expiresAt) and notes can be changed. Discover rule IDs via huntress_list_unwanted_access_rules.
Managed Accounts (Reseller)
huntress_approve_managed_account_remediations details
huntress_approve_managed_account_remediations details
[Huntress] Approve remediations for an incident report within a reseller-managed account selected by accountId. This is a bodyless action — the Huntress API approves all pending remediations for the report and takes no parameters beyond the path identifiers. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_create_managed_account details
huntress_create_managed_account details
[Huntress] Create a new reseller-managed account. The Huntress API REQUIRES name, subdomain, phone number, and an initial admin user (first name, last name, email). Requires reseller-level API credentials.
huntress_create_managed_account_membership details
huntress_create_managed_account_membership details
[Huntress] Invite a user (create a membership) within a reseller-managed account selected by accountId. The Huntress API REQUIRES email, first name, last name, and permissions. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_create_managed_account_organization details
huntress_create_managed_account_organization details
[Huntress] Create an organization within a reseller-managed account selected by accountId. The Huntress API REQUIRES name and key. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_delete_managed_account_membership details
huntress_delete_managed_account_membership details
[Huntress] Delete a user membership within a reseller-managed account selected by accountId. This removes the membership only; it does not delete the user. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_delete_managed_account_organization details
huntress_delete_managed_account_organization details
[Huntress] Delete an organization within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_disable_managed_account details
huntress_disable_managed_account details
[Huntress] PERMANENTLY disable a reseller-managed account. This is irreversible: it disables the account and uninstalls ALL of its agents after 10 days. Requires reseller-level API credentials.
huntress_get_managed_account details
huntress_get_managed_account details
[Huntress] Get a single reseller-managed account by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_get_managed_account_agent details
huntress_get_managed_account_agent details
[Huntress] Get a single agent within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_get_managed_account_external_port details
huntress_get_managed_account_external_port details
[Huntress] Get a single external-recon open port within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_get_managed_account_incident_report details
huntress_get_managed_account_incident_report details
[Huntress] Get a single incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_get_managed_account_invoice details
huntress_get_managed_account_invoice details
[Huntress] Get a single invoice for a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_get_managed_account_membership details
huntress_get_managed_account_membership details
[Huntress] Get a single membership within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_get_managed_account_organization details
huntress_get_managed_account_organization details
[Huntress] Get a single organization within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_get_managed_account_remediation details
huntress_get_managed_account_remediation details
[Huntress] Get a single remediation for an incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_get_managed_account_report details
huntress_get_managed_account_report details
[Huntress] Get a single summary report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_get_managed_account_signal details
huntress_get_managed_account_signal details
[Huntress] Get a single investigation signal within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.
huntress_isolate_managed_account_agent details
huntress_isolate_managed_account_agent details
[Huntress] Network-isolate an agent within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_list_managed_account_agents details
huntress_list_managed_account_agents details
[Huntress] List deployed agents within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.
huntress_list_managed_account_external_ports details
huntress_list_managed_account_external_ports details
[Huntress] List external-recon open ports discovered within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.
huntress_list_managed_account_incident_reports details
huntress_list_managed_account_incident_reports details
[Huntress] List incident reports within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.
huntress_list_managed_account_invoices details
huntress_list_managed_account_invoices details
[Huntress] List invoices for a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.
huntress_list_managed_account_memberships details
huntress_list_managed_account_memberships details
[Huntress] List user memberships within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.
huntress_list_managed_account_organizations details
huntress_list_managed_account_organizations details
[Huntress] List organizations within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.
huntress_list_managed_account_remediations details
huntress_list_managed_account_remediations details
[Huntress] List remediations for an incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated: when more pages exist, read next_page_token from the response's pagination object and pass it as pageToken.
huntress_list_managed_account_reports details
huntress_list_managed_account_reports details
[Huntress] List summary reports within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.
huntress_list_managed_account_signals details
huntress_list_managed_account_signals details
[Huntress] List investigation signals within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.
huntress_list_managed_accounts details
huntress_list_managed_accounts details
[Huntress] List the reseller-managed accounts available to the current credentials. Use this to discover the accountId required by every other Managed Account tool. Requires reseller-level API credentials. Paginated.
huntress_reject_managed_account_remediations details
huntress_reject_managed_account_remediations details
[Huntress] Reject remediations for an incident report within a reseller-managed account selected by accountId. The Huntress API REQUIRES comment and useful. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_release_managed_account_agent_isolation details
huntress_release_managed_account_agent_isolation details
[Huntress] Release network isolation on an agent within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_resolve_managed_account_incident_report details
huntress_resolve_managed_account_incident_report details
[Huntress] Resolve an incident report within a reseller-managed account selected by accountId. This is a bodyless action — the Huntress API takes no parameters beyond the path identifiers. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_uninstall_managed_account_agent details
huntress_uninstall_managed_account_agent details
[Huntress] Uninstall an agent within a reseller-managed account selected by accountId. This is an asynchronous, irreversible removal of the agent. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_update_managed_account details
huntress_update_managed_account details
[Huntress] Update a reseller-managed account. Requires reseller-level API credentials.
huntress_update_managed_account_agent details
huntress_update_managed_account_agent details
[Huntress] Update an agent within a reseller-managed account selected by accountId (tags, tamper-protection config). Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_update_managed_account_membership details
huntress_update_managed_account_membership details
[Huntress] Update a user membership's permissions within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
huntress_update_managed_account_organization details
huntress_update_managed_account_organization details
[Huntress] Update an organization within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.
Reseller Billing
huntress_create_reseller_subscription details
huntress_create_reseller_subscription details
[Huntress] Create a new reseller subscription. The Huntress API REQUIRES account_id, product, minimum (seat count), and purchase_order. Requires reseller-level API credentials.
huntress_get_reseller_invoice details
huntress_get_reseller_invoice details
huntress_get_reseller_subscription details
huntress_get_reseller_subscription details
huntress_list_reseller_account_usage_line_items details
huntress_list_reseller_account_usage_line_items details
[Huntress] List per-account usage line items for a reseller invoice; these require reseller-level API credentials. Paginated — use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
huntress_list_reseller_invoices details
huntress_list_reseller_invoices details
[Huntress] List reseller invoices; these require reseller-level API credentials. Paginated — use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
huntress_list_reseller_organization_usage_line_items details
huntress_list_reseller_organization_usage_line_items details
[Huntress] List per-organization usage line items for a reseller invoice; these require reseller-level API credentials. Paginated — use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
huntress_list_reseller_subscriptions details
huntress_list_reseller_subscriptions details
[Huntress] List reseller subscriptions; these require reseller-level API credentials. Paginated — use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
huntress_update_reseller_subscription details
huntress_update_reseller_subscription details
[Huntress] Update a reseller subscription. Requires reseller-level API credentials.
huntress_upgrade_reseller_subscription details
huntress_upgrade_reseller_subscription details
[Huntress] Upgrade a reseller subscription (e.g. raise the seat minimum). The Huntress API REQUIRES the new minimum. Requires reseller-level API credentials.
SIEM
huntress_query_siem details
huntress_query_siem details
[Huntress] Query SIEM logs with ES|QL. The `esql` query must begin with "FROM logs". Requires the SIEM product to be enabled on the account (returns 404 if not). Returns {logs:[...], pagination:{next_page_token?}}; pass the returned token as `pageToken` for the next page. Maximum 200 rows per page.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team