Skip to main content
Tools Reference

Huntress Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Huntress Tools

huntress_ · 92 tools · Free 55 · Pro 37 Huntress managed-detection API; raw JSON passthrough.

All connector tools · Huntress setup guide

Huntress tool groups

Account

ToolPlanAccessSummary
huntress_get_accountFreeRead-onlyGet the Huntress account associated with the current API credentials — name, subdomain, status, and high-level account metadata.
huntress_get_actorFreeRead-onlyGet the actor for the current API credentials — the set of entities (account, organizations, permissions) the key is authorized to act as.

[Huntress] Get the Huntress account associated with the current API credentials — name, subdomain, status, and high-level account metadata. Use this to confirm which account the key is operating against before drilling into agents, organizations, or billing with huntress_list_organizations / huntress_list_invoices.

[Huntress] Get the actor for the current API credentials — the set of entities (account, organizations, permissions) the key is authorized to act as. Use this to understand the effective scope and access of the credentials before making scoped calls.

Agents

ToolPlanAccessSummary
huntress_get_agentFreeRead-onlyGet a single Huntress agent by its numeric ID — full host detail, OS, platform, version, last-seen, and organization.
huntress_isolate_agentProDestructiveNetwork-isolate a Huntress agent's endpoint, cutting it off from the network except for Huntress communication.
huntress_list_agentsFreeRead-onlyList Huntress agents (deployed endpoint sensors) across the account.
huntress_release_agent_isolationProDestructiveRelease network isolation on a Huntress agent's endpoint, restoring normal network connectivity.
huntress_uninstall_agentProDestructiveUninstall the Huntress agent from an endpoint.
huntress_update_agentProWriteUpdate a Huntress agent — set its tags and/or tamper-protection-configured flag.

[Huntress] Get a single Huntress agent by its numeric ID — full host detail, OS, platform, version, last-seen, and organization. Discover agent IDs via huntress_list_agents.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric agent ID (from huntress_list_agents).

[Huntress] Network-isolate a Huntress agent's endpoint, cutting it off from the network except for Huntress communication. Optionally provide a reason and request strict isolation. Discover agent IDs via huntress_list_agents; reverse with huntress_release_agent_isolation.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric agent ID to isolate (from huntress_list_agents).
reasonstringnonullOptional human-readable reason for the isolation.
strictIsolationbooleannonullWhen true, request strict isolation (tighter lockdown).

[Huntress] List Huntress agents (deployed endpoint sensors) across the account. Returns a paginated list with host, OS, platform, version, and organization. Filter by organization, platform, hostname, OS, or version. Use huntress_get_agent for full detail on one agent, and huntress_list_organizations to discover organizationId values.

ParamTypeRequiredDefaultDescription
hostnamestringnonullFilter by hostname (exact match).
limitintegerno50Max results per page (default 50, capped at 500 by the API).
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
osstringnonullFilter by operating system string.
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
platformstringnonullFilter by platform: windows|darwin|linux.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|created_at|updated_at. Omit for default ordering.
versionstringnonullFilter by agent version string.

[Huntress] Release network isolation on a Huntress agent's endpoint, restoring normal network connectivity. Reverses huntress_isolate_agent. Discover agent IDs via huntress_list_agents.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric agent ID to release from isolation (from huntress_list_agents).

[Huntress] Uninstall the Huntress agent from an endpoint. This is an asynchronous, IRREVERSIBLE action — the sensor is removed and monitoring stops; reinstalling requires a fresh deployment. Discover agent IDs via huntress_list_agents.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric agent ID to uninstall (from huntress_list_agents).

[Huntress] Update a Huntress agent — set its tags and/or tamper-protection-configured flag. Tags are supplied as a comma-separated list and replace the agent's existing tags. Discover agent IDs via huntress_list_agents.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric agent ID to update (from huntress_list_agents).
tagsstringnonullComma-separated list of tags to set on the agent (replaces existing tags).
tamperProtectionConfiguredbooleannonullWhen true, mark tamper protection as configured for this agent.

Identities

ToolPlanAccessSummary
huntress_get_identityFreeRead-onlyGet a single ITDR identity by its numeric ID — full user detail, risk level, MFA status, and tenant.
huntress_list_identitiesFreeRead-onlyList ITDR identities (Microsoft 365 / Google Workspace users) monitored by Huntress.

[Huntress] Get a single ITDR identity by its numeric ID — full user detail, risk level, MFA status, and tenant. Discover identity IDs via huntress_list_identities.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric identity ID (from huntress_list_identities).

[Huntress] List ITDR identities (Microsoft 365 / Google Workspace users) monitored by Huntress. Returns a paginated list with risk level, MFA status, billable/enabled/external flags, and tenant. Filter by organization, tenant type, billable, enabled, external, risk level, or MFA status. Use huntress_get_identity for full detail on one identity.

ParamTypeRequiredDefaultDescription
billablebooleannonullFilter by billable status (true|false).
enabledbooleannonullFilter by enabled status (true|false).
externalbooleannonullFilter by external status (true|false).
limitintegerno50Max results per page (default 50, capped at 500 by the API).
mfaEnabledbooleannonullFilter by MFA-enabled status (true|false).
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
riskLevelstringnonullFilter by risk level: none|low|medium|high.
tenantTypestringnonullFilter by tenant type: microsoft_365|google_workspace.

Incident Reports

ToolPlanAccessSummary
huntress_approve_remediationsProDestructiveApprove the remediations recommended for a Huntress incident report, authorizing Huntress to apply them.
huntress_get_incident_reportFreeRead-onlyGet a single incident report by its numeric ID — full threat detail, indicators, severity, status, and SOC narrative.
huntress_get_remediationFreeRead-onlyGet a single remediation by its ID, scoped to its parent incident report — full remediation detail, type, and status.
huntress_list_incident_reportsFreeRead-onlyList incident reports — confirmed threats triaged by the Huntress SOC.
huntress_list_remediationsFreeRead-onlyList the remediations attached to a specific incident report — the recommended or applied remediation steps (assisted, manual, or containment).
huntress_reject_remediationsProDestructiveReject the remediations recommended for a Huntress incident report, declining to apply them.
huntress_resolve_incident_reportProDestructiveResolve a Huntress incident report.

[Huntress] Approve the remediations recommended for a Huntress incident report, authorizing Huntress to apply them. This is a bodyless action — the Huntress API approves all pending remediations for the report and takes no parameters beyond the report ID. Discover incident report IDs via huntress_list_incident_reports and remediations via huntress_list_remediations.

ParamTypeRequiredDefaultDescription
incidentReportIdintegeryesNumeric incident report ID whose remediations to approve (from huntress_list_incident_reports).

[Huntress] Get a single incident report by its numeric ID — full threat detail, indicators, severity, status, and SOC narrative. Discover report IDs via huntress_list_incident_reports; see remediation steps with huntress_list_remediations.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric incident report ID (from huntress_list_incident_reports).

[Huntress] Get a single remediation by its ID, scoped to its parent incident report — full remediation detail, type, and status. Discover remediation IDs via huntress_list_remediations.

ParamTypeRequiredDefaultDescription
incidentReportIdintegeryesNumeric incident report ID the remediation belongs to (from huntress_list_incident_reports).
remediationIdintegeryesNumeric remediation ID (from huntress_list_remediations).

[Huntress] List incident reports — confirmed threats triaged by the Huntress SOC. Returns a paginated list with indicator type, status, severity, platform, and the affected organization/agent. Filter by indicator type, status, severity, platform, organization, or agent. Use huntress_get_incident_report for full detail, and huntress_list_remediations to see the remediation steps for a report.

ParamTypeRequiredDefaultDescription
agentIdintegernonullFilter to a single agent ID (from huntress_list_agents).
indicatorTypestringnonullFilter by indicator type: footholds|monitored_files|ransomware_canaries|antivirus_detections|process_detections|managed_identity|mde_detections|siem_detections|favicon_detections|behavioral_detections|email_security_detections|app_control|ai_misuse.
limitintegerno50Max results per page (default 50, capped at 500 by the API).
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
platformstringnonullFilter by platform: windows|darwin|microsoft_365|google|linux|email_security|other.
severitystringnonullFilter by severity: low|high|critical.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|created_at|updated_at. Omit for default ordering.
statusstringnonullFilter by status: sent|closed|dismissed|auto_remediating|deleting|partner_dismissed.

[Huntress] List the remediations attached to a specific incident report — the recommended or applied remediation steps (assisted, manual, or containment). Filter by remediation type or status. Paginated: when more pages exist, read next_page_token from the response's pagination object and pass it as pageToken. Use huntress_get_remediation for one remediation's full detail; discover incident report IDs via huntress_list_incident_reports.

ParamTypeRequiredDefaultDescription
incidentReportIdintegeryesNumeric incident report ID the remediations belong to (from huntress_list_incident_reports).
limitintegerno50Max results per page (default 50, capped at 500 by the API).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|created_at|updated_at. Omit for default ordering.
statusesstringnonullFilter by comma-separated statuses: unapproved|approved|completed|failed|cancelled.
typesstringnonullFilter by comma-separated remediation types: assisted|manual|containment.

[Huntress] Reject the remediations recommended for a Huntress incident report, declining to apply them. The Huntress API REQUIRES comment and useful. Discover incident report IDs via huntress_list_incident_reports and remediations via huntress_list_remediations.

ParamTypeRequiredDefaultDescription
commentstringyesWhy the remediations were rejected. Required. Helps the Huntress SOC fix the plan and re-issue the incident report.
emailstringnonullEmail for the Huntress SOC to contact. Falls back to the API key's user if omitted.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request after the typed fields.
incidentReportIdintegeryesNumeric incident report ID whose remediations to reject (from huntress_list_incident_reports).
namestringnonullName of the user rejecting. Falls back to the API key's user if omitted.
phoneNumberstringnonullPhone number for the Huntress SOC to contact. Falls back to the API key's user if omitted.
usefulbooleanyesWhether the remediation plan was useful. Required.

[Huntress] Resolve a Huntress incident report. This is a bodyless action — the Huntress API takes no parameters beyond the report ID. Discover incident report IDs via huntress_list_incident_reports.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric incident report ID to resolve (from huntress_list_incident_reports).

Escalations

ToolPlanAccessSummary
huntress_get_escalationFreeRead-onlyGet a single escalation by its numeric ID — full detail, severity, status, due date, and the related organization.
huntress_list_escalationsFreeRead-onlyList escalations — items the Huntress SOC has escalated to the partner for action.
huntress_resolve_escalationProDestructiveResolve a Huntress escalation by recording a determination (expected vs unauthorized) and the scope it applies to (account, organization, or identity).

[Huntress] Get a single escalation by its numeric ID — full detail, severity, status, due date, and the related organization. Discover escalation IDs via huntress_list_escalations.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric escalation ID (from huntress_list_escalations).

[Huntress] List escalations — items the Huntress SOC has escalated to the partner for action. Returns a paginated list with status, severity, subtype, due date, and organization. Filter by status, severity, subtype, or organization. Use huntress_get_escalation for full detail on one escalation.

ParamTypeRequiredDefaultDescription
limitintegerno50Max results per page (default 50, capped at 500 by the API).
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
severitystringnonullFilter by severity: low|high|critical.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|severity|due_at|created_at|updated_at. Omit for default ordering.
statusstringnonullFilter by status: open|overdue|resolved.
subtypestringnonullFilter by escalation subtype.

[Huntress] Resolve a Huntress escalation by recording a determination (expected vs unauthorized) and the scope it applies to (account, organization, or identity). Discover escalation IDs via huntress_list_escalations.

ParamTypeRequiredDefaultDescription
determinationstringnonullDetermination: expected|unauthorized.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric escalation ID to resolve (from huntress_list_escalations).
scopestringnonullScope the determination applies to: account|organization|identity.

Platform Actions

ToolPlanAccessSummary
huntress_get_platform_actionFreeRead-onlyGet a single platform action by its numeric ID — full detail, severity, status, and the related organization.
huntress_list_platform_actionsFreeRead-onlyList platform actions — actions requested or taken on the Huntress platform.

[Huntress] Get a single platform action by its numeric ID — full detail, severity, status, and the related organization. Discover platform action IDs via huntress_list_platform_actions.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric platform action ID (from huntress_list_platform_actions).

[Huntress] List platform actions — actions requested or taken on the Huntress platform. Returns a paginated list with status, severity, subtype, and organization. Filter by status, severity, subtype, or organization. Use huntress_get_platform_action for full detail on one action.

ParamTypeRequiredDefaultDescription
limitintegerno50Max results per page (default 50, capped at 500 by the API).
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
severitystringnonullFilter by severity: low|high|critical.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|severity|due_at|created_at|updated_at. Omit for default ordering.
statusstringnonullFilter by status: open|overdue|resolved.
subtypestringnonullFilter by platform action subtype.

Signals

ToolPlanAccessSummary
huntress_get_signalFreeRead-onlyGet a single security signal by its numeric ID — full detail, type, status, related entity, and investigation timeline.
huntress_list_signalsFreeRead-onlyList security signals — investigated detections tied to entities (users, mailboxes, agents, identities).

[Huntress] Get a single security signal by its numeric ID — full detail, type, status, related entity, and investigation timeline. Discover signal IDs via huntress_list_signals.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric signal ID (from huntress_list_signals).

[Huntress] List security signals — investigated detections tied to entities (users, mailboxes, agents, identities). Returns a paginated list with status, type, the related entity, and investigation timestamps. Filter by investigated-at window, entity, organization, type, or status. Use huntress_get_signal for full detail on one signal.

ParamTypeRequiredDefaultDescription
entityIdstringnonullFilter to a single entity ID. Must be paired with entityType.
entityTypestringnonullFilter by entity type: user_entity|source|mailbox|service_principal|agent|identity. Required when entityId is supplied.
investigatedAtMaxstringnonullFilter to signals investigated at or before this ISO-8601 timestamp.
investigatedAtMinstringnonullFilter to signals investigated at or after this ISO-8601 timestamp.
limitintegerno50Max results per page (default 50, capped at 500 by the API).
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|created_at|updated_at|status. Omit for default ordering.
statusesstringnonullFilter by comma-separated statuses: reported|closed.
typesstringnonullFilter by comma-separated signal types.

Organizations

ToolPlanAccessSummary
huntress_create_organizationProWriteCreate a new organization within the Huntress account.
huntress_delete_organizationProDestructiveDelete a Huntress organization.
huntress_get_organizationFreeRead-onlyGet a single organization by its numeric ID — full detail, name, key, and metadata.
huntress_list_organizationsFreeRead-onlyList the customer organizations under the account.
huntress_update_organizationProWriteUpdate a Huntress organization — rename it.

[Huntress] Create a new organization within the Huntress account. Both name and key are REQUIRED by the Huntress API. List existing organizations via huntress_list_organizations.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request after the typed fields.
keystringyesUnique key/identifier for the new organization. Required.
namestringyesName for the new organization. Required.

[Huntress] Delete a Huntress organization. This is IRREVERSIBLE — the organization and its associations are removed. Discover organization IDs via huntress_list_organizations.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric organization ID to delete (from huntress_list_organizations).

[Huntress] Get a single organization by its numeric ID — full detail, name, key, and metadata. Discover organization IDs via huntress_list_organizations.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric organization ID (from huntress_list_organizations).

[Huntress] List the customer organizations under the account. Returns a paginated list with name, key, and metadata. The organization `id` returned here is the `organizationId` filter used across huntress_list_agents, huntress_list_identities, huntress_list_incident_reports, huntress_list_signals, and more. Filter by name or key; use huntress_get_organization for full detail.

ParamTypeRequiredDefaultDescription
keystringnonullFilter by organization key.
limitintegerno50Max results per page (default 50, capped at 500 by the API).
namestringnonullFilter by organization name.
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|created_at|updated_at|name|key. Omit for default ordering.

[Huntress] Update a Huntress organization — rename it. Discover organization IDs via huntress_list_organizations.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric organization ID to update (from huntress_list_organizations).
namestringnonullNew name for the organization.

Memberships

ToolPlanAccessSummary
huntress_create_membershipProWriteInvite a user to the Huntress account by creating a membership.
huntress_delete_membershipProDestructiveDelete a Huntress membership, revoking the member's access to the account.
huntress_get_membershipFreeRead-onlyGet a single membership by its numeric ID — full detail, the user, organization, and permission role.
huntress_list_membershipsFreeRead-onlyList memberships — the user-to-organization access grants and their permission roles.
huntress_update_membershipProWriteUpdate a Huntress membership — change the member's permissions.

[Huntress] Invite a user to the Huntress account by creating a membership. The Huntress API REQUIRES email, first name, last name, and permissions. Optionally scope the membership to an organization. List existing memberships via huntress_list_memberships.

ParamTypeRequiredDefaultDescription
emailstringyesEmail address of the user to invite. Required.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request after the typed fields.
firstNamestringyesFirst name of the user. Required.
lastNamestringyesLast name of the user. Required.
organizationIdintegernonullOptional organization ID to scope the membership to (from huntress_list_organizations).
permissionsstringyesPermissions to grant the new member. Required. One of: Admin, Security Engineer, User, Read-only, Finance, Marketing, Provisioner.

[Huntress] Delete a Huntress membership, revoking the member's access to the account. This is IRREVERSIBLE — it removes the membership but does NOT delete the underlying user. Discover membership IDs via huntress_list_memberships.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric membership ID to delete (from huntress_list_memberships).

[Huntress] Get a single membership by its numeric ID — full detail, the user, organization, and permission role. Discover membership IDs via huntress_list_memberships.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric membership ID (from huntress_list_memberships).

[Huntress] List memberships — the user-to-organization access grants and their permission roles. Returns a paginated list with user, organization, and permissions. Filter by organization, user, or permission role. Use huntress_get_membership for full detail on one membership.

ParamTypeRequiredDefaultDescription
limitintegerno50Max results per page (default 50, capped at 500 by the API).
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
permissionsstringnonullFilter by permission role: Admin|Security Engineer|User|Read-only|Finance|Marketing|Provisioner.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|user_id|created_at|updated_at. Omit for default ordering.
userIdintegernonullFilter to a single user ID.

[Huntress] Update a Huntress membership — change the member's permissions. Discover membership IDs via huntress_list_memberships.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric membership ID to update (from huntress_list_memberships).
permissionsstringnonullNew permissions to set for the member.

Invoices

ToolPlanAccessSummary
huntress_get_invoiceFreeRead-onlyGet a single invoice by its numeric ID — full billing detail, status, line items, and amounts.
huntress_list_invoicesFreeRead-onlyList billing invoices for the account.

[Huntress] Get a single invoice by its numeric ID — full billing detail, status, line items, and amounts. Discover invoice IDs via huntress_list_invoices.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric invoice ID (from huntress_list_invoices).

[Huntress] List billing invoices for the account. Returns a paginated list with status, amounts, and usage flags. Filter by status or whether the invoice has usage. Use huntress_get_invoice for full detail on one invoice.

ParamTypeRequiredDefaultDescription
hasUsagebooleannonullFilter to invoices that have (true) or do not have (false) usage.
limitintegerno50Max results per page (default 50, capped at 500 by the API).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|created_at|updated_at|status. Omit for default ordering.
statusstringnonullFilter by status: open|paid|failed|partial_refund|full_refund|draft|voided|processing.

External Recon

ToolPlanAccessSummary
huntress_get_external_portFreeRead-onlyGet a single External Recon port finding by its numeric ID — full detail, protocol, port, service, and risk classification.
huntress_list_external_portsFreeRead-onlyList externally-discovered open ports and exposed services found by Huntress External Recon.

[Huntress] Get a single External Recon port finding by its numeric ID — full detail, protocol, port, service, and risk classification. Discover finding IDs via huntress_list_external_ports.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric external port finding ID (from huntress_list_external_ports).

[Huntress] List externally-discovered open ports and exposed services found by Huntress External Recon. Returns a paginated list with protocol, port, service, and risky-service flag. Filter by organization, protocol, port, risky-service, or service name. Use huntress_get_external_port for full detail on one finding.

ParamTypeRequiredDefaultDescription
limitintegerno50Max results per page (default 50, capped at 500 by the API).
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
portintegernonullFilter to a single port number.
protocolstringnonullFilter by protocol: TCP|UDP.
riskyServicebooleannonullFilter to only risky (true) or non-risky (false) services.
servicestringnonullFilter by service name.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|port|protocol|created_at|updated_at. Omit for default ordering.

Summary Reports

ToolPlanAccessSummary
huntress_get_reportFreeRead-onlyGet a single summary report by its numeric ID — full report detail, type, period, and the related organization.
huntress_list_reportsFreeRead-onlyList summary reports — periodic monthly/quarterly/yearly account and organization summaries.

[Huntress] Get a single summary report by its numeric ID — full report detail, type, period, and the related organization. Discover report IDs via huntress_list_reports.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric summary report ID (from huntress_list_reports).

[Huntress] List summary reports — periodic monthly/quarterly/yearly account and organization summaries. Returns a paginated list with report type, period, and organization. Filter by period window, organization, or report type. Use huntress_get_report for full detail on one report.

ParamTypeRequiredDefaultDescription
limitintegerno50Max results per page (default 50, capped at 500 by the API).
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
periodMaxstringnonullFilter to reports whose period is at or before this ISO-8601 timestamp.
periodMinstringnonullFilter to reports whose period is at or after this ISO-8601 timestamp.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by: id|created_at|updated_at. Omit for default ordering.
typestringnonullFilter by report type: monthly_summary|quarterly_summary|yearly_summary.

Unwanted Access Rules

ToolPlanAccessSummary
huntress_create_unwanted_access_ruleProWriteCreate an unwanted-access rule that classifies identity sign-ins as expected or unauthorized.
huntress_delete_unwanted_access_ruleProDestructiveDelete an unwanted-access rule.
huntress_get_unwanted_access_ruleFreeRead-onlyGet a single unwanted access rule by its numeric ID — full detail, type, status, scope, category, and matching logic.
huntress_list_known_vpnsFreeRead-onlyList the reference catalog of known VPN providers recognized by Huntress ITDR.
huntress_list_unwanted_access_rulesFreeRead-onlyList unwanted access rules — ITDR location/VPN access policies that flag expected vs. unauthorized sign-in sources.
huntress_update_unwanted_access_ruleProWriteUpdate an unwanted-access rule.

[Huntress] Create an unwanted-access rule that classifies identity sign-ins as expected or unauthorized. The Huntress API REQUIRES type (expected|unauthorized). Set an optional category (country|vpn) and its match (countryCode or vpn), the matching logic, an active window (startsAt/expiresAt), and notes. List existing rules via huntress_list_unwanted_access_rules.

ParamTypeRequiredDefaultDescription
categorystringnonullRule category: country|vpn.
countryCodestringnonullCountry code to match when category=country.
expiresAtstringnonullISO-8601 timestamp when the rule expires.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
identityIdintegernonullLimit the rule to a single identity ID (from huntress_list_identities).
logicstringnonullMatching logic: standard|catchall|catchall_exception.
notesstringnonullFree-text notes for the rule.
organizationIdintegernonullLimit the rule to a single organization ID (from huntress_list_organizations).
startsAtstringnonullISO-8601 timestamp when the rule becomes active.
typestringyesRule type. Required. One of: expected|unauthorized.
vpnstringnonullVPN to match when category=vpn (from huntress_list_known_vpns).

[Huntress] Delete an unwanted-access rule. This is IRREVERSIBLE — the rule is removed and no longer classifies sign-ins. Discover rule IDs via huntress_list_unwanted_access_rules.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric rule ID to delete (from huntress_list_unwanted_access_rules).

[Huntress] Get a single unwanted access rule by its numeric ID — full detail, type, status, scope, category, and matching logic. Discover rule IDs via huntress_list_unwanted_access_rules.

ParamTypeRequiredDefaultDescription
idintegeryesNumeric unwanted access rule ID (from huntress_list_unwanted_access_rules).

[Huntress] List the reference catalog of known VPN providers recognized by Huntress ITDR. Returns the full list (no pagination, no parameters). Use these VPN identifiers when interpreting or building vpn-category unwanted access rules (see huntress_list_unwanted_access_rules).

[Huntress] List unwanted access rules — ITDR location/VPN access policies that flag expected vs. unauthorized sign-in sources. Returns a paginated list with type, status, scope, category, and matching logic. Filter by organization, identity, type, status, scope, category, country code, VPN, or logic. Use huntress_get_unwanted_access_rule for full detail, and huntress_list_known_vpns for the VPN reference list.

ParamTypeRequiredDefaultDescription
categorystringnonullFilter by category: country|vpn.
countryCodestringnonullFilter by ISO country code (for country-category rules).
identityIdintegernonullFilter to a single identity ID (from huntress_list_identities).
limitintegerno50Max results per page (default 50, capped at 500 by the API).
logicstringnonullFilter by matching logic: standard|catchall|catchall_exception.
organizationIdintegernonullFilter to a single organization ID (from huntress_list_organizations).
pageTokenstringnonullPagination cursor. Use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
scopestringnonullFilter by scope: account|organization|identity.
statusstringnonullFilter by status: active|scheduled|expired.
typestringnonullFilter by rule type: expected|unauthorized.
vpnstringnonullFilter by VPN provider (for vpn-category rules).

[Huntress] Update an unwanted-access rule. Only the active window (startsAt/expiresAt) and notes can be changed. Discover rule IDs via huntress_list_unwanted_access_rules.

ParamTypeRequiredDefaultDescription
expiresAtstringnonullISO-8601 timestamp when the rule expires.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric rule ID to update (from huntress_list_unwanted_access_rules).
notesstringnonullFree-text notes for the rule.
startsAtstringnonullISO-8601 timestamp when the rule becomes active.

Managed Accounts (Reseller)

ToolPlanAccessSummary
huntress_approve_managed_account_remediationsProDestructiveApprove remediations for an incident report within a reseller-managed account selected by accountId.
huntress_create_managed_accountProDestructiveCreate a new reseller-managed account.
huntress_create_managed_account_membershipProWriteInvite a user (create a membership) within a reseller-managed account selected by accountId.
huntress_create_managed_account_organizationProWriteCreate an organization within a reseller-managed account selected by accountId.
huntress_delete_managed_account_membershipProDestructiveDelete a user membership within a reseller-managed account selected by accountId.
huntress_delete_managed_account_organizationProDestructiveDelete an organization within a reseller-managed account selected by accountId.
huntress_disable_managed_accountProDestructivePERMANENTLY disable a reseller-managed account.
huntress_get_managed_accountFreeRead-onlyGet a single reseller-managed account by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_agentFreeRead-onlyGet a single agent within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_external_portFreeRead-onlyGet a single external-recon open port within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_incident_reportFreeRead-onlyGet a single incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_invoiceFreeRead-onlyGet a single invoice for a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_membershipFreeRead-onlyGet a single membership within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_organizationFreeRead-onlyGet a single organization within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_remediationFreeRead-onlyGet a single remediation for an incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_reportFreeRead-onlyGet a single summary report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_signalFreeRead-onlyGet a single investigation signal within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_isolate_managed_account_agentProDestructiveNetwork-isolate an agent within a reseller-managed account selected by accountId.
huntress_list_managed_account_agentsFreeRead-onlyList deployed agents within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_external_portsFreeRead-onlyList external-recon open ports discovered within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_incident_reportsFreeRead-onlyList incident reports within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_invoicesFreeRead-onlyList invoices for a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_membershipsFreeRead-onlyList user memberships within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_organizationsFreeRead-onlyList organizations within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_remediationsFreeRead-onlyList remediations for an incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_reportsFreeRead-onlyList summary reports within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_signalsFreeRead-onlyList investigation signals within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_accountsFreeRead-onlyList the reseller-managed accounts available to the current credentials.
huntress_reject_managed_account_remediationsProDestructiveReject remediations for an incident report within a reseller-managed account selected by accountId.
huntress_release_managed_account_agent_isolationProDestructiveRelease network isolation on an agent within a reseller-managed account selected by accountId.
huntress_resolve_managed_account_incident_reportProDestructiveResolve an incident report within a reseller-managed account selected by accountId.
huntress_uninstall_managed_account_agentProDestructiveUninstall an agent within a reseller-managed account selected by accountId.
huntress_update_managed_accountProWriteUpdate a reseller-managed account.
huntress_update_managed_account_agentProWriteUpdate an agent within a reseller-managed account selected by accountId (tags, tamper-protection config).
huntress_update_managed_account_membershipProWriteUpdate a user membership's permissions within a reseller-managed account selected by accountId.
huntress_update_managed_account_organizationProWriteUpdate an organization within a reseller-managed account selected by accountId.

[Huntress] Approve remediations for an incident report within a reseller-managed account selected by accountId. This is a bodyless action — the Huntress API approves all pending remediations for the report and takes no parameters beyond the path identifiers. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
incidentReportIdintegeryesNumeric ID of the incident report whose remediations to approve.

[Huntress] Create a new reseller-managed account. The Huntress API REQUIRES name, subdomain, phone number, and an initial admin user (first name, last name, email). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
adminEmailstringyesEmail address of the initial admin user for this account. Required.
adminFirstNamestringyesFirst name of the initial admin user for this account. Required.
adminLastNamestringyesLast name of the initial admin user for this account. Required.
fieldsJsonstringnonullAdditional body fields (e.g. support_type, products, billing_address) as a JSON object, merged into the request after the typed fields.
namestringyesDisplay name of the managed account. Required.
phoneNumberstringyesPrimary phone number used to contact the account owner. Required.
subdomainstringyesSubdomain for the managed account (e.g. 'acme' for acme.huntress.io). Required.

[Huntress] Invite a user (create a membership) within a reseller-managed account selected by accountId. The Huntress API REQUIRES email, first name, last name, and permissions. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
emailstringyesEmail address of the user to invite. Required.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request after the typed fields.
firstNamestringyesFirst name of the user. Required.
lastNamestringyesLast name of the user. Required.
organizationIdintegernonullOptional organization ID to scope the membership to.
permissionsstringyesPermission/role to grant. Required. One of: Admin, Security Engineer, User, Read-only, Finance, Marketing, Provisioner.

[Huntress] Create an organization within a reseller-managed account selected by accountId. The Huntress API REQUIRES name and key. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request after the typed fields.
keystringyesUnique key/identifier for the organization. Required.
namestringyesName of the organization to create. Required.

[Huntress] Delete a user membership within a reseller-managed account selected by accountId. This removes the membership only; it does not delete the user. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the membership to delete.

[Huntress] Delete an organization within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the organization to delete.

[Huntress] PERMANENTLY disable a reseller-managed account. This is irreversible: it disables the account and uninstalls ALL of its agents after 10 days. Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account to disable (from huntress_list_managed_accounts).

[Huntress] Get a single reseller-managed account by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.

[Huntress] Get a single agent within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the agent.

[Huntress] Get a single external-recon open port within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the external port record.

[Huntress] Get a single incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the incident report.

[Huntress] Get a single invoice for a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the invoice.

[Huntress] Get a single membership within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the membership.

[Huntress] Get a single organization within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the organization.

[Huntress] Get a single remediation for an incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
incidentReportIdintegeryesNumeric ID of the incident report the remediation belongs to.
remediationIdintegeryesNumeric ID of the remediation.

[Huntress] Get a single summary report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the summary report.

[Huntress] Get a single investigation signal within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the signal.

[Huntress] Network-isolate an agent within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric ID of the agent to isolate.
reasonstringnonullOptional reason for the isolation.
strictIsolationbooleannonullWhen true, applies strict isolation (blocks all traffic except Huntress).

[Huntress] List deployed agents within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
hostnamestringnonullFilter by hostname.
limitintegerno50Max results per page (default 50, max 500).
organizationIdintegernonullFilter by organization ID.
osstringnonullFilter by operating system.
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
platformstringnonullFilter by platform: windows|darwin|linux.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by: id|created_at|updated_at.
versionstringnonullFilter by agent version.

[Huntress] List external-recon open ports discovered within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
limitintegerno50Max results per page (default 50, max 500).
organizationIdintegernonullFilter by organization ID.
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
portintegernonullFilter by port number.
protocolstringnonullFilter by protocol: TCP|UDP.
riskyServicebooleannonullFilter to risky services only (true/false).
servicestringnonullFilter by service name.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by: id|port|protocol|created_at|updated_at.

[Huntress] List incident reports within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
agentIdintegernonullFilter by agent ID.
indicatorTypestringnonullFilter by indicator type: footholds|monitored_files|ransomware_canaries|antivirus_detections|process_detections|managed_identity|mde_detections|siem_detections|favicon_detections|behavioral_detections|email_security_detections|app_control|ai_misuse.
limitintegerno50Max results per page (default 50, max 500).
organizationIdintegernonullFilter by organization ID.
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
platformstringnonullFilter by platform: windows|darwin|microsoft_365|google|linux|email_security|other.
severitystringnonullFilter by severity: low|high|critical.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by (e.g. id, created_at, updated_at).
statusstringnonullFilter by status: sent|closed|dismissed|auto_remediating|deleting|partner_dismissed.

[Huntress] List invoices for a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
hasUsagebooleannonullFilter to invoices that have usage (true/false).
limitintegerno50Max results per page (default 50, max 500).
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by: id|created_at|updated_at|status.
statusstringnonullFilter by status: open|paid|failed|partial_refund|full_refund|draft|voided|processing.

[Huntress] List user memberships within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
limitintegerno50Max results per page (default 50, max 500).
organizationIdintegernonullFilter by organization ID.
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
permissionsstringnonullFilter by permission: Admin|Security Engineer|User|Read-only|Finance|Marketing|Provisioner.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by: id|user_id|created_at|updated_at.
userIdintegernonullFilter by user ID.

[Huntress] List organizations within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
keystringnonullFilter by organization key.
limitintegerno50Max results per page (default 50, max 500).
namestringnonullFilter by organization name.
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by: id|created_at|updated_at|name|key.

[Huntress] List remediations for an incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated: when more pages exist, read next_page_token from the response's pagination object and pass it as pageToken.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
incidentReportIdintegeryesNumeric ID of the incident report whose remediations to list.
limitintegerno50Max results per page (default 50, max 500).
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by (e.g. id, created_at, updated_at).
statusesstringnonullComma-separated list of remediation statuses: unapproved|approved|completed|failed|cancelled.
typesstringnonullComma-separated list of remediation types: assisted|manual|containment.

[Huntress] List summary reports within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
limitintegerno50Max results per page (default 50, max 500).
organizationIdintegernonullFilter by organization ID.
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
periodMaxstringnonullFilter to reports with period on/before this ISO-8601 timestamp.
periodMinstringnonullFilter to reports with period on/after this ISO-8601 timestamp.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by: id|created_at|updated_at.
typestringnonullFilter by report type: monthly_summary|quarterly_summary|yearly_summary.

[Huntress] List investigation signals within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts). Requires reseller-level API credentials. Paginated.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
entityIdstringnonullFilter by entity ID. Must be paired with entityType.
entityTypestringnonullFilter by entity type: user_entity|source|mailbox|service_principal|agent|identity. Required when entityId is set.
investigatedAtMaxstringnonullFilter to signals investigated on/before this ISO-8601 timestamp.
investigatedAtMinstringnonullFilter to signals investigated on/after this ISO-8601 timestamp.
limitintegerno50Max results per page (default 50, max 500).
organizationIdintegernonullFilter by organization ID.
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by: id|created_at|updated_at|status.
statusesstringnonullComma-separated list of signal statuses: reported|closed.
typesstringnonullComma-separated list of signal types.

[Huntress] List the reseller-managed accounts available to the current credentials. Use this to discover the accountId required by every other Managed Account tool. Requires reseller-level API credentials. Paginated.

ParamTypeRequiredDefaultDescription
limitintegerno50Max results per page (default 50, max 500).
namestringnonullFilter by account name.
pageTokenstringnonullUse the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by (e.g. id, created_at, updated_at, name).
statusstringnonullFilter by account status: enabled|disabled.
subdomainstringnonullFilter by account subdomain.

[Huntress] Reject remediations for an incident report within a reseller-managed account selected by accountId. The Huntress API REQUIRES comment and useful. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
commentstringyesWhy the remediations were rejected. Required. Helps the Huntress SOC fix the plan and re-issue the incident report.
emailstringnonullEmail for the Huntress SOC to contact. Falls back to the API key's user if omitted.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request after the typed fields.
incidentReportIdintegeryesNumeric ID of the incident report whose remediations to reject.
namestringnonullName of the user rejecting. Falls back to the API key's user if omitted.
phoneNumberstringnonullPhone number for the Huntress SOC to contact. Falls back to the API key's user if omitted.
usefulbooleanyesWhether the remediation plan was useful. Required.

[Huntress] Release network isolation on an agent within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the agent whose isolation to release.

[Huntress] Resolve an incident report within a reseller-managed account selected by accountId. This is a bodyless action — the Huntress API takes no parameters beyond the path identifiers. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the incident report to resolve.

[Huntress] Uninstall an agent within a reseller-managed account selected by accountId. This is an asynchronous, irreversible removal of the agent. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
idintegeryesNumeric ID of the agent to uninstall.

[Huntress] Update a reseller-managed account. Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts).
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
namestringnonullNew display name for the managed account.

[Huntress] Update an agent within a reseller-managed account selected by accountId (tags, tamper-protection config). Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric ID of the agent to update.
tagsstringnonullComma-separated list of tags to set on the agent.
tamperProtectionConfiguredbooleannonullWhether tamper protection is configured for the agent.

[Huntress] Update a user membership's permissions within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric ID of the membership to update.
permissionsstringnonullNew permission/role to grant (e.g. Admin, Security Engineer, User, Read-only).

[Huntress] Update an organization within a reseller-managed account selected by accountId. Targets a reseller-managed account (from huntress_list_managed_accounts); requires reseller-level credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account (from huntress_list_managed_accounts). Requires reseller-level API credentials.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric ID of the organization to update.
namestringnonullNew name for the organization.

Reseller Billing

ToolPlanAccessSummary
huntress_create_reseller_subscriptionProDestructiveCreate a new reseller subscription.
huntress_get_reseller_invoiceFreeRead-onlyGet a single reseller invoice by id; these require reseller-level API credentials.
huntress_get_reseller_subscriptionFreeRead-onlyGet a single reseller subscription by id; these require reseller-level API credentials.
huntress_list_reseller_account_usage_line_itemsFreeRead-onlyList per-account usage line items for a reseller invoice; these require reseller-level API credentials.
huntress_list_reseller_invoicesFreeRead-onlyList reseller invoices; these require reseller-level API credentials.
huntress_list_reseller_organization_usage_line_itemsFreeRead-onlyList per-organization usage line items for a reseller invoice; these require reseller-level API credentials.
huntress_list_reseller_subscriptionsFreeRead-onlyList reseller subscriptions; these require reseller-level API credentials.
huntress_update_reseller_subscriptionProDestructiveUpdate a reseller subscription.
huntress_upgrade_reseller_subscriptionProDestructiveUpgrade a reseller subscription (e.g. raise the seat minimum).

[Huntress] Create a new reseller subscription. The Huntress API REQUIRES account_id, product, minimum (seat count), and purchase_order. Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
accountIdintegeryesNumeric ID of the managed account this subscription is for (from huntress_list_managed_accounts). Required.
billingIntervalstringnonullOptional billing interval for the subscription.
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request after the typed fields.
minimumintegeryesSeat/unit minimum for the subscription. Required.
productstringyesProduct for the subscription. Required. One of: edr, sat, itdr, siem.
purchaseOrderstringyesPurchase order reference. Required.
ParamTypeRequiredDefaultDescription
idintegeryesNumeric ID of the reseller invoice (from huntress_list_reseller_invoices).
ParamTypeRequiredDefaultDescription
idintegeryesNumeric ID of the reseller subscription (from huntress_list_reseller_subscriptions).

[Huntress] List per-account usage line items for a reseller invoice; these require reseller-level API credentials. Paginated — use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.

ParamTypeRequiredDefaultDescription
invoiceIdintegeryesNumeric ID of the reseller invoice to list usage line items for (from huntress_list_reseller_invoices).
limitintegerno50Maximum number of results per page (default 50, max 500).
pageTokenstringnonullPagination cursor: pass the `next_page_token` from the previous response's `pagination` object to fetch the next page. Omit for the first page.

[Huntress] List reseller invoices; these require reseller-level API credentials. Paginated — use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.

ParamTypeRequiredDefaultDescription
limitintegerno50Maximum number of results per page (default 50, max 500).
pageTokenstringnonullPagination cursor: pass the `next_page_token` from the previous response's `pagination` object to fetch the next page. Omit for the first page.
statusstringnonullFilter by invoice status: open|paid|failed|partial_refund|full_refund|draft|voided|processing.

[Huntress] List per-organization usage line items for a reseller invoice; these require reseller-level API credentials. Paginated — use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.

ParamTypeRequiredDefaultDescription
invoiceIdintegeryesNumeric ID of the reseller invoice to list usage line items for (from huntress_list_reseller_invoices).
limitintegerno50Maximum number of results per page (default 50, max 500).
pageTokenstringnonullPagination cursor: pass the `next_page_token` from the previous response's `pagination` object to fetch the next page. Omit for the first page.

[Huntress] List reseller subscriptions; these require reseller-level API credentials. Paginated — use the `next_page_token` from the response's `pagination` object as `pageToken` for the next page.

ParamTypeRequiredDefaultDescription
limitintegerno50Maximum number of results per page (default 50, max 500).
pageTokenstringnonullPagination cursor: pass the `next_page_token` from the previous response's `pagination` object to fetch the next page. Omit for the first page.
productstringnonullFilter by product: edr|sat|itdr|siem.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField to sort by: id|status|minimum|created_at|updated_at.
statusstringnonullFilter by subscription status: draft|approved|accepted|active|completed.

[Huntress] Update a reseller subscription. Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request.
idintegeryesNumeric ID of the reseller subscription (from huntress_list_reseller_subscriptions).

[Huntress] Upgrade a reseller subscription (e.g. raise the seat minimum). The Huntress API REQUIRES the new minimum. Requires reseller-level API credentials.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request after the typed fields.
idintegeryesNumeric ID of the reseller subscription (from huntress_list_reseller_subscriptions).
minimumintegeryesNew seat minimum for the subscription. Required.
onRenewalbooleannonullWhether the upgrade applies on renewal rather than immediately.
purchaseOrderstringnonullPurchase order reference for the upgrade.

SIEM

ToolPlanAccessSummary
huntress_query_siemProWriteQuery SIEM logs with ES|QL.

[Huntress] Query SIEM logs with ES|QL. The `esql` query must begin with "FROM logs". Requires the SIEM product to be enabled on the account (returns 404 if not). Returns {logs:[...], pagination:{next_page_token?}}; pass the returned token as `pageToken` for the next page. Maximum 200 rows per page.

ParamTypeRequiredDefaultDescription
esqlstringyesES|QL query string. Required. Must begin with "FROM logs".
fieldsJsonstringnonullAdditional body fields as a JSON object, merged into the request after the typed fields.
pageTokenstringnonullPagination cursor: pass the `next_page_token` from the previous response's `pagination` object to fetch the next page. Omit for the first page.
rangeEndstringyesEnd of the time range to query (ISO 8601 timestamp). Required.
rangeStartstringyesStart of the time range to query (ISO 8601 timestamp). Required.