Skip to main content
Connector guides

Connect Datto EDR

Datto EDR is Kaseya's endpoint detection and response platform. An agent on each machine collects forensic detail — running processes, loaded modules and drivers, autostart entries, local accounts,…

Written By Christopher Scaminaci

Last updated 6 days ago

Datto EDR is Kaseya's endpoint detection and response platform. An agent on each machine collects forensic detail — running processes, loaded modules and drivers, autostart entries, local accounts, network connections and what is in memory — and Datto EDR judges what it finds, raises alerts, and gives you the containment verbs to act on them. It was built as Infocyte HUNT and acquired by Datto in 2022, which is why the addresses and some of the vocabulary still say Infocyte. StackJack talks to it through the API on your own Datto EDR instance.

Connecting Datto EDR to StackJack gives your AI assistant a family of dattoedr_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Work the alert queue — list alerts and read the detection behind each one, and reach back past 30 days into the alert archive for quarterly and annual reviews
  • Reconcile coverage — list installed agents with their last check-in, so you can answer whether every endpoint you bill for is actually protected and reporting in
  • Investigate an incident — read the forensic detail a scan collected: processes, loaded modules, drivers, memory findings, autostart and persistence entries, network connections, local accounts, scripts and installed software
  • Judge a file — look up a file's reputation by hash, and see how long it has been sitting in the estate, which is often the difference between a contained incident and a long-running one
  • Report for a QBR — vulnerability advisories linking installed software to known CVEs, compliance results down to the individual failed check, and the audit log of who did what
  • Follow work in flight — every scan and containment action returns a task; read its status, its per-machine progress, and the results it produced
  • Scan on demand (on Pro plans) — sweep a single machine or an entire target group, and run network discovery to find machines that have no agent yet
  • Contain a threat (on Pro plans) — isolate a compromised machine from the network, restore it once it is clean, terminate a process, collect evidence, and recover files
  • Tune and organize (on Pro plans) — manage target groups, scheduled scans, discovery queries, detection rules, extensions, triage flags and investigation notes

How StackJack authenticates to Datto EDR

Datto EDR uses a single API token that you create inside the product. There is no client ID, no second secret and no sign-in flow — you give StackJack the address you sign in to and the token, and that is the whole setup.

Decide whose account creates the token

This is the one decision worth making carefully, because it is the only control you have over what StackJack can reach.

A Datto EDR token has no permissions of its own. It can do exactly what the person who created it can do. An administrator's token reaches everything; an analyst's token reaches less; an external analyst's token less again. There is no per-token permission screen, and the reach cannot be narrowed afterwards — the only way to change it is to create a new token from a different account.

Steps

  1. Choose the account. Decide which Datto EDR user's level of access you want StackJack to have, per the point above.
  2. Create the token. Sign in to Datto EDR. Administrators create tokens for any user under Admin > Users & Tokens > API Tokens; everyone else creates their own under My Settings > API Tokens.
  3. Copy it immediately. The token is shown exactly once and cannot be retrieved afterwards. Copy it before you close the panel and store it as you would a password.
  4. Note the date. Datto EDR tokens stop working one year after they are created and cannot be renewed. Put a reminder in your calendar a few weeks ahead of that date.
  5. Enter both values in StackJack. Open the Datto EDR connector, paste the address you sign in to and the token, and save.
  6. Test the connection. A failure here is almost always a token truncated on copy, or a typo in the address.

Your account address

The address you sign in to ends in infocyte.com, not datto.com — for example https://acme.infocyte.com. The help site lives on a Datto address, but the product itself does not, and entering a datto.com address will not connect. You can paste the full address or just the subdomain; StackJack fills in the rest. Enter the host only, with nothing after it.

The one-year token expiry

Worth repeating on its own, because it is the single most common way a working Datto EDR connection stops working.

Datto EDR tokens expire one year from the day they are created. There is no renewal, no warning inside the API, and no way to extend one. When the token lapses, Datto EDR begins refusing every request, and StackJack switches the connector off after a few consecutive failed checks — so an integration that has run quietly for a year goes quiet without anyone touching it.

The fix is quick: create a fresh token in Datto EDR, paste it into StackJack, and the connector comes back. The important part is knowing to expect it. Diary the anniversary of every token you create.

What your AI can and cannot do

Reads are on the Free tier: alerts, agents, forensic results, file reputation, vulnerabilities, compliance and the audit log. They change nothing, but they return your customers' incident detail, so grant them deliberately.

Everything that changes something is Pro, and StackJack additionally marks the actions that reach a live machine as destructive. That covers isolating a host, restoring one, terminating a process, collecting evidence, recovering files, uninstalling an agent, launching a scan or a network sweep, scheduling a recurring scan, and every delete. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting, and grant only what you want an AI to reach.

Two are worth calling out because their risk is not obvious from the name:

  • Restoring an isolated host is treated as carefully as isolating one. Putting a machine back on the network during a live incident re-exposes everything it can reach, so it carries the same marking.
  • Importing or publishing an extension hands Datto EDR a script it will run on your customers' endpoints. It is the highest-risk action on this connector. Read anything you import, and prefer doing it in the Datto EDR interface where you can review it properly.

There is no test mode on this API. Every action is real, on real machines.

Things worth knowing before you rely on an answer

Alerts older than 30 days are somewhere else. Datto EDR keeps the last 30 days in its main alert list and moves everything before that into a separate archive. A quarterly or annual review that only reads the main list sees empty months. Ask for archived alerts when your window goes back further than a month.

Results cover the last 7 days unless you say otherwise. Datto EDR groups scan results into pre-computed rollups — Global or one target group, over 7, 30 or 90 days. If your question does not name one, StackJack reads from your Global Last 7 Days rollup, so the answer quietly covers only the last week. Name the rollup you mean when the question is about a longer period or a single customer. Ask for the list of rollups first if you are not sure which one you want. If your account has no Global rollup at all, the answer covers every rollup instead, so ask for one by name when the window matters.

Scans and containment actions do not return their results. Each one starts a task and hands back a task reference. Your AI follows the task to completion and then reads the findings from the scan, alert and extension-result tools. This is how the product works rather than a limitation, but it means "isolate that machine" is answered by "the isolation has started", with confirmation a moment later.

Narrow your questions. Datto EDR warns that broad, unfiltered queries slow its database down, and the forensic tables on a large estate are very large. A question scoped to a customer, a machine or a date range is faster and kinder to the platform than one that is not.

Plans and limits

Read tools are available on the Free tier. Everything that writes, contains, scans or changes configuration is Pro. Business reaches the same tools as Pro and differs by monthly call quota.

See the generated Datto EDR tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Datto EDR publishes no rate limit, so StackJack paces requests defensively and backs off on its own if the platform pushes back. A large read is usually slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Several customers

Every customer has their own Datto EDR account. Add one connection per customer from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.

Troubleshooting

"Datto EDR rejected the API token" — the token has almost certainly expired. Tokens last one year from creation and cannot be renewed, so on a connection that used to work this is the first thing to check. It can also mean the token was revoked, mistyped, or that the user who created it was removed from Datto EDR. Create a new token, paste it in, and run a Test Connection.

"Datto EDR accepted the token but refused this operation" — the account that created the token cannot reach that area. Because a token inherits its creator's access and has no settings of its own, the fix is to create the token again from an account with more access. There is no permission to switch on.

The connector switched itself off on its own — StackJack disables a connector after several consecutive failed checks. On Datto EDR the usual cause is the one-year token expiry arriving. Create a fresh token and re-enter it; the connector re-enables when the check passes.

"Could not find that record" — check the identifier still exists in Datto EDR, and check the instance address saved in StackJack matches the one you sign in to. Both look the same from outside. If you were looking for an older alert, remember the 30-day split.

A containment action reported that an extension is missing — the containment verbs run response extensions that have to be present in your instance. If the isolation extension has never been imported, or was deleted, StackJack refuses rather than starting an action that would quietly do nothing. Import the extension in Datto EDR and try again.

A machine shows no scan results — check it has an active agent, or a reachable address in the target group. A machine Datto EDR cannot reach looks the same as a machine with nothing to report.

Datto EDR tools

dattoedr_ · 96 tools · Free 61 · Pro 35

Platform

ToolWhat it does
dattoedr_count_records
Free · Read-only
Count the rows of any Datto EDR collection matching a filter, without fetching them.
dattoedr_get_box
Free · Read-only
Get one aggregation box by id, from dattoedr_list_boxes.
dattoedr_get_job
Free · Read-only
Get one platform job by id, from dattoedr_list_jobs.
dattoedr_get_task
Free · Read-only
Get one task's status by id — the follow-up call for EVERY scan and containment action on this connector, because none of them returns its result.
dattoedr_get_user_activity
Free · Read-only
Get one audit log entry by id, from dattoedr_list_user_activities.
dattoedr_get_version
Free · Read-only
Get the Datto EDR instance and API version.
dattoedr_list_boxes
Free · Read-only
List the aggregation boxes.
dattoedr_list_jobs
Free · Read-only
List Datto EDR's own background jobs — the platform's internal work, not the user tasks a scan or a containment action creates.
dattoedr_list_task_item_progress
Free · Read-only
List the progress messages beneath one task item — the running commentary for a single endpoint.
dattoedr_list_task_items
Free · Read-only
List a task's per-host items — one row per endpoint the task touched, with that endpoint's own outcome.
dattoedr_list_tasks
Free · Read-only
List user tasks.
dattoedr_list_user_activities
Free · Read-only
List the audit log — who did what in Datto EDR and when.
dattoedr_list_users
Free · Read-only
List the users of this Datto EDR instance.

Alerts

ToolWhat it does
dattoedr_get_alert
Free · Read-only
Get one alert by id, from dattoedr_list_alerts.
dattoedr_get_report
Free · Read-only
Get one report's metadata by id, from dattoedr_list_reports.
dattoedr_list_alerts
Free · Read-only
List alerts raised in the LAST 30 DAYS — threat name and weight, the host and file involved, and whether Datto EDR judged it malicious.
dattoedr_list_archived_alerts
Free · Read-only
List alerts OLDER than 30 days.
dattoedr_list_reports
Free · Read-only
List the reports Datto EDR has generated, with their type, scope and generation time.

Endpoints & Estate

ToolWhat it does
dattoedr_create_controller_group
Pro · Write
Create a controller group.
dattoedr_create_discovery_query
Pro · Write
Create an agentless discovery query — an IP range, hostname pattern, LDAP query or AWS query defining where to look for machines.
dattoedr_create_target_group
Pro · Write
Create a target group.
dattoedr_delete_address
Pro · Destructive
Delete one discovered address and its history.
dattoedr_delete_addresses
Pro · Destructive
Delete SEVERAL discovered addresses at once, by id.
dattoedr_delete_archived_target_group
Pro · Destructive
Permanently delete an ARCHIVED target group — one already removed from active use but still held for its history.
dattoedr_delete_controller_group
Pro · Destructive
Delete a controller group.
dattoedr_delete_discovery_query
Pro · Destructive
Delete a discovery query.
dattoedr_delete_target_group
Pro · Destructive
Delete a target group.
dattoedr_get_agent
Free · Read-only
Get one agent by id, from dattoedr_list_agents.
dattoedr_list_addresses
Free · Read-only
List the addresses discovery has found in a target group, with whether each one is reachable and when it was last accessed.
dattoedr_list_agents
Free · Read-only
List the installed Datto EDR agents, with each machine's hostname, operating system, version and last check-in.
dattoedr_list_controller_groups
Free · Read-only
List controller groups — the collectors that reach a customer's network on Datto EDR's behalf.
dattoedr_list_discovery_queries
Free · Read-only
List the agentless discovery queries defined on this instance — IP range, hostname, LDAP and AWS queries that find machines to scan.
dattoedr_list_target_groups
Free · Read-only
List target groups — the logical groupings of hosts Datto EDR scans and reports against.
dattoedr_uninstall_agent
Pro · Destructive
REMOVE the Datto EDR agent from one or more live endpoints.

Scan Credentials

ToolWhat it does
dattoedr_create_scan_credential
Pro · Destructive
Store a new scan credential in Datto EDR.
dattoedr_delete_scan_credential
Pro · Destructive
Delete a stored scan credential.
dattoedr_list_scan_credentials
Free · Read-only
List the credentials Datto EDR holds for agentless scanning — their names, types and where they are used.

Scans & Scheduling

ToolWhat it does
dattoedr_create_scan_record
Pro · Write
Create an empty scan record to hold the results of an offline survey import.
dattoedr_create_scheduled_job
Pro · Destructive
Create a RECURRING scan on a cron schedule.
dattoedr_delete_scheduled_job
Pro · Destructive
Delete a scheduled scan.
dattoedr_enumerate_target_group
Pro · Destructive
Run network discovery for a target group — an ACTIVE SWEEP of the customer's own infrastructure using that group's discovery queries.
dattoedr_get_scan
Free · Read-only
Get one scan by id, from dattoedr_list_scans.
dattoedr_list_scans
Free · Read-only
List scans, with each one's target group, timing and result counts.
dattoedr_list_scheduled_jobs
Free · Read-only
List the scheduled scans on this instance, with each one's cron expression, target group and scan options.
dattoedr_scan_target
Pro · Destructive
Launch a forensic scan of a SINGLE endpoint by hostname or IP address.
dattoedr_scan_target_group
Pro · Destructive
Launch a forensic scan of an ENTIRE target group — every endpoint in it, right now.

Response Actions

ToolWhat it does
dattoedr_collect_evidence
Pro · Destructive
Collect forensic evidence from an endpoint — data files, event logs and related artifacts — and copy it to the storage bucket configured in Datto EDR.
dattoedr_isolate_host
Pro · Destructive
ISOLATE an endpoint — cut it off the network so it can reach only Datto EDR and other security tools.
dattoedr_kill_process
Pro · Destructive
TERMINATE a process on a live endpoint, selected by name, SHA1 hash, process id or image path.
dattoedr_recover_files
Pro · Destructive
Copy named files off an endpoint to the recovery point configured in Datto EDR (an S3 bucket, FTP server or file share).
dattoedr_restore_host
Pro · Destructive
RESTORE an isolated endpoint to the network.
dattoedr_run_extension
Pro · Destructive
Run ANY named extension on a live endpoint.

Forensic Results

ToolWhat it does
dattoedr_get_extension_detail
Free · Read-only
Read a single extension execution result.
dattoedr_list_account_instances
Free · Read-only
List the local and domain accounts a scan found on the machines it examined.
dattoedr_list_account_instances_by_host
Free · Read-only
List account findings rolled up per machine — the same data as dattoedr_list_account_instances, grouped by host.
dattoedr_list_application_instances
Free · Read-only
List the installed applications a scan found across the estate.
dattoedr_list_artifact_instances
Free · Read-only
List the forensic artifacts a scan collected — the traces left behind by activity on the machine, rather than the running code itself.
dattoedr_list_autostart_instances
Free · Read-only
List the autostart and persistence entries a scan found — scheduled tasks, services, run keys and the rest of the ways code arranges to run again after a reboot.
dattoedr_list_box_extension_instances
Free · Read-only
List extension executions already aggregated across a box's whole window.
dattoedr_list_connection_instances
Free · Read-only
List the network connections a scan observed, with the process at each end.
dattoedr_list_driver_instances
Free · Read-only
List the kernel drivers a scan found loaded.
dattoedr_list_extension_details
Free · Read-only
List extension execution results WITH THEIR OUTPUT — success flag, threat verdict and the messages the extension wrote.
dattoedr_list_extension_instances
Free · Read-only
List extension executions — which extension ran, on which machine, and whether it succeeded.
dattoedr_list_memory_scan_instances
Free · Read-only
List what Datto EDR's memory scan found.
dattoedr_list_module_instances
Free · Read-only
List the modules and libraries loaded into processes during a scan.
dattoedr_list_process_instances
Free · Read-only
List the processes a scan found running, with each one's image path, hash and threat verdict.
dattoedr_list_scan_hosts
Free · Read-only
List the per-host results of scans — one row per machine, with its operating system, IP, the threat verdict Datto EDR reached and the totals it collected.
dattoedr_list_script_instances
Free · Read-only
List the scripts a scan found on the machines it examined.

Threat Intelligence & Triage

ToolWhat it does
dattoedr_add_comment
Pro · Write
Add a note to an object in Datto EDR.
dattoedr_create_flag
Pro · Write
Create a triage flag.
dattoedr_delete_flag
Pro · Destructive
Delete a triage flag.
dattoedr_get_file_dwell_time
Free · Read-only
Get one dwell-time record by its own id, from dattoedr_list_file_dwell_times.
dattoedr_get_file_reputation
Free · Read-only
Look up a file's reputation by its SHA1 hash — Datto EDR's verdict on whether that exact binary is known good, unknown or malicious.
dattoedr_get_flag
Free · Read-only
Get one triage flag by id, from dattoedr_list_flags.
dattoedr_list_comments
Free · Read-only
List the notes analysts have left on objects — the running commentary on an investigation.
dattoedr_list_file_dwell_times
Free · Read-only
List how long files have been present in the estate — first seen, last seen, and on how many machines.
dattoedr_list_flags
Free · Read-only
List the triage flags defined on this instance — the colored labels analysts apply to findings, each with a weight that influences how Datto EDR scores them.
dattoedr_replace_flag
Pro · Destructive
REPLACE a triage flag wholesale.

Vulnerabilities & Compliance

ToolWhat it does
dattoedr_get_cve
Free · Read-only
Get the detail of one CVE — the detection rules that cover it, its weakness classifications and its references.
dattoedr_list_application_advisories
Free · Read-only
List the advisories linking installed applications to known CVEs — the bridge between 'what software is on this estate' and 'which of it is vulnerable'.
dattoedr_list_compliance_result_items
Free · Read-only
List the individual checks inside compliance results — which control passed, which failed, and why.
dattoedr_list_compliance_results
Free · Read-only
List compliance scan results — one row per machine per compliance run, with its overall outcome.

Detection Rules & Extensions

ToolWhat it does
dattoedr_create_extension
Pro · Destructive
Import or create an extension — a script Datto EDR will execute on customer endpoints.
dattoedr_create_extension_global
Pro · Destructive
Create a global variable that extensions read at run time.
dattoedr_create_rule
Pro · Write
Create a detection rule.
dattoedr_delete_extension
Pro · Destructive
Delete an extension.
dattoedr_delete_rule
Pro · Destructive
Delete a detection rule.
dattoedr_get_extension
Free · Read-only
Get one extension by id, from dattoedr_list_extensions.
dattoedr_get_extension_latest_version
Free · Read-only
Get an extension's CURRENT SCRIPT and its checksum.
dattoedr_get_rule
Free · Read-only
Get one detection rule by id, from dattoedr_list_rules.
dattoedr_get_rule_latest_version
Free · Read-only
Get a detection rule's CURRENT BODY and its checksum.
dattoedr_list_extension_globals
Free · Read-only
List the global variables extensions read at run time — the shared configuration values that decide where an extension writes evidence, which endpoints it treats as exceptions, and so on.
dattoedr_list_extensions
Free · Read-only
List the extensions loaded in this instance — both the collection scripts that gather extra data during a scan and the response scripts that act on an endpoint.
dattoedr_list_rules
Free · Read-only
List the detection rules on this instance, with their names and current state.
dattoedr_publish_extension_version
Pro · Destructive
Publish a new version of an existing extension — new code that will execute on customer endpoints from the next run onward.
dattoedr_publish_rule_version
Pro · Write
Publish a new version of an existing detection rule.