Skip to main content
Connector guides

Connect ESET PROTECT

ESET PROTECT is ESET's cloud security-management platform, exposed to StackJack through the ESET Connect API. It covers endpoint protection, EDR/XDR (ESET Inspect), quarantine, policies, installers,…

Written By Christopher Scaminaci

Last updated 6 days ago

ESET PROTECT is ESET's cloud security-management platform, exposed to StackJack through the ESET Connect API. It covers endpoint protection, EDR/XDR (ESET Inspect), quarantine, policies, installers, patch and vulnerability management, and automation across your managed devices.

Connecting ESET PROTECT to StackJack gives your AI assistant a broad family of eset_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Inventory managed devices, the customer device-group tree, installers, and observed executables
  • Investigate detections, incidents, and EDR rules and exclusions — the EDR/XDR surface
  • Audit patch status, OS and application vulnerabilities, and quarantined objects
  • Review policies and their assignments, plus network-access and web-access rules
  • Act (on Pro plans) — run device tasks (scans, isolation, uninstall), restore or delete quarantine, write EDR rules and policies, manage device groups, roles, and users
  • Download (on Pro plans) quarantined binaries as short-lived, read-only SAS URLs

How StackJack authenticates to ESET PROTECT

ESET Connect authenticates through an OAuth 2.0 password grant using a dedicated API User. You enter that user's username and password. StackJack exchanges them at ESET's token endpoint (https://{region}.business-account.iam.eset.systems/oauth/token) for a short-lived (one-hour) access token plus a rotating refresh token, caches the access token, and rotates the refresh token automatically. There is nothing for you to refresh manually.

The access token inherits exactly the API User's access rights — everything your AI can see or change in ESET is bounded by what that API User can. A 403 from a tool means the API User lacks that specific right, not an account-wide block.

Regions

ESET Connect has no single global host — each region is a separate deployment. StackJack shows a Region dropdown (US / EU / DE / CA / JPN) that sets the base host https://{region}.esetconnect.eset.systems; every API call then targets a per-domain host derived from that region. Pick the region your ESET Business Account lives in. Choosing the wrong region fails fast at save.

Japan (JPN) region gap. The JPN deployment does not expose the quarantine family, the user-management family, or eset_list_detections (the v2 detections list; the v1 list still works). They work normally in US, EU, DE, and CA. Affected tools surface ESET's upstream not-found; there is no StackJack-side block.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In ESET: a Root or Superuser must create the dedicated user. ESET does not allow the Root/Superuser account itself to receive API access.
  • Know your region — the ESET Business Account region you'll select in StackJack.
  • Review ESET's current Create API user account, authentication, and rate-limit guidance.

Step 1 — Create a dedicated API User in ESET

  1. Sign in as the Root or Superuser to ESET Business Account, ESET MSP Administrator, or ESET PROTECT Hub.
  2. Create a separate user for StackJack. Do not use a personal administrator whose departure or password changes could interrupt the integration.
  3. Enable Integrations under that user's Access Rights (ESET Business Account / MSP Administrator) or Permissions (ESET PROTECT Hub).
  4. Assign the access rights the selected tools need: read access for reads and the corresponding write rights for devices, policies, quarantine, incidents/EDR, automation, and other actions you enable.
  5. Complete the invitation sent to the new user. For ESET PROTECT Hub, sign in as that user at least once before using the API.
  6. Record the API User's username and password.

Step 2 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Select the ESET PROTECT tile to open its details. Choose How To Connect to review the inline setup guide, or Configure to reveal the credential form in the drawer.
  3. Choose your Region from the dropdown (US / EU / DE / CA / JPN). The Instance URL field auto-fills from your choice — leave it as shown.
  4. Enter the API User Username and the API User Password.
  5. Click Save.

What happens when you save

  • The username and password are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure ESET PROTECT, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the credentials by acquiring a token and calling an ESET IAM permissions endpoint. Validation never blocks the save.
  • After saving, the form collapses and the connector drawer stays open. It shows Connected / Valid on success, or Needs Attention with Re-test and recovery guidance if validation failed.

How ESET's customer hierarchy works

ESET has no companyId parameter. The customer hierarchy is a device-group tree whose nodes carry entity types (MSP / COMPANY / SITE). Your AI enumerates companies and sites with eset_list_device_groups and manages membership through the group tools — there's no separate per-company credential to configure.

Plans and available tools

  • Free includes list/get/count/search operations across devices, device groups, detections, incidents, EDR rules, policies, quarantine, installers, executables, patches, vulnerabilities, users, and IAM.
  • Pro adds create/update/delete operations, policy assignment, quarantine restore/delete/purge, device tasks (scans, isolation, uninstall), EDR-rule and exclusion management, role assignment, and automations — plus the quarantine binary-download tools.
  • Business offers the same tool set as Pro with a higher monthly call quota.

See the generated ESET PROTECT tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

ESET has no per-user OAuth (the Connect API offers only the password grant), so there is no per-user attribution — all AI traffic authenticates as the single dedicated API User. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Safety note — malware egress. eset_download_quarantined_objects and eset_batch_download_quarantined_objects return short-lived, read-only SAS URLs to quarantined binaries in blob storage rather than plain JSON. Because those payloads are live malware samples by nature, both tools are Pro-gated. Scope your AI's access to them deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.

Rate limits

ESET publishes a limit of 10 API calls per second for each combination of API credentials, account, and originating IP. It also applies a Fair Use policy to very large bursts. StackJack uses a more conservative 300 calls per minute per tenant and records upstream 429 backoff. Other traffic sharing the same account or source IP can still contribute to ESET's limit.

Rotating or replacing the credentials

The API User's username and password are the recovery secret. If you change or reset the API User's password in ESET — or delete and recreate the API User — the stored credential becomes invalid. To restore access, open Connectors → ESET PROTECT → Configure in StackJack and enter the new password (re-select the region and username if needed), then Save.

Disconnecting ESET PROTECT

StackJack's Disconnect action removes the stored API User credential and stops future calls; it does not disable or delete that user in ESET. If the account is dedicated to StackJack and no longer needed, disable or remove it in the appropriate ESET account console as a separate, deliberate step. ESET notes that an already-issued access token can remain usable until its one-hour expiry after the user is removed. Subscription changes are separate from credential removal.

Several customers

Some MSPs need one ESET PROTECT connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.

Troubleshooting

SymptomLikely causeWhat to do
Needs Attention immediately after savingWrong region, mis-typed username/password, the invitation was not completed, Integrations is off, or a Hub user has never signed inCorrect the API User setup, update the credential, then use Re-test
Tools worked, then started failingThe API User's password was changed, or the API User was deleted, in ESETUpdate the credential in Connectors → ESET PROTECT → Configure with the current password
One tool returns a 403 while others succeedThe API User lacks the access right that tool exercisesGrant the API User the corresponding read/write right in ESET
Quarantine, user-management, or v2-detections tools return not-foundThe connector is on the JPN region, which omits those API familiesExpected in Japan; use the available families or the v1 detections list
Write or download tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the ESET PROTECT connector plan and check your tool selections on the MCP Setup page
A quarantine download link no longer worksThe SAS URL is short-lived and has expiredRe-run the download tool to mint a fresh SAS URL and fetch it promptly

ESET PROTECT tools

eset_ · 102 tools · Free 51 · Pro 51

Executables

ToolWhat it does
eset_block_executable
Pro · Write
Block an executable so it will not be executed on managed devices.
eset_get_executable
Free · Read-only
Get details of a specific executable.
eset_list_executables
Free · Read-only
List all executables observed across managed devices.
eset_unblock_executable
Pro · Destructive
Unblock a previously blocked executable so it can run again.

Groups (Asset Management)

ToolWhat it does
eset_create_group
Pro · Write
Create a static group (folder) in the asset hierarchy and receive its assigned UUID.
eset_delete_group
Pro · Destructive
Delete the group referenced by groupUuid AND every group and object beneath it — cascading and irreversible.
eset_move_group
Pro · Destructive
Move a group (and its subtree) under a different parent, reorganizing the MSP company/site tree and re-evaluating policy assignments along the new hierarchy — only within the same tenant.
eset_rename_group
Pro · Write
Change a group's display name.

Device Tasks (Automation)

ToolWhat it does
eset_create_device_task
Pro · Destructive
Create a device task that runs an action (scan / isolation / uninstall / power action) on target endpoints.
eset_delete_device_task
Pro · Destructive
Delete a device task.
eset_get_device_task
Free · Read-only
Get a single device task entity by UUID (its action, targets, and triggers).
eset_list_device_task_runs
Free · Read-only
List the run history (executions and results) of a device task, optionally scoped to one device or only the latest run per device.
eset_list_device_tasks
Free · Read-only
List all device tasks (scheduled actions run on endpoints).
eset_update_device_task_targets
Pro · Destructive
Replace the targets (which devices / device groups the task runs on) of an existing device task — re-aiming an endpoint action.
eset_update_device_task_triggers
Pro · Destructive
Replace the trigger list (when the task runs) of an existing device task.

Device Groups

ToolWhat it does
eset_list_device_group_members
Free · Read-only
List the devices that are members of a device group.
eset_list_device_groups
Free · Read-only
List all device groups.

Devices

ToolWhat it does
eset_batch_get_devices
Free · Read-only
Retrieve a specific set of devices at a consistent point in time.
eset_get_device
Free · Read-only
Get the full details of a single device.
eset_import_devices
Pro · Write
Import a batch of devices into device management (max 1000 per request).
eset_list_devices
Free · Read-only
List all managed devices, optionally filtered.
eset_move_device
Pro · Destructive
Move a device under a new parent group.
eset_rename_device
Pro · Write
Update a device's display name.

IAM (Roles & Permissions)

ToolWhat it does
eset_assign_role
Pro · Write
Assign a role to a subject over one or more scopes.
eset_create_role
Pro · Write
Create a custom role that bundles a set of permissions.
eset_delete_role
Pro · Destructive
Delete a custom role by name.
eset_list_permissions
Free · Read-only
List every permission the platform defines — the catalog you draw permissionNames from when creating a role with eset_create_role.
eset_list_role_assignments
Free · Read-only
List role assignments — which subjects (users, devices, user groups, managed identities, services) hold which roles over which scopes.
eset_revoke_role
Pro · Destructive
Remove a role from a subject over the given scopes.

Detections

ToolWhat it does
eset_batch_get_detections
Free · Read-only
Batch-retrieve detections by UUID in one atomic call (all-or-nothing).
eset_get_detection
Free · Read-only
Get a single detection by UUID (v2).
eset_get_detection_v1
Free · Read-only
Get a single detection by UUID (legacy v1 surface).
eset_list_detections
Free · Read-only
List detections (v2) matching the criteria, across device and ESET Cloud Office Protection sources.
eset_list_detections_v1
Free · Read-only
List detections (legacy v1 surface) matching the criteria.
eset_resolve_detection
Pro · Destructive
Mark a detection as resolved.

Detection Groups

ToolWhat it does
eset_get_detection_group
Free · Read-only
Get details about a single detection group by UUID.
eset_list_detection_groups
Free · Read-only
List detection groups (detections deduplicated/grouped by signature) matching the criteria.
eset_resolve_detection_group
Pro · Destructive
Mark ALL detections in a group as resolved in one call.
eset_search_detection_groups
Free · Read-only
Search detection groups with a filter expression (richer than the plain list).

EDR Rules & Exclusions

ToolWhat it does
eset_create_edr_rule
Pro · Write
Create an EDR (ESET Inspect) rule.
eset_create_edr_rule_exclusion
Pro · Destructive
Create an EDR rule exclusion.
eset_delete_edr_rule
Pro · Destructive
Delete an EDR rule permanently.
eset_delete_edr_rule_exclusion
Pro · Destructive
Delete an EDR rule exclusion permanently.
eset_disable_edr_rule
Pro · Destructive
Disable an EDR rule (stops it matching) without deleting it.
eset_enable_edr_rule
Pro · Write
Enable an EDR rule so it is used for matching.
eset_get_edr_rule
Free · Read-only
Get details of a single EDR rule by UUID.
eset_get_edr_rule_exclusion
Free · Read-only
Get details of a single EDR rule exclusion by UUID.
eset_list_edr_rule_exclusions
Free · Read-only
List EDR rule exclusions (patches that suppress one or more EDR rules' actions) matching the criteria.
eset_list_edr_rules
Free · Read-only
List EDR (ESET Inspect) rules matching the criteria, optionally filtered by severity level.
eset_update_edr_rule_definition
Pro · Destructive
Replace the XML definition of an existing EDR rule.
eset_update_edr_rule_exclusion_definition
Pro · Destructive
Replace the XML definition of an existing EDR rule exclusion.

Incidents

ToolWhat it does
eset_close_incident
Pro · Destructive
Close an incident.
eset_create_incident_comment
Pro · Write
Add a comment to an incident.
eset_delete_incident_comment
Pro · Destructive
Delete a comment from an incident permanently.
eset_get_incident
Free · Read-only
Get details of a single incident by UUID.
eset_get_incident_comment
Free · Read-only
Get a single incident comment by UUID.
eset_list_incident_comments
Free · Read-only
List all comments on a single incident, ordered by create time.
eset_list_incidents
Free · Read-only
List incidents matching an optional filter, ordered by order_by.
eset_reopen_incident
Pro · Write
Reopen a non-Open incident (sets status back to Open; assignee unchanged; a prior closing comment becomes a normal comment).
eset_update_incident_attributes
Pro · Write
Update chosen basic attributes of an incident.
eset_update_incident_comment
Pro · Write
Change the text of an existing incident comment.

Installers

ToolWhat it does
eset_create_installer
Pro · Write
Create a downloadable installer that drops components, activates products, and enrolls devices into a security group.
eset_delete_installer
Pro · Destructive
Delete an installer by UUID, invalidating its download URL.
eset_generate_installer
Pro · Write
Generate an ad-hoc GPO/SCCM-compatible configuration file for deploying the security product via Group Policy or System Center Configuration Manager.
eset_get_installer
Free · Read-only
Get details of one installer by UUID (download URL, expiry, activated products, installed components).
eset_list_installers
Free · Read-only
List the installers available to the caller (each carries a download URL and expiry).

Mobile Devices

ToolWhat it does
eset_activate_product_mobile_devices
Pro · Destructive
Create a product-activation task targeting a batch of mobile devices; the product is chosen automatically from each device's parent group.
eset_get_mobile_device_enrollment_links
Pro · Write
Generate enrollment links (valid on Android/iOS only) for a batch of up to 1000 mobile devices.

Network Access Protection

ToolWhat it does
eset_get_network_access_rule
Free · Read-only
Get details about a single IP set on a policy.
eset_list_network_access_rules
Free · Read-only
List all IP sets defined on a policy.
eset_update_network_access_rule
Pro · Destructive
Update an IP set on a policy.

Patch Management

ToolWhat it does
eset_get_patching_process_details
Free · Read-only
List device patching-process details (history of patch attempts).
eset_list_device_patch_status
Free · Read-only
List device patches (unpatched applications, packages, and operating systems).
eset_list_recent_patching_processes
Free · Read-only
List the patching details of all application patching attempts performed recently (within the last few days).

Policies

ToolWhat it does
eset_create_policy
Pro · Write
Create a policy carrying feature configurations.
eset_create_policy_assignment
Pro · Destructive
Assign a policy to a target (device, device group, or subscription).
eset_delete_policy
Pro · Destructive
Delete a policy by UUID.
eset_delete_policy_assignment
Pro · Destructive
Remove a policy assignment (unassign a policy from its target); remaining assignments on that target are reordered.
eset_get_policy
Free · Read-only
Get one policy's details (its feature configurations) by UUID.
eset_get_policy_assignment
Free · Read-only
Get one policy assignment (policy, target, and rank) by UUID.
eset_list_policies
Free · Read-only
List all policies visible to the caller.
eset_list_policy_assignments
Free · Read-only
List policy assignments (which policies are applied to which targets, and at what rank).
eset_update_policy_assignment_ranking
Pro · Destructive
Move a policy assignment to a new rank on its target (rank 1 = highest priority).

Quarantine

ToolWhat it does
eset_batch_delete_quarantined_objects
Pro · Destructive
Permanently delete a batch of quarantined objects by UUID — irreversible.
eset_batch_download_quarantined_objects
Pro · Read-only
Download a batch of quarantined objects (by UUID) as a ZIP archive.
eset_batch_restore_quarantined_objects
Pro · Destructive
Restore a batch of quarantined objects (by UUID) to their original locations — re-releases potentially-malicious files onto endpoints.
eset_count_quarantined_objects
Free · Read-only
Count quarantined objects matching the filter (same filter fields as eset_list_quarantined_objects).
eset_download_quarantined_objects
Pro · Read-only
Download quarantined objects matching a filter as a ZIP archive.
eset_get_quarantined_object
Free · Read-only
Get a single quarantined object by UUID.
eset_list_quarantined_objects
Free · Read-only
List quarantined objects (files, email messages, email attachments) matching the filter.
eset_purge_quarantined_objects
Pro · Destructive
Permanently delete every quarantined object matching a filter (criteria-based delete) — irreversible.
eset_restore_quarantined_objects_by_filter
Pro · Destructive
Restore every quarantined object matching a filter to its original location — re-releases potentially-malicious files onto endpoints.

Users

ToolWhat it does
eset_batch_get_users
Free · Read-only
Retrieve a specific set of users at a point in time (max 1000 per request).
eset_get_user
Free · Read-only
Get the details of a single user by their unique identifier.
eset_list_users
Free · Read-only
List users, optionally filtered by active-product, cloud-office, display name, email, protection status, or user group.

Vulnerabilities

ToolWhat it does
eset_list_device_os_vulnerabilities
Free · Read-only
List operating-system vulnerabilities for devices.
eset_list_device_vulnerabilities
Free · Read-only
List device vulnerabilities matching the criteria.
eset_list_recent_vulnerability_scans
Free · Read-only
List the scan details of all vulnerability scans performed recently (within the last few days).
eset_list_vulnerable_devices
Free · Read-only
List vulnerable devices matching the criteria.

Web Access Protection

ToolWhat it does
eset_list_web_address_rules
Free · Read-only
List the web-address rules on a policy, optionally narrowed to rules that reference a given domain.
eset_update_web_address_rule
Pro · Destructive
Replace all domains inside a web-address rule.

Async Continuation

ToolWhat it does
eset_resume_async
Free · Read-only
Resume any ESET operation that returned a 202 pending marker.