Huntress
Huntress is a managed endpoint detection and response (EDR) platform. This connector brings in the devices that have the Huntress agent installed, and, if your account includes Huntress identity threat detection (ITDR), the Microsoft 365 / Google Workspace identities it monitors, across every organization in your Huntress account.
Beta. This connector was built from Huntress’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact [email protected].
At a glance
| Data provided | Devices, Users |
|---|---|
| Authentication | API Key + API Secret (HTTP Basic) |
| Where to configure | Connectors → Add a Connector → Huntress |
Required permissions
Navigator only reads the agent and identity lists. Create the credential for a dedicated, read-only Huntress user rather than an individual’s admin account: a Huntress User API Credential mirrors the permissions of the user it is created for, so a read-only user keeps the key read-only, and a shared integration user means the connection won’t break if an individual leaves.
Huntress also offers a single account-level API key. Huntress has deprecated it in favor of user credentials, so prefer a user credential.
Setup
- Sign in to the Huntress portal as a user with Admin privileges.
- Open the menu (top right) and choose API Credentials.
- In the User API Credentials section, click Add.
- Select the user the credential is for (see above) and give it a descriptive name, such as
Navigator. - Copy the API Key and API Secret. Store the secret somewhere safe — treat it like a password.
- In Navigator, go to Connectors → Add a Connector → Huntress.
- Enter the API Key and API Secret, then save. Navigator validates the credentials and enqueues a first sync immediately.
Huntress’s own guide: Generating API Keys.
What data this connector provides
-
Devices: every Huntress agent, including hostname, serial number, operating system (Windows releases are told apart by build number), internal and external IP addresses, MAC addresses, and the time Huntress last heard from the device.
-
Users: every identity Huntress monitors (ITDR), with its username, email, whether it is enabled, and whether MFA is enabled.
Known limitations
- Huntress limits each account to 60 API requests per minute. Navigator fetches 500 devices per request, so this is not a concern in practice.
- Users only appear if your Huntress account is licensed for identity threat detection (ITDR). Without it, Huntress refuses the request; Navigator records a note and syncs devices normally rather than showing an error.
- Guest/external status, risk level and password age are not shown in Navigator yet.
- Huntress agent tags, organization names, and security status (EDR, Defender, firewall, tamper protection) are not shown in Navigator yet.