EDR / XDR integration

Automate Huntress Managed EDR / XDR with plain language

Read Huntress agents, incident reports and organizations, and confirm the state of a host the SOC has flagged.

What you can do

Huntress — Managed EDR Public API v1

  • List deployed agents
  • Read incident reports
  • Read managed organizations

Connection: basic authentication against https://api.huntress.io. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.

Example

Ask in plain English

Prompt: “Isolate the laptop with the latest critical detection in Huntress Managed EDR”

Result: VernacSecure SuperBot™ reads recent detections, confirms the device and isolates it, with a full audit entry.

Get started free

Read actions
  • Fetch agents — Lists deployed Huntress agents.
  • Fetch incident reports — Lists incident reports.
  • Fetch organizations — Lists managed organizations.
Write actions

This integration is read-only today. Write actions are added upstream as the vendor API exposes them.