Overview
The Huntress integration enables ThreatAware to collect read-only data from your Huntress console, providing visibility into endpoint threat detection, incidents, and security posture across your organisation.Connection Method: API Credentials
Setup Time: 15 minutes
Access Required: Huntress Account with API access
Data collected
The Huntress integration provides:- Endpoint detection and response data
- Security incidents and alerts
- Threat intelligence and behavioural analysis
- Device inventory and threat status
Use cases
Threat Detection
Monitor threats detected by Huntress across your endpoints
Incident Management
Track security incidents and response activities in Huntress
Endpoint Security
Monitor endpoint security posture and protection status
Investigation Support
Correlate Huntress threat data with device information in ThreatAware
Setup instructions
1
Log in to ThreatAware Dashboard
Open the ThreatAware dashboard and navigate to Settings > Systems.
2
Search for Huntress
In the search bar, search for “Huntress.”
- Click Connect, and a pop-up window will appear with further instructions
3
Access Huntress Account
Navigate to your Huntress account:
- Go to your-subdomain.huntress.io and log in to your account
- Replace your-subdomain with your actual Huntress subdomain
4
Access API Credentials
Generate your API keys:
- Click the profile menu in the dropdown located in the top-right corner
- Select API Credentials from the menu options
5
Generate API Key Pair
Create your API credentials:
- Click on the green Setup button to initiate the process
- You will be redirected to the API credentials page
- Click on the Generate button to create a new key pair
- A public and private key pair will be generated
- Make sure to note down both keys immediately (you won’t be able to see them again)
6
Input Credentials in ThreatAware
Return to ThreatAware:
- Copy the API Key (public key) and paste it into ThreatAware
- Copy the API Secret Key (private key) and paste it into the corresponding field
- Click the Authorize button to complete the integration
7
Verify Connection
After connecting:
- Check that the Integration Status shows as Active
- Confirm that threat data is appearing in ThreatAware
Required credentials
API Key (Public Key)
API Key (Public Key)
Field Name: Huntress API Key
Type: String
Description: The public key generated in your Huntress accountThis key identifies your integration and must be kept confidential.
API Secret Key (Private Key)
API Secret Key (Private Key)
Field Name: Huntress API Secret Key
Type: Password (encrypted)
Description: The private key generated in your Huntress accountStore this credential securely in your organisation’s password manager. This key is only displayed once during generation.
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings > Systems in ThreatAware
- Confirm the Huntress integration shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait up to 60 minutes for initial data synchronization
- Check that threat incidents and detections appear in ThreatAware
- Verify the data matches your Huntress console
-
Test Queries
- Create a test query to filter endpoints monitored by Huntress
- Verify threat detection data is being collected correctly
Troubleshooting
Invalid Credentials Error
Invalid Credentials Error
Symptoms: Integration status shows authentication failureSolutions:
- Verify both the API Key and API Secret Key are correctly entered
- Ensure neither credential has extra spaces or was truncated
- Confirm the credentials were copied from the correct API key pair
- Check if the API key has been revoked or deleted in Huntress
- Generate a new API key pair if the original is suspect
Permission Issues
Permission Issues
Symptoms: Integration connects but no threat data appearsSolutions:
- Verify the API key pair was generated from an account with appropriate permissions
- Check that your Huntress account has active threat detection enabled
- Ensure endpoints are enrolled in Huntress and sending data
- Review Huntress documentation for API access requirements
- Contact Huntress support to verify API permissions
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify the Huntress console is accessible at your subdomain
- Check firewall rules allow outbound HTTPS (443) to Huntress API endpoints
- Confirm your network connectivity is stable
- Test accessing your Huntress console directly in a browser
No Data After 1 Hour
No Data After 1 Hour
Symptoms: Integration shows active but no threat data appearsSolutions:
- Verify there are endpoints enrolled in Huntress and active
- Check that threat detection is enabled in your Huntress account
- Confirm the API key hasn’t been revoked or rotated
- Wait for the next sync cycle (typically hourly)
- Review ThreatAware integration logs for error messages
Additional resources
Huntress Console
Access your Huntress console
ThreatAware Support
Contact ThreatAware support for integration assistance