Huntress
Purpose
Synchronizes managed endpoints, organizations, incident reports, and console access from Huntress so EDR inventory and detections appear alongside the rest of your environment.
tip
Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.
Required Fields
| Field | Secret? | Description |
|---|---|---|
huntress_api_key |
Yes | Huntress account API key: its AWS Secrets Manager ARN, or the value pasted into the vault |
huntress_api_secret |
Yes | Huntress API secret key: its AWS Secrets Manager ARN, or the value pasted into the vault |
huntress_base_uri |
No | Huntress API base URI (default https://api.huntress.io) |
Setup Steps
- Sign in to the Huntress console and open Account → API Credentials.
- Select Setup, then Generate.
- Copy both values immediately. Huntress only displays the secret key during generation.
- In SubImage, set
huntress_api_keyandhuntress_api_secret, then save the module.
Notes
- The sync is read-only. The credential needs read access to the account, organizations, agents, and incident reports.
- Membership access is optional. Without it, Huntress users and roles are skipped while the rest of the module continues to sync.
- Huntress agents can contribute to canonical
Devicenodes.
Troubleshooting
Sync fails with 401. Generate a new API key and secret key pair, then update both fields in SubImage.
Users and roles are missing. Grant the API credential permission to list memberships.