Huntress

Overview

This document will walk you through setting up an integration with Huntress in your ImmyBot instance.

Setting up this integration allows you to:

  • Agent identification by adding an inventory script to be run against all of your endpoints
  • Importing agents from linked clients into ImmyBot
  • Mapping clients from the integration to tenants in ImmyBot
  • Getting an install token for a specific client
  • Getting the URL for an agent at the external provider’s site

Prerequisites

An active ImmyBot subscription or trial

Admin access to your Huntress account

Process

Gather Huntress Integration Information

  1. Log into your Huntress Account
  2. Click the menu drop down and select Download Agent
description
  1. Expand the Get Your Keys section of the page and copy your Account Key
  2. Create an API user with a Read-Only role
  3. Click the menu drop-down and select API Credentials
description
  1. Under User API Credentials, click Add
  2. Select the Read-Only user that was created earlier and click Create.
  3. The API Secret will only be shown once.
  4. Copy the API Key and API Secret
Note
The account API credentials can be used, but they have more permissions than necessary.

Set up the Integration with ImmyBot

  1. Navigate to Show More > Integrations
  2. Click add integration
  3. Click Huntress
  4. Change the name of the integration if desired.
  5. Input your Account Key
  6. Input API Key and API Secret
  7. Click update
  8. Toggle your capabilities (see above for more information)
  9. Toggle the enable integration switch
  10. Click on the Clients tab to link your SentinelOne Sites to your ImmyBot tenants
Note

While Huntress can be installed without linking clients, as the install script will fall back to the ImmyBot Tenant name if the client is not linked and the deployment parameter is configured to allow that fallback. Other functionality will not be available if the client is not linked. This does mean you can install the Huntress agent using ImmyBot and then link the client in the integration afterwards with the suggested mappings.

Was this article helpful?

Previous Article

SentinelOne