Huntress alerts, worked from the ticket.
Neo reads the incident behind a Huntress ticket and gathers the evidence before a technician opens it. With your approval, it approves the remediation, isolates the host and resolves the incident.
What Neo does with Huntress.
The alert, with its evidence
Neo reads the incident report, its findings and indicators, and the affected host. It also reads signals, managed identities, exposed ports and SIEM logs.
Containment, one approval away
Neo prepares the action: approve or reject remediations, isolate or release a host, resolve the incident. A technician approves each one before it runs.
Access rules and organizations
Neo creates travel, VPN and IP access rules, and creates, renames or removes organizations during onboarding and offboarding.
Concrete work Neo handles in Huntress.
Context before the portal
A Huntress ticket arrives. Neo pulls the incident report, its indicators and the affected host into the ticket, so the technician starts with the facts.
Host isolation on approval
Neo prepares the isolation and a technician approves it. Huntress isolates asynchronously, so Neo reports the host as contained only after Huntress confirms it.
Travel exceptions that expire
A user abroad sets off unwanted-country escalations. Neo creates a geolocation exception with an expiry date, and it ends with the trip.
Reports and invoices
Neo reads monthly, quarterly and yearly summary reports and account invoices, so QBR and reconciliation agents work from Huntress's own numbers.
Live in under an hour.
Connect, configure, go. No code, no long implementation.
Connect Huntress
An Admin generates an API key pair in the Huntress portal. Paste the public key and the secret into Neo, and Neo tests the pair before it saves.
Set access per agent
Pick Read Only, Helpdesk, IT Admin or Full Automation, or set each area yourself. Detections and Reporting & Billing are always read only.
Go live
When you enable a Huntress area on an agent, Neo adds the Huntress tool to it. Start with Read Only to see the alert context on each ticket.
Questions about the Huntress integration.
What can Neo change in Huntress?+
Only the areas you allow per agent: incidents, hosts, unwanted access rules, organizations and portal users. Detections and Reporting & Billing are read only. Neo cannot change a customer's Huntress subscription.
Which actions need technician approval?+
Isolating a host, uninstalling its Huntress agent, approving or rejecting remediations, resolving an incident or escalation, and any change to portal access always need approval. You cannot turn this off.
What credentials does Neo need?+
One Huntress API key pair covers every customer in the account. The default account key is read only. For writes, generate a user-based key for a dedicated Huntress user that holds those permissions.
How are Huntress organizations mapped to PSA companies?+
Neo matches each organization to a PSA company by name and shows the result on the Organization Mapping tab. You can map or re-map any organization by hand, and your mapping survives every sync.
Ready to wire up Huntress?
14-day free trial. No credit card. Live in under an hour, right inside your stack.