{"_id":"@avantguardllc/mcp-huntress","_rev":"7-65fa1a771d9187b6c143919a30cb1b50","name":"@avantguardllc/mcp-huntress","dist-tags":{"latest":"1.0.6"},"versions":{"1.0.0":{"name":"@avantguardllc/mcp-huntress","version":"1.0.0","license":"MIT","_id":"@avantguardllc/mcp-huntress@1.0.0","maintainers":[{"name":"avantguardllc","email":"appadmin@avantguard.it"}],"bin":{"mcp-huntress":"dist/index.js"},"dist":{"shasum":"8659d84906cfcbd9bfcf35a26cebd82889672bb1","tarball":"https://registry.npmjs.org/@avantguardllc/mcp-huntress/-/mcp-huntress-1.0.0.tgz","fileCount":62,"integrity":"sha512-pXIId5D7q+QOR46ESBYqIpTZC4uVv4D487Xr5U+6UjTcRj3Wpehaerkkwv/DduuHK6e7hHSk1hL/Wpm0+VdJnw==","signatures":[{"sig":"MEYCIQCbIt1cvLREfrAbc2bxJ14J0u6goYddiVs7I8PXxC76mgIhALNORAolfflfBoHrG2a3dCPtT60Z5Fm1TEf6S8ediopZ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":80140},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"2887e37c5921241c325c69378b0e015d1e0dabad","scripts":{"dev":"tsc --watch","build":"tsc","clean":"rm -rf dist","start":"node dist/index.js","start:http":"MCP_TRANSPORT=http node dist/index.js"},"_npmUser":{"name":"avantguardllc","email":"appadmin@avantguard.it"},"_npmVersion":"10.8.2","description":"Huntress MCP server with decision tree architecture for Claude","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@modelcontextprotocol/sdk":"^1.12.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.3","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-huntress_1.0.0_1779902647321_0.1997312646300362","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@avantguardllc/mcp-huntress","version":"1.0.1","license":"MIT","_id":"@avantguardllc/mcp-huntress@1.0.1","maintainers":[{"name":"avantguardllc","email":"appadmin@avantguard.it"}],"bin":{"mcp-huntress":"dist/index.js"},"dist":{"shasum":"d53b721c3f7d7f4f2716c3b878e9aad6a78cd8d3","tarball":"https://registry.npmjs.org/@avantguardllc/mcp-huntress/-/mcp-huntress-1.0.1.tgz","fileCount":63,"integrity":"sha512-3XiyFEuDTteWUxyXcoLvVxkJFoaEuOiYRenUbU00/Hu64rCFyJdW+L6ioDabYIt+ufdzx0zKmOh8jQkuwzZnNQ==","signatures":[{"sig":"MEUCID0myIydEOy4qRgMysng/Hh1qR3PtkGr7/Uz5EWndV5dAiEAur0Tcs4Yv8yrid6k9pjtHWHyD9HE5JY2eIxHPX1k24E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":84273},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"718610bd43a8cb1e8aec99205f73905a5ea01506","scripts":{"dev":"tsc --watch","build":"tsc","clean":"rm -rf dist","start":"node dist/index.js","start:http":"MCP_TRANSPORT=http node dist/index.js"},"_npmUser":{"name":"avantguardllc","email":"appadmin@avantguard.it"},"_npmVersion":"10.8.2","description":"Huntress MCP server with decision tree architecture for Claude","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@modelcontextprotocol/sdk":"^1.12.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.3","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-huntress_1.0.1_1779903292748_0.7320141427328226","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@avantguardllc/mcp-huntress","version":"1.0.2","license":"MIT","_id":"@avantguardllc/mcp-huntress@1.0.2","maintainers":[{"name":"avantguardllc","email":"appadmin@avantguard.it"}],"bin":{"mcp-huntress":"dist/index.js"},"dist":{"shasum":"11666a3ff70cd7ffb970744d9ebf4b52eeb650b6","tarball":"https://registry.npmjs.org/@avantguardllc/mcp-huntress/-/mcp-huntress-1.0.2.tgz","fileCount":63,"integrity":"sha512-9ke3Npu+07El7ocYUYptTpupRw0qPksbjmbTXdOjCFPG8Wk7zpQyeCNNfhqCjT4nHgJwIR+wPg+hlytmBZVdmg==","signatures":[{"sig":"MEUCIBEGANYzvB/EmLg5n0rYL8Fwt7eX7jGS9E0oWWyIT1sTAiEAmUIH4xj3t9EH5JcK11RBqigJPcIzdZ8GFcJNe+7+j38=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":88197},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"fca311aeccf90f69b824a96c1d09630e9c3a57cd","scripts":{"dev":"tsc --watch","build":"tsc","clean":"rm -rf dist","start":"node dist/index.js","start:http":"MCP_TRANSPORT=http node dist/index.js"},"_npmUser":{"name":"avantguardllc","email":"appadmin@avantguard.it"},"_npmVersion":"10.8.2","description":"Huntress MCP server with decision tree architecture for Claude","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@modelcontextprotocol/sdk":"^1.12.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.3","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-huntress_1.0.2_1779903878319_0.7094886955094619","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@avantguardllc/mcp-huntress","version":"1.0.3","license":"MIT","_id":"@avantguardllc/mcp-huntress@1.0.3","maintainers":[{"name":"avantguardllc","email":"appadmin@avantguard.it"}],"bin":{"mcp-huntress":"dist/index.js"},"dist":{"shasum":"0e35075124967758d2b20ef17355a22c1659fe39","tarball":"https://registry.npmjs.org/@avantguardllc/mcp-huntress/-/mcp-huntress-1.0.3.tgz","fileCount":79,"integrity":"sha512-xWodDn/58sCslQJhRyYTpbEznuxoZ03poHNHecopja7vyXK6WP8qAU0b4ZtvVKrMRTOwPmFrpSlHdnO65zXfjA==","signatures":[{"sig":"MEUCIBWsalRr4Xl2/1etZpj8CEGBTjKTuJTXJ24tn5rrf3ItAiEAlAg7GjwqyBMCBK/yzGLFPGgWlUaCAPT+idf00aSX8GY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":134882},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"fca311aeccf90f69b824a96c1d09630e9c3a57cd","scripts":{"dev":"tsc --watch","build":"tsc","clean":"rm -rf dist","start":"node dist/index.js","start:http":"MCP_TRANSPORT=http node dist/index.js"},"_npmUser":{"name":"avantguardllc","email":"appadmin@avantguard.it"},"_npmVersion":"10.8.2","description":"Huntress MCP server with decision tree architecture for Claude","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@modelcontextprotocol/sdk":"^1.12.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.3","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-huntress_1.0.3_1779909530361_0.27595705213922783","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@avantguardllc/mcp-huntress","version":"1.0.4","license":"MIT","_id":"@avantguardllc/mcp-huntress@1.0.4","maintainers":[{"name":"avantguardllc","email":"appadmin@avantguard.it"}],"bin":{"mcp-huntress":"dist/index.js"},"dist":{"shasum":"a193b8ae91e9fa11572aaa43980c1244c8c121b6","tarball":"https://registry.npmjs.org/@avantguardllc/mcp-huntress/-/mcp-huntress-1.0.4.tgz","fileCount":79,"integrity":"sha512-68PyGRCm06Nl6z5VMoYCVGyYkortRmp6c4Gduj2C8TMEX2uECX2Mn3IleyqiFAfS3OuAzg4XEVl4+7uaEcb+9Q==","signatures":[{"sig":"MEUCIBCVpYgAKpoFmOq0NUajsFOZjYQphMY+Y9dkDtSARRN3AiEAq8y2Fb6rJRpuhWbOWUp5BiROb6ggoWjLga5H9ROyj/k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":137621},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"07a185e5b4596148c8307e9779c16e78e6fe63f7","scripts":{"dev":"tsc --watch","build":"tsc","clean":"rm -rf dist","start":"node dist/index.js","start:http":"MCP_TRANSPORT=http node dist/index.js"},"_npmUser":{"name":"avantguardllc","email":"appadmin@avantguard.it"},"_npmVersion":"10.8.2","description":"Huntress MCP server with decision tree architecture for Claude","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@modelcontextprotocol/sdk":"^1.12.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.3","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-huntress_1.0.4_1779909865268_0.5522503123518794","host":"s3://npm-registry-packages-npm-production"}},"1.0.5":{"name":"@avantguardllc/mcp-huntress","version":"1.0.5","license":"MIT","_id":"@avantguardllc/mcp-huntress@1.0.5","maintainers":[{"name":"avantguardllc","email":"appadmin@avantguard.it"}],"bin":{"mcp-huntress":"dist/index.js"},"dist":{"shasum":"1f49e38511c9a056d7628477f7ff27fa80ea6447","tarball":"https://registry.npmjs.org/@avantguardllc/mcp-huntress/-/mcp-huntress-1.0.5.tgz","fileCount":87,"integrity":"sha512-CGqTcfukxJdzNzlPpYEx7r29MEbiGg9TCSohVBZkaV3Yu2uOgpQ8rIEaAOMKhdTMY6OEx+bpMm/pR1uDVEtncQ==","signatures":[{"sig":"MEQCIEApk42XpXFYCQ4mHv/CKin8D/o8PtW3WCCxDiM4Kx2KAiBhgiHDzyrpx+prfVEJn4rhIrhAHIX6Wy6wmaiNgsq0Gw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":154796},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"02503f47152983431718e844dd243cb1487e274e","scripts":{"dev":"tsc --watch","build":"tsc","clean":"rm -rf dist","start":"node dist/index.js","start:http":"MCP_TRANSPORT=http node dist/index.js"},"_npmUser":{"name":"avantguardllc","email":"appadmin@avantguard.it"},"_npmVersion":"10.8.2","description":"Huntress MCP server with decision tree architecture for Claude","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@modelcontextprotocol/sdk":"^1.12.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.3","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-huntress_1.0.5_1779910973660_0.00793918184150133","host":"s3://npm-registry-packages-npm-production"}},"1.0.6":{"name":"@avantguardllc/mcp-huntress","version":"1.0.6","description":"Huntress MCP server with decision tree architecture for Claude","type":"module","main":"dist/index.js","types":"dist/index.d.ts","bin":{"mcp-huntress":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js","start:http":"MCP_TRANSPORT=http node dist/index.js","dev":"tsc --watch","clean":"rm -rf dist"},"dependencies":{"@modelcontextprotocol/sdk":"^1.12.0"},"devDependencies":{"typescript":"^5.3.3","@types/node":"^20.0.0"},"engines":{"node":">=20.0.0"},"license":"MIT","_id":"@avantguardllc/mcp-huntress@1.0.6","gitHead":"f09b4d716eccb700efb0ca345fd6dd4d4aa2d0f5","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-0JigmlcGl8+Xi1DtGgFF2qz7DXMC1gn+bhz82xRgyRc5/QrzzHQk/J7K8ehzVs7rR4XpQUU8ksyix3gFKZWLTw==","shasum":"fe675571fa6615110546adbfe750d1ca43efb852","tarball":"https://registry.npmjs.org/@avantguardllc/mcp-huntress/-/mcp-huntress-1.0.6.tgz","fileCount":87,"unpackedSize":155567,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDOeO8ndnfe92PMxUQGF671IaNzGrXh9SWGI1+RvRUHbAIhAJwpyNgyuup2GcKofJObpLswuBt6yi2916JlR/j3GPHX"}]},"_npmUser":{"name":"avantguardllc","email":"appadmin@avantguard.it"},"directories":{},"maintainers":[{"name":"avantguardllc","email":"appadmin@avantguard.it"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-huntress_1.0.6_1779916022820_0.4167359652683551"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-27T17:24:07.203Z","modified":"2026-05-27T21:07:03.080Z","1.0.0":"2026-05-27T17:24:07.453Z","1.0.1":"2026-05-27T17:34:52.888Z","1.0.2":"2026-05-27T17:44:38.478Z","1.0.3":"2026-05-27T19:18:50.555Z","1.0.4":"2026-05-27T19:24:25.424Z","1.0.5":"2026-05-27T19:42:53.833Z","1.0.6":"2026-05-27T21:07:02.973Z"},"license":"MIT","description":"Huntress MCP server with decision tree architecture for Claude","maintainers":[{"name":"avantguardllc","email":"appadmin@avantguard.it"}],"readme":"# Huntress MCP Server\n\nA Model Context Protocol (MCP) server for interacting with the Huntress security platform, featuring a decision tree architecture for efficient tool loading.\n\n## Architecture\n\nThis MCP server uses a **hierarchical tool loading approach** instead of exposing all tools upfront:\n\n1. **Navigation Phase**: Initially exposes only a navigation tool (`huntress_navigate`)\n2. **Domain Selection**: User selects a domain from the 14 available domains\n3. **Domain Tools**: Server exposes domain-specific tools after selection\n4. **Lazy Loading**: Domain handlers are loaded on-demand\n\nThis architecture provides:\n- Reduced cognitive load (fewer tools to choose from)\n- Faster initial load times\n- Better organization of related operations\n- Clear navigation state\n\n## Installation\n\n```bash\nnpm install @avantguardllc/mcp-huntress\n```\n\n## Configuration\n\nSet the following environment variables:\n\n| Variable | Required | Description |\n|----------|----------|-------------|\n| `HUNTRESS_AUTH_HEADER` | One of | Pre-encoded Authorization header value, including the `Basic ` prefix (e.g. `Basic dXNlcjpwYXNz`). Use this when you already have the header available from another service. |\n| `HUNTRESS_API_KEY` | these | Huntress API Key — combined with `HUNTRESS_API_SECRET` to build `Basic base64(key:secret)` automatically. |\n| `HUNTRESS_API_SECRET` | two | Huntress API Secret — required when using `HUNTRESS_API_KEY`. |\n\n## Usage\n\n### Running Standalone\n\n```bash\n# Option A: pre-encoded auth header (includes \"Basic \" prefix)\nexport HUNTRESS_AUTH_HEADER=\"Basic <your-base64-encoded-key:secret>\"\n\n# Option B: raw key + secret\nexport HUNTRESS_API_KEY=\"your-api-key\"\nexport HUNTRESS_API_SECRET=\"your-api-secret\"\n\n# Run the server\nnpx @avantguardllc/mcp-huntress\n```\n\n### Claude Desktop Configuration\n\nAdd to your Claude Desktop `claude_desktop_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"huntress\": {\n      \"command\": \"npx\",\n      \"args\": [\"@avantguardllc/mcp-huntress\"],\n      \"env\": {\n        \"HUNTRESS_API_KEY\": \"your-api-key\",\n        \"HUNTRESS_API_SECRET\": \"your-api-secret\"\n      }\n    }\n  }\n}\n```\n\n### Docker\n\n```bash\ndocker run -e HUNTRESS_API_KEY=*** -e HUNTRESS_API_SECRET=*** ghcr.io/avantguardllc/mcp-huntress\n```\n\n## Available Domains\n\n### Accounts\nView current account info and manage sub-accounts.\n\nTools:\n- `huntress_get_current_account` - Get details for the authenticated account\n- `huntress_list_accounts` - List all accounts accessible to the API key\n- `huntress_get_account` - Get details for a specific account\n- `huntress_create_account` - Create a new account\n- `huntress_update_account` - Update an existing account\n- `huntress_delete_account` - Delete an account\n\n### Actor\nGet information about the authenticated API key owner.\n\nTools:\n- `huntress_get_actor` - Get the current authenticated actor (API key owner info)\n\n### Agents\nView and manage Huntress agents installed on endpoints.\n\nTools:\n- `huntress_list_agents` - List agents with optional filters\n- `huntress_get_agent` - Get details for a specific agent\n\n### Escalations\nView escalated threats requiring attention.\n\nTools:\n- `huntress_list_escalations` - List escalations\n- `huntress_get_escalation` - Get details for a specific escalation\n- `huntress_resolve_escalation` - Mark an escalation as resolved\n\n### External Ports\nView external ports detected across endpoints.\n\nTools:\n- `huntress_list_external_ports` - List external ports with optional filters\n- `huntress_get_external_port` - Get details for a specific external port entry\n\n### Identities\nManage identities tracked by Huntress identity protection.\n\nTools:\n- `huntress_list_identities` - List identities with optional filters (org, tenant type, risk level, MFA status, etc.)\n- `huntress_get_identity` - Get details for a specific identity\n\n### Incidents\nView and manage security incident reports and remediations.\n\nTools:\n- `huntress_list_incidents` - List incident reports with optional filters\n- `huntress_get_incident` - Get details for a specific incident report\n- `huntress_resolve_incident` - Mark an incident report as resolved\n- `huntress_list_remediations` - List remediations for an incident report\n- `huntress_get_remediation` - Get details for a specific remediation\n- `huntress_bulk_approve_remediations` - Bulk approve remediations for an incident\n- `huntress_bulk_reject_remediations` - Bulk reject remediations for an incident\n\n### Invoices\nView invoices and billing for the current account.\n\nTools:\n- `huntress_list_invoices` - List invoices with optional filters\n- `huntress_get_invoice` - Get details for a specific invoice\n\n### Memberships\nManage agent/organization membership associations.\n\nTools:\n- `huntress_list_memberships` - List memberships with optional filters\n- `huntress_create_membership` - Create a new membership\n- `huntress_get_membership` - Get details for a specific membership\n- `huntress_update_membership` - Update a membership\n- `huntress_delete_membership` - Delete a membership\n\n### Organizations\nManage organizations (clients) in Huntress.\n\nTools:\n- `huntress_list_organizations` - List all organizations\n- `huntress_get_organization` - Get details for a specific organization\n- `huntress_create_organization` - Create a new organization\n- `huntress_update_organization` - Update an existing organization\n- `huntress_delete_organization` - Delete an organization\n\n### Reports\nRetrieve summary and detail reports.\n\nTools:\n- `huntress_list_reports` - List available reports\n- `huntress_get_report` - Get details for a specific report\n\n### Reseller\nManage reseller invoices, subscriptions, and usage.\n\nTools:\n- `huntress_list_reseller_invoices` - List reseller invoices\n- `huntress_get_reseller_invoice` - Get details for a specific reseller invoice\n- `huntress_list_reseller_invoice_account_usage` - List account usage line items for a reseller invoice\n- `huntress_list_reseller_invoice_org_usage` - List organization usage line items for a reseller invoice\n- `huntress_list_reseller_subscriptions` - List reseller subscriptions\n- `huntress_get_reseller_subscription` - Get details for a specific subscription\n- `huntress_create_reseller_subscription` - Create a new subscription\n- `huntress_update_reseller_subscription` - Update a subscription\n- `huntress_upgrade_reseller_subscription` - Upgrade a subscription\n\n### SIEM\nQuery SIEM event data in Huntress.\n\nTools:\n- `huntress_siem_query` - Query SIEM data/events with filters (query string, time range, organization)\n\n### Signals\nView threat detection signals.\n\nTools:\n- `huntress_list_signals` - List signals with optional filters\n- `huntress_get_signal` - Get details for a specific signal\n\n### Known VPNs\nList VPN providers tracked by Huntress, used in conjunction with unwanted access rules.\n\nTools:\n- `huntress_list_known_vpns` - List known VPN providers tracked by Huntress\n\n### Unwanted Access Rules\nManage rules that define conditions under which access is considered unwanted (e.g., logins from specific countries or VPN providers).\n\nTools:\n- `huntress_list_unwanted_access_rules` - List unwanted access rules with optional filters\n- `huntress_get_unwanted_access_rule` - Get details for a specific unwanted access rule\n- `huntress_create_unwanted_access_rule` - Create a new unwanted access rule\n- `huntress_update_unwanted_access_rule` - Update an existing unwanted access rule\n- `huntress_delete_unwanted_access_rule` - Delete an unwanted access rule\n\n## Navigation Tools\n\nAlways available:\n- `huntress_navigate` - Select a domain to work with\n- `huntress_status` - Show current state and credential status\n- `huntress_back` - Return to main menu (when in a domain)\n\n## Example Workflow\n\n```\nUser: Check my security incidents\nClaude: [calls huntress_navigate with domain=\"incidents\"]\n       -> Navigated to incidents domain. Available tools: ...\n\nUser: List open incidents\nClaude: [calls huntress_list_incidents]\n       -> [incident list results]\n\nUser: Now show me agents\nClaude: [calls huntress_back]\n       -> Navigated back to main menu.\n       [calls huntress_navigate with domain=\"agents\"]\n       -> Navigated to agents domain.\n```\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}