Huntress Escalations

List, retrieve, and resolve Huntress SOC escalations via API.

39|17|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill huntress-escalations
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Huntress Escalations
Source: https://github.com/wyre-technology/msp-claude-plugins/tree/main/msp-claude-plugins/huntress/huntress/skills/escalations
Command: npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill huntress-escalations

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill streamlines the process of managing high-priority notifications from the Huntress SOC, ensuring prompt review and resolution of critical security events.

Core Features & Use Cases

  • List Escalations: View open or filtered escalations from the Huntress SOC.
  • Get Escalation Details: Retrieve comprehensive information about a specific escalation, including summaries, details, and recommended actions.
  • Resolve Escalations: Mark escalations as resolved after appropriate action has been taken.
  • Use Case: When an alert comes in, use this Skill to list all open escalations, review their details, understand the recommended actions, and then resolve them once the necessary steps are completed.

Quick Start

Use the Huntress Escalations skill to list all open escalations.

Frequently Asked Questions about Huntress Escalations

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage Huntress SOC escalations for incident response?

Manage Huntress SOC escalations by listing open security notifications, retrieving detailed summaries with recommended actions, and updating their status to resolved for timely incident response.

Can I filter security escalations by organization and status?

Filter security escalations by organization and status to isolate specific critical notifications. This narrows the incident response scope, allowing targeted review of active threat management alerts within the Huntress SOC.

What details are included when retrieving a specific security escalation?

Retrieving a specific security escalation provides comprehensive information, including summaries, details, recommended actions, and related incidents, ensuring analysts have the context needed for threat management.

How do I resolve a critical security notification after taking action?

Resolve a critical security notification by updating the escalation status via API interaction after completing the recommended actions, ensuring the threat management lifecycle is closed and timely incident response is maintained.

Do I need an API connection to query and resolve Huntress escalations?

An API connection is required to query and update escalation statuses. This interaction enables listing open incidents, retrieving detailed threat management data, and resolving critical security notifications directly through the Huntress SOC.