Endpoint security data in Recapp is used for coverage analysis. Recapp does not modify threat policies, quarantine files, or take any action inside your security platforms.
Available endpoint security integrations
SentinelOne
SentinelOne
Syncs: Agents, Threats, Applications, PoliciesSentinelOne connects via a management console API token. Recapp syncs your SentinelOne sites and their associated agents to give you full visibility into endpoint coverage.Required credentials
Huntress
Huntress
Syncs: Organizations, AgentsHuntress is a managed detection and response (MDR) platform. Recapp connects via the Huntress API using a key and secret pair to sync your organizations and their agents.Required credentials
Sophos Central
Sophos Central
Syncs: Tenants, EndpointsSophos Central uses an OAuth 2.0 client credentials flow scoped to your MSP partner account. Recapp syncs your managed tenants and their associated endpoints.Required credentials
After a successful connection test, Recapp displays the detected account type, account ID, and data region. Confirm these match your Sophos Central partner account before saving.
Webroot
Webroot
Syncs: Endpoints, Threats, Console UsersWebroot connects via the Webroot Unity API, which requires five separate credentials: a login email, password, OAuth client ID, client secret, and a GSM keycode.Required credentials
ThreatLocker
ThreatLocker
Syncs: Agents, Sites, PoliciesThreatLocker is a zero-trust endpoint security platform. Recapp connects via the ThreatLocker Portal API using an API token. You can optionally specify your portal instance to target the correct regional endpoint.Required credentials
Field Effect
Field Effect
Syncs: Accounts, Endpoints, ThreatsField Effect is a managed security service. Recapp connects with a single API key to sync your accounts and their associated endpoints.Required credentials
Datto EDR
Datto EDR
Syncs: Locations, AgentsDatto EDR (formerly Infocyte) is an endpoint detection and response platform. Recapp connects via the Datto EDR API using a URL and API key.Required credentials
The API URL varies by Datto EDR instance. If you are on a custom or regional instance (e.g. an
.infocyte.com subdomain), use that instance’s /api endpoint instead of the default.Zorus
Zorus
Syncs: Customers, EndpointsZorus provides DNS filtering and web security for MSPs. Recapp connects via the Zorus API using a single API token to sync your customers and their associated endpoints.Required credentials