Don’t let overlooked obligations become incidents. Learn how.
Utility navigation bar redirect icon
Portal LoginSupportContact
Search
Close search
Huntress Logo in Teal
  • Platform Overview
    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Managed ESPM

    Proactively secure endpoints against attacks.

    Managed ESPM

    Proactively secure endpoints against attacks.

    Integrations
    Integrations
    Support Documentation
    Support Documentation
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
  • Threats We Stop
    Phishing
    Phishing
    Business Email Compromise
    Business Email Compromise
    Ransomware
    Ransomware
    Infostealers
    Infostealers
    View Allright arrowView Allright arrow
    Industries We Serve
    Education
    Education
    Financial Services
    Financial Services
    State and Local Government
    State and Local Government
    Healthcare
    Healthcare
    Law Firms
    Law Firms
    Manufacturing
    Manufacturing
    Utilities
    Utilities
    View Allright arrowView Allright arrow
    Tailored Solutions
    MSPs
    MSPs
    Resellers
    Resellers
    SMBs
    SMBs
    Compliance
    Compliance
    What Gets Overlooked Gets Exploited

    Most days, nothing happens. But one day, something will.

    Huntress Cybersecurity
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
  • Pricing
  • Community Series
    The Product Lab

    Shape the next big thing in cybersecurity together.

    The Product Lab

    Shape the next big thing in cybersecurity together.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    Resources
    Upcoming Events
    Upcoming Events
    Ebooks
    Ebooks
    On-Demand Webinars
    On-Demand Webinars
    Videos
    Videos
    Whitepapers
    Whitepapers
    Datasheets
    Datasheets
    Cybersecurity Education
    Cybersecurity 101
    Cybersecurity 101
    Cybersecurity Guides
    Cybersecurity Guides
    Threat Library
    Threat Library
    Real Tradecraft, Real Results
    Real Tradecraft, Real Results
    2026 Cyber Threat Report
    2026 Cyber Threat Report
    The Huntress Blog
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
  • Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    The Huntress SOC

    24/7 Security Operations Center

    The Huntress SOC

    24/7 Security Operations Center

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Community

    Get in touch with the Huntress Community team

    Community

    Get in touch with the Huntress Community team

    Compare Huntress
    Bitdefender
    Bitdefender
    Blackpoint
    Blackpoint
    Breach Secure Now!
    Breach Secure Now!
    Crowdstrike
    Crowdstrike
    Datto
    Datto
    SentinelOne
    SentinelOne
    Sophos
    Sophos
    Compare Allright arrowCompare Allright arrow
  • HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    Partners
    MSPs

    Join our partner community to deliver expert-led managed security.

    MSPs

    Join our partner community to deliver expert-led managed security.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Tech Alliances

    Driving innovation through global technology Partnerships

    Tech Alliances

    Driving innovation through global technology Partnerships

    Microsoft Partnership

    A Level-Up for Your Business Security

    Microsoft Partnership

    A Level-Up for Your Business Security

  • Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Awards
    Awards
    Contact Us
    Contact Us
  • Portal Login
  • Support
  • Contact
  • Search
  • Get a Demo
  • Start for Free
Portal LoginSupportContact
Search
Close search
Get a Demo
Start for Free
HomeBlog
Clearing the Air: Huntress Myths and Misconceptions
Published:
October 27, 2022

Clearing the Air: Huntress Myths and Misconceptions

By:
James Mason
Share icon
Glitch effectGlitch effectGlitch effect

They’re saying what about us?!

We’ve seen some pretty interesting points of view on how we do what we do and why, specifics around our technology and the capabilities we possess.

With all the time we spend investigating intrusions, reverse engineering malware, hunting for bad actors and generally trying to make the security world a safer place, it may be hard – especially if you’re new here – to put your finger on what Huntress does and how we do it.

We wanted to set the record straight in true Huntress fashion – complete transparency – so here we go!

What Even Is a “Huntress”?

In the interest of fair play, we’d like to note some of the misconceptions and myths floating around to provide clarity on what we actually do.

Huntress exists to help secure the 99% – the small and medium-sized businesses that lack the resources to properly defend themselves against today’s cyber threats.

What We Offer

Huntress provides managed endpoint protection in The Huntress Managed Security Platform by leveraging endpoint detection and response (EDR).

We use human operators who investigate cybersecurity threats and categorize the threats. Then, our 24/7 Security Operations Center (SOC) provides granular, tailored remediation guidance that often consists of a single click of a button within the Huntress dashboard. Finally, we send a report to our partners and customers detailing the incident at hand.

We also recently acquired a security awareness training platform to protect – and educate – the 99%.

The Myths

Now you’ve got a good idea of what it is we do, let’s take a look at some of the things we’ve heard through the grapevine.

Myth #1: Huntress can't do anything without other cybersecurity products picking stuff up first.

One component of the Huntress suite of tools – Managed Antivirus – leverages Microsoft Defender to notify analysts of threats that have been quarantined. The other tools in our arsenal don’t have the same contingency, but let’s not sleep on Managed AV. Kyle Hanslovan, Annie Ballew and Matt Anderson have shared how Huntress’ Managed AV has thwarted advanced threat actors.

Whilst Managed AV is pretty good, it isn’t perfect. Having antivirus by itself isn’t enough; monitoring and detecting capabilities are essential in today’s security landscape. With the addition of Managed EDR – Huntress’ own EDR solution—into our platform, we can see all types of attacks and follow a threat actor as they (attempt to) progress along the cyber kill chain. Whether an adversary is in their discovery phase and attempting to enumerate the Active Directory or trying to escalate their privileges, Managed EDR sees it all.  

In a Summer 2022 webinar, Ed Murphy, Josh Lambert and Sharon Martin shared the Managed EDR journey. For the curious reader, you’ll also find that this webinar shines the light on real security intrusions that Managed EDR has empowered the Huntress SOC team to solve.

And moreover, the Huntress bread and butter was and is our footholds tooling. Our detections, alerts and reports for persistence are homegrown with no dependencies on other security products. This is also true for our Ransomware Canary tools. 

Our External Recon tooling reveals an organization's external network perimeter, highlighting external ports and services. Analysts can gently nudge a partner or customer when they maybe have an undesirable port open to the internet they maybe don’t want exposed (I’m looking at you, RDP!).

Myth #2: Huntress does nothing to keep RMM/IT tools safe and secure.

We served as a helping hand in a particularly nasty RMM tool vulnerability in July 2021, identifying first and working with the vendor and the MSP community to help keep systems safe. 

Now, this isn’t something our toolset does as a standard. This was a moment of Huntress seeing an issue and deciding we should step in and help out as we had the expertise to do so.

One thing we pride ourselves on is our community-driven mindset, so just because our tools aren’t specifically built to look into vulnerabilities in RMM/IT tools, you can bet that we’ll be right there should any future issues like the one we saw happen again. That’s just Huntress; we can’t help ourselves… Living in the shadows so you don’t have to! #ShadyByNature

Myth #3: There is no automated ransomware response built into the product.

Ransomware is all the way at the end of the cyber kill chain. A ransomware actor has to pull a ton of prior moves in a network before they make this impact. And the entire time they’re doing that, Huntress is monitoring, working with you to neutralize the security threat. Host Isolation allows us to undermine an adversarial campaign before it can materialize into a business risk.

Isolation can scale easily to include a single machine or the entire organization. In addition, partners and customers can tag specific machines so that mass isolation does not affect those tagged machines. To prevent a threat actor in the midst of deploying ransomware, for example, it has been incredibly useful to mass-isolate all machines in the domain, denying the adversary their goal of extortion. 

As part of our ransomware-related suite of tools, we deploy canary files to alert us to a malicious encryption event (think of the analogy 'canary in a coal mine'—same principle).

We don’t allow anything to automatically trigger isolation. This is always instigated by a SOC analyst, who will have assessed the validity of the canary alert before quarantining the machine. Isolation denies the ransomware further propagation and ejects the threat actor from connecting to that machine.

For the curious reader, we do not automate isolation for various reasons, the chief being that false positives can trigger from the activities of legitimate, authorized encryption solutions (like Microsoft EFS). We aren’t in the business of quarantining machines for no good reason! 

Myth #4: Huntress can't capture fileless attacks on endpoints.

Huntress Managed EDR once again can work on both file-based and fileless malwares, like Kovter malware, for example. Nearly everything a computer does has to be initiated through a process; we cast a wide net with Managed EDR. But let's take a step back and get a little nerdy and specific here about the fileless myth.

Whether something 'touches disk' in the form of a file, or stays in memory, it's immaterial to Managed EDR. Managed EDR is monitoring the computer's processes and doesn't rely on Windows event logs, or file system monitoring, or anything else of the kind. 

And, whilst we're at it, what do members of the community mean when they say fileless?

Fileless malware may compile once it reaches the machine, or never compile and stay in memory, or use the Windows Registry as a staging ground. Harlan Carvey, a leading practitioner of digital forensics and incident response, has noted that when some in the community discuss supposed ‘fileless’ malware, they often do not realize the contradiction that the Windows Registry is still a file on the operating system. 

All of this is to say, Huntress Managed EDR has your back regardless of the file form of the threat. 😉

Myth #5: Huntress just uses machine learning and AI. A real human doesn't send the reports!

What in tarnation! 

Huntress definitely deploys infrastructure automation to streamline detections and evidence collection—like single-click buttons to collect Windows Event Logs when we have a really complex investigation.

However, for all of our streamlining, the 24/7 SOC team still investigates, contextualizes, drafts and sends reports. The Huntress team consists of analysts based in America, Australia and the UK, and many of the team share their very manual, very non-machine-learning approaches to security investigations:

  • Detection engineer Matthew Brennan had a wildly popular post about dissecting Cobalt Strike
  • Senior analyst Matt Anderson has shared firsthand real world evidence from intrusions he’s worked
  • Analyst Tim Kasper has a blog post sharing his MANUAL method behind unraveling a PowerShell reverse shell
  • Analyst Molly N. has shared her manual method behind unraveling Cobalt Strike in her PonchoSec blog
  • Sr. Director of SOC Max Rogers has shared insight from real threat patterns we have identified in our telemetry
  • Analyst and team lead Dray Agha has shared a couple of things from real-world intrusions we have manually worked [ 1 , 2 , 3, 4 ]

This isn’t to say that ML, AI or other automations are bad. They're just not how Huntress rolls. We’ve been proud to share the behind-the-scenes for the very manual, human-led investigations that Huntress is all about.

***

I hope this clears the air about some myths and misconceptions about us swirling around in the wild. Got questions? Drop us a line – we’re happy to help! 

If you’re curious to gather some more technical security details from Huntress, why not check out our Tradecraft Tuesdays? These technical webinars show how hackers hack, defenders defend, and are garnished with some spicy takes from the team.  

Categories
Huntress News
Summarize this postClose Speech Bubble
ChatGPTClaudePerplexityGoogle AI

See Huntress in action

Our platform combines a suite of powerful managed detection and response tools for endpoints and Microsoft 365 identities, science-backed security awareness training, and the expertise of our 24/7 Security Operations Center (SOC).

Book a Demo
Share
Facebook iconTwitter X iconLinkedin iconDownload icon
Glitch effect

You Might Also Like

  • Cloudy with a Chance of Misinformation: Debunking Microsoft 365 & Identity Myths

    Don’t fall for common Microsoft 365 identity security myths. Here, Huntress debunks misconceptions around logins, MFA, Conditional Access, Impossible Travel, and security tuning.
  • Clearing the Air: Overblown Claims of Vulnerabilities, Exploits & Severity

    Our team has been tracking conversations surrounding ConnectWise Control vulnerabilities and alleged exploitation. We politely disagree with the threat and criticality presented by the security researcher.
  • Debunking 5 Major macOS Myths

    Let Huntress debunk the biggest Mac security myths. macOS is now a popular target for hackers, so learn the truth about its vulnerabilities and discover practical steps to enhance protection against cyber threats.
  • Creating macOS Ransomware

    With the beta release of the Huntress macOS agent, we wanted to share some of the Apple-y stuff we’ve been up to behind the scenes.
  • What Endpoint Detection and Response (EDR) Looks Like Under the Hood

    We’re going to try to cut through the noise and shed some light on EDR to understand the variance, capability, and efficacy of EDR solutions in the market.
  • Breaking Down the Cost of Cybersecurity

    Learn about the costs of cybersecurity—and the risks of not having the right security stack—in this blog.
  • Huntress Service: Ransomware Canaries

    Read about the value of Huntress' Ransomware Canaries service, a mechanism to deliver faster detection of a ransomware incident.
  • Huntress Series B: Our Next Chapter of Growth

    We’ve been focused on expanding our platform and helping you better protect your customers. And we’re just getting started.

Sign Up for Huntress Updates

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.
Privacy • Terms
By submitting this form, you accept our Terms of Service & Privacy Policy
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Huntress Managed Security PlatformManaged EDRManaged EDR for macOSManaged EDR for LinuxManaged ITDRManaged SIEMManaged Security Awareness TrainingManaged ISPMManaged ESPMBook a Demo
PhishingComplianceBusiness Email CompromiseEducationFinanceHealthcareManufacturingState & Local Government
Managed Service ProvidersResellersIT & Security Teams24/7 SOCCase Studies
BlogResource CenterCybersecurity 101Upcoming EventsSupport Documentation
Our CompanyLeadershipNews & PressCareersContact Us
Huntress white logo

Protecting 215k+ customers like you with enterprise-grade protection.

Privacy PolicyCookie PolicyTerms of UseCookie Consent
Linkedin iconTwitter X iconYouTube iconInstagram icon
© 2025 Huntress All Rights Reserved.

Join the Hunt

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy