Changelog
Follow up on the latest improvements and updates.
RSS
new
Managed ITDR
Onboarding Escalation Throttle Now Live in Managed ITDR
The first days after a tenant connects are the roughest: there's no baseline yet, so everything looks anomalous and escalations arrive in a burst - right when you're forming your first impression of a new client and have the least context to triage.
Managed ITDR now paces escalation flow while baselines build. A new tenant's first week produces a manageable, prioritized stream instead of a flood, so you can onboard clients without warning your techs to brace for the noise.
No configuration needed - this is on by default for all new tenants.
new
Managed ITDR
Microsoft Usage Location Inference Live in Managed ITDR
Previously, when a Microsoft 365 identity lacked an Entra usage location, Huntress had no means to know the user's home country. That gap caused two kinds of noise: "Unexpected Country" escalations for people logging in from their own home country, and a steady stream of "login without usage location" escalations. Setting usage location tenant-by-tenant has been one of the top requests on this board (81 votes) - so we are thrilled to share that Microsoft Usage Location Inference is now live in Managed ITDR (thank you for the feedback!).
With this functionality, Huntress now infers the home country directly from the tenant, with zero partner configuration required. That inferred value stands in as the identity's Expected Country for Unexpected Country evaluation, and it automatically resolves the existing backlog of missing-usage-location escalations. NOTE: An identity's own usage location always takes precedence when present, and a real value from Entra will supersede the inferred one.
Nothing to configure on your end. Enjoy!
new
Managed ITDR
IP-Based Expected Rules Now Available in Managed ITDR
Partners and customers can now create single-IP Expected Unwanted Access rules in Managed ITDR to eliminate escalations for known office or remote-worker IPs. This means that you only need to declare an IP address or an entire CIDR range as Expected
once
- thereafter, logins from that network will stop escalating. Every other detection, including datacenter and token theft coverage, remains fully active. No more overly broad country or VPN rules.Partners can now opt into a new Investigations view that makes Huntress SOC work more visible across your account. Instead of only seeing investigations that become incident reports, you can now review both Reported and Closed-Benign investigations across Managed EDR, ITDR, and SIEM.
Each completed investigation includes a chronological timeline showing the signals Huntress reviewed, the actions taken, any remediations applied, and the final outcome. The view is available in Early Access today for partners. To opt in, select "Investigations" in the top nav of your Huntress portal, then look for the "Try the new investigations view" banner.
Once you opt in, the new view automatically shows completed investigations from the last 90 days so you can better understand what Huntress investigated on your behalf and the work that was done to reach each conclusion.
Our fifth simulation is now in general availability. This simulation will be accompanying July's managed learning assignment and will give learners a new and improved experience to learn the risks of oversharing online.
You can now onboard Microsoft Defender for Endpoint (MDE) tenants in GCC High environments.
Once you follow the setup steps in KB article, your login, Graph, and MDE API traffic will automatically route to the correct GCC High .us endpoints.
This brings MDE in line with our existing GCC High support for ITDR, so if you've already mapped a GCC High tenant in ITDR, you can now onboard that same tenant into MDE
improved
API
Platform
Billing
ConnectWise and HaloPSA billing sync now accurately totals across multiple orgs per company
PSA billing sync has been updated to correctly aggregate counts when more than one Huntress organization is mapped to the same company in ConnectWise or HaloPSA. Previously, billing reflected only the value from whichever organization was processed last, which resulted in undercounting. You will now see an accurate sum across all mapped organizations, so your billing data reflects the full scope of what you manage.
improved
Managed EDR
Huntress Managed EDR for macOS now ejects deceptive installers
The Huntress Agent for macOS now automatically ejects malicious DMGs before their payload can execute, stopping infostealer malware in its tracks. Affected users receive an on-screen notification explaining the action, and every disruption triggers a Huntress SOC investigation to confirm the macOS endpoint is clean.
No action required. Huntress gets in the way before damage is done!
Huntress Managed EDR now catches the moment an end user is tricked into overriding Apple's Gatekeeper to launch an infostealer, a critical step in the attack pattern. Infostealers are now one of the most prevalent macOS threat families.
Available now on macOS 14 and later.
Now that we've had partners and customers successfully use Custom HTML Scenarios in Huntress Managed SAT, we are ready to call it general availability. Early adopters are using it to spearphish employees with scenarios ranging from impersonating trusted vendors to using actual employee names and communication style to better prepare their team.
Load More
→