Changelog

Follow up on the latest improvements and updates.

RSS

We're excited to announce that all ITDR incident reports now include an Executive Summary.
The Executive Summary automatically turns deep technical ITDR findings into plain-English executive summaries you can hand directly to business leaders, insurers, and legal without rewriting.
The summary clearly explains what happened, why it matters, and what’s been done/what to do, saving hours per incident while building client trust and speeding decisions.
The Executive Summary appears in plain text at the top of every ITDR incident report, and is also available to download as a standalone PDF from the portal, ready to share directly with your client. Simply click the “Export PDF” button at the top of the incident report, and a PDF download will be queued.
Huntress Managed ITDR has officially begun using per-identity escalations for new Unexpected Country and Unexpected VPN activity.
With this change, each identity that generates new escalatable activity will receive its own Huntress escalation and notification—making it easier to see exactly which identity needs your attention.
What this means for you:
  • You may see more email or PSA notifications when multiple identities are involved in the same type of activity.
  • If your PSA integration receives Huntress Escalation notifications, each per-identity escalation can generate its own PSA ticket.
  • This does not mean one notification per login. Repeated activity for the same identity may continue to update an existing escalation until it’s resolved.
  • Existing grouped escalations will remain unchanged; the new model applies to new escalation records created on or after August 19.
No action is required
to receive per-identity escalations. However, we recommend reviewing your
account-level notification and PSA settings
today to make sure the right categories and recipients are configured for your team.
You can review your options in Huntress Platform and Alert Notifications and learn more in ITDR: Unwanted Access Overview.
Managed EDR now displays all IPv4 addresses collected by the Base Agent survey, not just the first. That makes a server with multiple NICs or a laptop on wired and wireless easier to match to firewall logs, network alerts, and investigation findings. The Internal IP / IP Address field still shows one address; hover the additional-address indicator to see the rest, or pull the full list from exports and the ipv4_addresses REST API field.
Huntress EDR now surfaces Windows Subsystem for Linux (WSL) status on your Windows endpoints, showing where Linux workloads run across your fleet.
WSL lets users run Linux directly on Windows, which may often go unnoticed, making it a blind spot for shadow IT and unsanctioned use. Now you can see whether it's running and decide whether to allow it, investigate it, or remove it.
Because WSL environments are tied to a Windows user account, the EDR agent page in your portal now shows:
  • WSL status: Installed or Uninstalled
  • Per account with WSL: instance name, user account, SID, WSL version, and state (running or stopped)
We are now approaching 80 security controls in Managed ISPM. As we continue to build out depth of controls to harden Microsoft 365 environments, we have added the following:
Exchange Online Protection:
  • Ensure Anti-Malware policies meet the Microsoft Standard baseline
  • Ensure Anti-Spam policies meet the Microsoft Standard baseline
  • Ensure Anti-Phishing policies meet the Microsoft Standard baseline
Microsoft Defender for Office 365:
  • Ensure Safe Links policies meet the Microsoft Standard baseline
  • Ensure Safe Attachments protection meets the Microsoft Standard baseline
  • Ensure Safe Documents is turned on for Office clients
  • Ensure Anti-Phishing policies meet the Microsoft Standard spoof protection baseline
A new dashboard that makes Huntress SOC investigations more transparent for partners and customers is now generally available. For both closed-benign and reported investigations, you can view a chronological timeline showing the signals Huntress reviewed, the actions taken, any remediations applied, and the final outcome.
Key improvements introduced in the new dashboard:
  • Review details of all reported and closed-benign investigations across Managed EDR, ITDR, and SIEM
  • Export investigations via CSV/Excel for reporting and recordkeeping
  • Get up to speed quickly with a summary section that shows key stats on investigations
To access the new dashboard, log in to your Huntress portal, then click “Investigations” in the top navigation. The new view is on by default for all partners.
Partners now get a one-page, executive-friendly summary for each organization every month, distilling the existing Threat Report into a snapshot non-technical stakeholders can actually read and share.
Each report highlights the layers of protection in place (EDR, ITDR, SIEM, etc.), a plain-language summary of signals investigated and threats contained, and how Huntress and the partner kept that organization protected over the period.
Reports are delivered via email link to partners and are also available under Reports in the Huntress portal so they can be easily forwarded to end customers. They complement, rather than replace, the full monthly/quarterly Threat Report, and are the first in a series of reporting improvements coming to the platform.
You can now query remote access connections observed by Huntress across your environment via the API, including ConnectWise ScreenConnect hosts, with agent hostname, relay host, port, and first/last seen timestamps. This data was previously only available in the ScreenConnect Hosts view in the portal, which made it harder to automate audits, reporting, and response. See the Remote Access section of the API docs for details.
We're excited to announce that Early Access to our redesigned ITDR dashboard is now available! This is the first step in a broader dashboard refresh, designed to help you investigate identity threats faster, validate suspicious activity with greater confidence, and quickly find the context you need during active investigations.
New features include:
- Rapid Identity Triage –
Have an end user worried about a potential compromise? Simply enter their email into the new Rapid Identity Triage panel to get an immediate overview of all of that user's activity over the past 24 hours. From there, you can export that data to show your user a timeline of activity, and/or revoke that user's sessions and disable their account.
- Failed Login Characterization –
Get a complete view of failed login attempts from across the globe, with specific characterization of logins from residential proxies, VPNs, and datacenters.
- Quick SIEM Search –
Huntress ingests the entirety of the Entra Unified Audit Log and stores it in the Huntress SIEM for free for all ITDR customers for up to a year. Now you can quickly view those logs from within the ITDR dashboard - we've pre-populated popular queries for quick access to your most relevant data.
You can access the new dashboard from the ITDR icon in the left-hand navigation. The existing dashboard remains available alongside it during Early Access, so nothing changes in how you currently work.
Any questions? Check out our new KB: Huntress Managed ITDR - Dashboard (Early Access).
You can now create IP address-based rules for Managed ITDR Unwanted Access through the API. The endpoint supports a single IP address, a CIDR range, or a list of IPs in a single call, giving you more flexibility to automate how Huntress responds to identity access attempts. See the API docs for details.
Load More