Changelog

Follow up on the latest improvements and updates.

RSS

As we continue to build out depth of controls to harden Microsoft 365 environments, we have added the following protections against Unwanted Access and Shadow Workflows:
Microsoft Entra:
  • Ensure sign-in is blocked for member accounts inactive for 90 days 
  • Ensure sign-in is blocked for guest accounts inactive for 30 days
Microsoft Exchange Online:
  • Ensure sign-in to shared mailboxes is blocked 
  • Ensure outbound spam policies set explicit sending limits and block senders 
  • Restrict Shared Bookings creation to selected users
These recommended controls may now be scheduled for deployment. Due to potential impact on end users, they will not be rolled out automatically as part of Managed Deployments.
You can now choose exactly which security controls roll out to your environment and when.
Modified Deployments
gives you full control over your rollout. Build your own set of controls from the complete Huntress policy library, pick low, medium, or high impact items, and set the days you want them deployed. When Huntress adds new controls to the library, you'll get notified, but nothing rolls out until you approve it.
This is an org-level setting, ideal for organizations under strict compliance or change control requirements.
Managed Deployments
remain the recommended default, where Huntress selects low-impact controls, schedules them for deployment, and deploys new low-impact controls automatically as they become available. You can preview or skip, but your identity security posture keeps improving without effort from you.
Learn more:
We've given Unsecured Credentials a complete overhaul, with a new dashboard, full visibility into what's being flagged, and the ability to allowlist files you don't want reported on.
What's new
  • Credential Files page. A new home for Unsecured Credentials, available from the Process Insights dashboard in Managed EDR. View and manage every file triggering an Unsecured Credentials report in one place.
  • See before you enable. You can now preview which Credential Files would generate an Incident Report, without turning reporting on!
  • Allowlisting. Exclude the files you've reviewed and accepted, so reports stay focused on what actually needs attention.
Turned these off before? Give them another look.
If you disabled Unsecured Credential Incident Reports because they were too noisy, allowlisting and the new preview view solve exactly that problem. Now's a good time to revisit.
As we continue to build out depth of controls to harden Microsoft 365 environments, we have added the following protections against Shadow Workflows:
Microsoft Exchange Online:
  • Ensure Direct Send is disabled
Microsoft Defender for Office 365:
  • Tenant Allow/Block list should contain zero entries in the allow list
These recommended controls may now be scheduled for deployment. Due to potential impact on end users, they won't be rolled out automatically as part of Managed Deployments.
The agent overview page now shows the last user to log into a macOS endpoint, so you can attribute a host to an individual user during triage and asset review. Previously, this field was only available on Windows.
The value reflects the most recent interactive (console/GUI) login, collected during the agent's routine survey. System-owned login windows and shutdown records are excluded, so you see the last real user rather than a service account. The field populates as endpoints check in on Agent v0.14.196 or later.
Remote graphical access over Screen Sharing used to be invisible to the agent. Huntress now reports each session as it starts, with the source address, session user, and authentication type. You can suppress any of those fields per host. This functionality requires Agent v0.14.196.
That visibility powers a new detection that fires when a session attaches to a root user session via a legacy authentication handshake that current clients no longer use. It's the signature of a pre-auth flaw in Apple's Screen Sharing service, disclosed in July 2026, that allows an unauthenticated remote party to read arbitrary files on an unpatched host. Cloud and VPS Macs lag behind Apple updates, so they carry the most risk.
The existing file-transfer detection stays in place for older agents and macOS below 13.0.
You can now turn Network File Scanning and Archive File Scanning on or off for Microsoft Defender in Managed Antivirus. These were previously fixed to Huntress defaults. Defaults are unchanged, so nothing changes on your endpoints unless you change it.
  • Network File Scanning stays off by default. Scanning mapped network drives can slow things down when many endpoints hit the same share.
  • Archive File Scanning stays on by default. It catches malware inside ZIPs, RARs, and similar files.
Find both in EDR → Managed Antivirus → Defender Configuration → Scans, alongside your other scan settings.
macOS tags downloaded files with a quarantine attribute, which triggers the Gatekeeper warning before an untrusted app runs. Attackers strip that tag so their payload launches silently. Huntress now catches this. It's a common step in AMOS, Poseidon, Odyssey, and MacSync infostealer attacks.
We watch the system call itself, not the xattr command, so it doesn't matter whether the attacker uses a shell script or a compiled binary. Requires Agent v0.14.196.
Three detections ship with this release:
  • Quarantine removed from a file in a common malware staging folder by a script or shell — the pattern ClickFix and AMOS droppers use.
  • Quarantine removed from a file on a mounted disk image — how fake installers get around Gatekeeper.
  • A fake installer mounted and a quarantine strip on the same machine within five minutes — a strong sign a payload is about to run.
Each detection shows the file, the attribute removed, and the process that removed it. That makes it easy to tell a build tool stripping its own file from malware, clearing its own flag. Apple's own backup and file-sharing services accounted for about 99% of the noise in testing, so we filter those out.
The Huntress Configuration Wizard for macOS no longer shows the welcome screen every time it opens. Reopening the wizard takes you straight to the first incomplete setup step or to the completion page if macOS configuration is already done.
This helps anyone who doesn't finish the permission sequence in one sitting, like a partner returning to grant a skipped permission or a technician walking a user through setup. First-run behavior is unchanged: new users still see the welcome screen.
We're excited to announce that all ITDR incident reports now include an Executive Summary.
The Executive Summary automatically turns deep technical ITDR findings into plain-English executive summaries you can hand directly to business leaders, insurers, and legal without rewriting.
The summary clearly explains what happened, why it matters, and what’s been done/what to do, saving hours per incident while building client trust and speeding decisions.
The Executive Summary appears in plain text at the top of every ITDR incident report, and is also available to download as a standalone PDF from the portal, ready to share directly with your client. Simply click the “Export PDF” button at the top of the incident report, and a PDF download will be queued.
Load More
→