Sign in

Huntress

@huntress.com
415 followers 15 following 71 posts

Managed endpoint protection, detection and response designed to help the 99% fight back against today’s cybercriminals.

PostsRepliesMedia
Huntress @huntress.com · 13/02/2026
We’re running nearly 1 billion Sidekiq background jobs a day to power all of the telemetry processing and detections. Can Redis scale with your workload? Here are the receipts. @mike.contribsys.com where does that rank in your experience?
Screenshot of the Sidekiq dashboard showing nearly 1 billion jobs a day
020
Huntress @huntress.com · 13/05/2025
Timeline of the Attack: 🕛 00:45:43 UTC – VPN Compromise ➡️ A brute-force attack led to initial access. This was discovered through retrospective forensic analysis ➡️ Huntress' SIEM would have caught this had it of been deployed in the network
100
Huntress @huntress.com · 08/05/2025
🔑 Followed up with brute-force credential attacks tied to known Makop tooling. 🚀 Lateral Movement & Persistence: Deployed a renamed Mesh Agent via PsExec. 🔍 Attempted to disguise their remote access tool as a benign binary (wvspbind.exe).
100
Huntress @huntress.com · 06/05/2025
The bad guys authenticated using a suspicious IP and workstation name. But as you check out below, they began to stage files in the “Music” directory on the host. Moving quickly, they pivoted to deleting shadow copies to prevent recovery after encryption.
100
Huntress @huntress.com · 05/05/2025
.@jaiminton.com is a modern-day Doc Holliday. A lawman so feared that threat actors flee at the mere mention of his name… Introducing Celestial Stealer, a notorious infostealer with a surprising connection to Huntress.
100
Huntress @huntress.com · 30/04/2025
✅ The attacker used a compromised VPN account (no MFA) to log in with a malicious device. ✅ Explored the network, hid findings in a shady folder, & dug through browser cookies for auth info. ✅ Files were staged on the network file server, ready for exfiltration or encryption.
100
Huntress @huntress.com · 22/04/2025
Huntress continues to observe in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in Gladinet CentreStack and Triofox
112
Huntress @huntress.com · 17/04/2025
A threat actor brute forced a manufacturer's VPN appliance 🏭 Here’s what happened👇 📌 Successfully compromised one account for initial access 📌 Enumerated the domain, focusing on trust relationships and domain controllers 📌 Modified the registry and local firewall to enable lateral RDP movement
100
Huntress @huntress.com · 16/04/2025
➡️ A suspected ransomware group impaired Windows Defender using registry modifications to exclude *.DLL ➡️ Then with Windows Defender on the fritz they dropped a malicious GoLang DLL payload: rundll32.exe C:\\ProgramData\\HP\\Installer\\Temp\filter.dll,Entry
100
Huntress @huntress.com · 14/04/2025
➕At the time of writing, Huntress has seen seven different orgs compromised ➕The flaw was recently added to CISA’s Known Exploited Vulnerabilities database and is related to hardcoded keys set by default in the CentreStack’s configuration file
110
Huntress @huntress.com · 08/04/2025
Threat actors can gain access to your network through an account that’s already on your system. The built-in Windows Guest account is often overlooked because it’s usually disabled by default—but that’s exactly what makes it a stealthy tool for attackers to exploit.
100
Huntress @huntress.com · 07/04/2025
Threat actors used CrushFTPService.exe in order to then install an AnyDesk RMM instance, using the commands below:
100
Huntress @huntress.com · 04/04/2025
CVE-2025-31161 is the latest example of a critical severity authentication bypass vulnerability in CrushFTP, a growing trend we’re seeing from attackers targeting managed file transfer (MFT) platforms.
110
Huntress @huntress.com · 01/04/2025
Things you might spot in a #smishing text ⬇️ ✅ Sketchy phone number: Pretty sure the USPS isn’t sending out texts from the Philippines ✅ Unclickable links: On the off chance it actually was the USPS, they’d send a link you can click without basically having to solve a riddle
120
Huntress @huntress.com · 24/03/2025
✅ The telemetry gave our analysts a pivot point to trace the identity theft source ✅ They reviewed the endpoint and found evidence of the phish kit and landing page used to steal the victim’s credentials Investigations don’t always start and end at an endpoint or in the cloud.
100
Huntress @huntress.com · 24/03/2025
Do you detect phishing from the endpoint or the cloud? 🎣 If you’re part of our Security Operations Center, the answer’s both. Here’s an example 👇 ✅ A proactive, human-led investigation led to our SOC identifying a potentially compromised Microsoft 365 identity
100
Huntress @huntress.com · 12/03/2025
✅ Splashtop beaconed to the malicious public IP ✅ Transferred and ran credential dumping tools with Splashtop Our SOC reacted fast—analyzed the attack, isolated the network, and shut down the persistence path.
100
Huntress @huntress.com · 10/03/2025
Here’s an example of VPN compromise 👇 ✅ It’s a super common technique we see all the time ✅ Effects businesses of every size ✅ Usually caused by a simple configuration mistake, like an account without MFA enabled Yet it can often lead to network-wide compromise 😟
130
Huntress @huntress.com · 04/03/2025
🍞 They scanned the network using netscan.exe 🍩 Prepped for lateral movement with PsExec.exe 🥩 Opened the door for further RDP ingress by modifying firewall rules and registry settings Good news: our SOC stepped in and shut down the threat.
100
Huntress @huntress.com · 20/02/2025
A ransomware actor compromised a sport club’s network 🏌️ Here’s what went down 👇 ✅ They prepared to launch ransomware by deleting volume shadow copies ✅ Attempted to frustrate defenders by clearing the logs and neutralizing defenses
131
Huntress @huntress.com · 17/02/2025
➡️ Deployed a malicious Cobalt Strike beacon named x64.exe ➡️ Tried to install an attacker-controlled ScreenConnect instance Our Managed Defender configuration stopped the threat early. Then our SOC isolated the machine, found the root cause, and shut the intrusion down.
100
Huntress @huntress.com · 13/02/2025
If you administer at least one Microsoft 365 tenant, you might find some surprising results if you audit your #OAuth applications 👀 Statistically speaking, there’s a good chance your tenant is infected with a rogue app that could be malicious 😱
132
Huntress @huntress.com · 12/02/2025
In this example, a malicious PDF promises a user details on a “salary bonus scheme”—but only if they scanned the QR code. Except on the other end of that QR code, they wouldn’t find any bonus, just an attempt to phish their credentials. But our SOC shut it down before that could happen 💪
100