Changelog

Follow up on the latest improvements and updates.

RSS

Managed EDR now displays all IPv4 addresses collected by the Base Agent survey, not just the first. That makes a server with multiple NICs or a laptop on wired and wireless easier to match to firewall logs, network alerts, and investigation findings. The Internal IP / IP Address field still shows one address; hover the additional-address indicator to see the rest, or pull the full list from exports and the ipv4_addresses REST API field.
Huntress EDR now surfaces Windows Subsystem for Linux (WSL) status on your Windows endpoints, showing where Linux workloads run across your fleet.
WSL lets users run Linux directly on Windows, which may often go unnoticed, making it a blind spot for shadow IT and unsanctioned use. Now you can see whether it's running and decide whether to allow it, investigate it, or remove it.
Because WSL environments are tied to a Windows user account, the EDR agent page in your portal now shows:
  • WSL status: Installed or Uninstalled
  • Per account with WSL: instance name, user account, SID, WSL version, and state (running or stopped)
We are now approaching 80 security controls in Managed ISPM. As we continue to build out depth of controls to harden Microsoft 365 environments, we have added the following:
Exchange Online Protection:
  • Ensure Anti-Malware policies meet the Microsoft Standard baseline
  • Ensure Anti-Spam policies meet the Microsoft Standard baseline
  • Ensure Anti-Phishing policies meet the Microsoft Standard baseline
Microsoft Defender for Office 365:
  • Ensure Safe Links policies meet the Microsoft Standard baseline
  • Ensure Safe Attachments protection meets the Microsoft Standard baseline
  • Ensure Safe Documents is turned on for Office clients
  • Ensure Anti-Phishing policies meet the Microsoft Standard spoof protection baseline
A new dashboard that makes Huntress SOC investigations more transparent for partners and customers is now generally available. For both closed-benign and reported investigations, you can view a chronological timeline showing the signals Huntress reviewed, the actions taken, any remediations applied, and the final outcome.
Key improvements introduced in the new dashboard:
  • Review details of all reported and closed-benign investigations across Managed EDR, ITDR, and SIEM
  • Export investigations via CSV/Excel for reporting and recordkeeping
  • Get up to speed quickly with a summary section that shows key stats on investigations
To access the new dashboard, log in to your Huntress portal, then click “Investigations” in the top navigation. The new view is on by default for all partners.
Partners now get a one-page, executive-friendly summary for each organization every month, distilling the existing Threat Report into a snapshot non-technical stakeholders can actually read and share.
Each report highlights the layers of protection in place (EDR, ITDR, SIEM, etc.), a plain-language summary of signals investigated and threats contained, and how Huntress and the partner kept that organization protected over the period.
Reports are delivered via email link to partners and are also available under Reports in the Huntress portal so they can be easily forwarded to end customers. They complement, rather than replace, the full monthly/quarterly Threat Report, and are the first in a series of reporting improvements coming to the platform.
You can now query remote access connections observed by Huntress across your environment via the API, including ConnectWise ScreenConnect hosts, with agent hostname, relay host, port, and first/last seen timestamps. This data was previously only available in the ScreenConnect Hosts view in the portal, which made it harder to automate audits, reporting, and response. See the Remote Access section of the API docs for details.
We're excited to announce that Early Access to our redesigned ITDR dashboard is now available! This is the first step in a broader dashboard refresh, designed to help you investigate identity threats faster, validate suspicious activity with greater confidence, and quickly find the context you need during active investigations.
New features include:
- Rapid Identity Triage –
Have an end user worried about a potential compromise? Simply enter their email into the new Rapid Identity Triage panel to get an immediate overview of all of that user's activity over the past 24 hours. From there, you can export that data to show your user a timeline of activity, and/or revoke that user's sessions and disable their account.
- Failed Login Characterization –
Get a complete view of failed login attempts from across the globe, with specific characterization of logins from residential proxies, VPNs, and datacenters.
- Quick SIEM Search –
Huntress ingests the entirety of the Entra Unified Audit Log and stores it in the Huntress SIEM for free for all ITDR customers for up to a year. Now you can quickly view those logs from within the ITDR dashboard - we've pre-populated popular queries for quick access to your most relevant data.
You can access the new dashboard from the ITDR icon in the left-hand navigation. The existing dashboard remains available alongside it during Early Access, so nothing changes in how you currently work.
Any questions? Check out our new KB: Huntress Managed ITDR - Dashboard (Early Access).
You can now create IP address-based rules for Managed ITDR Unwanted Access through the API. The endpoint supports a single IP address, a CIDR range, or a list of IPs in a single call, giving you more flexibility to automate how Huntress responds to identity access attempts. See the API docs for details.
Logins from corporate-managed devices no longer generate location and VPN escalations by default for new accounts. Existing partners can turn this on and choose exactly which trust levels qualify — compliant, domain-joined, or registered — per account or per organization.
This is expected to cut unexpected-login escalation volume by 40–50%, from ~36 to ~21 per 1,000 identities.
For step-by-step instructions on choosing your trust levels, see our KB article: Huntress Managed ITDR: How to Configure Trusted Device Suppression Rules.
The first days after a tenant connects are the roughest: there's no baseline yet, so everything looks anomalous and escalations arrive in a burst - right when you're forming your first impression of a new client and have the least context to triage.
Managed ITDR now paces escalation flow while baselines build. A new tenant's first week produces a manageable, prioritized stream instead of a flood, so you can onboard clients without warning your techs to brace for the noise.
No configuration needed - this is on by default for all new tenants.
Load More