Changelog
Follow up on the latest improvements and updates.
RSS
new
Managed EDR
Last logged in user now visible for macOS endpoints
The agent overview page now shows the last user to log into a macOS endpoint, so you can attribute a host to an individual user during triage and asset review. Previously, this field was only available on Windows.
The value reflects the most recent interactive (console/GUI) login, collected during the agent's routine survey. System-owned login windows and shutdown records are excluded, so you see the last real user rather than a service account. The field populates as endpoints check in on Agent v0.14.196 or later.
Remote graphical access over Screen Sharing used to be invisible to the agent. Huntress now reports each session as it starts, with the source address, session user, and authentication type. You can suppress any of those fields per host. This functionality requires Agent v0.14.196.
That visibility powers a new detection that fires when a session attaches to a root user session via a legacy authentication handshake that current clients no longer use. It's the signature of a pre-auth flaw in Apple's Screen Sharing service, disclosed in July 2026, that allows an unauthenticated remote party to read arbitrary files on an unpatched host. Cloud and VPS Macs lag behind Apple updates, so they carry the most risk.
The existing file-transfer detection stays in place for older agents and macOS below 13.0.
improved
new
Managed EDR
New MAV Configuration Settings: Network File Scanning and Archive File Scanning
You can now turn Network File Scanning and Archive File Scanning on or off for Microsoft Defender in Managed Antivirus. These were previously fixed to Huntress defaults. Defaults are unchanged, so nothing changes on your endpoints unless you change it.
- Network File Scanning stays off by default. Scanning mapped network drives can slow things down when many endpoints hit the same share.
- Archive File Scanning stays on by default. It catches malware inside ZIPs, RARs, and similar files.
Find both in EDR → Managed Antivirus → Defender Configuration → Scans, alongside your other scan settings.
macOS tags downloaded files with a quarantine attribute, which triggers the Gatekeeper warning before an untrusted app runs. Attackers strip that tag so their payload launches silently. Huntress now catches this. It's a common step in AMOS, Poseidon, Odyssey, and MacSync infostealer attacks.
We watch the system call itself, not the xattr command, so it doesn't matter whether the attacker uses a shell script or a compiled binary. Requires Agent v0.14.196.
Three detections ship with this release:
- Quarantine removed from a file in a common malware staging folder by a script or shell — the pattern ClickFix and AMOS droppers use.
- Quarantine removed from a file on a mounted disk image — how fake installers get around Gatekeeper.
- A fake installer mounted and a quarantine strip on the same machine within five minutes — a strong sign a payload is about to run.
Each detection shows the file, the attribute removed, and the process that removed it. That makes it easy to tell a build tool stripping its own file from malware, clearing its own flag. Apple's own backup and file-sharing services accounted for about 99% of the noise in testing, so we filter those out.
improved
Managed EDR
macOS Configuration Wizard now opens on the step you left off at
The Huntress Configuration Wizard for macOS no longer shows the welcome screen every time it opens. Reopening the wizard takes you straight to the first incomplete setup step or to the completion page if macOS configuration is already done.
This helps anyone who doesn't finish the permission sequence in one sitting, like a partner returning to grant a skipped permission or a technician walking a user through setup. First-run behavior is unchanged: new users still see the welcome screen.
new
Managed ITDR
Executive Summaries Now in ITDR Incident Reports
We're excited to announce that all ITDR incident reports now include an Executive Summary.
The Executive Summary automatically turns deep technical ITDR findings into plain-English executive summaries you can hand directly to business leaders, insurers, and legal without rewriting.
The summary clearly explains what happened, why it matters, and what’s been done/what to do, saving hours per incident while building client trust and speeding decisions.
The Executive Summary appears in plain text at the top of every ITDR incident report, and is also available to download as a standalone PDF from the portal, ready to share directly with your client. Simply click the “Export PDF” button at the top of the incident report, and a PDF download will be queued.
Huntress Managed ITDR has officially begun using per-identity escalations for new Unexpected Country and Unexpected VPN activity.
With this change, each identity that generates new escalatable activity will receive its own Huntress escalation and notification—making it easier to see exactly which identity needs your attention.
What this means for you:
- You may see more email or PSA notifications when multiple identities are involved in the same type of activity.
- If your PSA integration receives Huntress Escalation notifications, each per-identity escalation can generate its own PSA ticket.
- This does not mean one notification per login. Repeated activity for the same identity may continue to update an existing escalation until it’s resolved.
- Existing grouped escalations will remain unchanged; the new model applies to new escalation records created on or after August 19.
No action is required
to receive per-identity escalations. However, we recommend reviewing your account-level notification and PSA settings
today to make sure the right categories and recipients are configured for your team.You can review your options in Huntress Platform and Alert Notifications and learn more in ITDR: Unwanted Access Overview.
Managed EDR now displays all IPv4 addresses collected by the Base Agent survey, not just the first. That makes a server with multiple NICs or a laptop on wired and wireless easier to match to firewall logs, network alerts, and investigation findings. The Internal IP / IP Address field still shows one address; hover the additional-address indicator to see the rest, or pull the full list from exports and the ipv4_addresses REST API field.
Huntress EDR now surfaces Windows Subsystem for Linux (WSL) status on your Windows endpoints, showing where Linux workloads run across your fleet.
WSL lets users run Linux directly on Windows, which may often go unnoticed, making it a blind spot for shadow IT and unsanctioned use. Now you can see whether it's running and decide whether to allow it, investigate it, or remove it.
Because WSL environments are tied to a Windows user account, the EDR agent page in your portal now shows:
- WSL status: Installed or Uninstalled
- Per account with WSL: instance name, user account, SID, WSL version, and state (running or stopped)
We are now approaching 80 security controls in Managed ISPM. As we continue to build out depth of controls to harden Microsoft 365 environments, we have added the following:
Exchange Online Protection:
- Ensure Anti-Malware policies meet the Microsoft Standard baseline
- Ensure Anti-Spam policies meet the Microsoft Standard baseline
- Ensure Anti-Phishing policies meet the Microsoft Standard baseline
Microsoft Defender for Office 365:
- Ensure Safe Links policies meet the Microsoft Standard baseline
- Ensure Safe Attachments protection meets the Microsoft Standard baseline
- Ensure Safe Documents is turned on for Office clients
- Ensure Anti-Phishing policies meet the Microsoft Standard spoof protection baseline
Load More
→