The Huntress EDR portal now surfaces successful logon events, providing a clear audit trail of who accessed an endpoint and how. In addition, the logon events show the type of logon (interactive, remote interactive, unlocked), user name, domain, and security identifier (SID).
This visibility exposes "living off the land" tactics, in which attackers use valid credentials to fly under the radar. Surfacing these events directly in the dashboard helps distinguish standard local logins from suspicious remote sessions, allowing Managed EDR to shut down unauthorized access before it escalates.