Integrations, Webhooks, APIs

We've made significant updates to our APIs and have rolled out webhooks and an MCP server. Check out the documentation to learn more: API | Webhooks | MCP
Browser-native protection for ClickFix, malicious extensions, and SaaS risk
I wanted to share product feedback based on what I am seeing with SMB and mid-market clients. Huntress already covers a major part of the risk stack with EDR, ITDR, SAT, SIEM, and now ESPM/ISPM. The gap I see is the browser. A growing amount of compromise is happening before traditional endpoint tools get a clean signal. The main use cases are: ClickFix-style attacks where users are tricked into copying and running malicious commands from fake CAPTCHA, fake Cloudflare, fake browser update, or fake document pages. Malicious browser extensions that collect credentials, hijack sessions, inject scripts, exfiltrate data, or abuse permissions after being installed by the user. SaaS and identity abuse where users approve rogue OAuth apps, reuse passwords, enter corporate credentials into unmanaged apps, or upload sensitive data into shadow SaaS and AI tools. This feels like a natural Huntress expansion because these attacks sit between endpoint, identity, and SaaS. Today, the practical answer is to use Intune/GPO/Chrome Enterprise/Edge policies for extension governance and a separate browser-native tool such as Push Security for in-browser user protection. That creates another tool, another agent/extension, and another dashboard for MSPs. The ideal Huntress capability would be a lightweight managed browser extension or browser-security module that can: Detect ClickFix behavior, including malicious copy/paste instructions, fake verification flows, and suspicious browser-to-command execution paths. Inventory Chrome and Edge extensions across managed endpoints. Score extensions by risk based on permissions, publisher reputation, install source, update behavior, and known malicious indicators. Alert on risky extensions, new high-permission extensions, sideloaded extensions, and suspicious extension changes. Help enforce extension allowlists or integrate with Intune/Chrome/Edge policy management. Detect corporate password reuse or credential entry into unapproved sites. Detect risky OAuth grants and connect that back to Huntress ITDR. Warn users in-browser before they enter credentials, approve OAuth access, copy malicious commands, or upload sensitive data into risky SaaS/AI tools. Give MSPs simple client-facing reporting: risky extensions, risky SaaS usage, browser-driven phishing exposure, and user behavior trends. The business reason is simple: attackers are moving into the browser because it is where identity, SaaS, credentials, AI tools, and user decision-making all meet. Huntress already has strong coverage after compromise. A browser-native protection layer would help move Huntress closer to prevention without losing the managed detection value that makes the platform useful for SMBs. My ask: please consider adding browser extension governance and ClickFix/browser-native protection to the roadmap, either as part of ITDR, ESPM, ISPM, or as a dedicated managed browser security module. This would be highly valuable for MSPs and small security teams that want Push Security-like browser protection without adding another standalone platform.
0
·
Feature Request
Dynamic training assignment audience management via IdP group membership - API support
We are building automation to keep SAT training assignments in sync with employee lifecycle changes (joiners, movers, leavers) using our Google Workspace IdP as the source of truth. Currently the API does not expose the controls we need to make this fully automated, requiring manual UI or CSV intervention. What we need (at least one option): Learner tag management via API The ability to create, assign, and remove tags from learners programmatically. Tags appear to be the intended mechanism for cross-group segmentation, but they are not exposed as documented API operations today. Assignment audience extras via API Expose the Assignment > Audience > Enrollment > Extras > Include learner workflow as an API endpoint. This would allow us to add or remove individual learners from an assignment's audience directly, as an alternative to tag-based targeting. Use case / motivation: When an employee joins a team or changes role, we want to automatically enroll them in the relevant security training and remove them when they leave or change. (The only option today is the value of the Department mapping or all Organization, that is not granular enough to give additional training across departments but not everyone). Our IdP already manages group membership - we just need the API to reflect those changes in SAT assignments without manual steps. Current workaround: Manual UI updates with the (Assignment > Audience > Enrollment > Extras > Include learner workflow), which do not scale and introduce lag and human error between changes Reference: Huntress support ticket 247087
0
·
Feature Request
Load More