Huntress’ cover photo
Huntress

Huntress

Computer and Network Security

Columbia, Maryland 151,983 followers

Enterprise-grade #cybersecurity for ALL businesses. Managed EDR, ITDR, SIEM, SAT, & ISPM built to wreck hackers.

About us

Protect Your Endpoints, Identities, Logs, and Employees. The agentic managed security platform for peace of mind. Designed to deliver the next-level outcomes you need: Endpoint Integrity, Identity Resilience, Operational Readiness. Powered by custom-built enterprise technology for mid-market enterprises, small businesses, and the MSPs that support them. Backed by unrivaled industry analysts in our 24/7 AI-centric Security Operations Center. By delivering a suite of purpose-built solutions that meet budget, security, and peace-of-mind requirements, Huntress is how the globe’s most under-resourced businesses defend against today’s cyber threats. As long as hackers keep hacking, we keep hunting.

Industry
Computer and Network Security
Company size
501-1,000 employees
Headquarters
Columbia, Maryland
Type
Privately Held
Founded
2015
Specialties
Cyber Breach Detection, Incident Response, Endpoint Protection, Malware Analysis, and Managed Services

Locations

Employees at Huntress

Updates

  • View organization page for Huntress

    151,983 followers

    A rogue SimpleHelp agent quietly joined a host at 2:10 in the morning. We flagged the RMM violation just eight minutes later... But nobody outside the SOC saw it, so it just sat there. 24 hours and 49 minutes later, that same foothold turned into LockBit ransomware ripping through the environment. And the whole thing could've been stopped at hour one if the partner had known their allow-list had been broken. Attackers reach for the same tools your IT team runs every day. Why build new malware when you can just pull it off the shelf? It looks like a trusted tool, so the abuse blends into normal activity. Tomorrow, Dray Agha and Jai M. are sitting down with AnyDesk Software's Matthew Caldwell to show how attackers hide inside trusted RMM tools, and what it takes to shut that access down. Grab your spot for the livestream: https://okt.to/9mJgVX

    • No alternative text description for this image
  • Your IT team relies on remote access tools to keep things running. So do attackers. LIVE tomorrow at 12pm ET / 5pm BST: https://lnkd.in/eSVzprDu RMM abuse is up 277% year over year, and it's not because attackers got more sophisticated. They're using software that's already installed and already trusted, so nothing looks out of place until the damage is done. Dray Agha and Jai Minton are walking through how that plays out on real endpoints, joined by Matthew Caldwell, AnyDesk's Director of Fraud Prevention, and sharing what it takes to close the gap beyond visibility alone. Joining from APAC? Your session is Aug 19 at 10am AEST / 12pm NZST: https://lnkd.in/e8a__QGZ

  • Huntress reposted this

    Huntress just shipped an iOS app for admins! Most of security work isn't at your desk. You're driving between client sites, you're at dinner, you're asleep at 2am, that’s why you have a 24x7 SOC! The new Huntress mobile app closes part of that gap: • See incident reports and escalations as they come in • Check agent status without opening a laptop • Isolate and unisolate endpoints straight from your phone That last one matters. Checking incidents used to mean finding wifi, opening the portal, and hoping your hotspot held. Now it's a few taps. Now you’ll always have Huntress at your finger tips! Open the App Store and search Huntress! #Huntress #iOS

  • View organization page for Huntress

    151,983 followers

    "Ransomware doesn't target small businesses." That's what Sara thought too. Sara runs a pediatric clinic. One morning, her computers stopped working. Her network was encrypted and she had 24 hours to pay $500,000. Small businesses are some of the most attractive targets out there because they usually have less security and more pressure to pay. Watch what happens when Sara gets the message. Then try the free ransomware simulator yourself: https://okt.to/cjMFk8

  • View organization page for Huntress

    151,983 followers

    Huntress made the 2026 #Inc5000 list of America's fastest-growing private companies. 🙌 Growth like this doesn't happen without trust. Thank you to our partners and community, who trust us every day to protect what matters without piling on complexity or a bank-breaking price tag. Because of you, we're now securing 5M+ endpoints for over 270K businesses, protecting 14M+ identities, and still chasing down attackers at every chance we get.

    • No alternative text description for this image
  • We've seen an uptick in breaches starting with a little-known RMM called Tiflux. One moment, you’re opening an email with an attachment. The next, this RMM appears on your machine…along with a lot more. One of the earliest examples we saw started with a service agreement phish. Once attackers gain initial access via Tiflux, we’ve seen them install additional RMM tools and even outdated drivers to elevate their access. This gave them persistence, allowed them to transmit screenshots, and let them run commands to collect system profiling information. One innocuous remote tool gave attackers full access. But this barely scratches the surface of what RMM abuse can be used for. It was the #1 threat in our latest Cyber Threat Report for a reason, jumping 277% in the last year. On August 18, we're breaking down why RMMs are still such a problem, and what it actually takes to close the gap beyond visibility alone. Save your spot: https://okt.to/ZpJnoQ

    • No alternative text description for this image
  • Not many people question a legit RMM tool. It's just part of the daily workflow, and these days attackers are counting on exactly that. A few examples we've tracked recently: - An authentication bypass and account takeover bug in N-able N-central - A phishing email disguised a service agreement that dropped the RMM Tiflux - A fake Bank of America alert that quietly installed ScreenConnect Different entry points, same outcome. Attackers are running the exact RMM tools your team already relies on every day. If an attacker was already inside your RMM, would you know?

  • Sponsored search results aren’t always just annoying advertisements. In a recent incident detected by Huntress, a victim clicked on a sponsored Google result after searching for how to install Claude on a Mac. Directed to a legit Anthropic page hosting a shared Claude conversation, they were instructed to open Terminal and paste a single line. Instead of installing Claude, the command launched a loader for MacSync stealer. While the device was taken offline before we could recover the on-disk artifacts, we were able to pull a malware sample directly from the operator's delivery infrastructure. Josh Kiriakoff walks through the incident, including detailed malware analysis of all six stages of the MacSync stealer payload: https://okt.to/uqydrh

    • No alternative text description for this image
  • View organization page for Huntress

    151,983 followers

    The federal government just handed the private sector something it's never had before: legal cover to hack back. The new memorandum lets vetted companies target foreign cybercrime groups directly, with DOJ and DHS sign-off and a $1 million bond on the line. Our CEO Kyle Hanslovan told Cybersecurity Dive why the timing makes sense: the old model of public-private collaboration wasn't built for AI-powered autonomous threats. "The only viable solution is a stronger coalition of the willing, which we've been eager to support." DOJ and DHS have 60 days to write the operating rules. What's your take? Read the full article here: https://okt.to/9rv4y8

    • No alternative text description for this image
  • View organization page for Huntress

    151,983 followers

    Next week's livestream "Trusted Tools in Untrusted Hands": https://okt.to/b51BVg Last year, 1 in 3 attacks used remote monitoring and management tools (RMMs). "If I were the attacker, I'd do the same thing." — Eric Stride, Huntress Chief Security Officer Here's why: RMMs are legit tools that have have remote access, file transfer, and command execution. Basically everything an attacker would build into a custom backdoor, but they're already installed and ignored by antivirus. RMM abuse has grown 270% year over year from 2024-2025. That's why we built RMM Guard to map what's expected on your network, then flag or shut down anything that doesn't belong. Join us August 18 for "Trusted Tools in Untrusted Hands," a live session with our detection and threat hunting teams (and a guest from AnyDesk Software) on how RMM abuse actually plays out, and how to stop it.

Similar pages

Browse jobs