Huntress W

thecomputerguy

Well-Known Member
Reaction score
1,479
I began rolling our EDR to some of my clients for testing purposes ... less than 50 or so endpoints.

It has been quiet since the beginning of the year and I was beginning to wonder if it was doing anything at all. I knew it was industry standard to use EDR so I just left it on my 50 points and moved on.

This weekend I finally got my first TWO alerts.

1.) Low severity ... PUP called PcAppStore showed up in the startup ... Huntress remediated it automatically.

2.) High severity ... Client downloaded a file called document.vbs opening it and then the VBS script proceed to install two remote access agents, Fleetdeck Agent, and ScreenConnect agent at roughly 5:40pm on Saturday

By 6:00pm Saturday Huntress had deleted the respective services to kill the access. The files were still left behind so some manual cleanup was necessary but I imagine on any HIGH alert I'd be in contact with the client anyways, so not a big deal.

Client claimed, "What? Saturday at 5:40 ... I wasn't even here"

THATS NOT WHAT YOUR BROWSER HISTORY SAYS BUD
 
We love Huntress....cut over to them last year....we were in SentinelOne.
We also had clients on Eset, and prior to S1 BitDefender was our big go to.

Huntress has found so many installs of roque screen connect relays it's sickening......I can't believe screen connect has allowed this to happen so rampantly. They really need to work with other AV vendors and stamp their files or whatever it takes to whitelist legit installs..and let the rogue installs get detected by all the other AV products.

We also love their ITDR module....which is what plugs into your customers M365 tenants...and does a TON of monitoring....and it's fantastic.

ALSO..their upcoming ISPM module...which they released to some beta testers about a month ago (of course I signed up). Identity Security Posture Management. This will be a pay for add-on once it's fully released....it is part of the addition to their stack since they purchased "Inside Agent 365". There's another component from that tool but only avail if you also use their full SEIM.
 
Back
Top