Your business’ toughest competition might be criminal. See why.
Utility navigation bar redirect icon
Portal LoginSupportContact
Search
Close search
Huntress Logo in Teal
  • Platform Overview
    Managed EDR

    Get full endpoint visibility, detection, and response

    Managed EDR

    Get full endpoint visibility, detection, and response

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Integrations
    Integrations
    Support Documentation
    Support Documentation
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
  • Threats We Stop
    Phishing
    Phishing
    Business Email Compromise
    Business Email Compromise
    Ransomware
    Ransomware
    View Allright arrowView Allright arrow
    Industries We Serve
    Education
    Education
    Financial Services
    Financial Services
    State and Local Government
    State and Local Government
    Healthcare
    Healthcare
    Law Firms
    Law Firms
    Manufacturing
    Manufacturing
    Utilities
    Utilities
    View Allright arrowView Allright arrow
    Tailored Solutions
    MSPs
    MSPs
    Resellers
    Resellers
    SMBs
    SMBs
    Compliance
    Compliance
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
  • Pricing
  • Community Series
    The Product Lab

    Shape the next big thing in cybersecurity together.

    The Product Lab

    Shape the next big thing in cybersecurity together.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    Resources
    Upcoming Events
    Upcoming Events
    ebooks
    ebooks
    On-Demand Webinars
    On-Demand Webinars
    Videos
    Videos
    Whitepapers
    Whitepapers
    Datasheets
    Datasheets
    Cybersecurity Education
    Cybersecurity 101
    Cybersecurity 101
    Cybersecurity Guides
    Cybersecurity Guides
    Threat Library
    Threat Library
    Real Tradecraft, Real Results
    Real Tradecraft, Real Results
    2026 Cyber Threat Report
    2026 Cyber Threat Report
    The Huntress Blog
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
  • Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    The Huntress SOC

    24/7 Security Operations Center

    The Huntress SOC

    24/7 Security Operations Center

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Community

    Get in touch with the Huntress Community team

    Community

    Get in touch with the Huntress Community team

    Compare Huntress
    Bitdefender
    Bitdefender
    Blackpoint
    Blackpoint
    Breach Secure Now!
    Breach Secure Now!
    Crowdstrike
    Crowdstrike
    Datto
    Datto
    SentinelOne
    SentinelOne
    Sophos
    Sophos
    Compare Allright arrowCompare Allright arrow
  • HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    Partners
    MSPs

    Join our partner community to deliver expert-led managed security.

    MSPs

    Join our partner community to deliver expert-led managed security.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Tech Alliances

    Driving innovation through global technology Partnerships

    Tech Alliances

    Driving innovation through global technology Partnerships

    Microsoft Partnership

    A Level-Up for Your Business Security

    Microsoft Partnership

    A Level-Up for Your Business Security

  • Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Awards
    Awards
    Contact Us
    Contact Us
  • Portal Login
  • Support
  • Contact
  • Search
  • Get a Demo
  • Start for Free
Portal LoginSupportContact
Search
Close search
Get a Demo
Start for Free
HomeBlog
Huntress MDR for Microsoft 365 Update
Published:
December 6, 2023

Huntress MDR for Microsoft 365 Update

By:
Kyle Hanslovan
Share icon
Glitch effectGlitch effectGlitch effect

Over the last year, we’ve worked our asses off to prepare for an inbound tidal wave of identity-focused tradecraft. Considering our partners’ significant investments in the Microsoft 365 ecosystem, we’ve specifically targeted emerging business email compromise (BEC) and account takeover tactics, techniques, and procedures (TTPs). Since releasing our new product Managed ITDR a few months ago, we’ve onboarded hundreds of thousands of identities and reported 1,000+ incidents before shit could hit the fan. However, we think there’s a handful of things we probably got wrong in these first few releases and want to lay it all on the table.

Before we get into the good stuff, let me start with the same mantra I used to found this company eight years ago: At Huntress, we deliver ruthless transparency, hold ourselves most accountable, and always give back more than we take. Today is no different, and we’ll keep communicating openly as long as it’s needed. Said more directly, we will own/address any fuck-ups or missteps promptly.

Considering our obsession with no-BS transparency, we’ve put together the following sections to address the most popular themes, answer questions, and kickoff dialog:

  • Current capabilities and our R&D approach
  • What we likely missed or got wrong
  • What we are working on next

Have something urgent? Hit me up at kyle [squiggly a symbol] huntress.com.

Current Capabilities and Our R&D Approach

Every product built at Huntress consists of multiple “capabilities” (think Persistent Footholds, Ransomware Canaries, etc.). We select these capabilities based on “what will have the biggest impact?” and “how will these capabilities layer to provide compensating coverage?”. Once selected, these capabilities are perpetually maintained by product engineers, researchers, detection engineers, and SOC analysts.

As of today, we’ve selected and prioritized the following Managed ITDR capabilities based on hacker tradecraft and risk probability for SMBs:

Unwanted Logins

Few things are more brutal than an account takeover. As a result, we invested significant research into fully understanding this technique and the massive number of offensive sub-techniques that can lead to an unwanted login. Our tech behind this capability starts by parsing Microsoft 365 audit logs and enriching these events with information on “where” and “how.” For our first line of detection, we compare this data against known bad locations and shady IP sources (e.g., data centers known for harboring adversary workloads and uncommon providers with high percentages of malicious activity) to identify threat actors accessing accounts early and lock them out using Huntress’ identity isolation. We’ve had solid success finding malicious activity and isolating affected identities with this method, but we've also observed the fragility of location-based detection (geofencing) and created multiple bypasses using token theft, faux-device registration, etc.

Suspicious Login Location (2)

Take a peek at our Product Lab webinar episodes one and two for our commentary on these. Needless to say, the perpetual improvement cycle for Unwanted Logins is just getting started.

Shadow Workflows

Another tactic exploited by threat actors is manipulating mail delivery using inbox rules and mail forwarding techniques. After an unwanted login occurs, these shadow workflows are often leveraged to exfiltrate sensitive data and to obfuscate emails from the intended recipient by moving or deleting incoming mail. Our initial detection capabilities parsed and stored relevant new workflow events for algorithmic and human analysis. Shortly afterward, we expanded our data collection capability to gather and analyze pre-existing workflows (i.e., historical inbox rules) to uncover past indicators of compromise. These techniques follow a formulaic pattern that Huntress uses to determine if they are illegitimate and queue up remediations. We’ll continue to mature our detection routines throughout the foreseeable future to maximize discovery efficacy and minimize false positives.

Suspicious Inbox Rule (1)

Evasive Behaviors

There isn’t just a single bridge across the castle moat when it comes to Microsoft 365. Threat actors may ignore the standard user login portal and use their ill-gotten credentials with different access methods, including the Microsoft Graph API, the Azure command line, and the Azure SDK. Each approach varies greatly in observability, and similar shady actions produce different indicators based on the access method. Recently released offensive security frameworks like GraphRunner show the power of these alternative access methods. We have prioritized expanding observability for threat actor activity when they leverage these alternative access methods to catch their shadiness.

Suspicious Access Method (1)

Rogue Apps

Within SMBs, we’ve observed threat actors installing malicious applications or weaponizing legitimate Microsoft 365 applications to exfiltrate data and establish persistence within a Microsoft 365 environment. These apps will often have extensive permissions to access the desired Microsoft 365 data while avoiding administrator and defender scrutiny. We’ve also witnessed threat actors using the permissions of installed applications to act on their behalf, bypassing the need to elevate a compromised identity’s privileges. The rogue apps detector is still in its early stages but will see rapid R&D investments to continue to combat this emerging tradecraft.

Application Impersonation (1)

Although there’s plenty of additional offensive tradecraft lurking out there, we feel very confident that continuing to develop these four capabilities before adding more will deliver the most impactful value to our customers and partners today.

What We Likely Missed or Got Wrong

Since our initial launch, we have gotten tons of solid feedback from our customers, partners, and prospects that largely aligns with our own positive, but sometimes spicy, assessments. In this section, we’re going to dive into what we think we would have done differently or better.

Unwanted Logins

When we first approached the account takeover and BEC problem, we prioritized many harder problems first. One of these problems was “impossible travel” detection. Based on our red team assessments, we feel other vendors' geolocation approach to impossible travel is fairly brittle and easily bypassed by junior threat actors. Furthermore, depending on inaccurate and unreliable IP data can create a ton of false positives. We prioritized innovating in this area rather than starting with the basic geofiltering functionality that many expect. This was a mistake as our long-term approach is still maturing, which can allow low-hanging fruit to slip by.

What we’ve already done to address it: In the first week of December, we released detectors focused on anonymous VPN usage and anomalous logins. In the short time since we rolled out the new anonymous VPN and anomalous user location detections, we’ve seen a huge improvement in our efficacy. Approximately two-thirds of the malicious activity we see comes from an anonymizing service and almost half from VPNs. To be clear, while our end goal is the same, our approach is not what most people think of when they hear “impossible travel.” Instead, our solution utilizes anonymous VPN and anomalous user location data to determine suspicious logins. We have even more improvements coming in December, and we will be releasing geo-allowlisting functionality for more granular control (see the “What We Are Working On Next” section to learn more).

Balancing true detections and false positives

Historically, we’ve been extremely committed to minimizing false positives in our Managed EDR product. It’s been a core element of our mission, which is why we took the same approach with MDR for Microsoft 365. In some cases, we over-adjusted this ratio because we were concerned we would pass along too many false positives to our partners. As a result, we missed some activity that we should have caught. Nothing pisses us off more than missing threat actor activity. Nothing.

What we’ve already done to address it: Getting the detection tuning right for any security product is a task that’s never truly finished, but we have made significant improvements. We are now generating more false positives than we did before, but our SOC can filter most of those out before our users see them. As a result, we’re detecting even more threats.

Onboarding

We had some significant issues with onboarding in the product's initial release that caused pain for our partners and customers.

What we've already done to address it: We have streamlined the onboarding process, removing lengthy steps and quickly releasing fixes for the most common errors associated with the process. These include escalations to detect integration issues, establish direct integration as default, and introduce integration repair functionality. Integrating a Microsoft 365 tenant now takes less than 90 seconds. As a result of these improvements, over 90% of onboarding processes are now completed without any issues. We know that isn’t 100% yet, but when issues do arise, we solve them in less than 48 hours on average.

What We Are Working On Next

I mentioned above that we have already released updates to detect anonymized VPN usage and anomalous VPN detection. We have many more updates scheduled to be live by the end of December. This includes over a dozen new Microsoft 365 detections based on locations and threat intelligence data, which should deliver on our promise to detect suspicious activity with a more innovative and effective approach. We are also working on additional detections and geo-allowlisting that will more closely resemble what most people think of when they refer to impossible travel.

Other updates we are working on include:

  • “User behavior fingerprints” to provide additional improvements to our recent anomaly detections.
  • Improved inbox rule creation and modification detection to make it harder for adversaries to evade detection.
  • Weekly cadence of reports for users with compromised credentials, detected as successful username/password, new and suspect location, with or without VPN, but failed MFA. Higher risk detections will still be actioned and reported on immediately.
  • Proactive communication to partners when Huntress receives Microsoft 365 events for any newly onboard tenants, providing proof of life for the product.

• • •

Hopefully, this gives you some valuable insight into our Managed ITDR product, where we’ve come from, and where we are going. But we aren’t going to stop here. We are committed to delivering regular updates on our progress on our blog and through release notes to our partners.

If you want to dive deeper into the world of account takeover threats, Matt Kiely and Dray Agha will discuss Microsoft 365 attack and defense in next week’s (December 12) holiday-themed Tradecraft Tuesday. It should be a fun one!

As always, you can reach out to the team at Huntress or to me directly, and we will be happy to answer any questions you may have.

Categories
Huntress News
Summarize this postClose Speech Bubble
ChatGPTClaudePerplexityGoogle AI

See Huntress in action.

Our platform combines a suite of powerful managed detection and response tools for endpoints and Microsoft 365 identities, science-backed security awareness training, and the expertise of our 24/7 Security Operations Center (SOC).

Book a Demo
Share
Facebook iconTwitter X iconLinkedin iconDownload icon
Glitch effect

You Might Also Like

  • Combating Emerging Microsoft 365 Tradecraft: Initial Access

    Threats evolve, and so does Huntress. Let’s talk about evolving our approach to hitting the hackers where it hurts on Microsoft 365.
  • Cloudy with a Chance of Misinformation: Debunking Microsoft 365 & Identity Myths

    Don’t fall for common Microsoft 365 identity security myths. Here, Huntress debunks misconceptions around logins, MFA, Conditional Access, Impossible Travel, and security tuning.
  • The Case For SigParser

    Court is in session! In this blog post, we examine the use of a legitimate Microsoft 365 application called “SigParser” identified during an identity compromise. How are OAuth apps used during identity intrusions? Find out here!
  • Huntress MDR for Microsoft 365: The Full Story

    Read up on how and why Huntress built its Managed ITDR (formerly MDR for Microsoft 365) solution to help combat the growing threat of business email compromise (BEC).
  • Time to Act: Gaining the Edge with Huntress Response Capabilities

    Discover how Huntress MDR can respond swiftly to cyber threats and give you the critical time advantage in your ongoing battle against attackers.
  • Time Travelers Busted: How to Detect Impossible Travel

    Impossible Travel is one of the earliest indicators of user compromise, and it works against any user-centric event that can be tied back to a location. Huntress goes in-depth on this problem, explaining how it works, revealing challenges surrounding it, and offering real-world examples occurring within Microsoft 365.
  • Level Up Your Business Security: Huntress Launches New Collaboration with Microsoft

    Huntress is collaborating with Microsoft to help your business get the most out of your Microsoft security investments.
  • What Is Managed Detection and Response?

    What is managed detection and response (MDR) and why is it so important? Dive into the benefits of MDR services and how it can address critical security gaps.

Sign Up for Huntress Updates

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.
Privacy • Terms
By submitting this form, you accept our Terms of Service & Privacy Policy
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Huntress Managed Security PlatformManaged EDRManaged EDR for macOSManaged EDR for LinuxManaged ITDRManaged SIEMManaged Security Awareness TrainingBook a Demo
PhishingComplianceBusiness Email CompromiseEducationFinanceHealthcareManufacturingState & Local Government
Managed Service ProvidersResellersIT & Security Teams24/7 SOCCase Studies
BlogResource CenterCybersecurity 101Upcoming EventsSupport Documentation
Our CompanyLeadershipNews & PressCareersContact Us
Huntress white logo

Protecting 215k+ customers like you with enterprise-grade protection.

Privacy PolicyCookie PolicyTerms of UseCookie Consent
Linkedin iconTwitter X iconYouTube iconInstagram icon
© 2025 Huntress All Rights Reserved.

Join the Hunt

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy