App Control for the 99%: Why We’re Building Managed ESPM

Key Takeaways

  • Attackers increasingly abuse legitimate RMM tools, turning phishing clicks into persistent access.

  • Traditional app control is effective but too complex and resource-intensive for most lean IT teams.

  • Huntress Managed ESPM brings pragmatic, managed app control, starting with blocking rogue RMMs, within reach of the 99% who can't run a full app control program themselves.

Suppose an employee gets an email about a "pay increase" meeting. The link looks routine enough, the page feels familiar, and they're understandably excited. Unfortunately, it's a phishing email. With one click, they download and run a malicious attachment.

Behind the scenes, that single action quietly installs a Remote Monitoring and Management (RMM) tool: LogMeIn Resolve. This is the kind of thing that keeps defenders up at night, because the attacker now has persistent access into their environment. It didn't even require a novel exploit. LogMeIn Resolve is a legitimate tool that's regularly used by IT admins, so the attacker can hide in plain sight.

This isn't a hypothetical example. It's a real incident that happened recently. Thankfully, the device was secured by Huntress Managed Endpoint Detection and Response (EDR), and the combination of endpoint telemetry and a 24/7 Security Operations Center (SOC) made the difference. The activity was detected, investigated, and contained before the attacker could turn that foothold into something far worse. That's a success story.

But it also raises a fair question:

What if that remote access tool had never been allowed to run in the first place?

Especially since RMM-based attacks increased 277% over the last year.

Huntress found in 2025, RMM-based attacks increased 277% from 2024

Proactively blocking unknown, unwanted, and malicious tools from running is exactly what application control promises to do. But unfortunately, most solutions that offer this capability have been designed with enterprise teams and budgets in mind, leaving MSPs and lean IT teams underprotected. 

This is about why that needs to change. And how Huntress is building Managed Endpoint Security Posture Management (ESPM) to close the gap

Detection vs. prevention: Why app control matters

Many organizations and MSPs already rely on tools like EDR to secure endpoints when something looks suspicious. They're essential, and we're not arguing otherwise. But by definition, they only come into play after something has tried to run. That's like catching a thief who's already broken into your house. 

Application control changes that conversation. Instead of trying to identify bad things happening, you take the step of only allowing known-good software to run. This applies not just to obvious malware, but also to legitimate remote access tools that attackers love to misuse.

In fact, 32% of all incidents Huntress has observed this year so far could've been prevented by blocking rogue RMM tools from running.

This is like proactively putting bars on your windows so thieves can't break in to begin with. On paper, this sounds straightforward. In reality, the path from good intentions to a stable, enforced application control policy is where most teams hit a brick wall.

Why traditional app control is so hard to get right

The fundamental challenge with application control is that if you accidentally block legitimate tools employees need, then you destroy productivity and generally piss off a lot of coworkers. But the line between work-critical apps and those that attackers abuse is often quite blurry. Because of this, organizations have to be cautious about how they roll out blocking policies. 

If you look at how industry frameworks recommend implementing application control, you'll see a very deliberate, multi‑stage process. It's effective, but it also assumes you have the time and people to lean on. A typical guidance framework breaks the journey into four big phases:

  1. Pre-implementation planning (4-6 weeks): Get leadership buy-in, categorize endpoints, understand software sources, and integrate app control into change management. 

  2. Policy building and refinement (6-12 weeks): Deploy in audit mode so the agent can crawl file systems, watch process behavior, and build a baseline of what's really in use.

  3. Pilot and enforcement rollout (3-6 weeks): Select a small, representative group of endpoints to go from audit into true enforcement. Roll out to broader groups in phases after that.

  4. Ongoing operations and tuning (indefinitely): Handle exceptions for new software, previously unseen behaviors, and mistagged applications, adjust policies, and periodically audit. 

When this is done well, you get a strong reduction in attack surface and a meaningful layer of protection. But there are several predictable reasons that organizations fail to achieve this, including:

  • Overly broad default-deny policies that block business‑critical applications.

  • Exception queues that become unmanageable, slowing down users and burning out admins.

  • Misconfigured containment rules that block application dependencies and cause outages.

The end result is that managing application control projects can become a full-time role, and many teams eventually decide the cost is too high to justify continuing. 

The two‑tier reality attackers rely on

Large enterprises may be able to justify the time and budget to make application control work. But for an MSP or lean IT team that's already juggling backups, tickets, patching, and incident response, anything that requires weeks of "pre-implementation planning" simply isn't realistic.  

This creates a clear divide in how endpoint hardening plays out in the real world. Vendors build solutions for large enterprises, but MSPs and small to mid‑market organizations that face the same attack techniques simply don't have the resources to handle the complexity.

Attackers have adapted to that reality and happily pick vulnerable targets. That's part of the reason they're increasingly leaning on dual‑use tools common in IT operations and often implicitly trusted. They know many environments have strong detection, but very little control over what can be installed or executed in the first place.

Our goal with Huntress Managed ESPM is to narrow that gap, with a managed approach to app control that's designed specifically for the 99% who can't afford a dedicated app control team.

Managed ESPM: Bringing app control within reach

Huntress Managed ESPM is our take on making proactive endpoint hardening accessible to MSPs and lean IT teams. It covers application control, visibility into critical vulnerabilities, configuration management, and more, but "managed" is the keyword.

Instead of handing you another long implementation guide and a framework for detailed policy design, Huntress takes on the heavy lifting on your behalf.

We use the visibility we already have across millions of devices and thousands of customers to close some of the most common endpoint vulnerabilities. And we do it in a way that keeps end users productive.

But when it comes to application control, enforcement is where Huntress takes a different approach from traditional solutions.

A look at the Managed ESPM dashboard

Enforce Where It Makes Sense: Starting With RMM Guard

Instead of explicitly allowing or blocking every application out of the gate, which requires a complex and time-consuming learning and policy-building process, we're going to start by focusing on specific categories of software that are disproportionately abused by threat actors.

As mentioned above, 32% of all incidents Huntress has observed this year could have been prevented by blocking rogue RMM tools from running. That's why we built RMM Guard.

Think of this as a targeted use case of app control, focused specifically on remote access tools. It inventories every RMM running across your environment and blocks any that aren't explicitly authorized, including attacker-controlled instances of approved tools like ScreenConnect. 

A snapshot of RMM Guard

This targeted approach is designed to rapidly address the threats our SOC sees every day across millions of endpoints, without asking customers to solve the whole problem at once. Enable the capability, and you get meaningful protection almost immediately. 

In addition to blocking RMMs, we are exploring other categories of software that could benefit from targeted app control as well, such as AI or file-sharing programs. Our ultimate goal is to help customers achieve full, enforceable app control where every app is explicitly allowed or blocked, but we're going to do it one step at a time. That will keep end-users from being stuck and save admins from having to live inside a never-ending policy exception inbox.

RMM Guard Now Available for Free for All Customers

Managed ESPM is in Early Access today. During this phase, we're building out capabilities, testing our approach, and collecting real‑world feedback from partners and customers as we refine how this works at scale over the next few months. 

But we've already seen so much potential for RMM Guard to impact real-world security outcomes that we don't want to delay its release. So, we've decided to make RMM Guard fully available for free to all Huntress customers/partners with an agent deployed until ESPM is ready for sale. 

Previously, RMM Guard was limited to Learning Mode and required Managed SIEM, but those limitations have now been removed. If you're an existing Huntress customer, you can have this capability enabled in your account to detect and block rogue RMMs running across your endpoints.

Just reach out to your account manager to get onboarded to the ESPM Early Access program. You can choose to test all the ESPM features as they are added, or just RMM Guard. 

Closing the Gap

With Huntress Managed ESPM, we're working to bring proactive endpoint hardening and app control within reach of the organizations that are often targeted most and resourced least. It won't eliminate every risk, and it won't remove every hard decision, but it does offer a realistic path toward:

  • Fewer unexpected executables running on endpoints.

  • Less room for attackers to abuse the same tools IT relies on.

  • A more balanced partnership between usability and security.

If you're an existing partner/customer and you'd like to kick the tires of Managed ESPM and provide your feedback, talk to your Huntress account team about joining Early Access. Otherwise, stay tuned. We expect to announce more in the near future.