Your business’ toughest competition might be criminal. See why.
Utility navigation bar redirect icon
Portal LoginSupportContact
Search
Close search
Huntress Logo in Teal
  • Platform Overview
    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Huntress Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Huntress Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Huntress Managed ESPM

    Proactively secure endpoints against attacks.

    Huntress Managed ESPM

    Proactively secure endpoints against attacks.

    Integrations
    Integrations
    Support Documentation
    Support Documentation
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
  • Threats We Stop
    Phishing
    Phishing
    Business Email Compromise
    Business Email Compromise
    Ransomware
    Ransomware
    View Allright arrowView Allright arrow
    Industries We Serve
    Education
    Education
    Financial Services
    Financial Services
    State and Local Government
    State and Local Government
    Healthcare
    Healthcare
    Law Firms
    Law Firms
    Manufacturing
    Manufacturing
    Utilities
    Utilities
    View Allright arrowView Allright arrow
    Tailored Solutions
    MSPs
    MSPs
    Resellers
    Resellers
    SMBs
    SMBs
    Compliance
    Compliance
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
  • Pricing
  • Community Series
    The Product Lab

    Shape the next big thing in cybersecurity together.

    The Product Lab

    Shape the next big thing in cybersecurity together.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    Resources
    Upcoming Events
    Upcoming Events
    ebooks
    ebooks
    On-Demand Webinars
    On-Demand Webinars
    Videos
    Videos
    Whitepapers
    Whitepapers
    Datasheets
    Datasheets
    Cybersecurity Education
    Cybersecurity 101
    Cybersecurity 101
    Cybersecurity Guides
    Cybersecurity Guides
    Threat Library
    Threat Library
    Real Tradecraft, Real Results
    Real Tradecraft, Real Results
    2026 Cyber Threat Report
    2026 Cyber Threat Report
    The Huntress Blog
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
  • Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    The Huntress SOC

    24/7 Security Operations Center

    The Huntress SOC

    24/7 Security Operations Center

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Community

    Get in touch with the Huntress Community team

    Community

    Get in touch with the Huntress Community team

    Compare Huntress
    Bitdefender
    Bitdefender
    Blackpoint
    Blackpoint
    Breach Secure Now!
    Breach Secure Now!
    Crowdstrike
    Crowdstrike
    Datto
    Datto
    SentinelOne
    SentinelOne
    Sophos
    Sophos
    Compare Allright arrowCompare Allright arrow
  • HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    Partners
    MSPs

    Join our partner community to deliver expert-led managed security.

    MSPs

    Join our partner community to deliver expert-led managed security.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Tech Alliances

    Driving innovation through global technology Partnerships

    Tech Alliances

    Driving innovation through global technology Partnerships

    Microsoft Partnership

    A Level-Up for Your Business Security

    Microsoft Partnership

    A Level-Up for Your Business Security

  • Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Awards
    Awards
    Contact Us
    Contact Us
  • Portal Login
  • Support
  • Contact
  • Search
  • Get a Demo
  • Start for Free
Portal LoginSupportContact
Search
Close search
Get a Demo
Start for Free
HomeBlog
Threat Recap: Huntress Managed EDR Trial by Fire
Published:
January 25, 2022

Threat Recap: Huntress Managed EDR Trial by Fire

By:
Roger Koehler
Share icon
Glitch effectGlitch effectGlitch effect

In cybersecurity, time is critical.

Whether you’re chasing down a threat actor who’s laterally moving through your networks or working to isolate a host to stop a ransomware attack in its tracks, even one second can make all the difference.

I’m fortunate to work with incredible technology and the best cybersecurity experts in the industry, as they afford us the agility to respond quickly to events.

We saw this firsthand during the first holiday weekend in 2022. Surprise, surprise—the first holiday weekend of the year happened to mark the date of our first threat advisory of the year as well. 

A Recap of Events

1448 ET - January 14, 2022

It’s a normal Friday afternoon. Our 24/7 ThreatOps team is hard at work, threat hunting and sending incident reports to our partners to ensure their customers are protected. 

At 2:48pm ET, one of our analysts investigates a Windows Defender alert (we review these to weed out Defender false positives). After a quick investigation, it’s determined that it’s Cobalt Strike, a remote access tool (RAT) that attackers use to maintain unauthorized access to either install additional malicious software (e.g. ransomware) or attempt to laterally move through the network to other systems to increase their ability to cause havoc. Once confirmed, our analyst sends a critical report to the partner.

behavior

Within minutes, another Windows Defender alert comes in from another system from a completely different organization. Once again, the analyst performs a quick investigation and sends a critical incident report to the partner.

In both cases, Windows Defender did its job and protected the endpoint from the RAT being executed. But one thing to consider, and a key reason we added our Managed Antivirus solution, is that attackers will often try something else if they are blocked. Monitoring antivirus detections is a critical aspect of a defense-in-depth strategy and provides context to call the bigger picture into view.

1700 ET - January 14, 2022

As our analysts continue to do their job, one analyst notices a commonality between the two previous reports that both are VMware Horizon servers. After further review and some open-source research, we determine that this may be a bigger incident. 

Our Head of Threat Operation Center quickly puts out a message on Twitter to let others know we’re observing Cobalt Strike activity as well. 

Screen Shot 2022-01-25 at 9.45.13 AM

At this point, it’s starting to look like this is related to the UK’s National Health Service (NHS) alert from January 5 that hackers were actively targeting Log4Shell vulnerabilities in VMware Horizon servers in an effort to establish persistent access via web shells.

And then, it clicks: It’s not just another Friday, but it's a holiday weekend—a prime time for cyberattacks. For defenders, that can often mean a long and busy weekend is ahead.

We start letting our entire ThreatOps team and others at Huntress know that it might be a rough night. Luckily, we have such an amazing team that instead of shutting down the computer for the holiday weekend, many of our teammates jump back online to help out a lending hand—although I’m sure we were all feeling the sentiment described below.

Happy Thanksgiving

1938 ET - January 14, 2022

After a quick team-wide debrief, one of our leaders on the Huntress product team recommends we roll out our managed endpoint detection and response (EDR) capability, Process Insights, to all systems with VMware Horizon. This new endpoint detection and response (EDR) capability is based on an acquisition we made in early 2021 that allows us to proactively detect and respond to non-persistent malicious behavior by giving us the ability to collect detailed information about processes. After a quick chat, we contacted a few of our private beta participants and let them know our plan to roll them out to these servers due to the growing possibility of a large-scale incident.

1945 ET - January 14, 2022

Now that we had confidence that this was not a false alarm, we decided to get the word out to the community. We post on r/msp, notify many in the MSP peer group and begin working on notifying our partners. The ThreatOps team puts together a spreadsheet that includes all of our partners with customers using VMware Horizon servers. We give that to our sales team, executives and others who were anxious to give a lending hand to our partners.

After a short period of time, ThreatOps is able to update the list to include other key details, including the version of VMware Horizon server which allows us to further pinpoint the affected systems. After giving a few thankful partners the heads up—as well as inadvertently scaring a few partners that had already patched—we stopped the calls so we could use this new spreadsheet and give a more focused notification.

At this time, with the additional information on versions of VMware Horizon servers that are vulnerable to Log4Shell, we decide to proactively roll out our managed EDR feature to all of these systems.

2105 ET - January 14, 2022

We decided to start digging into VMware’s articles as well as VMware’s Security Advisory to better understand their recommendation. As we dug into VMware’s mitigation tool, we realized that if a web shell is discovered, the tool does not do anything to remove the web shell.

We continued to analyze this and decided that the best way to ensure that no web shells exist on the system would be to restore from backups. In order to do this, we really needed to download every JavaScript file and analyze it to determine which had web shells and when they were inserted so we had a good timeline of the original attack.

pasted image 0

0054 ET - January 15, 2022

After long hours of digging into every vulnerable host, updating our spreadsheet to include which ones had already been exploited and had web shells, one of our researchers recreated the backdoor trigger and was able to execute a simple “whoami” command.

runcurl2

We were now able to confirm this wasn’t just a theory—this was bad. The web shell gave system access just as the earlier research had indicated.

The good news was that within a couple of minutes of processing time, our new managed EDR capability was able to not only see this command but also give us a visualization of the process tree.

pasted image 0 (2)
(Rendered in Elastic Kibana with Huntress' Process Insights)

Within 15 minutes, our team was able to create a detector based on this behavior and similar behaviors which allowed Process Insights to alert us of web shell triggers giving us visibility into previously unknown execution. 

This was a moment we all realized the hard work that has been put into Process Insights over the last year was worth it. We now not only had our beliefs that Process Insights would be game-changing for our partners and their customers, but we now had a real-world example of it in action. We also solidified why our Managed Antivirus capability was so vital because we were able to turn an alert into a detector that can give us an earlier warning on malicious behavior. This was all done in less than a 12-hour window.

0530 ET - January 15, 2022

At this point, we’d sent out reports to all of our customers, we’d updated our Reddit post with the most up-to-date information including mitigation techniques and we had called every partner with web shells installed. Our analyst in Australia was finishing up his shift while our analyst in the United Kingdom was fully up-to-speed and ready to go for the day. At this point, our incident response team decided to call it a night as we knew it would be a busy day with follow-up questions and details.

The Rest of the Holiday Weekend

Our team was hard at work continuing to send incident reports for Cobalt Strike, cryptominers and other malware being installed on the VMware Horizon servers. We continued to contact our partners to let them know that they really needed to patch before this escalated into something more serious—like attackers spreading throughout the network or even launching ransomware. Many of our partners believed they had patched, but most of the time, they were just running the mitigation script and not actually patching.

Lessons Learned

We’ve said it many times before, but it bears repeating: No security vendor is going to be able to stop something 100 percent of the time. As many cybersecurity experts say, there is no silver bullet in security, so it’s important that you have patching, security-focused processes, multi-factor authentication (MFA), and other defense-in-depth practices. 

And as for Process Insights, our managed EDR capability? It’s now generally available to all new and existing partners! If you're a Huntress partner, please reach out to your account manager or support for more information.

Categories
Threat Analysis
Summarize this postClose Speech Bubble
ChatGPTClaudePerplexityGoogle AI

See Huntress in action

Our platform combines a suite of powerful managed detection and response tools for endpoints and Microsoft 365 identities, science-backed security awareness training, and the expertise of our 24/7 Security Operations Center (SOC).

Book a Demo
Share
Facebook iconTwitter X iconLinkedin iconDownload icon
Glitch effect

You Might Also Like

  • Threat Advisory: VMware Horizon Servers Actively Being Hit With Cobalt Strike

    Huntress is monitoring an incident in which VMware Horizon Servers are being hit with Cobalt Strike. Read our up-to-date blog to learn more.
  • All in a Day’s Work: Fighting Log4Shell with Huntress Managed EDR

    Read how our ThreatOps team used Huntress Managed EDR and Managed Antivirus to stop bad actors who were exploiting Log4Shell vulnerabilities.
  • How to Crush Cybercriminals with Managed Antivirus

    Dive into the types of threats we’ve thwarted with Managed Antivirus and how IT teams are seeing more value from making the switch.
  • Checking the EDR Box: Evolving Endpoint Protection and the Next Iteration of Huntress

    Discover how Process Insights brings new managed EDR functionality to The Huntress Managed Security Platform to help you detect cyberattacks as they happen.
  • Unraveling a Reverse Shell with Huntress Managed EDR

    Read about our journey to unravel a PowerShell reverse shell—and how our Managed EDR feature tipped us off that something wasn’t right.
  • Disrupting Endpoint Attacks with Huntress Managed EDR

    Standard EDR creates a gap between detection and action. Huntress closes it. Learn how our Attack Disruption Engine automatically disrupts threat actors and reduces the impact of endpoint attacks.
  • The Value of Managed EDR for the Modern MSP

    Our partners at Clear Guidance Partners experienced the value of our EDR capabilities in real-time, pitting them against an active ransomware attack.
  • Healthy or Unhealthy? Huntress’ New Client-Side API Brings Endpoint Clarity

    Get to know Huntress' new client-side API for EDR, which enables real-time agent health checks and simplifies endpoint management. With instant “healthy” or “unhealthy” status updates, you can ensure your security is running smoothly.

Sign Up for Huntress Updates

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.
Privacy • Terms
By submitting this form, you accept our Terms of Service & Privacy Policy
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Huntress Managed Security PlatformManaged EDRManaged EDR for macOSManaged EDR for LinuxManaged ITDRManaged SIEMManaged Security Awareness TrainingManaged ISPMManaged ESPMBook a Demo
PhishingComplianceBusiness Email CompromiseEducationFinanceHealthcareManufacturingState & Local Government
Managed Service ProvidersResellersIT & Security Teams24/7 SOCCase Studies
BlogResource CenterCybersecurity 101Upcoming EventsSupport Documentation
Our CompanyLeadershipNews & PressCareersContact Us
Huntress white logo

Protecting 215k+ customers like you with enterprise-grade protection.

Privacy PolicyCookie PolicyTerms of UseCookie Consent
Linkedin iconTwitter X iconYouTube iconInstagram icon
© 2025 Huntress All Rights Reserved.

Join the Hunt

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy