Cybercrime’s Evolving—Hear How at the Huntress Booth

March 23 - March 26  |  South Expo, Booth 3301

New strategies, new tradecraft, new threats—hackers are changing the game. Find out how to stay ahead of ‘em at RSAC 2026 with Huntress.

Huntress platform

Join Us: Huntress After Hours

Elements Bar & Lounge

165 O'Farrell St, 4th Floor

San Francisco, CA 94102

6pm - 8pm


Join Huntress and your peers for an exclusive meet-up where you can eat, drink, and unwind with fellow security pros. We’ll talk tech, trade war stories from the front lines, and show you how our team hunts down real-world threats every day.

Huntress platform

Stop by the Booth #S-3301

We have 20+ bite-sized booth sessions planned, led by the folks who live in the trenches of cyber defense every day. From real-world tradecraft to practical how-tos, our experts will break down what’s really happening in the wild—and what you can do about it. Come for the education, stay for the war stories, and walk away smarter than when you showed up.

Huntress platform

Gear Up with Ransomwear

Get your Huntress tee and gear up in the latest Ransomwear. Stop by the booth to watch how we wreck ransomware in the wild, meet the team, and walk away with real security insights (and swag) that stick.

Booth Theater Sessions

Stop by S-3301 and Listen for a Chance to Win

  • 5:15pm-5:30pm - Ghost Hunting: Dissecting SocGholish operation

  • 5:30pm-5:45pm - Alert Fatigue Is Real: Here’s How We Shut Up the Noise

  • 5:45pm-6:00pm - Teaching Your Human Firewall to Think Like a Hacker

  • 6:00pm-6:15pm - Shifting Left on Threats: Closing Endpoint & Identity Posture Gaps

  • 6:30pm-7:00pm - The Hackers Playbook & AMA with Huntress DE&TH Team
  • 11:00am-11:15am - Defending the Rest of Us
  • 12:00pm-12:15pm - Defending the Rest of Us
  • 1:00pm-1:15pm - Defending the Rest of Us
  • 2:00pm-2:15pm - Defending the Rest of Us
  • 3:00pm-3:15pm - Identity Abuse in M365 and Google Workspace
  • 3:30pm-3:45pm - Alert Fatigue Is Real: Here’s How We Shut Up the Noise
  • 3:45pm-4:00pm - From React2Shell to Root: Anatomy of a Modern Linux Attack
  • 4:00pm-4:15pm - Teaching Your Human Firewall to Think Like a Hacker
  • 4:30pm-4:45pm - The Identity Breach You Didn’t Know You Had: Google Workspace
  • 5:00pm-5:15pm - Behind the Screens: How Real Threats Are Spotted, Investigated, and Shut Down
  • 5:30pm-5:45pm - Hype vs Harm: Reframing Security Priorities
  • 11:00am-11:15am - Defending the Rest of Us
  • 12:00pm-12:15pm - Defending the Rest of Us
  • 1:00pm-1:15pm - Defending the Rest of Us
  • 2:00pm-2:15pm - Defending the Rest of Us
  • 3:00pm-3:15pm - Identity Abuse in M365 and Google Workspace
  • 3:30pm-3:45pm - The Identity Breach You Didn’t Know You Had: Google Workspace
  • 3:45pm-4:00pm - From React2Shell to Root: Anatomy of a Modern Linux Attack
  • 4:00pm-4:15pm - Hype vs Harm: Reframing Security Priorities
  • 4:15pm-4:30pm - Teaching Your Human Firewall to Think Like a Hacker
  • 4:30pm-4:45pm - Alert Fatigue Is Real: Here’s How We Shut Up the Noise
  • 5:00pm-5:15pm - Shifting Left on Threats: Closing Endpoint & Identity Posture Gaps
  • 5:30pm-6:00pm - The Hackers Playbook
  • 11:00am-11:15am - Defending the Rest of Us
  • 12:00pm-12:15pm - Defending the Rest of Us
  • 1:00pm-1:15pm - Defending the Rest of Us
Glitch effect

Speaker Sessions

SocGholish Unmasked: Lessons from 100+ SocGholish Cases

3/23 | 2:20pm PDT - 3:10pm PDT | HTA-M07

Anna Pham
| Senior Hunt & Response Analyst, Huntress


SocGholish is one of the most effective initial access operations feeding ransomware groups like RansomHub. This session will break down findings from 100+ real-world SocGholish cases, tracing its evolution and exposing payloads including the advanced GhostWeaver backdoor. Attendees will leave with detection and mitigation strategies to stop SocGholish before it opens the door to ransomware.

Storms on the Horizon: Defending Against the Next Storm-2372

3/24 | 8:30am - 9:20am PDT | HT-T01

Jenko Hwong | Principal Threat Researcher, Huntress


With Storm-2372 (2025), Russian threat actors used OAuth Device Code Phishing to abuse the device registration process to hijack the Primary Refresh Token. This session will recreate the attack, compare valid activity, showing logging, access policies, and detection rules. Attendees will take away concrete implementation guidance and what can be changed to mitigate/detect/respond more effectively.

Master Threat Hunting: Hands-On with Elastic and Forensics Tools

3/24 | 8:30am - 10:30am PDT | LAB2-T01



Edward Crowder
| Principal Research, Crowder Enterprise Consulting


Anna Pham
| Senior Hunt & Response Analyst, Huntress


Dive deep into a real two-month Latrodectus intrusion using Elastic Stack, CyberChef, Volatility, and Wireshark. Participants will hunt through network traffic, memory dumps, and SIEM data to uncover the complete attack chain from JavaScript loader to data exfiltration. Gain hands-on experience with industry-standard tools while building practical threat hunting skills.

Glitch effectGlitch effect

Book Your Booth Session

Lock in 20 minutes with the Huntress team at RSAC to get face-to-face time, knock out your biggest questions, and walk away with a clear, actionable plan for your security stack.

By submitting this form, you accept our Terms of Service & Privacy Policy
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Huntress platform

Huntress 2026 Cyber Threat Report

From changing strategies, streamlining attack playbooks, and leveling up their tradecraft, hackers shook things up in 2025.

Huntress glitch effect