Full Report
Our workshop dedicated to hacker tradecraft is back November 14-16. Mark your calendars, sign up today and don't forget your hacker hat!
Analysis Summary
# Industry News: Huntress Announces hack_it 2022 Training Event
## Summary
Managed detection and response (MDR) provider Huntress has announced the return of "hack_it," a virtual three-day training event focused on hacker tradecraft and defensive strategies. Scheduled for November 14–16, 2022, the workshop aims to bridge the gap between cybersecurity awareness and practical, actionable technical skills for defenders.
## Key Details
- **Date:** November 14–16, 2022 (Announced October 4, 2022)
- **Companies Involved:** Huntress
- **Category:** Industry Training / Community Engagement
## The Story
Huntress is launching the 2022 iteration of its "hack_it" workshop, a free educational initiative designed to help security professionals view the landscape through the lens of an attacker. The event features sessions led by Huntress leadership, including CEO Kyle Hanslovan and senior research staff.
The curriculum is divided into thematic tracks:
1. **Hacker Archetypes:** An interactive session debunking stereotypes to identify the "true face" of modern cybercriminals.
2. **Market Accountability:** A panel dedicated to deconstructing industry "buzzwords" and holding vendors accountable for their marketing claims.
3. **Technical Deep Dives:** Hands-on sessions focusing on Remote Monitoring and Management (RMM) tool vulnerabilities and DLL hijacking techniques.
Additionally, the event offers an optional "$0-Day Training Lab" for a $99 fee, providing a virtual environment for practitioners to simulate breach identification and response.
## Business Impact
### For the Companies Involved
- **Brand Authority:** By providing high-level technical training, Huntress solidifies its position as a thought leader and a "research-first" organization rather than just a software vendor.
- **Lead Generation:** The free event serves as a top-of-funnel engagement tool to showcase the expertise behind the Huntress SOC and platform.
### For Competitors
- **Competitive Pressure:** Other MDR and security providers may face pressure to offer similar community-focused educational value to maintain brand loyalty among MSPs and technical practitioners.
- **Marketing Accountability:** The "Don't Let the Buzzwords Fool You" session specifically targets the hyperbolic marketing often used by competitors, potentially shifting how buyers evaluate security products.
### For Customers
- **Skill Acquisition:** End-users and MSP partners receive low-cost, high-value technical training that improves their ability to defend their specific environments.
- **Better Vendor Vetting:** Participants gain frameworks to better evaluate security claims, leading to more informed purchasing decisions.
### For the Market
- **Shift to Transparency:** The event signals a trend toward radical transparency in the security industry, moving away from "black box" solutions toward community-shared tradecraft.
## Technical Implications
The focus on **DLL hijacking** and **RMM tool vulnerabilities** highlights a critical trend in the threat landscape: the weaponization of legitimate administrative tools. This technical focus prepares defenders for "living-off-the-land" attacks that bypass traditional signature-based detection.
## Strategic Analysis
- **Market Positioning:** Huntress is positioning itself as the "Defender of the Mid-Market/MSP," emphasizing practical utility over corporate jargon.
- **Competitive Advantage:** By teaching the "offensive" side, Huntress builds higher trust with technical audiences who are often skeptical of traditional sales pitches.
- **Challenges:** Maintaining a balance between high-level educational content and the underlying goal of product promotion without alienating the technical community.
## Industry Reactions
- **Market Response:** Historically, Huntress's tradecraft-focused events have seen high engagement from the MSP community, which often lacks access to expensive, high-end cybersecurity research labs.
## Future Outlook
- **Predictive Trend:** Expect to see an increase in "lab-based" marketing where vendors provide sandbox environments to prove product efficacy against real-world tradecraft.
- **Watch For:** Updates on RMM vulnerabilities, as these tools remain a primary target for supply-chain attacks.
## For Security Professionals
This event is highly relevant for practitioners looking to move beyond "Cybersecurity Awareness" into "Cybersecurity Capability." The focus on DLL hijacking and RMM exploits provides immediate, applicable knowledge for those managing environments reliant on remote management software.