Full Report
Read up on how and why Huntress built its Managed ITDR (formerly MDR for Microsoft 365) solution to help combat the growing threat of business email compromise (BEC).
Analysis Summary
# Industry News: Huntress Rebrands and Expands Managed ITDR to Combat BEC
## Summary
Huntress has officially pivoted its "MDR for Microsoft 365" solution to **Managed Identity Threat Detection and Response (ITDR)** to address the $50 billion Business Email Compromise (BEC) crisis. The solution combines automated log monitoring with a 24/7 Security Operations Center (SOC) to protect SMBs from identity-based attacks that bypass traditional perimeter defenses.
## Key Details
- **Date:** October 16, 2023
- **Companies Involved:** Huntress, Microsoft
- **Category:** Product Launch / Rebranding
## The Story
Recognizing that Business Email Compromise (BEC) has become one of the most financially devastating threats to small and medium-sized businesses (SMBs), Huntress has evolved its service offerings to focus heavily on identity security. The newly branded **Managed ITDR** (formerly MDR for Microsoft 365) specifically targets the BEC attack chain—from initial reconnaissance and credential theft to the creation of malicious inbox rules and unauthorized payment redirection.
The service leverages a "human-plus-software" model. Automated detectors ingest massive volumes of Microsoft 365 tenant data (user logs, application events, and API calls), filtering out noise to identify suspicious patterns like anomalous user agents or "traitorware" (legitimate apps used for persistence). Confirmed threats are then managed by Huntress’ 24/7 SOC, which has the authority to isolate compromised identities and provide guided remediation to partners.
## Business Impact
### For the Companies Involved
- **Huntress:** Solidifies its reputation as the premier security partner for the "99%" (SMBs) by moving up the stack from endpoint security into identity and cloud productivity security.
- **Microsoft:** Benefits from a specialized partner that enhances the value of M365 licenses by providing the active monitoring and remediation that many SMBs cannot manage internally.
### For Competitors
- Managed Service Providers (MSPs) and MDR vendors who only offer endpoint protection (EDR) now face pressure to include identity-centric monitoring.
- The shift to ITDR sets a new baseline for what "managed protection" looks like in a cloud-first world.
### For Customers
- SMBs gain access to enterprise-grade SOC expertise at a price point suited for their scale.
- Faster response times for BEC attempts can prevent significant financial losses (averaging hundreds of thousands of dollars per incident).
### For the Market
- Signals a broader industry shift from "Device-Centric" security to "Identity-Centric" security as the primary battleground for cybercrime.
## Technical Implications
Huntress Managed ITDR focuses on specific technical indicators of BEC:
- **Anomalous User Agents:** Detecting logins from non-standard browsers or scripted environments.
- **Persistence via Apps:** Identifying when attackers grant permissions to third-party apps to maintain access without needing a password.
- **Inbox Manipulation:** Monitoring for hidden rules that redirect sensitive financial emails.
## Strategic Analysis
- **Market Positioning:** Huntress is positioning itself as an essential layer atop the Microsoft ecosystem, transforming "passive logs" into "active defense."
- **Competitive Advantage:** The use of a 24/7 human SOC to perform remediation, rather than just sending alerts, provides a critical "last mile" service that automated tools lack.
- **Challenges:** Heavy reliance on Microsoft’s API stability and log quality; the need to scale human analysts as the SMB customer base grows.
## Industry Reactions
- **Analyst Opinions:** Analysts view this as a necessary evolution, as identity is now the "new perimeter."
- **Market Response:** Strong demand is expected from the MSP community, which currently struggles to monitor disparate M365 tenants for identity-based anomalies.
## Future Outlook
- **Predictions:** Expect Huntress to expand ITDR capabilities to other SaaS platforms (e.g., Google Workspace, Salesforce) as attackers move beyond Microsoft 365.
- **What to watch for:** Increased integration between ITDR and traditional Endpoint Detection and Response (EDR) for a holistic view of the "Identity-to-Endpoint" attack path.
## For Security Professionals
Practitioners should note that traditional MFA is no longer a silver bullet. This news highlights the necessity of monitoring **post-authentication behavior**. Professionals should review their current visibility into M365 audit logs and evaluate whether they have the 24/7 capacity to respond to suspicious inbox rule changes or unauthorized app registrations in real-time.