Full Report
Do you have what it takes to hack_it? Read on for a sneak peek into our upcoming hack_it event and how it can help you better understand how hackers use their skills against you.
Analysis Summary
# Industry News: Huntress Announces hack_it 2021.2 to Drive "Threat-Informed Defense"
## Summary
Managed detection and response (MDR) provider Huntress has announced the second iteration of its 2021 "hack_it" event, a community-focused training initiative designed to teach IT professionals how to think like attackers. The event emphasizes a "threat-informed defense" strategy, offering hands-on workshops and gamified sessions to demystify hacker tradecraft for the Managed Service Provider (MSP) community.
## Key Details
- **Date:** October 25–27, 2021
- **Companies Involved:** Huntress (Primary), MITRE (Framework reference)
- **Category:** Community Event / Educational Initiative / Market Development
## The Story
Huntress is doubling down on its commitment to cybersecurity education with the launch of hack_it 2021.2. The event is structured around the concept of "threat-informed defense," a methodology championed by MITRE that relies on a deep understanding of adversary tactics to build more resilient security postures.
The event kicks off with a paid "0-Day Training Lab" focused on Windows-based breaches, followed by several free sessions. These include a gamified "cybercrime mystery" to identify threat actors, a "dark web safari" to analyze real-world compromised data, and a deep-dive technical session on creating and defending against macro-enabled malware in phishing campaigns.
## Business Impact
### For the Companies Involved (Huntress)
- **Brand Authority:** Strengthens Huntress’ position as a thought leader in the MSP security space rather than just a software vendor.
- **Customer Retention:** By educating their partner base (MSPs), Huntress ensures their users are more effective at using their tools, reducing churn and increasing product value.
### For Competitors
- **Raising the Bar:** Competitors in the MDR and EDR space may need to increase their own community engagement and educational offerings to remain competitive in the "partner-enablement" category.
- **Market Differentiation:** Huntress is differentiating itself by focusing on the "human" element of security (mindset and tradecraft) rather than solely on automated detection.
### For Customers (MSPs and SMBs)
- **Skill Gap Mitigation:** Provides low-cost, high-value training for IT staff who may not have dedicated security roles.
- **Improved Defense:** Direct exposure to "offense" allows MSPs to better configure their clients' environments against real-world threats.
### For the Market
- **Shift toward Open Education:** The move toward free, gamified technical training suggests a market trend where vendors must provide educational value to capture market share.
- **Adoption of MITRE Frameworks:** Further solidifies the MITRE ATT&CK and threat-informed defense models as the industry standard for SMB/MSP security.
## Technical Implications
- **Tradecraft Analysis:** The event focuses on TTPs (Tactics, Techniques, and Procedures), specifically Windows-based attack vectors and macro-enabled malware.
- **Environmental Simulation:** The use of a "modernized virtual environment" for the 0-Day lab reflects the industry's shift toward lab-based, hands-on learning over passive webinars.
## Strategic Analysis
- **Market Positioning:** Huntress is positioning itself as the "Security Ally" for the MSP channel, filling the gap between basic antivirus and high-end enterprise SOC services.
- **Competitive Advantage:** By fostering a community-based approach, Huntress builds a moat of brand loyalty that is harder to disrupt than software features alone.
- **Challenges:** As hacker tradecraft evolves rapidly, maintaining the relevance of educational content requires constant R&D investment.
## Industry Reactions
- **Analyst Opinions:** Analysts generally view Huntress’ focus on the MSP community as a savvy move, as MSPs are currently the primary targets for supply-chain ransomware attacks.
- **Market Response:** The decision to host the event twice in one year indicates high demand for accessible, offensive-minded security training.
## Future Outlook
- **Predictive Trend:** Expect more "purple team" (combined offensive and defensive) training events from mid-market vendors.
- **What to Watch for:** Watch for whether Huntress integrates these training "labs" directly into their product platform as a permanent feature.
## For Security Professionals
- Practitioners should take note of the shift toward **threat-informed defense**. Understanding how macros are currently being weaponized and how to "dumpster dive" for leaked credentials on the dark web are becoming baseline skills for modern defenders.