Full Report
See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign.
Analysis Summary
# Incident Report: Huntress "Glass Box" Transparency Initiative
## Executive Summary
This report summarizes the transition of the Huntress SOC from a "Black Box" to a "Glass Box" investigation model via the new Investigations View. The update addresses the lack of visibility into benign findings, providing partners with full chronological timelines of SOC activities. The primary outcome is increased transparency, allowing stakeholders to validate SOC value and understand the reasoning behind threat resolutions.
## Incident Details
- **Discovery Date:** August 24, 2026 (Feature Launch)
- **Incident Date:** Continuous (Applies to all past and future investigations)
- **Affected Organization:** Huntress Partner Ecosystem
- **Sector:** Cybersecurity / Managed Service Providers (MSPs)
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** Continuous / Real-time
- **Vector:** EDR (Endpoint Detection & Response) and ITDR (Identity Threat Detection & Response) telemetry.
- **Details:** Investigations are triggered by signals from managed assets, including suspicious endpoint behavior or identity-based anomalies.
### Lateral Movement
- **Details:** The SOC tracks potential lateral movement by monitoring signals across multiple tenants and endpoints, consolidated within the new Investigations Dashboard.
### Data Exfiltration/Impact
- **Details:** In the context of this platform update, the "impact" is the previous lack of visibility for partners regarding benign closures, which hindered reporting and client communication.
### Detection & Response
- **How it was discovered:** Partner feedback regarding the difficulty of explaining SOC value for non-malicious events.
- **Response actions taken:** Development and deployment of the "Investigations View," featuring chronological timelines, analyst notes, and PDF export capabilities.
## Attack Methodology
*Note: As this article describes a platform feature rather than a single specific breach, the methodology below reflects what the SOC monitors for.*
- **Initial Access:** Monitored via EDR and ITDR signals.
- **Persistence:** Tracked through persistent footprint analysis in the SOC timeline.
- **Defense Evasion:** Identified via AI signal triage and human analyst review.
- **Discovery:** SOC performs reconnaissance on signals to determine if activity is benign or malicious.
- **Impact:** The tool aims to mitigate operational impact by providing clear remediation steps.
## Impact Assessment
- **Financial:** N/A (Internal platform improvement).
- **Data Breach:** None; focused on improving data transparency for security events.
- **Operational:** Significant improvement in the ability of MSPs to conduct Quarterly Business Reviews (QBRs).
- **Reputational:** Positive; increases trust through "Glass Box" transparency.
## Indicators of Compromise
- **Behavioral indicators:** The platform now explicitly lists the specific behavioral signals (e.g., suspicious PowerShell execution, unauthorized login attempts) that trigger an investigation, even if later cleared.
## Response Actions
- **Containment measures:** The new view allows partners to see exactly when and how the SOC contained a threat.
- **Eradication steps:** Clear, documented remediation steps are provided in the incident timeline.
- **Recovery actions:** Automated and manual remediation status tracking.
## Lessons Learned
- **Key takeaways:** Visibility into "nothing happened" (benign results) is as important for business operations as visibility into "something happened."
- **What could have been done better:** Historically, the "black box" nature of SOC work led to gaps in demonstrating value to end-customers.
## Recommendations
- **Prevention measures:** Partners should utilize the "Investigations Dashboard" to proactively identify high-risk organizations within their accounts based on signal volume.
- **Continuous Monitoring:** Leverage the new PDF export feature to maintain a permanent audit trail of all SOC investigations for compliance purposes.