Full Report
A recap of hack_it 2021, a virtual security training event packed with interactive exercises, malware analysis, hacking workshops and more.
Analysis Summary
# Industry News: Huntress Leverages Offensive Security Training to Drive MSP Market Engagement
## Summary
Huntress hosted its second annual "hack_it" virtual training event, focusing on offensive security techniques and malware analysis to educate Managed Service Providers (MSPs) and internal IT teams. The event highlights a growing market trend where security vendors use community-driven education and "hacker-perspective" training to demonstrate the limitations of traditional Antivirus (AV) solutions.
## Key Details
- **Date:** March 31, 2021
- **Companies Involved:** Huntress (Primary), various MSP/IT community leaders
- **Category:** Community Engagement / Brand Positioning / Technical Training
## The Story
The hack_it 2021 event was structured to pivot the traditional defensive mindset by forcing participants to act as "Shady Incorporated," a fictional cybercrime entity. By reversing the NIST cybersecurity framework, attendees planned attacks, focusing on reconnaissance, initial access, and exfiltration rather than just identification and protection.
Key technical tracks included live demonstrations of how attackers bypass antivirus software and a collaborative "Tales from the Trenches" panel where IT leaders shared horror stories involving unpatched systems, phished users, and the Hafnium (Exchange Server) exploitation. The core narrative of the event was that prevention-only strategies are failing, and defenders must understand adversarial tradecraft to survive.
## Business Impact
### For the Companies Involved (Huntress)
- **Brand Authority:** Strengthens Huntress's position as a "thought leader" that understands the adversary, not just the software.
- **Lead Generation:** Using educational content as a top-of-funnel strategy to convert MSPs into platform users.
### For Competitors
- **Pressure to Innovate Training:** Traditional AV vendors face increased pressure to justify their efficacy as Huntress demonstrates how easily these tools are bypassed.
- **Community Loyalty:** Competitors may find it harder to displace Huntress in accounts where the MSP feels a strong community and educational connection to the brand.
### For Customers (MSPs and IT Pros)
- **Skills Gap Mitigation:** Provides low-cost, high-value training to teams that may lack the budget for premium certifications like OSCP.
- **Risk Realism:** Helps IT managers secure budget for more than just AV by demonstrating real-world bypasses to non-technical stakeholders.
### For the Market
- **Shift Toward EDR/MDR:** The event reinforces the market shift from "preventative" security to "detection and response," highlighting that breach is inevitable.
## Technical Implications
The event highlighted the technical reality that attackers are successfully flipping the NIST framework. Specifically, the "Slipping Past Prevention" session showcased how modern malware uses obfuscation and memory-only execution to remain invisible to signature-based and even some heuristic-based AV engines.
## Strategic Analysis
- **Market Positioning:** Huntress is positioning itself as the "Defender of the MSP," filling a gap between basic AV and high-end enterprise EDR.
- **Competitive Advantage:** By focusing on the "human" element—both the attacker's mindset and the community's shared experiences—Huntress creates a "sticky" ecosystem that is harder to churn than a simple software subscription.
- **Challenges:** As they expose zero-day vulnerabilities in event platforms (as noted in the linked articles), Huntress must maintain its own high security standards to avoid becoming a target of the same supply chain attacks they warn against.
## Industry Reactions
- **Expert Commentary:** Attendees noted that the training "brings a new level of awareness to how persistent hackers actually are."
- **Market Response:** The success of the virtual format during the pandemic era highlights the demand for interactive, gamified cybersecurity training over static webinars.
## Future Outlook
- **Predictions:** Expect more security vendors to adopt "CTF" (Capture The Flag) style marketing to engage technical audiences.
- **What to Watch For:** Continued focus on the "Hafnium" and "Exchange" aftermath, as these vulnerabilities provided the catalyst for many MSPs to upgrade their security stacks in 2021.
## For Security Professionals
Practitioners should take note of the "Shady Inc." methodology: identifying targets via reconnaissance and focusing on exfiltration profit. The takeaway is clear—if your security strategy relies solely on a "Detect" phase without a robust "Respond" and "Recover" plan, you are vulnerable to the tactics demonstrated at hack_it.