Log inSign up
Huntress
4,254 posts
Image
user avatar
Huntress
@HuntressLabs
Managed #cybersecurity without the complexity. EDR, ITDR, SIEM & SAT crafted for under-resourced IT and Security teams.
Maryland, USA
huntress.com
Joined June 2015
533
Following
40.3K
Followers
  • user avatar
    Huntress
    @HuntressLabs
    Oct 22, 2021
    And getting paid to turn @_JohnHammond into a meme? Priceless. 😏 Happy Friday! #CybersecurityAwarenessMonth
    Image
  • user avatar
    Huntress
    @HuntressLabs
    Dec 24, 2021
    Image
  • user avatar
    Huntress
    @HuntressLabs
    Feb 11, 2022
    People lie, but web shells don't. 😉
    Image
  • user avatar
    Huntress
    @HuntressLabs
    Oct 14, 2021
    Yes, there's a class for pretty much everything these days, but...choose wisely, folks. 😅 #CybersecurityAwarenessMonth #FightThePhish #phishing @_JohnHammond
    Image
  • user avatar
    Huntress
    @HuntressLabs
    May 8, 2025
    Our SOC tackled an attempted ransomware intrusion tied to Makop ransomware tactics. Here’s what went down 👇
    48K
  • user avatar
    Huntress
    @HuntressLabs
    Nov 21, 2016
    DLL injection, persistence, and bypassing UAC w/Windows environment variables. Fun read w/some source code. breakingmalware.com/vulnerabilitie… #DFIR
    Image
  • user avatar
    Huntress
    @HuntressLabs
    Jun 1, 2019
    More attackers are using WMI EventConsumer's to execute PowerShell payloads that retrieve obfuscated payloads from Google Docs (google.com domain). Great example of how a firewall or DNS filter could allow hackers to slip by.
    Image
    Image
  • user avatar
    Huntress
    @HuntressLabs
    Jun 12, 2025
    defendnot disables Windows Defender by creating a fake AV product using undocumented WSC APIs—no reg tweaks, no policies. We break down how to detect it from a blue team perspective + share Sigma rules to catch it in action. huntress.com/blog/defendnot…
    Image
    21K
  • user avatar
    Huntress
    @HuntressLabs
    Dec 11, 2021
    We’ve created a tool to help you detect applications that are vulnerable to CVE-2021-44228. (h/t @calebjstewart, @jslagle & @_JohnHammond) This is intended for testing purposes only and should be used on systems you’re authorized to test. hubs.ly/Q010G3ZG0
    Image
  • user avatar
    Huntress
    @HuntressLabs
    Feb 3, 2025
    A threat actor compromised a healthcare company’s VPN appliance 👇 Once inside the network, they:
    43K
  • user avatar
    Huntress
    @HuntressLabs
    Oct 13, 2016
    Hacker tool automatically steals KeePass' credentials 4min after the software launches. Uses a permanent WMI event. kitploit.com/2016/10/powerl…
    Image
  • user avatar
    Huntress
    @HuntressLabs
    Jan 13, 2025
    A threat actor broke into a Wisconsin food factory’s network Our SOC saw every move they made 👇
    32K
  • user avatar
    Huntress
    @HuntressLabs
    Jul 2, 2021
    Our team is tracking a critical #ransomware incident affecting MSPs and their customers, which appears to be a #KaseyaVSA supply chain attack. Follow our latest updates and threat intel on Reddit: hubs.ly/H0Rx6-P0
    Image
  • user avatar
    Huntress
    @HuntressLabs
    Jul 29, 2022
    You might be a cybercriminal if...(a thread). 🧵
    Image

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms of Service|Privacy Policy|Cookie Policy|Accessibility|Ads info|© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up