Huntress, a security company founded by former NSA threat hunters, wants managed services providers to “break out your hacker hoodie and prepare to get shady” as an attendee at its “Making the Malware: A Choose-Your-Own Adventure” exercise on Tuesday, March 23.

The interactive exercise will let participants make the tough decisions — like should you build your own malware? Or buy it from the dark web? And it’s part of Huntress’ second Hack It event that kicks off on Monday, March 22.

The event reinforces Huntress’ mission of education and raising awareness. “We say raising the cybersecurity poverty line,” explained John Hammond, a senior security researcher at Huntress. “Getting folks aware and in the know about upcoming threats and new vulnerabilities.”

The massive SolarWind hack, discovered in December, was one of these teachable moments that sparked discussions about supply-chain security. And more recently the Microsoft Exchange attack stepped in as the biggest, baddest threat in the room.

Hammond said the Huntress team, which combined automated detection with human threat hunters, was the first to report via an managed services provider partner that these Microsoft Exchange Server zero-day vulnerabilities were first detected as early as Feb. 27. Since then, Huntress has discovered more than 100 webshells across about 1,500 vulnerable servers with anti-virus protection and endpoint detection and response installed. And now the coin miners and ransomware gangs have moved in, he added.

“Now, more than ever, we need to be paying attention to this stuff,” Hammond said. “Understanding how the offense works is the best defense. So maybe it sounds kind of weird to say we’re gonna play pretend hacker, we’re gonna put these sessions together, making the malware and cooking up cybercrime, but we really think that’s necessary.”

Huntress’  Roots

This second Hack It event includes a Hacking Windows pre-day. “That’s more of a classroom style session,” Hammond said. “It’s a four-hour training where the audience members are getting into a virtual environment, playing in a cyber range, and learning how do the hackers work the way that they do. We’re looking at tools, looking at frameworks, and actually being able to hunt down those persistent footholds. And we’re really excited about that because it lets folks really get hands on keyboard, be an operator, and do it for real, not just talk about it.”

Huntress was founded in 2015 and is headquartered in Maryland. It’s raised $19.8 million to date, and over the last year has seen “significant growth” in managed services provider partners especially in the wake of the SolarWinds hack. The service providers are all based in North America, but Huntress plans to expand into other regions while also growing its team of threat hunters “so we can follow the sun, and have someone on staff always willing to respond and able to react incidents across all time zones,” Hammond says. He joined the team in August as Huntress’ 30th employee and since then the company has grown to about 90 employees.

Huntress’ threat detection and response platform originally focused on persistent footholds: “the hackers’ backdoor, or the implant that they leave behind to maintain their access into organizations’ environments,” Hammond explained.

Moving Into Ransomware Protection, XDR

More recently, the platform expanded its capabilities to include a service called Ransomware Canary, which Huntress says enables faster ransomware detection, and a managed antivirus service in beta that lets its customers monitor and manage Microsoft Defender Antivirus. And finally, its External Recon highlights external attack surfaces and exposes easy entrance points to improve organizations’ security postures. This capability uses network-aware endpoint detection and response (EDR) technology that Huntress acquired from Level Effect in January and allowed the company to move into the hot extended detection and response (XDR) space.

The Level Effect acquisition brought malicious network traffic detection and expanded forensic capabilities to the Huntress platform regardless of endpoint location, Hammond said. “It opens the door for us to more of that XDR, or both network- and host-detection based technology where we have visibility into the bigger picture.”