ITSecurityGuru

Huntress Makes RMM-Blocking Feature Free for All Customers as Attacks Surge 277%


Cybersecurity vendor Huntress has opened up a new application control capability to its entire customer base for free, as new data shows attacks abusing remote monitoring and management (RMM) tools rose sharply over the past year.

The feature, called RMM Guard, is part of a broader product Huntress is building called Managed Endpoint Security Posture Management (ESPM), currently in early access. RMM Guard inventories every remote access tool running across a customer’s environment and automatically blocks any that haven’t been explicitly authorised, including attacker-controlled copies of legitimate tools such as ScreenConnect.

The move comes as Huntress reports that RMM-based attacks increased by 277% over the past year, and that roughly a third of all incidents its analysts observed so far this year could have been prevented by blocking unauthorised RMM software from running in the first place.

Attackers have increasingly turned to legitimate remote access software as a way to gain persistent footholds inside victim environments, since such tools are widely trusted by IT teams and rarely raise alarms on their own. Huntress cited a recent case in which a phishing email disguised as a “pay increase” notice led an employee to install LogMeIn Resolve, giving an attacker remote access that was only caught thanks to endpoint monitoring and its 24/7 Security Operations Centre.

Application control, sometimes called allow-listing, is a long-established security practice that only permits known, approved software to run rather than trying to catch malicious activity after the fact. Huntress argues, however, that most application control products on the market were designed for large enterprises with dedicated security teams, and are too complex and resource-intensive for smaller IT teams and managed service providers (MSPs) to implement. Industry frameworks typically call for months of planning, policy-building and phased rollout before a full application control programme becomes usable, a timeline the company says is unrealistic for lean teams already stretched across other priorities.

Rather than asking customers to build out a full allow-list policy for every application, Huntress says its approach will focus first on categories of software most frequently abused by attackers, starting with RMM tools, before expanding to other categories such as AI and file-sharing applications.

RMM Guard was previously restricted to a learning mode and required a Huntress Managed SIEM subscription. Those restrictions have now been lifted, and the capability is available at no additional cost to any Huntress customer or partner with an agent deployed, while Managed ESPM remains in early access ahead of a wider commercial release.

Existing Huntress customers can request access to the ESPM early access programme through their account manager.



Source link