Summary: This article provides an overview of the data Huntress products collect. This may change over time as products and detections evolve. Keep an eye on the changelog and other announcements for the latest updates. For more details on how data is collected and handled, view our privacy policy.
Jump to the following products:
Managed EDR
Huntress collects details about persistent (auto-starting or autorun) applications/files, Microsoft Defender data (AV and Firewall), and running processes on endpoints. This data is used to help determine if an autorun or process is legitimate.
Persistent applications and system information
The data collected includes:
- File path
- File metadata (size, timestamp, hashes, etc.)
- The user account the autorun starts under
- How the autorun starts (registry value, task, service, etc.)
- The version of the operating system and installed updates
- Computer configuration (CPU make/model, amount of RAM, amount of free and used storage, uptime)
- Network configuration (hardware type, IP address, MAC address, hostname, Active Directory status, Defender Firewall status)
- Limited Microsoft Defender data (update times, scan times, past detections, exclusions, other AV solutions, remediation status, quarantined files, etc.)
Managed Defender
With Managed Defender enabled, Huntress collects the following data provided by Microsoft Defender:
- Infected file and any resources used or linked to the infection (malware artifacts, registry keys, etc.)
- Infected file metadata (size, timestamp, path)
- The user account the infection was discovered under
Process Insights
Huntress also collects details about running processes on endpoints with Process Insights (on by default). This data includes:
- Process file path
- Process metadata (parameters, PID, start/end time, certificate(s), size, hash, etc.)
- Process parent data (PID, name, metadata)
- The user account the process started under
Managed ITDR
Huntress collects audit events, directory and identity data, mailbox data, and configuration details from connected Microsoft 365 and Google Workspace tenants in order to determine if user behavior is legitimate.
Microsoft 365 audit events
The data collected includes:
- Audit log events from Entra ID, Exchange Online, SharePoint and OneDrive, and the general Microsoft 365 workload feed (Teams, Purview, Defender, and others)
- For each event, Huntress keeps the user, timestamp, source IP address, application, operation, and the details Microsoft includes (for example, device compliance, browser, operating system, and session ID)
- Entra sign-in logs from the Microsoft Graph API, where the tenant license allows it (Entra ID P1 or P2)
- Entra ID Protection risk status for each user (risk level, risk state, and reason), where the tenant license allows it
- At onboarding, Huntress also runs a one-time historical search of Microsoft's audit log to find existing inbox rules
Microsoft 365 directory and identity data
The data collected includes:
- For each user: user principal name (UPN), email address, Microsoft object ID, account enabled status, guest status, usage location, assigned licenses, last password change date, and on-premises sync status
- MFA registration status, registered methods, and default method from Microsoft's authentication methods report, plus the tenant's security defaults and per-user MFA settings
- Admin role memberships and group names
- Verified domains and the tenant's organization record
- The countries and regions each user has signed in from, with event counts
- Last activity dates from Microsoft usage reports (Exchange, SharePoint, OneDrive, Teams), used for billing reconciliation; only the user and date are kept
Mailbox and email data
The data collected includes:
- Mailbox inventory (alias, display name, Exchange GUID)
- Inbox rule names, conditions, and actions (stored for as long as the rule exists)
- For every message a user sends, the recipient count, message ID, and send time. Huntress does not read the message at this stage.
- When a user's sending volume is far outside their normal pattern, Huntress retrieves the subject, body, attachment flag, and recipients of the affected messages so the Huntress SOC can confirm whether it is a phishing campaign and remove it. Message content retrieved this way is kept with the resulting signal and incident report.
- Organizations with Sensitive Data Mode enabled, and all GCC High tenants, are excluded from message content retrieval
Applications and configuration
The data collected includes:
- Enterprise applications and app registrations in the tenant: name, publisher, permissions granted, consent type, redirect URLs, and which users or admins granted consent (used for rogue application detection)
- Conditional Access policies and named locations
- Exchange Online configuration: transport rules, connectors, spam and malware policies, Safe Links and Safe Attachments policies, OWA and sharing settings, and admin role group membership
Sign-in page tracking for AiTM detection
Huntress adds a small style sheet to the tenant's Microsoft sign-in page branding. This lets Huntress detect when a phishing proxy is serving your login page. When the page is loaded, Huntress records:
- The tenant
- The IP address that loaded the page
- The referring web address
Google Workspace
The data collected includes:
- Google login audit events for each user (successful and failed logins, challenges, source IP, and application)
- Directory information for each user: primary email, Google ID, suspended or archived status, two-step verification enrollment and enforcement, Gmail enabled, and organizational unit
- Third-party OAuth application grants per user (application name and the scopes granted)
- Gmail filters and labels per user (conditions, forwarding, and labeling actions), stored for as long as the filter exists
- Verified domains
Huntress does not currently read Gmail message content, Google Drive content, or Gmail delegation and forwarding settings, although some of these scopes are requested for future detections.
Enrichment added to every event
Huntress adds the following context to each event it collects:
- IP geolocation (country, region, city) from a commercial geolocation provider
- Network context for the source IP: hosting provider, autonomous system, and whether it is a known VPN, proxy, Tor, or data center exit, including the operator name
- Parsed browser and operating system from the user agent string
Managed ISPM
Huntress connects to Microsoft 365 tenants and evaluates tenant configuration against the Huntress-managed identity security framework. The data collected is used to identify posture gaps, detect configuration drift, and maintain compliant settings through automated remediation or partner escalation.
Tenant configuration and security-control state
The data collected includes settings for:
- Multi-factor authentication (MFA)
- Administrative accounts
- Users and groups
- Passwords
- Conditional Access policies
Identity and directory attributes
Where required to resolve control scope and assess impact, the data collected includes:
- Display names
- Usernames or UPNs
- Email addresses
- Microsoft Entra object IDs or GUIDs
- Group names and memberships
- Role assignments
- Usage location or country
- License assignments
Conditional Access policy configuration
Where applicable, the data collected includes:
- Policy assignments and exclusions
- Locations
- Applications
- Grant controls
- Session controls
Sign-in context
The data collected may include:
- Sign-in event ID
- IP address
- Country
- User identity
- Resource accessed
- Outcome
- Risk or threat information
- Device compliance
- Conditional Access policy triggers or blocks
Managed SIEM
Huntress Managed SIEM collects the log data you choose to forward from endpoints, network devices, and third-party applications. It converts that data to the Elastic Common Schema (ECS) so it can be searched, correlated, and used for detection and reporting. SIEM takes in the full contents of each log it receives, so the exact fields collected depend on the source and how it's configured. For the full list of supported sources, see Supported Data Sources.
Log sources
Huntress collects log data from the following source types:
- Windows Event Logs (Security log and select Application logs)
- Linux logs (AuditD and JournalD)
- Syslog (RFC 5424, RFC 3164, LEEF, and CEF) from firewalls, network devices, and other appliances
- HTTP Event Collector (HEC)
- API-based integrations with third-party applications:
- 1Password
- Bitwarden
- Cisco AMP
- Cisco Umbrella
- CrowdStrike Falcon
- Datto RMM
- Duo
- IT Glue
- Meraki Cloud
- Mimecast
- Okta
- Salesforce
Data collected
Depending on the source, the data collected may include:
- Event timestamps and event types
- User account names and identities
- Authentication activity (sign-ins, failures, MFA events)
- Hostnames, IP addresses, and ports (source and destination)
- Process and command-line activity (Windows and Linux)
- Network, DNS, and web activity
- Administrative and configuration changes
- Security alerts and detections from third-party tools