TEAM: Huntress Managed Endpoint Security Posture Management (Managed ESPM)
PRODUCT: Huntress ESPM, RMM Guard, and Application Control
ENVIRONMENT: Windows Only
SUMMARY: How to prepare and enroll for Early Access into ESPM (Endpoint Security Posture Management). Use this guide for learning about RMM Guard, App Control, Defender ASR allow list, resource consumption issues, or for understanding what effects RefreshPolicy.exe, Rio.exe, WDAC, and Defender Attack Surface Reduction rules have when operating alongside ESPM.
Onboarding and Early Access (EA) Frequently Asked Questions (FAQ)
How to Enable or Disable ESPM for an Organization
Requirements
Due to the nature of how ESPM functions, other security vendors may falsely flag the Huntress Agent as malicious once ESPM is deployed. Before enrolling in ESPM, please configure your third-party security tools to allow Huntress. Following the Allow List Huntress in Third Party Software guide beforehand will prevent potential software conflicts.
-
Supported Operating Systems
- Windows Edition - Professional, Enterprise, Education, and Education/SE are supported. Home is currently not supported.
- Windows 10 patch 1903+ 32-bit and 64-bit
- Windows 11 32-bit and 64-bit
- Server 2022+
- RMM Guard Blocking Mode Requirements:
- Active, deployed, and healthy RMM Guard Policy
- 1 post-deploy reboot (suggested 12-24 hours after the endpoint is enrolled in ESPM).
- 14 day soak where the Huntress portal learns about the machine
- 1-day learning period, separate from 14-day soak - 14 Days may get reduced in the future
- No recent unreviewed RMM detections in the last 7 days. - This does reset the 7-day timer when an unreviewed RMM is detected.
-
[Coming soon!] Microsoft Defender for Endpoint for Vulnerability Visibility.
- The versions of MDE that will support Vulnerability Management are:
-
Defender for Endpoint Plan 2
- “Microsoft Defender for Endpoint P2 is available as a standalone license and as part of the following plans:
- Windows 11 Enterprise E5/A5
- Windows 10 Enterprise E5/A5
- Microsoft 365 E5/A5/G5 (which includes Windows 10 or Windows 11 Enterprise E5)
- Microsoft Defender Suite/EDU/GOV/FLW
- Microsoft Defender + Purview Suite FLW”
- “Microsoft Defender for Endpoint P2 is available as a standalone license and as part of the following plans:
- Microsoft Defender Vulnerability Management
- Microsoft Defender for Servers P1
-
Defender for Endpoint Plan 2
- The versions of MDE that will support Vulnerability Management are:
- Huntress EDR version 0.7.75 or higher
Onboarding and Early Access FAQ
-
How to enroll in ESPM?
- Click on the ESPM icon on the far left on your Huntress dashboard.
-
What are the ESPM capabilities and features being launched with EA?
- Application Control - in development
- Vulnerability Visibility (via Microsoft Defender for Endpoint)
- Dashboards and Reporting
- App blocking is not included in EA, ESPM is read-only currently!
-
Are any other Huntress products required to join ESPM EA?
- As of August 4th, there are no other products required.
-
Is EDR required to join the ESPM EA?
- No, but it's highly recommended to see the full benefit However, Managed EDR + Managed SIEM customers are great candidates to see the benefits of how ESPM can reduce the attack surface threat actors commonly abuse in order to establish and maintain persistence on an endpoint to move laterally through a network in order to achieve their goals.
-
How long will the Huntress portal be in learning mode/"Pre-Deployment Verification" before going active?
- This phase of EA is Learning Mode only. See requirements above for an idea of the baseline requirements for learning mode to be turned on, once Huntress has turned on Blocking Mode.
ESPM Functionality FAQ
-
How will Application Control work?
- During EA, Application Control will focus on two capabilities:
- Auditing applications on endpoints with the intent to configure policies to allow known-good applications.
- RMM Guard will handle blocking unwanted RMM and RAT (Remote Access Tool)
- During EA, Application Control will focus on two capabilities:
-
Will I be able to apply App Control policies at different levels?
- This is planned for the future. Currently App Control can be turned on or off at the account, organization, or endpoint level, while RMM Guard policy can control policy at the account or organization level.
-
What does the "New" tag mean in the RMM Guard dashboard?
- It means the tool is new to that MSP's environment, typically triggered when a new customer is onboarded and brings a remote tool that hadn't been seen before. The tag clears once someone approves or rejects the application.
-
How does ESPM handle application updates?
- Microsoft's WDAC supports an inheritance model where updates to previously approved applications can be automatically approved without partner intervention — essentially, if QuickBooks was approved, a QuickBooks update inherits that approval as long as the directory structure and certificates didn't change drastically. In other words, going from QuickBooks 24.0 to 24.1 is highly likely to be auto-approved, while going from QuickBooks 10.0 to 24.0 will likely require approval as a new app.
-
What is Huntress ‘managing’ for partners/customers?
- ESPM uses threat intel and adversary activity insights to inform App Control (i.e. managing WDAC). ESPM also provides notifications and guidance when new apps or updates are discovered to allow partners to determine how to react.
-
What is the role of the SOC in ESPM?
- Managed ESPM is a proactive solution so it doesn’t generate incidents, but it provides context to SOC investigations when used with Managed EDR, ITDR, and SIEM. Additionally, Huntress’ threat experts and SOC is the intelligence engine behind ESPM. EDR incidents tell us which attack paths and applications are most abused, and where ESPM can improve posture. Managed ESPM operationalizes threat intel and attacker tradecraft to help reduce the endpoint attack surface.
RMM Guard App Blocking FAQ
Note that application blocking is not available yet! Learning mode only for this phase of EA.
-
How to put ESPM RMM Guard in blocking mode?
-
Blocking mode is not available yet! However, we are anticipating the requirements for turning on app blocking for each endpoint are:
- Active, deployed, and healthy RMM Guard Policy
- 1 post-deploy reboot (suggested 12-24 hours after the endpoint is enrolled in ESPM).
- 14 day soak where the Huntress portal learns about the machine
- 1 day learning period, separate from 14 day soak
- No recent unreviewed RMM detections in the last 7 days.
-
Blocking mode is not available yet! However, we are anticipating the requirements for turning on app blocking for each endpoint are:
-
How to unblock an app or undo an app rejection?
- Click the app in RMM Guard and a window should slide out of the right side with the "Unreject" option"
-
Where will ESPM blocked events and alerts surface in the Huntress Portal?
- This is to be determined at a later date.
-
What do the status fields in RMM Guard indicate when in Blocking Mode?
- If the app is approved, it is allowed to run.
- If the app is unreviewed and not new, it is allowed to run.
- If the app is unreviewed and new to the environment, the app will be blocked from running.
- If the app is rejected, it will be blocked from running.
- None of the status have any affect on the endpoint or policy while in Learning / read-only mode.
-
What happens to an endpoint that joins an ESPM-enabled org/account already in blocking mode?
- The endpoint must meet the requirements before blocking mode can be turned on, so no action will take place until the requirements are met.
-
What does blocking an app do while in Learning Mode?
- The Huntress portal saves the decision but does not enforce until Blocking Mode is enabled, i.e. no affect on the machine or app while in Learning Mode.
-
Does blocking an app prevent installation or execution?
- It depends. For tools like ScreenConnect, which don't require a traditional installer, the executable is blocked even if it's not actually "installed" on the machine.
-
What does the end user see when an app is blocked?
- Windows will display a generic "App Control for Business" block message. We will likely change this in the future to have a Huntress or Partner-specific message to help the user understand who to contact.
-
Does blocking an app remove the app from the machine?
- No, blocking only prevents the execution, it can't uninstall the app (possibly a future improvement).
-
Does removing Huntress revert WDAC policy?
- Yes! The CIP file is queued for deletion, and the CI Policies are refreshed.
-
Why is _____ driver or ____ device getting blocked when ESPM is enabled, despite the driver/device not being on the block list?
- There's an issue with Microsoft's WDAC where poorly signed, revoked, or non-WHQL drivers could be rejected by WDAC even without a specific policy and even in audit mode. This was addressed with a workaround, so if you're still encountering this issue contact Huntress Support.
-
Can ESPM block software by version (not just hash/cert)?
- Yes in some cases.
How to Enable and Disable ESPM for an Organization
Enablement
- Log in to the Huntress Dashboard
- Select the ESPM button from the Icon bar on the left side of the screen.
- Select Settings
- By Default, Account Settings will be set to disabled.
- To enable an organization, select the + Add Organization Overide button. Override functionality allows you to override the Account-level settings to enable/disable ESPM for specific organizations without impacting the entire account.
- To enable an endpoint instead, select the + Add Endpoint Overide button.
- In the Organization or Endpoint drop-down menu, select the org or endpoint for which you would like it enabled
- Under Settings, select enabled
- Select the Save button.
Disablement
- Log in to the Huntress Dashboard
- Select the ESPM button from the Icon bar on the left side of the screen.
- Select Settings
- By Default, Account Settings will be set to disabled.
- To Disable an organization or endpoint, select the "Remove Override" button located next to the organization or endpoint.
- Confirm in the pop-up window that you would like to remove the Override to disable ESPM for a specific organization.
General FAQ
-
When will ESPM be Generally Available?
- The specific date is to be determined.
-
What is the difference between App Control and RMM Guard?
- App Control is a broad enforcement framework that audits applications, builds a trusted baseline, and enforces which applications may execute.
- RMM Guard applies the App Control framework to RMM and RATs (Remote Access Tools) specifically to block threat actors often use legitimate tools to avoid detection and RMM/RAT's are extremely powerful in the wrong hands.
-
Is this a new product or an add-on?
- ESPM is a net-new product.
-
Is Linux or Mac Supported?
- No. Linux and Mac are currently not supported. We want to focus on our Windows launch before pursuing other operating systems.
-
How should I report any bugs to the ESPM team?
- Reach out to your Account Manager with any bugs you may encounter.
-
How does an EA participant provide feedback or request a new feature on their Managed ESPM experience?
- Submit feedback/feature requests to https://feedback.huntress.com/espm
-
I am not seeing any ESPM data. Is there an issue?
- ESPM data does currently require a restart to see the RMM services. We will not be able to establish the initial connection until either the Endpoint/Host/Agent or the RMM service is restarted.
- Verify that you meet the above minimum requirements.
- Restart the Endpoint.
- It can take up to 24 hours after the above was completed.
- ESPM data does currently require a restart to see the RMM services. We will not be able to establish the initial connection until either the Endpoint/Host/Agent or the RMM service is restarted.
-
What is Learning Mode and Blocking Mode?
- Learning mode, AKA Audit mode, is currently the only mode available during this stage of EA. We are using Learning mode to audit and collect specific information related to Apps and RMM's. We monitor running applications across your endpoints and build a clear picture of normal activity for your environment. Once that baseline is established and unexpected activity has been reduced, enforcement can then be introduced with greater confidence. This helps ensure decisions are informed by real-world usage before anything is blocked.
- Blocking mode is not yet available in this stage of EA, however when it is available the app's that you've rejected and new apps will be prevented from running on all endpoints with active ESPM. See System Requirements above for the more info.
-
Is there a separate Huntress-managed block policy beyond what partners configure?
- This is planned for future improvements.
-
Will ESPM support compliance framework mapping (PCI, HIPAA, Essential 8)?
- This is planned for the future. The longer-term goal is for the Huntress console to serve as a single pane of glass for demonstrating compliance posture. Third-party validation (similar to what DefCert did for CMMC) is on the post-GA roadmap.
-
Will ESPM have control over removable media?
- Not at EA. It is being discussed as a future feature.