Team: Huntress Managed Endpoint Detection and Response (EDR)
Product: Microsoft Defender, Microsoft Defender for Endpoint (MDE)
Environment: Windows
Summary: Learn why some Microsoft Defender detections do not automatically generate individual Huntress Incident Reports, and which signals may lead to SOC investigation and response.
Overview
We ingest a broad spectrum of signals from MDE and Defender AV, but we only escalate the subset that matches our threat intelligence or indicates something has slipped past prevention. In the event that our detection engine flags behavior that matches known indicators of compromise, our Analysts can leverage these alerts for additional context during the investigation.
Telemetry and Remediation Strategy
The Huntress Agent analyzes endpoint telemetry, including running processes, persistence mechanisms, and system artifacts, to contain and remediate active threats in your environment.
When Microsoft Defender or Microsoft Defender for Endpoint successfully prevents execution or quarantines a malicious file, the threat is neutralized. Because there is no active threat remaining to contain or remediate, Huntress does not necessarily generate a standalone incident report for that single event.
Tip: Huntress recommends deploying Managed EDR as part of a defense in depth security stack alongside preventive controls like antivirus, application control, and vulnerability management.
How the SOC Uses Defender Signals
Even when a severe threat from Defender or Defender for Endpoint is detected, the detection is not ignored:
Context for Active Threats: Detections from Microsoft Defender and Defender for Endpoint provide critical context for the Huntress Security Operations Center (SOC). If malicious activity executes or establishes persistence, our SOC opens an investigation, issues a Huntress Incident Report, and delivers containment and remediation steps.
High-Fidelity Signals: Specific high-severity security events, such as those suggesting disabled protection or active compromise, may be treated as high-fidelity signals by our Detection Engineering team and used to support threat investigations across your endpoints, depending on the event’s severity and context.
How Huntress Responds to Active Threat Activity
Huntress ingests Defender signals and automatically triages qualifying events; only some result in a reported incident.:
Behavioral Investigation: The Huntress Agent continuously monitors endpoint process activity and persistence mechanisms. The Huntress SOC investigates active threats based on malicious behavior detected on the endpoint, using Defender and Defender for Endpoint telemetry as supporting context.
Reporting Follow-On Activity: If follow-on activity occurs, such as lateral movement, privilege escalation, or new persistent footholds, the Huntress SOC creates a Huntress Incident Report detailing the active threat.
Containment and Remediation: In addition to reporting, Huntress provides tailored manual, assisted, or active remediation steps, including host isolation, to stop active threats before they cause further impact.
Learn more about Defender for Endpoint Incident Reports