Cybersecurity News

Filters
Tag
Reset

Filtered by tag: threat detection × Clear

Wazuh and AI For Enhanced SOC Workflows

Matched: health

Wazuh, an open-source security platform, is being integrated with AI to improve Security Operations Center workflows. AI helps automate repetitive tasks, detect hidden patterns in large datasets, and accelerate decision-making. In cybersecurity, both defenders and attackers leverage AI — making it critical for SOC teams to adopt AI-enhanced tools like Wazuh to strengthen threat detection, response, and overall security operations efficiency.

Incident Response Plans: What to Include & Why They Matter

Organizations need incident response plans to minimize damage during cyberattacks. Key components include defined roles, communication protocols, detection and containment procedures, recovery steps, and post-incident analysis. Without a plan, response times slow and costs rise. Huntress helps by providing threat detection, guided remediation, and support that keeps businesses prepared before, during, and after security incidents.

Introducing Huntress Webhooks. Get Real-Time Security Alerts.

Huntress has launched a webhooks feature that delivers real-time security alerts directly to tools like Slack, PSA platforms, or SIEMs. Unlike polling-based methods, webhooks push incident and escalation notifications instantly. The feature is designed for quick setup, giving security teams faster visibility into threats without manual checking or delays.

What Our AI SOC Analyst Can Do (and What We Won’t Let It Do)

Huntress has introduced an AI SOC analyst called Athena that can autonomously investigate security threats and take actions, but operates within boundaries defined by human analysts. The system is designed to handle routine security operations work while keeping humans in control of key decisions, illustrating how the company is approaching governance around agentic AI in cybersecurity contexts.

How We Cut Noise Before It Hits the Analyst

Huntress uses AI-driven triage to filter out low-priority alerts before they reach human analysts. By automating the sorting of incoming signals, the system reduces noise and lets analysts focus on genuine threats. This approach is designed to improve response times and reduce alert fatigue, making security operations more efficient without overwhelming staff with false positives or routine notifications.

Meet Athena: Huntress' Agentic SOC Analyst

Huntress has launched Athena, an AI-powered SOC analyst that autonomously investigates security signals end-to-end. Athena handles triage and analysis tasks typically done by human analysts, aiming to speed up threat detection and response. Human analysts retain final decision-making authority. The tool is designed to reduce analyst workload and improve efficiency in security operations centers.

5 Modern Threats You Need to Watch

Cybersecurity threats increasingly bypass traditional malware, instead starting with legitimate-looking logins. Key patterns to watch include ransomware, business email compromise, and social engineering attacks. IT and security teams are urged to recognize these threats early, focusing on detecting suspicious access attempts rather than relying solely on conventional malware-detection approaches.

LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress

Attackers increasingly use "Living off the Land" techniques, abusing legitimate tools like PowerShell, WMI, and RMM software to blend in with normal IT activity. Key red flags include scripts running outside business hours, encoded commands, unusual parent-child process relationships, and tools accessing systems they don't normally touch. Context and behavioral baselines are critical for distinguishing malicious use from routine administrator work.