Cybersecurity News
Filters
Filtered by tag: threat detection × Clear
Wazuh and AI For Enhanced SOC Workflows
Matched: health
Wazuh, an open-source security platform, is being integrated with AI to improve Security Operations Center workflows. AI helps automate repetitive tasks, detect hidden patterns in large datasets, and accelerate decision-making. In cybersecurity, both defenders and attackers leverage AI — making it critical for SOC teams to adopt AI-enhanced tools like Wazuh to strengthen threat detection, response, and overall security operations efficiency.
Meet the Huntress MCP Server
Huntress launched an MCP (Model Context Protocol) server that lets AI assistants connect directly to Huntress security data, including incidents, agents, and billing information. The integration allows users to query and manage their Huntress account through an AI assistant without logging into the Huntress portal.
What Is Zero Trust Security? A Guide for Businesses
This appears to be marketing copy or a webpage snippet rather than a news article. There isn't enough substantive content here to summarize as a news story. Please share the full article text and I'll be happy to summarize it.
Huntress hits an inflection point
Huntress CEO Kyle Hanslovan says the cybersecurity firm is at a strategic turning point, scaling its research-driven approach while integrating AI with human oversight to counter faster, automated threats. The company is also expanding its partner network to extend protection to more small and mid-sized businesses increasingly targeted by sophisticated cyberattacks.
Incident Response Plans: What to Include & Why They Matter
Organizations need incident response plans to minimize damage during cyberattacks. Key components include defined roles, communication protocols, detection and containment procedures, recovery steps, and post-incident analysis. Without a plan, response times slow and costs rise. Huntress helps by providing threat detection, guided remediation, and support that keeps businesses prepared before, during, and after security incidents.
Introducing Huntress Webhooks. Get Real-Time Security Alerts.
Huntress has launched a webhooks feature that delivers real-time security alerts directly to tools like Slack, PSA platforms, or SIEMs. Unlike polling-based methods, webhooks push incident and escalation notifications instantly. The feature is designed for quick setup, giving security teams faster visibility into threats without manual checking or delays.
What Our AI SOC Analyst Can Do (and What We Won’t Let It Do)
Huntress has introduced an AI SOC analyst called Athena that can autonomously investigate security threats and take actions, but operates within boundaries defined by human analysts. The system is designed to handle routine security operations work while keeping humans in control of key decisions, illustrating how the company is approaching governance around agentic AI in cybersecurity contexts.
How We Cut Noise Before It Hits the Analyst
Huntress uses AI-driven triage to filter out low-priority alerts before they reach human analysts. By automating the sorting of incoming signals, the system reduces noise and lets analysts focus on genuine threats. This approach is designed to improve response times and reduce alert fatigue, making security operations more efficient without overwhelming staff with false positives or routine notifications.
Meet Athena: Huntress' Agentic SOC Analyst
Huntress has launched Athena, an AI-powered SOC analyst that autonomously investigates security signals end-to-end. Athena handles triage and analysis tasks typically done by human analysts, aiming to speed up threat detection and response. Human analysts retain final decision-making authority. The tool is designed to reduce analyst workload and improve efficiency in security operations centers.
5 Modern Threats You Need to Watch
Cybersecurity threats increasingly bypass traditional malware, instead starting with legitimate-looking logins. Key patterns to watch include ransomware, business email compromise, and social engineering attacks. IT and security teams are urged to recognize these threats early, focusing on detecting suspicious access attempts rather than relying solely on conventional malware-detection approaches.
LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress
Attackers increasingly use "Living off the Land" techniques, abusing legitimate tools like PowerShell, WMI, and RMM software to blend in with normal IT activity. Key red flags include scripts running outside business hours, encoded commands, unusual parent-child process relationships, and tools accessing systems they don't normally touch. Context and behavioral baselines are critical for distinguishing malicious use from routine administrator work.
