Uploaded September 2025 | Updated September 2026, 7 hours ago
On September 9, 2025, Huntress published a blog post detailing how they were able to trace the actions of a threat actor back almost 3 months thanks to the actor installing their Managed EDR product and inadvertently triggering a triage process.
The publication of details such as the threat actor's browsing habits generated some mild controversy online, with onlookers accusing Huntress of going too far with their triage and violating user privacy.
Much of this controversy stemmed from a general misunderstanding of Managed EDR, the length of time Huntress had access to the threat actor's machine, and the way some of the browsing information was presented in the blog.
Tib3rius sat down with Huntress employee and fellow content creator @_JohnHammond to get some answers to questions people may still have regarding this incident. Enjoy!
The Blog: huntress.com/blog/rare-look-inside-attacker-operation
Huntress Privacy Policy: huntress.com/privacy-policy
Huntress Terms of Service: huntress.com/terms-of-use
X: https://x.com/0xTib3rius
Bluesky: https://bsky.app/profile/tib3rius.bsky.social
Twitch: twitch.tv/0xTib3rius
InfoSec Exchange: https://infosec.exchange/@tib3rius
LinkedIn: linkedin.com/in/tib3rius
Courses: courses.tib3rius.com
Udemy: udemy.com/user/tib3rius
Discord: discord.com/invite/4qrvKMh
TikTok: tiktok.com/@0xtib3rius
Instagram: instagram.com/0xtib3rius
Threads: threads.net/@0xtib3rius
Facebook: facebook.com/0xTib3rius
On September 9, 2025, Huntress published a blog post detailing how they were able to trace the actions of a threat actor back almost 3 months thanks to the actor installing their Managed EDR product and inadvertently triggering a triage process.
The publication of details such as the threat actor's browsing habits generated some mild controversy online, with onlookers accusing Huntress of going too far with their triage and violating user privacy.
Much of this controversy stemmed from a general misunderstanding of Managed EDR, the length of time Huntress had access to the threat actor's machine, and the way some of the browsing information was presented in the blog.
Tib3rius sat down with Huntress employee and fellow content creator @_JohnHammond to get some answers to questions people may still have regarding this incident. Enjoy!
The Blog: huntress.com/blog/rare-look-inside-attacker-operation
Huntress Privacy Policy: huntress.com/privacy-policy
Huntress Terms of Service: huntress.com/terms-of-use
X: https://x.com/0xTib3rius
Bluesky: https://bsky.app/profile/tib3rius.bsky.social
Twitch: twitch.tv/0xTib3rius
InfoSec Exchange: https://infosec.exchange/@tib3rius
LinkedIn: linkedin.com/in/tib3rius
Courses: courses.tib3rius.com
Udemy: udemy.com/user/tib3rius
Discord: discord.com/invite/4qrvKMh
TikTok: tiktok.com/@0xtib3rius
Instagram: instagram.com/0xtib3rius
Threads: threads.net/@0xtib3rius
Facebook: facebook.com/0xTib3rius










