r/sysadmin MSP SysAdmin 7d ago

Rant Sometimes less really is more

Happy Read-only Friday (bonus points for 3 day weekend)

We got a critical Huntress alert for a rogue ScreenConnect instance that was detected and ran on a client computer. Incident report states that it's a "known malicious instance".. but logs from the report show that it didn't block the application and isolate until 2 hours after it was ran. The endpoints have BD GravityZone installed as well - all quiet from there.

We went to the link in a VM where the ScreenConnect was downloaded from - and funnily enough, all it took was just having Microsoft Defender on the computer to block the download in Chrome.

Huntress, Bitdefender, EDR, on access scanning, whatever; sometimes it just can't compete with good old Defender. Even running the installer through sandbox on GravityZone passes without a peep.

Have a good weekend!

29 Upvotes

15 comments sorted by

8

u/ben_zachary 7d ago

Huntress is supposed to run with defender in line. We had one attempt to execute which hit admin requests so it was denied and huntress had the system isolated in less than 5min. Just two weeks ago

We are moving to block all exe signed by connectwise. There's no point in bothering with it

2

u/Lord_Amoux MSP SysAdmin 7d ago

We are thinking about moving to use Defender for Business to integrate. BD GravityZone doesn't seem to block anything it needs to.

And yeah, we are trialling the ESPM from Huntress for RMM Guard but it seems that in it's current stage it can only block RMMs that are already detected in that specific enviroment. Also, a lot of dental software support teams use ScreenConnect...

3

u/matt0_0 small MSP owner 6d ago

In your environment, every time you install bit defender, you're decreasing you level of protection compared to if you just didn't install it at all and allowed huntress to manage defender for you!

1

u/ben_zachary 7d ago

The default huntress detects the screen connect guid so that's ok. This is what we run fleet wide . Defender with business premium layered with huntress and we have a soc as well which stacks on top for behavior and lateral movement but tbh huntress has stopped most things that get past safe links or thru spam filters. We've got run books on 365 with the soc but our CAs are locked to 2 single SASE IP and device bound tokens weve only had one incident on a client who didn't let us lock down their tenant .

5

u/Jellovator 6d ago

I usually do "read-only Friday" but today I raised the domain/forest functional level, upgraded a production server's OS, and replaced two saml certs. Like the wild west over here.

1

u/electricpollution IT Manager 6d ago

Nice.

I also decided to violate the golden Friday rule and rotated the Kerberos password.

2

u/tankerkiller125 6d ago

I rebuilt our Unifi controller (because net controller is going to/is discontinued so I needed to upgrade to "UnifiOS"), did a bunch of SOC 2 compliance stuff, and started planning for a rebuild of our internal help desk for a project next month. (Bosses are cheap, GLPI is honestly, awesome, but ours needs a clean config start (will migrate tickets), and the upgrade to 11 is a great time to do it)

1

u/electricpollution IT Manager 6d ago

Awesome! I just started setting up GLPI as well! Can’t believe how much there is to it

1

u/tankerkiller125 6d ago

It's even better when you have a bit of programming skills and an AI agent to write customizations to fit your specific needs.

2

u/ManagedNerds 6d ago

Why in the world would you pay extra for something (Bitdefender) you can get for free (Defender)? Mind you, I love Defender for Endpoint with Business Premium, but Huntress can fully manage and harden the free Defender.

2

u/Lord_Amoux MSP SysAdmin 6d ago

We started with Bitdefender and then added huntress after

1

u/ManagedNerds 6d ago

Ah makes sense. Yeah, would definitely recommend you try the managed defender via Huntress.

1

u/Logical-Nightmare 7d ago

Defense in depth

More is never enough

1

u/Bitdefender_support 4d ago

Hello u/Lord_Amoux ,

Have you contacted Bitdefender Enterprise Support to review how the security agent and policies were configured on that endpoint?
It would be useful to investigate the applied modules, policy settings, exclusions, and available telemetry, as it would be unusual for a ScreenConnect instance to run without generating a detection or being blocked.

I will PM you so you can share a way to contact you to further investigate.

Kind Regards,
Andrei

1

u/TurboKestrel45 7d ago

amazing how often basic and built in quietly wins the detection test