Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Why Attackers Don't Need Zero-Days to Breach You

Huntress
08/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


respective threats, focusing primarily on endpoints and identity posture. So when you think about it, attackers are still very much using the basics to breach organizations. What do I mean by that? So when you think about posture and security management, you hear in the news all about zero days and major breaches but oftentimes what you don't hear about is that MFA exclusion or MFA exception that somebody's temporarily allowed and that you've forgotten about right, that an adversary is taking advantage of. Or weak password management or poor password posture. Other things, common tools for example, that remote management and monitoring tool, so that RMM tool within your environment that you've since forgotten about that an adversary has installed and now has a direct backdoor into your environment. All of these are basic IT hygiene issues which oftentimes you've either forgotten about or have just let go by the wayside. And this is what attackers are primarily taking advantage of versus the zero days. Just in the last year as an example, our SOC has observed almost a 300% so 277% in RMM abuse. So coming back to that basic security hygiene issue that I mentioned, this is where adversaries, and I'll talk about an example later on, where adversaries for example fool and trick users, end users into installing legitimate tooling, so legitimate RMM tools, so that they can have a backdoor within your environment. Your EDR is not going to pick that up, your AV is not going to pick that up. Why? Because they're actually legitimate tools that are being misused by adversaries within your respective environment. Other areas as well, so almost 40% of organizations have had their identities or breached via shady logins. So what does that mean? So this doesn't necessarily mean a credential that shouldn't be within your environment. What we mean by that is they're using legitimate credentials within your respective environment of employees that they've probably gained access to those credentials on the dark web or coming back to easy or poor password management or poor credential management. So what does that really mean? We surveyed a number of organizations and what we found again in the last year that almost 50% of them had a major breach or incident that they had to deal with and it was not from a zero day. So this is what we see all the time, day in and day out, adversaries are taking advantage of simple misconfigurations, some of those examples that I mentioned earlier. Worse than that, when you think about beyond a breach, what happens when the posture within your environment impacts business operations? So a software install or a new application installed that you can't do because the respective security controls in the environment aren't up to snuff. So for example, your environment's not patched enough to install a software update and that delays a software update within the respective environment. In a survey that we conducted almost to what 55% of the more than half of organizations had to delay or cancel a software update within their respective environments due to weak posture management. And then of those respective organizations, many take more than a day, so more than 24 hours to actually update or correct that misconfiguration. Guess what? If an adversaries within your organization, they've probably got away with anything and everything that they need within the first 10 minutes within your organization. So guess how much data or how much information they can get away within your organization within a 24 hour period? Chances are they've got everything and they've done everything that they want to do within your organization. So this is an example of just one of the issues that I had mentioned earlier, where this is a phishing campaign that an adversary sent to an employee in one of our organizations that we protect. And as you can see, it's a Teams update and the end user, it looks really legitimate because from a phishing perspective, the end user thinks they're doing a Teams update. When they click on the Teams update, a rogue malicious RMM tool is installed within their environment. That's not necessarily something that's going to be picked up by EDR or AV. Why? Because when you look at the actual tool, it's a real RMM tool, but it's controlled by the adversary. So now from an IT perspective, if you don't have good controls or understand, should this RMM tool be installed in my environment? If I'm an IT person, am I looking in the environment and I see, for example, a data RMM tool installed within the environment, it's signed by Microsoft, it's a real RMM tool, but as the end user has given backdoor access into the respective environment, that RMM tool is controlled by an adversary. Your AV, your EDR, nothing's going to pick that up. The only real way to pick this up would be by using endpoint posture management. Because by using endpoint posture management, I understand this is a list of respective applications that I should be running within my environment that's approved within my environment. So in this case, had I been running endpoint posture management, I would have realized quickly that, hey, this data RMM tool shouldn't be installed within the respective environment and be able to block that. In another example, say MFA is great except for that one user who's complaining about MFA, and you create the exception for that one user, and you forget to re-enable MFA for that one user, and guess what? The adversary is going to find that one user account that doesn't have MFA and take advantage and abuse that. That's exactly what happened in this respective case here, where, let me go back, where the adversary took advantage of the only MFA account that was, excuse me, the only credential that didn't have MFA enabled in this respective environment and went ahead and infiltrated the respective organization. So this is really where it becomes super important to think about both endpoint and identity, where how can we shift left and look at the respective posture. It's got nothing to do with detecting malicious activity or behavior, it's more restricting your security controls and restricting what's allowed to run within your respective environment. Is my MFA configured correctly? So how do I shift left my security controls so that I not only lock down and address all of these simple misconfigurations, but at the same time then, when I'm shifting left, I'm addressing those misconfigurations and posture within my environment from an identity and endpoint perspective. And then within that environment, anything that does slip through, you have your ITDR, so your Identity Threat Detection and Response, and your EDR, so your Endpoint Detection and Response to address that. So you're not only moving the barriers, so remember I mentioned earlier, 50 odd percent or 45 odd percent of organizations had been breached last year in survey data that we had done simply from misconfigurations. So you're already wiping out almost 50% of issues that adversaries are taking advantage of. These are some of the use cases in that that we do focus on, so it's better from a security perspective to focus on what's the respective outcome that you're trying to achieve. Are you trying to achieve endpoint integrity? So to address some of those use cases, ransomware, infostealers, etc. Or are you looking to address identity resilience and protecting yourself from any things like account takeover or BEC attacks, as an example. Then ultimately, operational readiness, where you need to have full visibility of the respective environment, so that you're addressing what's going on between multiple attack vectors. So not only on your endpoint, but on your identities as well, and how do you stitch all of that together so you have visibility across all of those respective attack vectors.

TL;DR

  • Huntress SOC data shows a 277% increase in RMM tool abuse in the past year, with attackers using legitimate, signed tools to create backdoors that EDR and AV cannot detect.
  • Nearly 50% of organizations surveyed by Huntress experienced a major breach or incident caused by simple misconfigurations — not zero-day exploits — including forgotten MFA exceptions and weak credential hygiene.
  • Over 55% of organizations had to delay or cancel software updates due to poor posture management, and attackers inside an environment can accomplish their objectives within the first 10 minutes.
  • Huntress advocates a 'shift left' security model that pairs endpoint posture management and identity posture controls with ITDR and EDR, reducing the misconfiguration attack surface before detection is required.

The Real Attack Surface: Hygiene, Not Zero-Days

Recorded live at RSAC 2026, Huntress VP of Product Marketing Gavin Hill challenges the prevailing narrative that sophisticated zero-day exploits are the primary driver of enterprise breaches. Drawing on Huntress SOC telemetry, Hill argues that adversaries consistently exploit far more mundane weaknesses: forgotten MFA exceptions, poor password hygiene, and rogue remote monitoring and management (RMM) tools left running in environments long after their intended use. The Huntress SOC observed a 277% spike in RMM tool abuse over the past year alone — a figure that underscores how attackers weaponize legitimate, signed software to evade both EDR and AV controls. A survey of Huntress-protected organizations found that nearly 50% experienced a major incident attributable not to advanced exploits but to simple misconfigurations. Hill illustrates this with a concrete phishing scenario: a fake Microsoft Teams update prompt that silently installs a legitimate but adversary-controlled RMM tool, giving attackers persistent backdoor access that traditional detection tools will not flag.

Shifting Left: Posture Management Over Detection Alone

The core strategic argument Hill advances is that organizations must shift security left by combining endpoint posture management with identity posture controls, rather than relying exclusively on detection-and-response tooling. Endpoint posture management enables teams to maintain an approved application inventory, so an unauthorized RMM tool — even one signed by a legitimate vendor — triggers an immediate alert rather than blending into the environment. On the identity side, a single MFA exception created for a complaining user and never re-enabled represents exactly the kind of gap adversaries actively hunt for. Hill notes that 55% of surveyed organizations had to delay or cancel software updates due to weak posture management, and that when a misconfiguration goes uncorrected for more than 24 hours, an attacker already inside the environment has more than enough time to exfiltrate everything of value. The recommended architecture layers endpoint posture management and identity posture controls as a preventive first line, with ITDR and EDR serving as the backstop for anything that slips through — effectively eliminating the misconfiguration-driven 50% of incidents before detection is even needed.

Chapters

0:00 - Why Zero-Days Aren't the Real Threat
1:15 - RMM Abuse and Credential Exploitation
2:35 - Survey Data: Misconfigurations and Delayed Remediation
4:20 - Fake Teams Update: RMM Backdoor Example
6:18 - MFA Exception Exploitation Case Study
7:02 - Shifting Left: Endpoint and Identity Posture

Key Quotes

1:16 "Just in the last year as an example, our SOC has observed almost a 300% so 277% in RMM abuse."
2:55 "Adversaries are taking advantage of simple misconfigurations, some of those examples that I mentioned earlier."
3:58 "If an adversary's within your organization, they've probably got away with anything and everything that they need within the first 10 minutes within your organization."
5:40 "Your AV, your EDR, nothing's going to pick that up. The only real way to pick this up would be by using endpoint posture management."
7:09 "It's got nothing to do with detecting malicious activity or behavior, it's more restricting your security controls and restricting what's allowed to run within your respective environment."
8:10 "You're already wiping out almost 50% of issues that adversaries are taking advantage of."

FAQ

Why can't EDR or antivirus detect rogue RMM tools installed by attackers?

Because the RMM tools themselves are legitimate, commercially available software signed by real vendors. EDR and AV look for malicious code signatures or behaviors — a properly signed, functional RMM tool exhibits neither. Only endpoint posture management, which enforces an approved application inventory, can flag an unauthorized RMM tool regardless of its legitimacy.

What does 'shifting security left' mean in the context of endpoint and identity protection?

Shifting left means addressing misconfigurations and posture gaps proactively — before an attack occurs — rather than relying solely on detection after a threat is already active. This involves continuously auditing MFA configurations, maintaining approved application inventories, and enforcing credential hygiene, so that the gaps attackers exploit simply don't exist in the first place.

Categories:
  • » Webinar Library » Huntress
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Endpoint Management
  • Identity & Access
  • Threat Intelligence
  • Security Operations
  • Best Practices
  • Webinar
  • RMM tool abuse
  • endpoint posture management
  • identity threat detection and response
  • MFA misconfiguration
  • credential hygiene
  • EDR blind spots
  • ITDR
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Why Attackers Don't Need Zero-Days to Breach You

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version