Huntress
Huntress is a managed cybersecurity platform designed to protect businesses from modern cyber threats through a combination of lightweight endpoint technology, advanced automation, and a 24/7 human-led SOC. The platform continuously monitors for malicious footholds, identity-based attacks, ransomware activity, and suspicious behaviour—alerting and guiding remediation only when action is required
Features
- Persistent Foothold Detection
- Managed Endpoint Detection & Response (Managed EDR)
- Process Insights
- Ransomware Canaries
- Malicious Process Behaviour Detection
- Host Isolation
- Policy Change & Mail Flow Manipulation Detection
- Managed ITDR (Identity Threat Detection & Response)
- Endpoint Attack Resistance & Automatic Remediation
- Tamper Protection
Benefits
- 24/7 Human‑Led Threat Detection & Response
- Deep Endpoint Visibility & Early Threat Detection
- Managed EDR With Real Remediation
- Ransomware Early‑Warning (Ransomware Canaries)
- Managed Antivirus Enhancements (Microsoft Defender)
- Identity Threat Detection & Response (ITDR)
- External Recon & Exposure Reduction
- Low Noise & High‑Fidelity Alerts
- Lightweight, Easily Deployable Agent
- Continuous Telemetry & Process Insights
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 7 7 5 1 5 3 3 9 5 8 8 3 9 3
Contact
CENTRAL NETWORKS AND TECHNOLOGIES LIMITED
Tamar Waite
Telephone: 01706747474
Email: Sales@centralnetworks.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Central Support
- Cloud deployment model
- Public cloud
- Service constraints
- Public‑Cloud Dependency (No Private Cloud Option), Limited Visibility Outside Endpoints & Microsoft 365, Agent Dependent, Microsoft Defender Dependency for Managed AV, Ransomware Canaries – Endpoint‑Only and File‑Based
- System requirements
-
- Windows 10/11 (inc ARM support), Server 2016+
- MacOS 14 or above
- Linux Ubuntu 22.04 / 24.04 / 25.04
- Debian 11/12/13 or RHEL 8.6+/9.x/10.x
- CentOS Stream 9/10 or SUSE Linux 12.x/15.x or Fedora 41/42
- Network connectivity
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times are dependant on ticket categorisation and request type. Priority 1 Disaster, Response Time: 30 minutes, Target Fix: 4 hours. Priority 2 High, Response Time 1 hour, Target Fix: 8 hours. Priority 3 Medium, Response Time: 4 hours, Target Fix: 20 hours Priority 4 Low, Response Time: 10 hours, Target Fix: 30 hours Priority 5 informational, Response Time: 3 days, Target Fix: 90 days Out of hours service is available on request
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Our operations team is broken down into two areas, Service Desk and Engineering. The Service Desk acts as the primary source of all activity, where calls are categorised, prioritised and filtered to the relevant specialist if required. Our calls are given a priority level from 1-5; whereas P1 is Disaster, business is non-operational all the way through to P5, of which could be a cosmetic incident, for example. Our response times and levels are summarised below: P1 - Urgent - 15mins Response Time (RT), 4 hrs Target Full Fix Time(TFFT) P2 - Critical - 30mins RT, 8 hrs TFFT P3 - Very Important - 4 hrs RT, 20 hrs TFFT P4 - Important - 10 hrs RT, 30 hrs TFFT P5 - Informational - 3 days RT, 90 days TFFT (never normally this long) The majority of activity will be remote based working, however we will send either a senior engineer to the client site, or a cloud specialist to a cloud hosting datacentre site, as and when required, depending on the incident. All priority incidents are included in our pricing, defined by customised SLA's and can be in unlimited numbers if required, depending on the client's needs.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Central Networks incorporates training and consultation throughout the onboarding process to ensure the client fully understands the service and can use it effectively. During early engagement, Central conducts consultative discovery sessions to understand the client’s current environment, processes, and maturity level, helping shape how Huntress will be deployed and supported.
As part of any wider onboarding project, Central provides knowledge‑transfer sessions to introduce Huntress concepts, explain how incidents are handled, and show teams how to interact with Central’s service desk. These sessions help build confidence, clarify escalation paths, and ensure users understand how to log issues or request support.
Ongoing consultation continues after deployment through regular account management discussions, progress reviews, and opportunities to refine processes as the client’s security posture evolves. This ensures Huntress remains aligned with business needs and that changes—technical or procedural—are supported with clear communication and appropriate training. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Huntress services (EDR, ITDR, SIEM, SAT) rely on ongoing ingestion of telemetry. Once the contract ends and agents are removed or disabled, Huntress stops processing new data.
Any historical data the client wants must be exported before the contract formally ends. All data on the platform can be purged once the contract ends. - End-of-contract process
- At end of contract data will be destroyed held within the system within 90 days of license expiry. If customer would like to extract data contract Support or Account Manager to discuss options. Professional Services charges may apply for data extraction. Central will remove access and licenses from the platform at the end of any contract and will support remote removal of any agents.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The Huntress service interface is a cloud‑based dashboard designed to centralise endpoint, identity, and threat‑hunting activity. It prioritises clarity, low noise, and rapid visibility into what actions Huntress is taking on your behalf.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Huntress is accessed through a secure cloud dashboard using role‑based login or account‑level SSO. Admins and engineers can deploy agents, manage organisations, configure integrations, and act on security incidents. Users can view alerts, approve remediation, isolate endpoints, monitor Defender health, review identity threats, check ransomware canaries, and analyse external exposures. The platform provides reporting, SOC investigator notes, real‑time visibility of threats, and seamless multi‑tenant management. Normal end‑users never interact with the interface; it runs silently unless a threat is detected. The system centralises endpoint, identity, and threat‑hunting functions into one unified portal.
- Accessibility testing
- Conducted by Huntress
- API
- Yes
- What users can and can't do using the API
-
He Huntress Platform provides a REST API that offers programmatic, read‑only access to core operational data. Using authenticated requests to api.huntress.io/v1/, you can retrieve information about accounts, organizations, agents, incident reports, billing reports, and summary reports. This allows integration with PSA tools, SIEM platforms, reporting systems, and asset inventories. The API is fully documented, supports multiple languages via an OpenAPI specification, and has community libraries such as pyhuntress (Python), PowerShell modules, and an MCP server for automation. API keys are generated within the Huntress portal and allow consistent, secure access to tenant data.
However, the API does not provide administrative “write” capabilities. Actions such as approving or rejecting Assisted Remediation, isolating or de‑isolating endpoints, modifying Managed Microsoft Defender settings, or changing identity‑based detection rules are portal‑only and not available through documented endpoints. While Huntress announced future areas like incident webhooks, ransomware canary access, and managed AV interactions, these should not be assumed available unless explicitly published in the official documentation. The API is best suited for data extraction, monitoring, automation of reporting, and integrating Huntress insights into other systems, rather than performing operational or security actions directly within the Huntress environment. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Huntress can be customised in several ways to fit each organisation’s operational needs. Administrators can tailor notification routing, selecting which categories (Incident Reports, Escalations, Platform Actions and Account Notices) are sent to ticketing systems or email recipients.
Service behaviour can also be customised through API integrations, such as linking Huntress to HaloPSA for automated ticket creation and incident handling. These integrations allow each customer’s service desk workflow to be personalised.
Deployment is flexible: Huntress can be rolled out using Microsoft Intune, RMM tools, GPO, or scripts, depending on the customer’s environment and preferred device‑management tools. This gives granular control over how and where the agent is installed.
For identity protection (ITDR), administrators can customise tenant integrations, including Microsoft 365 SSO and conditional access alignment.
Reporting is also adaptable, as monthly reports can be filtered and reshaped to meet customer requirements before distribution.
Overall, Huntress allows tailored deployment, notification routing, integration options and reporting to match each organisation’s processes.
Scaling
- Independence of resources
- Huntress is designed to scale through a combination of distributed endpoint telemetry collection, automated high‑volume data processing, and a globally distributed SOC workforce, enabling the platform to handle dramatic increases in endpoints, identities, and tenants without operational slowdown.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Huntress provides clear, actionable security metrics across its dashboards and reports, including the total events analysed, entities protected, signals detected, signals investigated, and confirmed incident reports, alongside feature‑specific metrics such as autorun events analysed, foothold signals, ransomware canary coverage and incidents, plus operational indicators like agents registered, unresponsive agents, and SOC escalation counts, all of which combine to give a transparent view of threat activity, endpoint posture, SOC workload and overall estate health.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Huntress
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- The platform includes options for exporting data from the environment.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We do have our public facing MTTR (Mean time to respond) figure which is from detection to resolution i.e. Huntress detects suspicious activity, triages, investigates, enacts a response to protect the client environment and notifies CloudClevr via email/ticket/phone/SMS depending on severity level)
Our public facing MTTR figure for Huntress Managed EDR is 8 minutes. - Approach to resilience
- This information is available on request.
- Outage reporting
- All service status are displayed: https://huntressstatus.statuspage.io/?utm_source=zendesk&utm_medium=integrations&utm_campaign=guide
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Access is based on username and password with MFA. Access to functions is control via RBAC.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
- All security governance, security process and standard can be found at https://support.huntress.io/hc/en-us/sections/14691981748755-Privacy-Security
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- The Huntress Research and Development (R&D) department leverages a Continuous Integration / Continuous Delivery (CI/CD) pipeline for managing code deployments. Code changes are peer reviewed, approved by separate QA staff, and tested in a staging environment before they are pushed into production. The staging and production environments are logically separated, and no data is shared between them
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- The Huntress information security team performs monthly web application vulnerability scans. These scans are configured to run as authenticated scans. Any vulnerabilities found during these scans or any other vulnerability discovery activities are added to a vulnerability tracking system. There, the vulnerabilities are verified, categorized, and evaluated for actual risk. Vulnerabilities are remediated in accordance with the schedule
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Huntress' approach to manage protective monitoring is centered around a 24/7 Security Operations Center (SOC) that continuously monitors and responds to active intrusions. The platform is built to augment security teams and address the continually evolving threat landscape. Huntress' Managed Security Platform continuously adds new detection and response capabilities to meet security demands without requiring significant additional investment of time or money. The platform is designed to protect businesses from cybercriminals by providing a powerful suite of managed protection, detection, and response capabilities.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Ncidents are raised to the Security Team. Business impact of the incident is assessed and if customer data is at risk, customers are notified within 24 hours. Evidence is collected and stored securely by the Security Team and accessed only by investigators. All investigators are independent of the incident itself. A formal incident report is written to determine the root cause, this is then reviewed to determine corrective or preventative actions
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Test fully featured products, not a watered-down trial
Backed by the power of our 24/7 human-led SOC
Detect suspicious endpoint activity, uncover hidden adversaries, stop business email compromise, and more
Receive detailed incident reports packed with expert insights, written for all skill levels
Deploy in minutes with zero user disruption - Link to free trial
- https://www.huntress.com/start-trial?hnt=em1sv6ebs5no
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0.25%
- Between £250,000 and £500,000
- 0.5%
- Between £500,001 and £1,000,000
- 0.75%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 1.25%
- Over £5,000,001
- 1.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation
- ISO/IEC 27001 accreditation date
- Monday 19 May 2025
- What the ISO/IEC 27001 doesn’t cover
- None
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation
- ISO 9001 accreditation date
- Friday 3 January 2025
- What the ISO 9001 doesn’t cover
- None
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 79646496-1330-4827-b087-691615c42291
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 106b321e-346f-4e5c-abd9-51b4fc523fa0
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-