Huntress has released EDR/ITDR Correlations, a native integration between its Managed EDR and Managed ITDR products that automatically links endpoint compromise events to the Microsoft 365 cloud identities logged into affected machines. When an infostealer is detected on a Windows device, the platform immediately surfaces the exposed identities and enables session revocation and account disabling — all within a single Incident Report, without waiting for audit log delivery. This approach bypasses log latency bottlenecks that plague traditional EDR-then-identity workflows and XDR pipelines, collapsing a multi-step investigation into one coordinated response. Since release, the feature has stopped 64 incidents with zero false positives.
Table of contents
Infostealers: Quiet, scalable, and expensiveWhere traditional response breaks downClosing the gap with EDR/ITDR CorrelationsHow it works (without the wait)Why this approach is differentThis is what a platform actually doesSpeed changes everythingFrom fragmented tools to coordinated responseClosing the gap for good1 Impression