Remote monitoring and management (RMM) tools are allow-listed by design, capable of pushing code across entire device fleets, and trusted implicitly by endpoint security programs. That combination makes them the most efficient malware delivery channel available to threat actors today, no custom exploit required. RMM abuse has surged 277% year over year, now accounting for nearly 40% of malware deployments investigated by managed SOC teams. At the same time, AI-assisted reconnaissance has compressed attacker dwell time from 30-60 days down to hours, leaving defenders a shrinking window to detect and contain intrusions before damage is done.
In this interview on TFiR, Bryson Byrd, Cybersecurity Advisor at Huntress, breaks down how attackers weaponize trusted remote management software, why identity controls remain critically under-deployed, and what layered security resilience actually looks like for organizations from two-person operations to mid-market enterprises.
Guest: Bryson Byrd, Cybersecurity Advisor at Huntress
Show: TFiR
Here is what every security engineer, SOC analyst, and IT decision-maker needs to know.
Technical Deep Dive
Q: What is RMM abuse and why has it surged 277% year over year?
Bryson Byrd, Cybersecurity Advisor at Huntress, explains that remote monitoring and management tools have been abused by threat actors for close to a decade, but the scale and speed of abuse have changed dramatically. Because RMM tools are allow-listed in most security programs and give operators one-pane-of-glass control over entire device fleets, attackers no longer need to write or deploy custom malware to achieve the same access. Huntress’s SOC data shows RMM abuse now drives nearly 40% of malware deployment investigations, making it the dominant initial access and lateral movement technique across the customer base Huntress serves.
“We don’t need to reinvent malware to get our bad acting kind of deeds on a device. We can just use the tools that IT teams are out there using, because chances are they’ve been allow-listed in their security program.”
Bryson Byrd, Cybersecurity Advisor, Huntress
Q: How does RMM abuse work as an attack technique in practice?
Byrd describes attackers gaining initial access to an environment and then rapidly deploying an RMM tool, such as AnyDesk or TeamViewer, across the fleet using that same tool’s native remote execution capability. Because the software is already trusted by the endpoint security stack, it bypasses most automated detection checks. The technique is a direct evolution of living-off-the-land attacks, extended to commercial remote management products rather than native OS binaries.
“These tools are really good about being able to do one pane of glass. Threat actors got really smart in saying, hey look, we’ve got this tool.”
Bryson Byrd, Cybersecurity Advisor, Huntress
Q: How is AI compressing attacker dwell time and what does that mean for defenders?
Byrd is direct: AI is not changing attacker tactics or inventing new techniques. What it is doing is making every stage of the kill chain faster and more efficient. Dwell time that previously ran 30 to 60 days has collapsed to less than a week on average, and in many cases to hours from initial access. AI accelerates reconnaissance, vulnerability identification, phishing campaign construction, and malvertising, all of which are now more sophisticated and harder to detect with human review alone.
“AI is not changing workflows. AI is not revolutionizing threat actor behavior. What it is doing is making them way more efficient, way quicker.”
Bryson Byrd, Cybersecurity Advisor, Huntress
Q: Is AI the only driver of accelerating attacks, or are there other factors compressing the defender window?
Byrd describes the current threat environment as a perfect storm with multiple contributing factors. Defenders have improved significantly over the past decade, forcing attackers to adapt their techniques. That adaptation cycle aligned with the emergence of AI, which threat actors adopted earlier than most security vendors. The combined pressure of better defenses, cloud-scale attack surfaces, and machine-speed AI assistance pushed attackers to adopt new efficiency techniques simultaneously rather than sequentially.
“At Huntress, we saw that AI was first being adopted by threat actors long before vendors were picking up that torch to fight machine speed at machine speed.”
Bryson Byrd, Cybersecurity Advisor, Huntress
Q: Beyond RMM abuse, what other attack vectors are dominating SOC investigations right now?
Byrd identifies identity as the second major attack surface, and frames it as a present-tense operational reality rather than a future trend. Huntress data shows that approximately 70% of identity-based intrusions they investigate involve environments with no multi-factor authentication deployed, meaning attackers do not need to bypass MFA at all. The combination of endpoint compromise via RMM abuse and identity compromise via credential attacks without MFA represents the majority of what their SOC handles.
“Identity is not the future of that. That is the reality. We are seeing identity continuously exploited.”
Bryson Byrd, Cybersecurity Advisor, Huntress
Q: How should security teams rethink their stack when attackers are chaining endpoint and identity attacks?
Byrd pushes back on the idea of a complete rethink, arguing instead for disciplined execution of layered fundamentals that the security community has discussed for years. The complexity of chained attacks, where endpoint compromise is followed immediately by identity exploitation, now makes single-layer defenses inadequate regardless of how strong that one layer is. His prescription includes endpoint security posture management, identity security posture management, network perimeter controls, and detection and response capability operating simultaneously rather than prioritizing any single layer.
“The biggest piece that I think has changed is just the complexity that’s pushed us to adopt all of the layers that we can, versus the picking and choosing of one or two layers.”
Bryson Byrd, Cybersecurity Advisor, Huntress
Q: Who owns security accountability when it spans every layer of the organization?
Byrd acknowledges that making security everyone’s responsibility can result in it becoming no one’s responsibility in practice. His answer varies by organization size. For small businesses, the answer is an external partner who handles architecture, continuous monitoring, and incident response on their behalf. For mid-market organizations, it requires internal IT stakeholders and CISOs driving change while still relying on partners for coverage gaps. The common thread across both is cultural: people at every level must feel safe raising a security concern without fear of blame.
“You’ve got to make people comfortable saying, ‘Hey, I see a problem here, and maybe even I’m the one responsible, but the problem’s still here and we need to address it.'”
Bryson Byrd, Cybersecurity Advisor, Huntress
Q: What does a mature security culture look like when AI-powered threats make human behavior a primary attack surface?
Byrd draws on General McChrystal’s “Team of Teams” framework to argue that security resilience requires breaking down organizational silos so that best practices, failure signals, and threat intelligence flow laterally across teams rather than only top-down through policy. Administrative controls and awareness training create the baseline, but maturity requires shared ownership of a common business continuity goal. On the technology side, he points to zero trust and DLP practices being extended into AI chatbot environments as an emerging control that bridges culture and architecture.
“Security today is a culture issue as much as it is a technological issue.”
Bryson Byrd, Cybersecurity Advisor, Huntress
Q: How does Huntress address both prevention and detection across endpoint and identity layers?
Byrd describes Huntress as having expanded from its original detection and response roots, founded by former NSA operators, into a prevention-first architecture. The current platform spans EDR for endpoint detection and response, ITDR for identity threat detection and response, SIEM-type tooling for post-compromise visibility, endpoint security posture management, and identity security posture management. A 24×7 SOC operates across all layers. Byrd is explicit that partners can engage only the layers they need, with Huntress filling gaps rather than requiring a full platform replacement.
“The goal is security resilience and helping our partners and our customers move more and more resilient the best way we can.”
Bryson Byrd, Cybersecurity Advisor, Huntress
Resources & Documentation
- Huntress, human-led agentic security platform covering EDR, ITDR, SIEM, and security posture management for mid-market and SMB organizations
- Huntress Security Blog and SOC Reports, original threat research and RMM abuse data from the Huntress SOC team
- Team of Teams by General Stanley McChrystal, organizational framework for breaking down silos and sharing operational intelligence across teams (referenced by Byrd as a model for security culture)
***
👇 Click to Read Full Raw Transcript
Swapnil Bhartiya: There was a time when the cheapest way to get into any network was an exploit. It’s not anymore. Now it’s subscription attackers have kind of stopped writing malware because a signed trusted remote monitoring and management tool gets them the same access at cheaper rate, faster speed and it’s even harder to detect. RMM abuse have jumped like almost 277% last year and, and as we all know, AI is shrinking the window. Defenders have to respond. And today we have with us Bryson Byrd, cybersecurity advisor at Huntress to break it all down, what it means for cybersecurity teams and what they can do to protect themselves. First of all, Bryson, it’s good to have you on the show.
Bryson Byrd: Thank you so much for having me. I’m looking forward to kind of diving in on this topic and hopefully spreading some word around it.
Swapnil Bhartiya: As exciting as the topic is, so is the company and this is the first time you and I are talking, so I would love to know a bit about the company as well. So our audience, they do know who they are listening to?
Bryson Byrd: Yeah. So Huntress, we are a human led agentic security platform at the end of the day, right. So we offer our tools and our managed solution to help be force multipliers for so many of those security programs and security like minded companies that need help. Right. So we work with everyone from mid market all the way down to mom and pop that may be running a two person operation, right. So we really run the gamut but we also have some really interesting data because of our customer base that we serve disproportionately.
Swapnil Bhartiya: Now let’s talk about this problem area. How attackers are using new means to compromise network recompense systems as compared to what they used to do traditionally.
Bryson Byrd: Yeah, it’s really interesting. You touched on the statistic of 277 increase, right? That’s what our SOC in our data has seen year over year around RMM abuse. And I just want to lay out the table of what we mean by RMM abuse. Right. So RMMs, remote monitoring and management solutions, they’ve been around for a while. Some of these have been abused for a while for different type of threat actor activities. Sometimes this was used for ransomware. I know even back in 2020 when I was doing incident response, we saw some of these folks using AnyDesk or TeamViewer or insert here, right. They used all sorts of stuff. What we’ve seen now is they’re using those tools, they’re getting into an environment and they’re being able to rapidly deploy those tools to then launch their malware campaigns. Right. These tools are really good about being able to do one to pane of glass because that’s what it uses these tools for. Whether it be internal IT or outsourced through like a managed service provider, these RMM tools are how you update your fleet of computers remotely, how you push out new software, how you do all this. So threat actors got really smart in saying, hey look, we’ve got this tool. We don’t need to reinvent malware to get our bad acting kind of deeds on a device. We can just use the tools that are out there, that IT teams are out there because chances are they’ve been allow listed in their security program, if they have one. And so we can get around a lot of checks. It’s basically an evolution of the living off the land techniques that we’ve seen as folks in the security industry for quite some time now.
Swapnil Bhartiya: And can you also talk about because of AI, the gap, the time that defenders have to respond versus the good guys, sorry, the bad guys have to compromise systems. Talk about what does that compression actually look like? Then we’ll talk about of course what teams can do, but let’s just focus on the problem area first.
Bryson Byrd: Yeah, I mean to put it completely blunt from the beginning and the one thing I want to be clear about is AI is not changing workflows. AI is not revolutionizing threat actor behavior. What it is doing though is it’s making them way more efficient, it’s making it way quicker. Right? So when you look back at the timeline even again, going back to like pandemic days, what feels like the before times these days. But when you go back to look at the timescale back then, threat actors would stick around in an environment to gather all the detail they needed to exploit data, all of that, they would stick around for 30, 60 days, right? That dwell time now is shrunk to less than a week on average and a lot of times it could be within hours of their initial getting into a new network. So what that means and what overall what we’re seeing is threat actors are leveraging AI to make the entire reconnaissance portion of the kill chain, right? The recon of understanding what’s vulnerable. Also how do I get into what’s vulnerable much quicker as well as the phishing campaigns, malware, malvertising campaigns, all of these types of things are getting way more sophisticated and much harder to detect with just human eyes. Right. So all of these ways have made them far more efficient and far quicker at what they’re doing, but the overall TTPs haven’t changed a whole lot. Even RMM abuse that we just talked about, right, that’s been around for probably close to a decade of these guys using it. They’re just using it on a different scale and a different speed now.
Swapnil Bhartiya: Yeah, you’re absolutely right. AI is not changing, but it’s making it more sophisticated. Of course, scale and speed is also there. Is it just the arrival of AI that has accelerated it or other trends are also happening in the market. Everybody is on the cloud. The devices, the way we are consuming things, the way organizations operate. Is it just AI or there are other factors also that are playing some role there?
Bryson Byrd: That’s a really good question. And I think that it’s one that is often overlooked with a lot of folks that like to talk about the talking points around these. I think it’s the perfect storm, quite frankly. I think that us as defenders and our tool set has gotten a lot better. And if you look at the cat and mouse game of the history of cyber threats between defenders and attackers, it’s forced them to adapt. And in that same adoption cycle that they’ve been forced to do because we as defenders have gotten better, such as vendors like Huntress creating some of the EDR products to stop them in their tracks and some of the other things going on. You’ve also seen just the perfect timing of when AI was hitting the market. And quite frankly, at Huntress, we saw that AI was first being adopted by threat actors long before vendors were kind of picking up that torch to fight machine speed at machine speed.
Swapnil Bhartiya: You know, that kind of cat and mouse game. I always feel that when it comes to security, it’s never a product, it’s always a process. Also, good guys have to be right 101% of the time, bad guys have to be right only once. That’s all it takes. So the field is not an even playing field anymore. Now while we are talking about RMM attacks, abuse, but they are a lot because of AI agents where agents are making decisions on their own, they’re executing code on their own. You will look at an image, it will just look like a normal image, but to an agent, it may have some hidden code to execute something. Same thing. And we are dumping all the PDFs and everything in the AI with OCR to do that. What other kinds of attacks are you also seeing which may be on the similar league as RMM abuse?
Bryson Byrd: RMM abuse is definitely the one that’s pushing the majority. I mean we’re talking about almost 40% of what our SOC is investigating from a malware deployment is coming from RMM abuse. It’s why we push towards some of the prevention stuff that we can get in later. But I agree with you 100%. There is no vendor, there is no tool that’s going to solve the problems for organization cyber security resilience. Despite me working for Huntress, I will continue to say that moving forward because it’s just the fact, right. It’s culture and partnerships and that resilience kind of equation that organizations need to look into. But disproportionately, whether we talk about ransomware, whether we talk about other malware, the two main areas of focus that we are seeing over and over get exploited is on the endpoint, it’s through RMM abuse as the majority, and then identity. It’s not the future. We used to use the buzzwords around identity is the new firewall or identity is the new perimeter. It’s not the future of that. That is the reality. We are seeing identity continuously exploited. I think it’s something like 70% of the intrusions that Huntress investigates into identity are identity-based attacks that have no multi factor authentication in the environment to even have to bypass. So these are still very fundamental controls that organizations are still struggling to adopt at this time.
Swapnil Bhartiya: And as attackers are increasingly exploiting these trusted tools or the whole IAM. How should businesses rethink or think differently when it comes to their security stack? We have been talking about it. The only good thing that happened with cloud native is that security is no longer an afterthought. With the whole shift left movement, zero trust, it has become a board level discussion. Now we have CISOs as well. So this is not an afterthought. But given this more sophisticated scale and AI speed, how should businesses rethink their security stack?
Bryson Byrd: I don’t even think it’s a rethink. I think it’s just a focus on the fundamentals that we’ve been talking about in the security community for a very long time. And the one thing I will push back on a little bit is the notion of attackers have to be right only once. If we’re doing things properly and we’re building in layers, they have to be right one time for every layer of security that we’re looking at. Right. So we should not only be focused on the perimeter, whether we’re talking about identity, whether we’re talking about network perimeter, but we need those additional controls to layer across the environment. I think the main difference of where we’re at right now is the complexity of the chained attacks that we’re seeing is forcing us to adopt security at every layer. Whereas before, some of the advice that as a what I would call recovering CISO I used to advise on, hey, we need to focus on these two areas and these are the most important, now we need all the layers involved. We need identity, we need the perimeter to be taken care of. But we also need to be looking into posture management to begin with as well from an endpoint security posture management perspective as well as the controls that we’re putting in on the front end to prevent some of these attacks as well. So the biggest piece that I think has changed is just the complexity that’s pushed us to adopt all of the layers that we can versus the picking and choosing of one or two layers and we’re good.
Swapnil Bhartiya: But what does it mean by every layer, then whose responsibility is it? Where does the buck stop? Because sometimes what happens is that if something becomes everybody’s problem then it’s actually no one’s problem. So how does it actually look like in an organization when you do say that it has to go in every layer?
Bryson Byrd: I think you hit the nail on the head there. But the one thing I would say is for every organization it’s going to look a little bit different, right. For a two person mom and pop bakery, for those folks, they are going to need the partner, they’re going to need the help not only to set up what the security architecture looks like but also for the continuous monitoring, the continuous who has their back if anything fails. Right. One thing to prevent but we need some fail states on the back end. That’s why we’ve been preaching incident response plans for so long. Right. And then for your more complex mid market that may look like disproportionately internal IT with stakeholders and with your CISOs that are driving a lot of that change internally. But at the end of the day it’s going to take the village. I think that’s one of the things that we’re continuously talking about with some of the partners that I work with. You’ve got to be able to wrap your arms around the organization and allow the organization to understand that security today is a culture issue as much as it is a technological issue. Because you’ve got to make people comfortable saying, hey, I see a problem here, and maybe even I’m the one responsible, but the problem’s still here and we need to address it and put it on the roadmap.
Swapnil Bhartiya: When you’re talking about some of these risks, a lot has to do with social engineering, a lot has to do with culture. Also don’t just put your sensitive data in ChatGPT where it is going through somebody else’s eyes. Or once again don’t just scan random images. There are so many things that can go wrong. So from a culture point of view, while technologies are there, this problem is once again one of those problems that cannot be solved just by technology. In the security space you folks talk about culture a lot. So talk about when it comes to these AI-powered threats, what role culture can play and what kind of culture organizations can build. And let’s not just talk about the same world we have been talking about for a long time where employees themselves are proactive versus hey, this is what you have to do because that’s what management tells us.
Bryson Byrd: Yeah, really. I mean you’re touching on administrative versus technological controls and how that intertwines into the cultural dynamic. Right. Because as you put it, if it is just administrative controls that we’re relying on from a policy perspective or whatever, the heavy handed top down, it’s never going to work, we all know that. But it is a piece to begin the education process for those that are maybe more on the left side of the immaturity spectrum of security resilience. Right. But as you’re trying to move towards being more mature and more cybersecurity resilient, the way I think about this is there’s an old book that I reference a lot and it was General McChrystal’s book. The book is called Team of Teams. Right. So you talked about silos and all that. But a large portion of this is breaking down the silos as much as you can to share the best practices of what is working, what is not, as well as to understand that at the end of the day we’re all in the same fight. Right. The goal is still the same for each one of us within the organization and that is a business continuity goal. Right. So there are technological pieces to that. I mean, even on the AI front, one of the things that we’re seeing start to emerge is how do we bring zero trust and overall DLP practices into an AI chatbot for organizations. Right. These are technological pieces that drive that. But there also has to be a bare bones education layer that takes place from leaders, from top down in conjunction with the usual security awareness training that we all take and love so much at times.
Swapnil Bhartiya: Right. Perfect. Thank you. Now let’s talk about Huntress. Of course, you folks do a lot of work in the space, a lot of research, a lot of reports to understand where things are. How are you folks helping these teams, these organizations to first of all have that security at every layer easily. Also sometimes security can slow things down, can break things down. So no offense, but most people don’t like security folks. But the new mantra of security is less about putting gates and more about guardrails so that you can freely innovate within these models. And that actually gives developers more confidence to do whatever they want to do because the guardrails are in place. So talk about how do you folks help, what is your strategy for these organizations?
Bryson Byrd: Yeah, at Huntress we recognized the need and the history of it. We started off with our founders being former NSA folks that recognized there’s a real need of helping organizations with where they’re at versus where enterprise-selected tools want them to be at. Right. So what I mean by that is we’ve offered endpoint detection and response, an EDR product, we’ve offered some ITDR, identity threat detection and response, as well as SIEM-type tools for what happens once they’re in the environment. We can detect it, get them out. But we’ve really recognized the need to move to the prevention side. And so we’ve started on the tools of endpoint security posture management as well as identity security posture management. And the goal is to not only cover different layers, but provide both ends of the spectrum of both prevention and reaction to when things happen. Because no matter what we do, every now and then we are going to see some security defenses fail at one layer or another. And we need to be able to see that, investigate it, and get it out of the environment. That’s where our 24×7 SOC comes into play. Right. But at the end of the day, our goal is to meet our partners where they’re at. If they only need one of those things, they’ve already got the layers and the other pieces taken care of. We’ll take care of that, we’ll offer that and help them with that. But the goal is security resilience and helping our partners and our customers move more and more resilient the best way we can.
Swapnil Bhartiya: Bryson, thank you so much for taking your time out. This was a great conversation. And of course, those who are watching, please go and check Huntress.com to learn more about how they can help you. And Bryson, I look forward to chatting with you again because this is a conversation we need to be having about security and AI because things are getting out of control. But you folks are helping bring things under control. So thank you and I look forward to the conversation.
Bryson Byrd: Thank you so much for having me. I really appreciate the conversation.





