Huntress announced today that the company is expanding its Managed Identity Threat Detection & Response (ITDR) solution to Google Workspace (GWS). As part of Huntress Agentic Security Platform, and with the support of a 24/7, AI-centric SOC, the solution delivers advanced detection and response to one of the fastest growing targets for cloud-based identity attacks.
The expansion comes as Huntress exceeds 10 million Microsoft 365 identities which is protected by its Managed ITDR, in more than 93,000 organizations.
Google Workspace has become much more than a productivity suite – it is now the operational backbone of modern organizations, powering email, authentication, and SaaS access. Attackers have shifted their focus accordingly. Identity-based attacks accounted for 40 % of all security incidents in 2025, where attackers hijacked sessions, abused OAuth permissions, manipulated MFA flows and exploited trusted access paths that bypassed traditional endpoint defenses.
Yet many organizations still rely on legacy email security tools, making Google Workspace vulnerable to modern attacks.
Huntress Managed ITDR for Google Workspace Prioritizes attacker behaviors with high signal strength over noisy telemetry to detect and stop identity abuse in real time, including:
- Unexpected login activity – Identifies anomalous authentication behavior and applies configuration rules for trusted locations or VPN access.
- Persistence of malicious inbox rules – Detects attacker-created Gmail filters designed to suppress MFA notifications, hide security warnings, or delete victim correspondence to reduce dwell time and eliminate stealth persistence.
- Malicious data center use – Tracks when identities are authenticated from new data center providers (measured by ASN/ISP), and prioritizes the “usual suspects” most abused by threat actors.
”Hackers no longer break in, they log in, and Google Workspace is increasingly at the center of that risk,” says Prakash Ramamurthy, product manager at Huntress. ”As identity becomes the front door to the business, organizations need experts who can detect attacker behavior in real time and shut it down. With our expansion of Managed ITDR to Google Workspace, we’re ensuring businesses are protected across the cloud ecosystem without adding operational burden to resource-constrained security teams.”
The expansion is also based on Huntress existing Managed ITDR coverage for Microsoft 365, giving organizations unified identity recognition and responsiveness across the platforms that power today's workforce.
”As we increasingly rely on Google Workspace as our identity hub, we have realized that traditional email security is simply not enough,” says Blair Compston, IT Manager at BizStream. ”Huntress Managed ITDR for GWS gives us confidence that identity threats will be investigated and handled by experts, and not appear as another alert for our team to chase.”
Huntress Managed ITDR for Google Workspace is now available to new and existing Huntress customers. Learn more about Managed ITDR here or register for a free 14-day trial.
”Managing identity risks in our Google Workspace clients used to be a constant resource drain on our team, especially when attacks looked like normal user behavior,” says Jason Caine, Chief Engineer at CCP Tech. ”Huntress gives us a trusted partner that helps us protect our customers more effectively, while freeing up time to focus on what’s important to our customers and their growing businesses.”
About Huntress
Huntress is a global cybersecurity company with a mission to make enterprise products accessible to all businesses. Huntress Agentic Security Platform is purpose-built from the ground up and offers comprehensive protection in the AI age. From Endpoint Detection and Response (EDR) and Identity Threat Detection and Response (ITDR) to Security Information and Event Management (SIEM), Security Awareness Training (SAT) and Security Posture Management, the Huntress Agentic Security Platform offers targeted protection for endpoints, identities, data and employees, delivering reliable results and valuable peace of mind.
Its AI-centric security operations center (SOC) Open 24/7, Huntress is run by a team of world-renowned engineers, researchers, and security analysts dedicated to stopping cyberthreats before they cause harm. Huntress is often the first to respond to major hacks and incidents, and their expert security team shares real-time commodity analysis and actionable advice with the community.
Huntress currently protects more than 4 million endpoints and 10 million identities and empowers internal security and IT teams as well as Managed Service Providers (MSPs) around the world the opportunity to protect their businesses with affordable, enterprise-grade security products.








