At Huntress, customer protection shapes how we build and operate. Security isn’t a separate consideration for one team or one phase of development. It runs through the entire process, from product design to threat operations. That focus continues after release. A new feature is only useful if it helps defenders investigate faster, understand incidents more clearly, or catch activity they'd have otherwise missed. That’s why close collaboration between Product and frontline teams matters so much. You can already find plenty of detailed examples in our blogs from Dray Agha, Tactical Response, and the DE&TH (Detection Engineering & Threat Hunting) team. But what really drives those stories—and the successes behind them—is how Huntress teams actually use Managed SIEM. A tight feedback loop between Product and the front lines It starts with a tight feedback loop between Product and our frontline defenders: Tactical Response, DE&TH, Security Operations Center (SOC), and Adversary Tactics. These teams are often our earliest adopters, testing new features in real environments and giving us early, honest feedback to shape the value and use cases. Once a capability goes live, it gets put to work immediately by our teams. Whether it’s a major feature like correlation rules or a small quality-of-life improvement like case-insensitive queries, every enhancement is built to reduce detection time and make investigations more efficient. We evaluate success based on real-world impact. We ask ourselves, "Does this help us detect threats faster or catch techniques we couldn’t before?" Turning log data into faster investigations One recent example is our new support for COUNT and COUNT DISTINCT in ES|QL. These functions help our analysts quickly summarize vast amounts of log data to spot anomalies, trends, or one-off behaviors. Paired with deep knowledge of attacker behavior, this capability helps our Threat Hunting, SOC, and Adversary Tactics teams dig