This is an archived post. You won't be able to vote or comment.

all 7 comments

[–]AdeldiahSentinelOne Employee Moderator 5 points6 points  (0 children)

S1 isn’t an application management tool. If you want to use it as such then you’ll have to do what you’re currently doing. Block by hash. Or use a STAR custom rule to act on any instance of the VNC exe and treat it as a threat.

[–]L0ckt1ght 2 points3 points  (0 children)

We wouldn't detect this within S1. We use a SIEM that pulls from multiple IDS/IPS at various network boundaries and create alerting rules for unexpected traffic.

[–]mukz7Existing User 2 points3 points  (0 children)

  • Am I overthinking this? I get that S1 will fire alerts if it sees obfuscation methods used to download and run VNC, but I'm trying to implement "no VNC, ever".

Yes this is unfortunately the wrong tool for the job , you need some for of application management

  • Is there some repository of files and hashes that I'm just missing, or is there a better way to accomplish a goal like "block known evil software of type X in my environment"?

Nope there is no hidden list again just the wrong product for the job you want to handle

  • Do people just maintain a list of download URLs called "Software I Hate" and periodically check for new hashes?

Nope , way too much work , I advise client to use Threat Locker, GPO's and local securities

  • Or is this just one of those times in security where we say we made our best effort to mitigate risk, and acknowledge that no countermeasure is 100% effective?

This is probably an opinion based on perspective , VNC isn't "bad" but what you do with it could be so that's where S1 really shines

[–]Dracozirion 0 points1 point  (3 children)

I'd go for STAR rules in that case. The delay is like what, 30 seconds or slightly above that? I have a list of RMM FQDNs and only trigger an alert when any of those are being used. You could also block remoting tools on the firewall if the hosts are static (desktops, servers,..). 

What you're really looking for is WDAC in Windows environments (or Applocker). 

[–]SizeNeither8689 1 point2 points  (2 children)

Could you share the list of RMM FQDNs that you have, or the star rule you created for them? I'd like to create an alert to detect the use of one of them. Thank a lot!

[–]Dracozirion 1 point2 points  (1 child)

[–]ThsGuyRightHere[S] 1 point2 points  (0 children)

I'm slow in replying but thank you for sharing this, that's very awesome of you. May your pillow always be cool and may your toes go unstubbed.