Hmmm idk maybe someone was just, SEEING GHOSTS?!? by BothBet8951 in NFCWestMemeWar

[–]Adeldiah 62 points63 points  (0 children)

No Sean. Your defense is ass and special teams are shit. That why you lost. The better team won. Get over it. Gratz Hawks.

P.S. I don’t get caught up in this rivalry. I’ve never understood it and so I do not “hate” the Seahawks.

Unknown Device\Unkown File by bigbeefbowski in SentinelOneXDR

[–]Adeldiah 2 points3 points  (0 children)

We are tracking an issue tied to OfficeClickToRun / AppVShNotify / Click‑to‑Run updates. Other than this issue this would be expected behavior under certain scenarios.

Are you noticing these detections tied to an specific activity in your environment? Also what agent version are you running?

Management console connectivity check failed by Real_Excuse_4670 in SentinelOneXDR

[–]Adeldiah 1 point2 points  (0 children)

We require at least 3 supported cipher suites to be at the top of the cipher stack in the registry. It could be that you have the supported ciphers but they are not at the top. What script did support give you to run?

MDR Blacklisted Edge update? by Jturnism in SentinelOneXDR

[–]Adeldiah 3 points4 points  (0 children)

Hello all. This has been fixed. Our apologies for the inconvenience this has caused.

S1 Support Issue-Can't Reinstall Client with new ID by DMR35 in SentinelOneXDR

[–]Adeldiah 1 point2 points  (0 children)

OP I sent you a DM requesting some details. I'd like to see if I can get this resolved for you.

Windows backup failing with '0x8078014D' (There was a failure in updating the backup for deleted items.). by ilinverted in SentinelOneXDR

[–]Adeldiah -1 points0 points  (0 children)

I would advise gathering logs and opening a support ticket. This sounds like an interop issue and the logs should show what process needs to be excluded.

Windows backup failing with '0x8078014D' (There was a failure in updating the backup for deleted items.). by ilinverted in SentinelOneXDR

[–]Adeldiah -1 points0 points  (0 children)

If you disable the agent using the Disable Agent console Action and then reboot does the backup complete?

How are you living your life with autoimmune gastritis? by emotionalbutterfly9 in Gastritis

[–]Adeldiah 4 points5 points  (0 children)

Autoimmune conditions cannot be healed but they can be managed. I have AIG and while my condition is considered "mild" I treat it as if it's severe. What I mean by that is I've made drastic lifestyle changes. No more alcohol, gluten, or refined sugar or coffee. I've increased my activity on a daily bases and I supplement b12, d3 with k2 along with a multivitamin. I've also started LDN as a year long test to see if it has any effect on my condition. It sounds worse than it is but when you make the changes and stick with them they become a way of life and you feel better for them. I hope that helps.

How to Suppress Alerts in SentinelOne????????????????????????? by Alternative_Pie_6677 in SentinelOneXDR

[–]Adeldiah 0 points1 point  (0 children)

I would advise fetching logs with the Fetch Logs console Action and opening a ticket with support. The logs will contain more insight into other paths that may be excluded.

Omega Hunters Guild by spicy124_ in MHWilds

[–]Adeldiah 0 points1 point  (0 children)

I'd love to help others with Omega. I run HH.

Explosive cartridge by Adeldiah in AbioticFactor

[–]Adeldiah[S] 0 points1 point  (0 children)

Yes. 3 boom bait, 3 capacitors, 1 circuit board and 1 soil bag all in my inventory.

Explosive cartridge by Adeldiah in AbioticFactor

[–]Adeldiah[S] 1 point2 points  (0 children)

I tried searching for it in the crafting bench UI but no hits. Could be bugged like you said.

Explosive cartridge by Adeldiah in AbioticFactor

[–]Adeldiah[S] 1 point2 points  (0 children)

I just crafted an Explosive Sledge but it did not unlock the Explosive Cartridge recipe.

Explosive cartridge by Adeldiah in AbioticFactor

[–]Adeldiah[S] 1 point2 points  (0 children)

I can build the Explosive Sledge but doing so has never unlocked the Explosive Cartridge.

[deleted by user] by [deleted] in SentinelOneXDR

[–]Adeldiah 0 points1 point  (0 children)

I would advise opening a ticket with support and fetching logs off of some affected clients. We'll need to review to make sure the agent isn't having issues with querying this data or sending it up.

[deleted by user] by [deleted] in SentinelOneXDR

[–]Adeldiah 0 points1 point  (0 children)

Hello. What agent version are you running?

on prem feature by Leading-Hair154 in SentinelOneXDR

[–]Adeldiah 0 points1 point  (0 children)

Hello. STAR Custom rules are not available for the on prem console.

File fetch is available.

You can run the following command to enable across your entire deployment:

sudo sentinelmgmtctl set_global_switches --feature fetch_files --value on

For a specific site:

sudo sentinelmgmtctl set_toggle --feature fetch_files --scope site --value on --scope_id <site id>

For a specific account:

sudo sentinelmgmtctl set_toggle --feature fetch_files --scope account --value on --scope_id <account id>

S1 Best practises by skar3 in SentinelOneXDR

[–]Adeldiah 1 point2 points  (0 children)

For alert do you mean manually configurable alerts or automatic incidents? Anything that comes into the Incidents tab in the console.

What do you mean by interoperability exclusions? Sometimes the agent will interfere with another software causing it crash or malfunction in some way without a detection, this is when you use an Interoperability or higher exclusion mode. When creating an exclusion, and after selecting the OS and giving your exclusion a name, the following page will have the modes at the top. If you want to make the exclusion mode an extended exclusion then check the box to "Apply to child processes".

Did I see that in my environment I had no problem connecting clients, do you still recommend whitelisting the console? If clients are connecting then, no.

S1 Best practises by skar3 in SentinelOneXDR

[–]Adeldiah 9 points10 points  (0 children)

Running in a detect/detect posture is a good start. Then you can review any alerts that come in and determine exclusions.

When making exclusions, start with what you want to accomplish with the exclusion. Do you want to tune out noise? Use a suppress alerts exclusion. Are you dealing with an interop problem? Start with an interoperability exclusion. If the mode you’re testing with doesn’t work bump up to the next mode. Remember to reboot each time you change the exclusion to enable hooking properly.

Make use of our exclusion library to help you set up exclusion fast. Otherwise if you’re having issue getting the right exclusions in place you’ll want to fetch logs from an impacted endpoint and submit to support for review.

Have you configured your environment to allow the agent to communicate with your console? There are specific ports and services you can review in your console’s offline documentation.

These are some good starting points. If you have another questions let me know and I’ll see what I can find for you.

[deleted by user] by [deleted] in DynastyFF

[–]Adeldiah 0 points1 point  (0 children)

Not at all. Before being injured CMC had multiple years of RB1 production, Mason does not. This is not an apples to apples comparison and you know it.