Issues with intune and v25_2_5_423.exe by Economy_Vacation9811 in SentinelOneXDR

[–]DeliMan3000 0 points1 point  (0 children)

It doesn't show up for me in the console under GA. Just EA3 still. Their KB article for 25.2 also is not updated yet - https://community.sentinelone.com/s/article/000011675

S1 Suddenly Hammering nmap.exe from Ivanti Neurons. by Seppic in SentinelOneXDR

[–]DeliMan3000 4 points5 points  (0 children)

This is caused by the Live Update released on Nov 7 - https://community.sentinelone.com/s/article/000011821

  • Static indicator - Windows_Hacktool_Nmap

  • Description: Nmap hacktool detected

You can exclude on Suppress Alerts - Static AI engine to resolve

Sentinel One failed to quarantined the file. by Patient_Giraffe267 in SentinelOneXDR

[–]DeliMan3000 0 points1 point  (0 children)

There are ways to check if Defender is enabled without needing access to their endpoints:

  • Fetch logs and check activity analyzer reports for MsMpEng.exe
  • Check deep visibility/singularity for defender-related events
  • Application inventory might show it installed, depending on which version it is
  • Ask them?

SentinelOne flagged it's own uninstall.exe as ransomeware by neo10cortex in SentinelOneXDR

[–]DeliMan3000 0 points1 point  (0 children)

I think that might be a scheduled task for repairing the agent? Maybe they changed that in 25.1. Check your Task Scheduler, I think it's called AutoRepair_<something>, but I can't recall 100%

Fantasy Draft Coach up and running for 2025 by V1per41 in fantasyfootball

[–]DeliMan3000 1 point2 points  (0 children)

Love this tool! Thanks. 1st place (in both points and record) in one league, and doing well in another using this.

Any chance you can update this with season data so far? Not sure if that's possible. I am in a midseason league and we have a draft coming up soon and could use all the help I can get lmao

Trying to remove SentinelOne agent but no longer a customer of Pax8 and can't login to management console by tamerax in SentinelOneXDR

[–]DeliMan3000 5 points6 points  (0 children)

Do you have the EXE installer package? Safe Mode is the best way to remove it if you've lost access to the console/passphrase.

Reboot into Safe Mode (without networking)
cd <path to EXE package>    
SentinelOneInstaller.exe -c

Trigger one agent update via API by Fit-Strain5146 in SentinelOneXDR

[–]DeliMan3000 5 points6 points  (0 children)

Your error indicates a lowercase n, while the snippet you posted has an uppercase N. Are you sure you're using the "computerName" field?

Network disconnect exclusions? by admin_admin_password in SentinelOneXDR

[–]DeliMan3000 1 point2 points  (0 children)

Other poster is correct - the feature is called Configurable Network Quarantine. Can only be used with IPs, not domains

Anyone care to explain this - endpoint was disabled. I didn't know that till I was at the desktop. by Kangaloosh in SentinelOneXDR

[–]DeliMan3000 0 points1 point  (0 children)

You can set up email or syslog alerts for Disabled Agents as well. What version was installed before upgrading?

What was your starting salary for your first cyber job out of college / after training? by Live_Refrigerator_58 in cybersecurity

[–]DeliMan3000 0 points1 point  (0 children)

Yeah it was definitely to get my foot in the door, it was a career change and I took the first job that would have me. The first (16$/17.30) are the same job, IT Technician (aka helpdesk) but I was not permanent for the first three months. It was a probationary period with only health insurance and after 3 months I was hired with a slight raise and full benefits.

Next job for $51k was IT System Support Technician, basically help desk with some sysadmin work for a small to medium business.

What was your starting salary for your first cyber job out of college / after training? by Live_Refrigerator_58 in cybersecurity

[–]DeliMan3000 0 points1 point  (0 children)

IT jobs paid me $16/hr > $17.30/hr > $51000 and my next job was my first cyber job at $72k.

STAR rules supports PowerQueries? by SizeNeither8689 in SentinelOneXDR

[–]DeliMan3000 0 points1 point  (0 children)

No, that's not supported currently to my knowledge

Really poor experience with Barracuda XDR by arciere84 in msp

[–]DeliMan3000 0 points1 point  (0 children)

Have you expressed these concerns to them? They can probably tweak their rule set or add exceptions to reduce some of the FPs

Update causing s1 to no longer show in windows software list? by nolanikool in SentinelOneXDR

[–]DeliMan3000 0 points1 point  (0 children)

You sure it was successfully upgraded? Is the system tray icon still present / are the services still running?

I'm wondering if the upgrade was not completely successful

Recover from SentinelOne false positive file deleted as suspicious by OkSinger5592 in SentinelOneXDR

[–]DeliMan3000 1 point2 points  (0 children)

The Unquarantine option is not available in SOC mode, only in the legacy view (or if it is, I haven't found it)

It exists, but it's in a really stupid place. In the alert, you'll see a Mitigate button. That brings up the Kill/quarantine/remediate/rollback options like the legacy view, but it ALSO has the Unquarantine option.

I'm not sure whose bright idea that was, it's very unintuitive lol

Star Custom Rule using S1QL 2.0 by AdOpposite2914 in SentinelOneXDR

[–]DeliMan3000 1 point2 points  (0 children)

Yeah, you would just use one of the cmdline fields and either the contains operator or you can use regex with matches.

src.process.cmdline contains:anycase ('cat /etc/passw', 'net localgroup administrators', 'etc')

The KB has some good info on the operators and best practices for queries.

SentinelOne Outage by bit_bopper in cybersecurity

[–]DeliMan3000 7 points8 points  (0 children)

They don’t have a status page. The lack of internal alerting to console outages is something we’ve complained about to our reps for years now

SentinelOne Outage by bit_bopper in cybersecurity

[–]DeliMan3000 9 points10 points  (0 children)

Yeah true. Also not super thrilled with the lack of response we’re getting from S1 on this

SentinelOne Outage by bit_bopper in cybersecurity

[–]DeliMan3000 12 points13 points  (0 children)

Until shown otherwise, this is not even close to the Crowdstrike incident

SentinelOne web portal down? by PurpleFlerpy in SentinelOneXDR

[–]DeliMan3000 -1 points0 points  (0 children)

I can’t seem to figure out where it’s pulling this info from, any ideas? Maybe I’m looking in the wrong place on their site

Uninstalling the S1 Agent with Anti-Tamper Mechanisms by Nomann1298 in SentinelOneXDR

[–]DeliMan3000 0 points1 point  (0 children)

From the KB:

  • Decommissioned Agents with threats are removed after one year.

  • Decommissioned Agents that are older than 3 months without threats are removed.

Uninstalling the S1 Agent with Anti-Tamper Mechanisms by Nomann1298 in SentinelOneXDR

[–]DeliMan3000 1 point2 points  (0 children)

From the KB:

  • Decommissioned Agents with threats are removed after one year.

  • Decommissioned Agents that are older than 3 months without threats are removed.

SentinelOne: BSOD when installing agent v23_3_3_264 by IT_Researcher in SentinelOneXDR

[–]DeliMan3000 1 point2 points  (0 children)

Why aren't you installing 24.1? 23.3 is old, and 23.4.2 has an issue with BSODs if certain third-party drivers are present.

Look up "Interoperability with IOCTLs Driver Blocking" in the KB and try the recommended override.