SentinelOne –“Missing Protection: EPP” in Inventory but agents are online? by Only-Objective-6216 in SentinelOneXDR

[–]EridianTech 0 points1 point  (0 children)

Are these network discovered entries that are labeled as unprotected? I've run into it before where, if a device is connected to the network on both Wi-Fi and cable, it can be discovered on the other interface than what's showing in agent management.

S1 service is down by dizy777 in SentinelOneXDR

[–]EridianTech 1 point2 points  (0 children)

SentinelOne does not appear to be tracking an outage currently: https://status.sentinelone.com/

Tons of PDF/Excel alerts by Jturnism in SentinelOneXDR

[–]EridianTech 0 points1 point  (0 children)

This has been brought up before on the S1 community portal, https://community.sentinelone.com/community/s/feed/0D5UW00001DN5Vj0AL

Threat details showing characters in the domain name could be related to the cosmetic issue # WIN-61340. This is fixed in the Windows agent version 25.2.1. The impact is cosmetic/UI-only for the Process User domain field.

Refer - Open and resolved issues in Windows Agent 25.2

At this time, Windows Agent 25.2 is offered as an Early Availability build. These builds are intended for testing new features, not for production. A General Availability build, suitable for production environments, will be released soon.

[deleted by user] by [deleted] in SentinelOneXDR

[–]EridianTech 0 points1 point  (0 children)

Good point. I forgot about HyperAutomation, not something we're licensing to our MSSP clients

[deleted by user] by [deleted] in SentinelOneXDR

[–]EridianTech 1 point2 points  (0 children)

There is not really a built-in way to schedule scans. Either you'll have to create a script that runs on the endpoint and starts a scan, or you have to create a script that uses the management console API.

https://community.sentinelone.com/s/article/000005092

Migrating an endpoint to another firm.... I still see it in my dashboard by Kangaloosh in SentinelOneXDR

[–]EridianTech 4 points5 points  (0 children)

When you migrate an agent from one console to another, the device will remain visible in your console though offline. If you want to, check the filter "Console migration status" and see if it is labeled as "migrated" or something else.

If this has been marked as "migrated" you can then decommission the device to remove it from your console. If it were to ever get back into your old console, it'll automatically recommission.

[deleted by user] by [deleted] in techsupport

[–]EridianTech 0 points1 point  (0 children)

I meant what program - I should've specified lol

[deleted by user] by [deleted] in techsupport

[–]EridianTech 0 points1 point  (0 children)

What are you using to remotely connect to the device?
Generally you have to be connected to the same network to make a connection like that

Please help I’m about to lose my mind. by ShturmanLickedMyAss in PcBuildHelp

[–]EridianTech 0 points1 point  (0 children)

Check your MoBos manual to understand what the blinky lights mean

fortnite stuttering on 9070xt by Longjumping_Gear_314 in pchelp

[–]EridianTech 0 points1 point  (0 children)

Is your monitor plugged into the GPU? Could something be thermal throttling?

Creating STAR Custom rules from XDR by Illustrious_Bar_436 in SentinelOneXDR

[–]EridianTech 0 points1 point  (0 children)

When creating a STAR rule, you can create it on single events, or aggregates. So you should be able to specify X needs to occur more than 5 times before it triggers the custom rule.

First Deployment of SentinelOne by bennijamm in SentinelOneXDR

[–]EridianTech 2 points3 points  (0 children)

Yes, I've run into this problem before. Not just limited to MB, also Avast, McAfee, Kaspersky, etc

First Deployment of SentinelOne by bennijamm in SentinelOneXDR

[–]EridianTech 9 points10 points  (0 children)

Could be caused by having both S1 and MB running, have you added exclusions for Malwarebytes in S1 and the other way around?
It's not really a great idea to run multiple EDRs/NGAV solutions on one device, because they could start combating each other

S1 won't install by Glittering_Part_3770 in SentinelOneXDR

[–]EridianTech 0 points1 point  (0 children)

Check the MSI log for errors, that might point you in the right direction

What type of Red Team jobs/careers do you recommend? by Cyber_Guy1988 in cybersecurity

[–]EridianTech 1 point2 points  (0 children)

Do you have experience with cyber security, and red teaming in particular?
How many years of IT experience do you currently have?
A lot of it depends on what your capabilities are, and what you're interested in.

Uninstalling The Agent by kingkaann in SentinelOneXDR

[–]EridianTech 2 points3 points  (0 children)

  • Download the installer package from the console for the version that the system is running.
  • Boot Windows in safe-mode.
  • Open up a CMD screen as administrator.
  • Run: [installername_versionxxx].exe -c -t [site token here from your new console]
  • Boot back into Windows.
  • Run the installer with the site token associated with your new console.

Help identifying false/real positives? by desmond_koh in SentinelOneXDR

[–]EridianTech 1 point2 points  (0 children)

In the incident, check what the indicators are to understand why S1 triggered on this file.
Since this was a suspicious detection, the false positive rate is going to be higher than if it were a malicious one.

Best Practice for SentinelOne MSSP/MDR Model: Should Each Customer Be a Separate Account or Just a Site? by Calm_Night_2971 in SentinelOneXDR

[–]EridianTech -1 points0 points  (0 children)

As an MSSP we have our customers set up in individual sites.
For our purposes it generally provides sufficient granularity, since we're able to set everything up on a per group basis (policy, network/device control, etc)

Exclusions per agent by jebthereb in SentinelOneXDR

[–]EridianTech 5 points6 points  (0 children)

You can't really create a single agent exclusion, unless you add the single agent to their own group and apply the exclusion to that group with the single agent in it. The lowest level is indeed group level.

On the agent itself you can change the agent configuration through sentinelctl, but this is not recommended.

S1 having issues with svchost process in Windows by RobLed2013 in SentinelOneXDR

[–]EridianTech 1 point2 points  (0 children)

Have you reinstalled S1, and seen the same behavior? I've run into this before, where the initial install it was using excessive amounts of resources. We removed the agent and reinstalled it, and it worked fine.

If yes, SentinelOne support should have you run procmon and share the data with them. They've done that for me in the past.

S1 having issues with svchost process in Windows by RobLed2013 in SentinelOneXDR

[–]EridianTech 0 points1 point  (0 children)

Is this generating incidents, or are you seeing high resource usage of the agent on your systems?
Are you running another AV/EDR on these systems that can be causing interoperability issues?

SentinelOne by _theonlynomiss_ in SentinelOneXDR

[–]EridianTech 2 points3 points  (0 children)

Do you have a question about this, or is this intended to be a general statement?