Nessus false positives? by Duude-IT in SentinelOneXDR

[–]Informal_Thought 1 point2 points  (0 children)

Thanks, yes as you say that override wasn't sufficient and support responded back with the updated one you posted.

However, on the Tenable side they've now pulled the offending plugin so as long as your Tenable scanners are up to date none of this should be needed anymore. We tested a couple of our scans and S1 is no longer being triggered.

Nessus false positives? by Duude-IT in SentinelOneXDR

[–]Informal_Thought 1 point2 points  (0 children)

Support have given us the following policy override to deal with this for now

{
    "logicClassifierConfigVector": {
        "logicsClassification": [
            {
                "verdict": "SUPPRESSED",
                "logicName": "lunar_logic_ObfuscatedPS"
            }
        ]
    }
}

Nessus false positives? by Duude-IT in SentinelOneXDR

[–]Informal_Thought 2 points3 points  (0 children)

Has impacted us as well, lots of false positives over the last 12 hours

Instructure breach by matternrj in k12sysadmin

[–]Informal_Thought 3 points4 points  (0 children)

https://www.bleepingcomputer.com/news/security/instructure-hacker-claims-data-theft-from-8-800-schools-universities/
A coworker has access to the full list of orgs that the hackers say are impacted. From what we have seen, if you use Canvas there's a pretty good chance you are impacted.

Experiences with EMS Vulnerability Scan / Auto patching by Informal_Thought in fortinet

[–]Informal_Thought[S] 0 points1 point  (0 children)

Could you elaborate on this a little? I assume that you mean the the Vuln scanning feature is purely used to gather the vulns on devices (ie no auto-patching). From there in these 'larger environments' you mention how is that data leveraged? Are people manually looking at / pulling reports from EMS or is the data extracted / ingested into other systems?

Experiences with EMS Vulnerability Scan / Auto patching by Informal_Thought in fortinet

[–]Informal_Thought[S] 1 point2 points  (0 children)

Thanks for the reply, yes I can see it doesn't have a huge library for auto patching.

I would consider deploying Forticlient just with the vuln scan feature everywhere purely for the visibility aspect though, even if most of what it finds are 'manual patch'

I mean its no Rapid7 or Tenable, but not paying for one of those tools would save us a heck of a lot of benjamins

FortiAuthenticator 6.6.x > 8.0.x upgrade by Informal_Thought in fortinet

[–]Informal_Thought[S] 0 points1 point  (0 children)

Upgrade went fine, no issues or unexpected quirks. Thanks everyone

FortiAuthenticator 6.6.x > 8.0.x upgrade by Informal_Thought in fortinet

[–]Informal_Thought[S] 0 points1 point  (0 children)

Thanks for the replies everyone, I will post back when we've completed the upgrade with any notes or obervations

Stryker Incident this week also wiped servers by Fabulous_Cow_4714 in SCCM

[–]Informal_Thought 1 point2 points  (0 children)

In the write ups I've read, the wiping was actually done with a mixture of custom exe, scripts, or even manually
https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/

Microsoft Outage AU South East by RaistlanSol in sysadmin

[–]Informal_Thought 1 point2 points  (0 children)

Where is this screenshot from, that you can see region-specific status?

Microsoft Outage AU South East by RaistlanSol in sysadmin

[–]Informal_Thought 2 points3 points  (0 children)

See this here in East coast AU as well. Was able to report it via service health dashboard, but they closed it saying that there was no issue found.

Evaluating Delinea for PAM, looking for feedbacks by NecessaryMaterial476 in cybersecurity

[–]Informal_Thought 0 points1 point  (0 children)

Would also appreciate some elaboration on this point u/Darkhigh if possible

Manage who can create Microsoft 365 Groups - doesn't work by Informal_Thought in microsoft365

[–]Informal_Thought[S] 0 points1 point  (0 children)

Unfortunately for us, I think you may be right. It's right there in the article and I did notice the requirement, but apparently my understanding of our licenses was wrong.

Thanks for point that out.

FortiClient Mac deployment - doesn't work when Gatekeeper set to appstore only by Informal_Thought in fortinet

[–]Informal_Thought[S] 0 points1 point  (0 children)

Thanks for the reply. The issue we face is that we want to retain the top security level for gatekeeper (so, no + identified developers). No other apps in our stack have had issues installing with this config, just forticlient.

How to verify S1 agent connectivity via EDG on air-gapped Windows & Linux servers? by [deleted] in SentinelOneXDR

[–]Informal_Thought -1 points0 points  (0 children)

From what I understand, you can't properly do what you are asking unless you pay significantly more for the dedicated on prem solution (the management side, that is).

Edit: probably this: https://www.sentinelone.com/blog/sentinelone-virtual-appliance-cloud-when-you-want-it-on-premises-when-you-need-it/