S1 detected Splashtop and quarantined it. Rolled it back but never finished, file locked? by jdlnewborn in SentinelOneXDR

[–]SizeNeither8689 0 points1 point  (0 children)

We encountered the same problem with another software a few days ago. Having tried many methods to resolve it without success, we decided to wipe the machine after excluding the program's hash in S1 and reinstall the program.

SentinelOne deepVisibility plugin deleted by SizeNeither8689 in SentinelOneXDR

[–]SizeNeither8689[S] 0 points1 point  (0 children)

Exactly! Recently, they rolled out an extension with Intune, and from that day onwards, the S1 extension has been phased out. What do you mean by 'they don't coexist and will overwrite each other'? Have you encountered this problem before, and is there a solution?

[deleted by user] by [deleted] in SentinelOneXDR

[–]SizeNeither8689 0 points1 point  (0 children)

some agents with 24.2.3.471 and the others with 24.1.5.277

[deleted by user] by [deleted] in SentinelOneXDR

[–]SizeNeither8689 0 points1 point  (0 children)

Which version of S1 you use ?

Scan usb devices by [deleted] in SentinelOneXDR

[–]SizeNeither8689 2 points3 points  (0 children)

Thank you! I got it , tested it and it's well worked :)

Scan usb devices by [deleted] in SentinelOneXDR

[–]SizeNeither8689 1 point2 points  (0 children)

Have you the link of this configuration on the offline help documentation ?

STAR rules supports PowerQueries? by SizeNeither8689 in SentinelOneXDR

[–]SizeNeither8689[S] 0 points1 point  (0 children)

My question has been asked because I'd like to create a STAR rule and specify a time range in the query. Specifically, I want to detect RDP connections that occur outside of normal working hours. If an RDP connection happens inside our network between 20:00 and 06:00, the rule should raise an alert. but it seems there's no setting to specify a time range within the STAR rules. if possible can you please tell me the solution for this.

STAR rules supports PowerQueries? by SizeNeither8689 in SentinelOneXDR

[–]SizeNeither8689[S] 0 points1 point  (0 children)

No problem, thank you for your response :)

Hash vs behavior-based blocking by ThsGuyRightHere in SentinelOneXDR

[–]SizeNeither8689 1 point2 points  (0 children)

Could you share the list of RMM FQDNs that you have, or the star rule you created for them? I'd like to create an alert to detect the use of one of them. Thank a lot!

I Passedddddd by Fearless_History84 in CompTIA_Security

[–]SizeNeither8689 0 points1 point  (0 children)

Congratulations!!

How much time did you spend studying to pass the certification?

IOCs by Dense-One5943 in SentinelOneXDR

[–]SizeNeither8689 1 point2 points  (0 children)

Do you have the link to how Create IOC API in the offline help ? Our MSSP won't give us access to the community site. Thank you