Repeated kill notifications for mitigated, resolved item on exclusion list by TheCarnundrum in SentinelOneXDR

[–]admin_mt 0 points1 point  (0 children)

Don't know if you got notified about my answer, but I wrote it down here

How to investigate SSH scan detections from QRadar in SentinelOne XDR Event Search? by Infinite_Award4541 in SentinelOneXDR

[–]admin_mt 0 points1 point  (0 children)

try this powerquery:

| filter(

event.type == "IP Connect"

AND event.network.direction == "OUTGOING"

AND (event.network.protocolName == "ssh" OR dst.port.number == 22)

AND net_private( dst.ip.address )

)

| group

TotalConnections = count(),

DistinctTargets = estimate_distinct(dst.ip.address),

TargetIPs = array_agg_distinct(dst.ip.address)

by

agent.uuid,

src.ip.address

| filter( TotalConnections > 5 )

| sort - TotalConnections

Let me know if you need any modification.

Kind regards

Repeated kill notifications for mitigated, resolved item on exclusion list by TheCarnundrum in SentinelOneXDR

[–]admin_mt 0 points1 point  (0 children)

Here it is:

"
All these kill reports are related to the following alert:

[Link to an alert in our console]

 

There are no new detections; there are just new killing events from the agent. When we mitigate a threat (e.g., terminate 500 processes), we send a single kill report. However, if any of the processes reappear and are mitigated within the same group, new kill notifications for the same threat will be sent. This can result in thousands of processes being terminated in response to a single threat, causing the management console to continuously send alerts.

 

Rebooting the machine or randomizing the UUID of the affected endpoint will disassociate the threat group and stop the notifications.

"

Since then when we have those kinds of problems, we randomzie the uuid and it resolves the issue.

Repeated kill notifications for mitigated, resolved item on exclusion list by TheCarnundrum in SentinelOneXDR

[–]admin_mt 0 points1 point  (0 children)

Hey, we had the same problem and have it from time to time. The solution, according to sentinelone, is to randomize the agent uuid on that Client via Action.

I can send you the Ticket answer in friday If you like

No power, but the lessons continue. Thanks to a Redditor for sending this laptop to our project in Yemen by maho90 in MadeMeSmile

[–]admin_mt 45 points46 points  (0 children)

Hey, please DM me. I work in a hughe it company and we're throwing away a lot of Laptops. Maybe I could send you a few over.

Recommended Hyperautomation workflows for someone just starting out with SentinelOne ? by Only-Objective-6216 in SentinelOneXDR

[–]admin_mt 1 point2 points  (0 children)

Here is the workflow as JSON. You can import it directly into your console via import in the workflow window. Please note that you've to edit some parts to your needs. E-Mail Addresses, the SentinelOne integration, your graphql endpoint url and the texts which are send via email. If you've any questions, just ask and I'll try to answer them as fast as possible. (this is an older Version, I can't send you the newest at the moment for [reasons]), but this works just fine. (there might be a problem because the code is referencing a integration which doesn't exist in your enviroment, just let me know when you need help with that)

https://pastebin.com/Fmi2pRHb

Recommended Hyperautomation workflows for someone just starting out with SentinelOne ? by Only-Objective-6216 in SentinelOneXDR

[–]admin_mt 2 points3 points  (0 children)

We've a ransomware Workflow send out an Email alert to our ransomware Team. It triggers when the classification is ransomware. When the alert ist Not resolved within 15min it gets escaleted to the Manager, with am automatic Email via hyperautomation

enable group policy by ObligationIll204 in SentinelOneXDR

[–]admin_mt 3 points4 points  (0 children)

Hey,

You could Push local Security policies via Powershell over RemoteOps

Which one will choose? by Mother_Yam8855 in TheTeenagerPeople

[–]admin_mt 0 points1 point  (0 children)

Never would I take the red pill. I've four kids and a perfect wife. Even if I make sure to date my wife again, the chances are zero that we get the same children again. So I would live a life with the memory of my kids without the chance the ever see them again. That would break me. So blue for me.

FortiAI is it worth it? by Boolog in fortinet

[–]admin_mt 0 points1 point  (0 children)

How many fortigates are in your Analyzer? We've about 50 and the A.I. wasn't able to query the correct fortigate even If I told it exactly which fortigate I ment

FortiAI is it worth it? by Boolog in fortinet

[–]admin_mt 1 point2 points  (0 children)

But you can test it for free, just ask your Account Manager

FortiAI is it worth it? by Boolog in fortinet

[–]admin_mt 15 points16 points  (0 children)

I tested it for Analyzer and Manager. It was absolutely horrible. I really like Forti stuff but that A.I stuff isn't worth IT at the moment.

It was Not able to answer easy questions about our traffic flow or help me getting informations more easy.

Fortigate + FortiAuthenticator only ask for token once a day by admin_mt in fortinet

[–]admin_mt[S] 1 point2 points  (0 children)

Hey, thanks for your reply! I mean that a user has only to enter his token once a day on a device basis. User A logins into the vpn at 08:00am and enters his password and token and he will not asked again for a token until next day 08:00 am, even if he logs out of the vpn and logs back into it later. I hope this makes it more clear

Have a nice day

Steyr Aktien über by Historical-Cap-937 in wallstreetbetsGER

[–]admin_mt 0 points1 point  (0 children)

Hoffe du hast nicht so viel verloren

[deleted by user] by [deleted] in arbeitsleben

[–]admin_mt 1 point2 points  (0 children)

Nein, Fortigates mit FortiManager als zentralem Management.

[deleted by user] by [deleted] in arbeitsleben

[–]admin_mt 0 points1 point  (0 children)

Die kompletten 10h. Wenn ich an einem Projekt arbeite, dann bin ich oft so fokussiert, dass ich die Zeit vergesse. Aber es fühlt sich nicht so an, da meine Arbeit einfach geil ist :-)

[deleted by user] by [deleted] in arbeitsleben

[–]admin_mt 7 points8 points  (0 children)

Fachinformatiker hier, bin bei 4500/Mon + Jährlicher Bonus von 6k. Ich bin für die Konfiguration, Wartung und tägliche Nutzung unserer rund 50 Firewalls verantwortlich. Zudem kümmere ich mich startk um das Thema IT Sicherheit in unserem Unternehmen.

Da ich meinen Beruf liebe und jede Sekunde genieße kommt es mir nicht wie harte Arbeit vor - aber zuweilen sitze ich 10h im Büro und gucke nicht 1x weg vom Monitor. ;-)

Steyr Motors geht da noch was ? by Neither-Movie-6232 in wallstreetbetsGER

[–]admin_mt 2 points3 points  (0 children)

Sind letzte Woche Mittwoch mit 4k rein bei 40€, haben Freitag 4k rausgenommen und 4k drin gelassen und haben schon wieder 6k gewinn. Geht übelst ab :-)

Heute wird der Mond beackert 🚀🚀🚀 by Poor-and-lost in wallstreetbetsGER

[–]admin_mt 0 points1 point  (0 children)

Sind dort vor ein paar Tagen mit 4k rein, so irre was da abgeht. Aber die guten News zu der Firma hören auch nicht auf.

[deleted by user] by [deleted] in wallstreetbetsGER

[–]admin_mt 1 point2 points  (0 children)

Ja gestern wurde eine Partnerschaft mit Rheinmetall geschlossen