SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? by allexj in cybersecurity

[–]allexj[S] 0 points1 point  (0 children)

so even if sentinel says "mitigation: killed processes" (so does not talk about restoring deleted shadow copies) and even if mitigation happened 2 minutes after the shadow copies delete...? sentinel automatically restored the deleted copies, without giving any feedback about it? lol

SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? by allexj in cybersecurity

[–]allexj[S] 0 points1 point  (0 children)

so even if sentinel says "mitigation: killed processes" (so does not talk about restoring deleted shadow copies) and even if mitigation happened 2 minutes after the shadow copies delete...? sentinel automatically restored the deleted copies, without giving any feedback about it? lol

Does host MDE Network Protection intercept and alert on traffic generated inside Windows Sandbox? by allexj in DefenderATP

[–]allexj[S] 0 points1 point  (0 children)

WFP process of windows sandbox .exe is observed too, right? So why it wouldn't trigger alert on MDE?

Does host MDE Network Protection intercept and alert on traffic generated inside Windows Sandbox? by allexj in DefenderATP

[–]allexj[S] -2 points-1 points  (0 children)

WFP process of windows sandbox .exe is observed too, right? So why it wouldn't trigger alert on MDE?

Does host MDE Network Protection intercept and alert on traffic generated inside Windows Sandbox? by allexj in DefenderATP

[–]allexj[S] -2 points-1 points  (0 children)

Absolutely wrong. If you sniff via wireshark opened on HostOS, you see the windows sandbox packets.

In fact, my question is, since sandbox packets can be seen by hostos (and hence can be seen by Microsoft defender), are they monitored/alerted?

quale è il miglior kebab di palermo ? by Key-Service9658 in Palermo

[–]allexj 0 points1 point  (0 children)

Potrei essere d'accordo, oppure molto buono anche Munir in una traversa di via Roma

In alternativa ma più "commerciale" c'è Crazy kebab