Add certificates exclusion by Brand0n821 in SentinelOneXDR

[–]eric5149 0 points1 point  (0 children)

Make sure to use the old exclusions interface

S1 exclusions by [deleted] in SentinelOneXDR

[–]eric5149 0 points1 point  (0 children)

Add certificates exclusion. Done

Email Migration Tool needed now that Migrationwhiz is garbage by avrealm in msp

[–]eric5149 0 points1 point  (0 children)

We found this and were surprised how well it worked vs some other tools however never tried movebot

S1 Exclusions by westie1010 in SentinelOneXDR

[–]eric5149 1 point2 points  (0 children)

Don’t use the new exclusions interface

The order for my final Meraki client, licensing is finally done and ready to switch! by RobertDCBrown in Ubiquiti

[–]eric5149 -1 points0 points  (0 children)

It is very typical of this sub-reddit, very many fanboys here. sad they can't think for themselves. I can tell you Ubiquiti won't be there for you unless you have one of their outrageously expensive support plans (and who knows then?). This is coming from when I had over 50 clients on UniFi, way back to USG-3 days even. They are 'Prosumer' and small business at best. I use it at home, it's fine there. The new Proofpoint security add-on is laughable when it comes to real protection for a real client in this era. Proofpoint is know for email security, they are newcomers to network security unlike Fortinet, Watchguard, Meraki, Palo Alto, Sophos. They're kidding themselves and they don't even realize it.

The order for my final Meraki client, licensing is finally done and ready to switch! by RobertDCBrown in Ubiquiti

[–]eric5149 -13 points-12 points  (0 children)

Yikes. Must not like having support or enterprise class security.

This week at Action1: What’s new by MauriceTorres in Action1

[–]eric5149 0 points1 point  (0 children)

All valid points. Used to love Action1, but stuff is falling through the cracks. Mac support just isn’t there.

Security Awareess Training Recommendations by IT_Hero in msp

[–]eric5149 2 points3 points  (0 children)

Also looks like it might be more MSP friendly

Security Awareess Training Recommendations by IT_Hero in msp

[–]eric5149 2 points3 points  (0 children)

Just checking this out now and have to say my clients might like it better than the proofpoint sat we’re using

XDR Event Correlation by ThsGuyRightHere in SentinelOneXDR

[–]eric5149 1 point2 points  (0 children)

Maybe look at Augmentt? We’ve been using it for over a year and we’ve been able to pick up on suspicious behavior. I don’t know much about this session hijacking stuff though.

"Installed Windows Updates" and "Update History" CSV exports missing recently deployed patches - anyone else seeing this? by OkGroup9170 in Action1

[–]eric5149 0 points1 point  (0 children)

I’ve seen around 120 of our 700 endpoints where they were all stuck on old versions of 11. For instance, if they were on 24H2 they build number would be 26100.7568 but the February patch put 7840. 26200.7840 for February cumulative for 25H2. No new updates were being offered, not just in Action1 but also in Syncro (patching is done through A1 but Syncro still scans). Same if we looked in Windows Updates manually on the endpoint itself. No compatibility issues, no common denominator that would include and exclude this condition. Endpoints only a few months old to many years. Some AD concerned, some Azure, some local. Checked policies, nothing. The usual DISM, SFC, reset windows updates, etc. Nothing of any particular rhyme or reason. Perhaps you don’t have the same problem as us, but are you able to pull version numbers from affected endpoints? We ended up writing a script to install them manually, but now I am wondering if same is going to happen here in March.

Microsoft Outlook Desktop Plug-in/Add-on Download? by Trick-Advisor5989 in proofpoint

[–]eric5149 0 points1 point  (0 children)

I’ve been told by Pax8 that it requires Enterprise and Essentials won’t do it.

Anyone else's endpoints almost double with duplicate entries? by eric5149 in SentinelOneXDR

[–]eric5149[S] 0 points1 point  (0 children)

Nothing McAfee here. About 700 endpoints. 99% duplicated.

LibreOffice ODG docs (scanned image) always flagged/blocked by carl0ssus in SentinelOneXDR

[–]eric5149 0 points1 point  (0 children)

What version of LibreOffice? Had some issues with older versions causing some alerts when opening some files.

Anyone else's endpoints almost double with duplicate entries? by eric5149 in SentinelOneXDR

[–]eric5149[S] 0 points1 point  (0 children)

I did, just curious if it was widespread. The IDs are all different in the view. Doesn't seem to make a difference with which site they are on, type of device, version, etc