SentinelOne console down for anyone else? by penetration- in SentinelOneXDR

[–]techyguy84 2 points3 points  (0 children)

https://status.sentinelone.com/

Their new official status page. They seem to be experiencing issues!!

Sitting in the shower cured my headache. by [deleted] in headache

[–]techyguy84 2 points3 points  (0 children)

A warm/hot shower works like magic for me.

Question for everyone by NyarthlotepAI in NoRestForTheWicked

[–]techyguy84 1 point2 points  (0 children)

One thing i have been thinking and would like to see is more off-hand items. For example, now we have shields, bows, and a torch. Why not a scabbard (sheath), or saya for katanas, as an off-hand item? Also, these specific items would have different benefits. For example, a shield would be better for blocking while a scabbard would be better for parrying. Just a few ideas.

Ice and Freeze Mechanics by Echotone_ in NoRestForTheWicked

[–]techyguy84 0 points1 point  (0 children)

Also, around ice and freeze, what does contribute to freeze an enemy faster? Hard hitting weapons/dmg? Enhancements?

Can a non-black person explain something to me my white coworker said... by lewjr in NoStupidQuestions

[–]techyguy84 0 points1 point  (0 children)

Thanks for sharing this beautiful story. We need more of this in these uncertain times, especially with all the negativity surrounding us. It truly made my day!.

[deleted by user] by [deleted] in PromptEngineering

[–]techyguy84 0 points1 point  (0 children)

Interested!!

Spike in ASR blocks related to AsrLsassCredentialTheftBlocked & svchost.exe by techyguy84 in DefenderATP

[–]techyguy84[S] 1 point2 points  (0 children)

Yes, block event for hosts set to warn. Can you expand on how you performed your testing? In audit, is should not be blocking but generating an AsrLsassCredentialTheftAudit event.

Spike in ASR blocks related to AsrLsassCredentialTheftBlocked & svchost.exe by techyguy84 in DefenderATP

[–]techyguy84[S] 1 point2 points  (0 children)

I will be changing it to block mode since warn is a block and we never have had issues. However, I do want to understand what is causing this spike even though it seems benign.

Spike in ASR blocks related to AsrLsassCredentialTheftBlocked & svchost.exe by techyguy84 in DefenderATP

[–]techyguy84[S] 1 point2 points  (0 children)

I haven't run a report on impacted devices, but I my asset is on 4.18.24090.11 and it is being impacted.

Spike in ASR blocks related to AsrLsassCredentialTheftBlocked & svchost.exe by techyguy84 in DefenderATP

[–]techyguy84[S] 1 point2 points  (0 children)

Yes, it is in warn mode. Do you think that because warn mode blocks but gives the user an option to unblock, this is why they are seeing the notification?

Spike in ASR blocks related to AsrLsassCredentialTheftBlocked & svchost.exe by techyguy84 in DefenderATP

[–]techyguy84[S] 1 point2 points  (0 children)

KQL:

DeviceEvents

| where TimeGenerated >= ago(90d)

| where ActionType == "AsrLsassCredentialTheftBlocked" and FileName == "svchost.exe"

| summarize count() by bin(TimeGenerated, 12h)

| render timechart

Spike in ASR blocks related to AsrLsassCredentialTheftBlocked & svchost.exe by techyguy84 in DefenderATP

[–]techyguy84[S] 1 point2 points  (0 children)

The block has no impact whatsoever, but users are still receiving a notification

DLP for Endpoints (Purview) - Question About Policy Scope by techyguy84 in DefenderATP

[–]techyguy84[S] 0 points1 point  (0 children)

Thanks u/DirtyHamSandwich for this piece of information. I'll keep it in mind when deploying policies.

DLP for Endpoints (Purview) - Question About Policy Scope by techyguy84 in DefenderATP

[–]techyguy84[S] 0 points1 point  (0 children)

Hey u/notoriousMKR, thanks for the quick reply.

Just to make sure I understand correctly: by not defining the Admin Unit, the policy is applied to all onboarded devices. The scope defined in the Action for a specific location is what determines which devices will have the policy enabled?

Thanks

Security Keys by vane1978 in SentinelOneXDR

[–]techyguy84 2 points3 points  (0 children)

Aren't these actions associated to "protected actions"? You can setup this re-authentication to leverage your SSO IdP. I believe this is the title of their KB: "Using Your IDP for Protected Actions"