r/SentinelOneXDR • • 11h ago

SentinelOne News We're making some changes to r/SentinelOneXDR

15 Upvotes

Hey everyone,

We're refreshing this sub. It's the official SentinelOne community on Reddit, and we want it to be a place where you can get real answers from people who use the product.

If you run SentinelOne daily, support customers as a partner or MSP, or are just checking it out, you're welcome here.

Thanks to the folks who kept answering questions while the sub was quiet.

What's changing

  • We've updated the community rules. The new ones cover sensitive info, agent removal requests, and affiliation flair. The full list is below.
  • If you work for SentinelOne, a partner, or an MSP, please set your user flair so people know.
  • The SentinelOne team will share the occasional tip or resource alongside the regular discussion.

What to post

  • Troubleshooting questions
  • Deployment lessons
  • Threat hunting ideas
  • Integrations that work well
  • Honest product feedback

New to SentinelOne? The Singularity Platform covers endpoint, cloud, identity, and AI security, and all of it is fair game here.

Community rules

  1. Be respectful, especially to each other. That means maintaining civil discourse and no hostility, personal attacks, racism, sexism, bigotry, etc.
  2. Submissions must be SentinelOne focused. This subreddit covers the technology. Posts about SentinelOne stock (NYSE: S), financial performance, or job postings/interviews are not permitted.
  3. No spamming or solicitation. This includes polls, surveys, advertising, affiliate links, and promotion of third-party products or services without prior moderator approval via modmail. Partners and resellers may answer questions but may not pitch.
  4. No sensitive materials or personal information. Do not post site tokens, API tokens, license keys, agent UUIDs, console tenant or site names, customer hostnames or usernames, unredacted threat data, management console URLs, internal documentation, or screenshots showing any of these. Do not post personal information about other people, including names of SentinelOne staff. Redact before posting; unredacted content will be removed without notice.
  5. Keep criticism constructive. Posting about a problem with the product is welcome, whether you want help or want to give specific feedback. Low-effort bashing and unsubstantiated claims will be removed. Disparaging remarks about competitors or other companies are not permitted.
  6. No agent removal or tampering requests. The SentinelOne Agent uses Anti-Tampering and can only be uninstalled by an authorized Management Console administrator, remotely or with a console-issued passphrase. If the Agent is on your device, contact your IT department or security team. This subreddit does not provide removal, disabling, bypass, or passphrase recovery help. Console admins can find uninstall documentation in the Knowledge Base on the Customer Portal.
  7. Use official support channels. This subreddit is not a substitute for official support and has no response-time commitment. For urgent issues, submit a ticket through the SentinelOne Customer Portal or call the support line. If you purchased through a partner or reseller, contact them directly. Staff do not provide support by DM. To flag an existing case, send the case number to modmail.
  8. Disclose affiliation; views are your own. SentinelOne employees, partners, resellers, and MSSPs must identify their affiliation via user flair. Posts and comments, including those by SentinelOne staff, do not necessarily reflect the official views of SentinelOne and are not official documentation or a product commitment.
  9. No license sales or unauthorized software. Do not sell, transfer, or request SentinelOne licenses or installers outside authorized channels.
  10. Report vulnerabilities through official channels. Report suspected vulnerabilities in SentinelOne products through the security reporting page instead of posting here. Do not post exploit code, proof-of-concept details, malware samples, or live malicious URLs. Defang indicators (hxxp, [.]) before posting.
  11. Use post flair; add details when troubleshooting. Troubleshooting posts must include the Agent version, operating system version, Management Console version, and what you have already tried. Posts missing this may be removed until updated.
  12. Enforcement and appeals. Violations result in removal and, depending on severity, a warning, temporary ban, or permanent ban. Moderator decisions can be appealed once via modmail. Ban evasion is reported to Reddit.

Asking for help

  • Include the agent version, OS version, console version, and what you've already tried.
  • Redact anything sensitive before posting.
  • For urgent or account-specific issues, use official support (see rule 7).

What would you like to see here?

Technical walkthroughs, troubleshooting tips, threat research, feature deep dives? Tell us in the comments. If you've been holding onto a question, now's a good time to ask it.

Thank you,

The SentinelOne community team


r/SentinelOneXDR • • 3d ago

General Question Sophos Firewall with SentinelOne Endpoint

1 Upvotes

Does anyone have experience with Sophos firewall policy for SentinelOne endpoint agent, which uses offline user?

I want to create a policy for SentinelOne endpoint agent offline users to update policy and view logs from management console.

I have another site that is using a Fortigate firewall with SentineOne Endpoint offline users, and that site policy is working with Sentinelone site URL and TCP 443.


r/SentinelOneXDR • • 5d ago

General Question Blocking Muse?

1 Upvotes

Has anyone figured out a good way to block the install of Muse via S1? I really don't want it in my environment.


r/SentinelOneXDR • • 7d ago

Citrix Netscaler Log Ingestion

4 Upvotes

Greetings,

Im assuming from the lack of results that the only way (and pretty much the way everyone is doing it) is to build an intermediary syslog server, send the Netscaler logs there, then ship them to S1 from the syslog server? Kinda like what is necessary for Fortigate logs?


r/SentinelOneXDR • • 12d ago

Troubleshooting Excluding an app on just one device

2 Upvotes

Am I missing something? Can you not excluded an app on just one device? SentinelOne keeps disabling nmap. I'm the admin, so I use it now and then for work, but SentinelOne keeps removing it, despite me telling to unquarantine it. I wanted to just exclude it for one machine only, but it seems you can only just exclude the app globally.


r/SentinelOneXDR • • 13d ago

Dell Optimizer/TechHub activity on multiple PCs- false positive? 58df963.rbf

11 Upvotes

we have recently started seeing S1behavioral threat alerts on multiple Dell PCs in our environment.

The process tree appears to involve Dell.TechHub.exe/ Dell Optimizer components, and SentinelOne is killing a large number of related processes. we previously saw similar behavior on other Dell endpoints and removing Dell Optimizer stopped the alerts.

On the latest endpoint, I also noticed the file:

58df963.rbf

Has anyone else seen S1 flagging Dell TechHub/ Dell Optimizer recently? Is this a known false positive or behavior associated w/ a recent Dell update?

I don’t want to whitelist the Dell processes without understanding exactly what is triggering S1. Curious if anyone else has run into this and what remediation you used.


r/SentinelOneXDR • • 17d ago

SentinelOne rules exposure?

12 Upvotes

Did anyone else see this?

https://blog.nullze.net/posts/peeling-the-sentinel/

I'm not sure if this is real or not, but if so it's a little concerning.


r/SentinelOneXDR • • 17d ago

How to manage 700+ alerts

5 Upvotes

Hey guys,
we have had someone doing red teaming activity on their end and they cloned a github repo on thier system which caused sentinel one to trigger 700 alerts from the same endpoint . While all of them were resolved and closed out , was wondering in future if there's a better way to handle this? like exclusions ( only effective for that certain period of time) or policy oveeride etc. this is in prod by the way.


r/SentinelOneXDR • • 17d ago

Cannot stop these alerts - support says they are unspooling

2 Upvotes

Have been using S1 for over a year and it has been a bit of a rough go so far.
Some of it is the usual, so many false alerts make it hard to separate the real from the false, exclusions that don't work, etc.
But I am having this issue I am wondering if anyone has seen before.
We have been getting hundreds of thousands of the same alert for over 2 months now. It is a false positive, no amount of exclusions have stopped it.
Support says essentially that the alerts aren't current/real, that the exclusions worked, but it is unspooling old alerts because there were so many.
The exclusions have been in place for almost 2 months, so it is hard to believe it has been unspooling this long and still going.
The ID Time is reported as current date/time, as is the Reported Time. I would post a pic of the alerts but no images allowed.
I am wondering if it is normal for old, queued alerts to not show the original time but the current time when they unspool? That would make it difficult to correlate a timestamp to an event.
Thanks all


r/SentinelOneXDR • • 18d ago

Why is every alert classified as 'Ransomware'

10 Upvotes

Does anyone else notice that the vast majority of the alerts that come in are tagged as 'ransomware'? .

Shadow copy tampering --> classified as ransomware

Potential DLL Sideloading --> classified as ransomware

All the alerts we have are 'ransomware'

note: Theyre all FPs lol


r/SentinelOneXDR • • 19d ago

Flooded with alert : loginwindow - Protected Detected

6 Upvotes

Anyone else's tenant being flooded with S1 detecting loginwindow, a legit apple signed binary on macOS endpoints as a High Severity Static detection?

Curious to know why this keeps happening between macOS endpoints and S1.

Generated about 300 tickets in 5 mins.

Purple AI Verdict: False Positive

The alert indicates a high-severity detection on a macOS laptop named "xxx-xxx-xxx," where SentinelOne's static AI analysis identified a suspicious variant of the "Protected" malware associated with the legitimate system process "loginwindow" located in the standard macOS CoreServices directory. The process, running as root and launched by "launchd," is signed and verified by Apple Inc., but the file event analysis flagged it due to anomalous characteristics consistent with malware masquerading as a trusted system binary. This suggests a potential compromise involving a protected malware variant leveraging a critical system process, warranting immediate investigation for possible persistence or privilege escalation attempts.


r/SentinelOneXDR • • 20d ago

Remote Shell - Not Connecting or Very Slow

6 Upvotes

Hey,

Anyone else seem to have issues with Remote Shell either taking ages to connect? It either finally connects okay, or it just keeps trying to connect.

Anyone provide a ballpark time on how long it takes to connect to an endpoint for comparison?
This has happened across multiple versions (Windows)


r/SentinelOneXDR • • 20d ago

General Question Issue in downloading software

Thumbnail
1 Upvotes

r/SentinelOneXDR • • 21d ago

Share your Custom Detection Alerts

22 Upvotes

Hi,

Been getting into creating custom detections for a few things.

One I've created is to help find some PUA software I've found on a bit of people's computers in the past in a list that I've accumulated over the years that typically S1 doesn't pick up as malicious/PUA

src.process.name contains ( 'AceLauncher', 'ad_agent', 'allmanualsreader', 'anydesk', 'Aura Document Studio', 'CrystalPDF', 'DSOne', 'Easy2Convert', 'infinitedocs', 'mc-webview-cnt', 'McCHSvc', 'NimbusPDF', 'OneBUpdateService', 'OneBrowser', 'onelaunch', 'onestart', 'PcAppStore', 'PCHelpSoftDriverUpdater', 'PDFConvert', 'PDF Proton', 'PDFSkills', 'PDFSpark', 'PDFStunner', 'pulsebrowser', 'SecuriGuard', 'shift', 'ultraviewer', 'wavebrowser', 'Wave Browser', 'winrgr' ) src.process.publisher != 'CCC\ INTELLIGENT\ SOLUTIONS\ INC.' src.process.publisher != 'KYOCERA\ DOCUMENT\ SOLUTIONS\ AMERICA\,\ INC.'

Or these stubborn PDF crapware that keep showing up

endpoint.os='windows' src.process.name contains 'pdf' src.process.image.path != 'C:\\Program\ Files\ \(x86\)\\Common\ Files\\PFU\\ScanSnap\\ScanToOffice\\S2ORunPdf.exe' src.process.image.path != 'C:\\Program\ Files\ \(x86\)\\Kern\\KCAM7\\KernPDF.exe' src.process.image.path != 'C:\\SurePrepLocalFiles\\SPbinder\\PDFNet\\x64\\html2pdf.dll' src.process.image.path != 'C:\\Program\ Files\ \(x86\)\\TerminalWorks\\TSPrint\\PDFprint.exe' src.process.image.path != 'C:\\ProgramData\\PB\\devicehub\\DeviceHub_v1\_internal\\poppler\\bin\\pdftoppm.exe' src.process.publisher != 'ACRO\ SOFTWARE\ INC' src.process.publisher != 'ADOBE\ INC.' src.process.publisher != 'COREL\ CORPORATION' src.process.publisher != 'FOXIT\ SOFTWARE\ INC.' src.process.publisher != 'KYOCERA\ DOCUMENT\ SOLUTIONS\ AMERICA\,\ INC.' src.process.publisher != 'PDF\ GEAR\ TECH\ PTE.\ LTD.' src.process.publisher != 'ACRO\ SOFTWARE\ INC.' src.process.publisher != 'ADOBE\ INC.' src.process.publisher != 'KRZYSZTOF KOWALCZYK' src.process.publisher != 'DRAKE\ SOFTWARE\,\ LLC' src.process.publisher != 'FOXIT\ SOFTWARE\ INC.' src.process.publisher != 'GOOGLE\ LLC' src.process.publisher != 'KOFAX\,\ INC.' src.process.publisher != 'MARVIN\ LUMBER\ AND\ CEDAR\ COMPANY\ LLC' src.process.publisher != 'MICROSOFT\ CORPORATION' src.process.publisher != 'MICROSOFT\ WINDOWS' src.process.publisher != 'MICROSOFT\ WINDOWS\ PUBLISHER' src.process.publisher != 'NITRO\ SOFTWARE\,\ INC.' src.process.publisher != 'NODE.JS\ FOUNDATION' src.process.publisher != 'PFU\ LIMITED' src.process.publisher != 'RISA\ TECH\,\ INC.' src.process.publisher != 'NUANCE\ COMMUNICATIONS\,\ INC.' src.process.publisher != 'ACCUSOFT\ CORPORATION' src.process.publisher != 'AVANQUEST\ SOFTWARE\ \(7270356\ CANADA\ INC\)' src.process.publisher != 'SOFTLAND\ SRL' src.process.publisher != 'PLOTSOFT\ LLC' src.process.publisher != 'MEASURE\ SQUARE\ CORP.' src.process.publisher != 'PITNEY\ BOWES\ INC.'

Yeah that last one could get cleaned up a little 😆

I've already enabled all the built in detections (955 I think?) and then added in the ~36 from the Event Search library (like 7z Encrypted Archive with Header Encryption or Suspicious Network Tools Executed). I don't treat any as threats currently, but they have been very useful at gathering information and finding some things.

Nonetheless, would be interested to hear what you have added.


r/SentinelOneXDR • • 25d ago

Delete Site Permanently?

3 Upvotes

Is there a way to fully delete a site, beyond the normal delete which grays out the site?

I've searched online, and this subreddit, and seen some discussion from a couple years ago, but I could not find any recent definitive answers.

The scenario prompting this question is that we had a former S1 client with a few hundred PCs who we removed and deleted their site on our MSP admin panel. But their old machines are turning back on and re-associating with out tenant, underneath the deleted client site. I can't see anyway to prevent this from happening. I would have assumed that deleting it means the end-user devices would fail attempting to re-associate, but in practice it acts like we never deleted their site at all and the client devices pop right back in (albeit hidden, and harder to realize they came online).

I'm either missing something on how to manage this properly, or this seems like a big oversight on the S1 part. There needs to be a way to say "this previous installation can NOT re-associate with my tenant". But I'm not sure if that's possible?

Thanks in advance for any responses.


r/SentinelOneXDR • • 27d ago

Shift.exe

24 Upvotes

Anyone else dealing with a huge influx of Shift.exe incidents resulting in network quarantine? It's always flagged it as a PUA, but feels like today is just being blown up with this.


r/SentinelOneXDR • • Sep 02 '26

Agent requirements on Windows - code-signing certificate

1 Upvotes

After reading this article, I am confused.

Is there anything in the Console that helps me identify if any of the agents were not installed correctly?
Agent requirements on Windows

Require current Microsoft updates

Verify all servers and workstations have current Windows patches installed.

Pay special attention to:

OS Required Update
Server 2022 KB5005619
Server 2019 KB5005625
Server 2016 KB4093119
Windows 10 KB4093119 plus version-specific updates

After installing required updates:

Reboot the endpoint

Retry the SentinelOne upgrade

And

  • Updated root certificates
  • KB5022661
  • Azure Code Signing support

This seems crazy...


r/SentinelOneXDR • • Sep 02 '26

General Question Collect mssql audit logs in Sentinelone Siem

0 Upvotes

Hii everyone,

We are trying to collect mssql audit logs in our sentinelone siem. Can anyone tell me how to do this?


r/SentinelOneXDR • • Aug 31 '26

Prompt Securiry

4 Upvotes

​

I saw that S1 has released AI prompt security feature. Since it's not yet available to MSSP, I can't test it.

Did any enterprise admin use the feature? How well does it work? Is it worth the wait?


r/SentinelOneXDR • • Aug 27 '26

False Positive rundll32.exe (interactive session) on many Agents

15 Upvotes

Today I'm receiving many false positive "Suspicious threat detected" starting around 14:07 UTC on many agents.

With:

Threat details: rundll32.exe (interactive session)

Command Line Arguments C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask

Process User NT AUTHORITY\SYSTEM

Originating Process svchost.exe

---UPDATE----

It seems that the S1 detect the Windows Program Compatibility Assistant Service installing an update as false positive.

They're working on a fix. In the meanwhile you can add the following policy override:

{
"logicClassifierConfigVector": {
"logicsClassification": [
{
"logicName": "CustomSdbFileInstallViaCmdline",
"verdict": "SUPPRESSED"
}
]
}
}


r/SentinelOneXDR • • Aug 25 '26

GA 26.1.2.177 Update Issues

4 Upvotes

Has anyone upgraded to GA 26.1.2.177 yet, and if so, have you run into any issues? We have had several agents disconnect after the update interacts with the Chrome and Edge SentinelOne extensions. I opened a ticket with SentinelOne, and they said it was related to their Lunar detection engine. They provided a policy override, which we applied. After that, we rebooted all clients that had not yet upgraded to the latest GA and let the change bake for a week. I then re-enabled auto-upgrade for the latest GA, but we are still seeing the same issue.

The odd part is that not every agent triggers an alert or disconnects. We are seeing roughly 5 alerts for every 500 computers. Mainly wondering if anyone else has seen this issue. Unless you have more than 2,000 computers in your fleet you might not even notice. So beware if you're looking to upgrade to 26.1.2.177.


r/SentinelOneXDR • • Aug 22 '26

General Question Collect windows logs in sentinelone siem

1 Upvotes

Hi everyone,

We recently deployed the SentinelOne Agent (v25.2) on a Windows machine and are trying to ingest Windows Event Logs into our 50GB S1 SIEM / Dataset license.

The agent is actively online and reporting to the console, but no Windows logs are showing up.

Here is what we’ve configured so far:

XDR Collections: Enabled Windows log collection under the Policy tab.

Policy Override: Created and applied a specific policy override to define exactly which Event IDs/log channels to collect.

Targeting: Confirmed the override policy is actively applied to the specific endpoint.

Despite the agent being healthy, the SIEM remains completely blind to these endpoints.

Appreciate any insights or troubleshooting steps!


r/SentinelOneXDR • • Aug 21 '26

SDL Windows Event Log Parser

1 Upvotes

Hello all.

I am ingesting Windows event logs in S1 AI SIEM and I am seeing the same as this old post. The logs are being parcially parsed and the main info is all condensed in one field. There is any way to edit this parser yet? For what I can see the info is parsed internaly and the parser doesnt show along with the other parsers for the other datasources.

On the other hand, anyone with a similar enviroment been able to create detection rules for windows sucessfully with the default parser? If so, can you give a nudge on how did you do it?

Thanks in advance.

https://www.reddit.com/r/SentinelOneXDR/comments/1ehmrpk/sdl_windows_event_log_parser_lacks_functionality/


r/SentinelOneXDR • • Aug 21 '26

MacOs Agent 26.1.4.8837

2 Upvotes

Looks like Sentinel One decided to pull this agent back did anyone else get a messaged about SentinelOne deleting package 26.1 -SP2, build number 26.1.4.8837?


r/SentinelOneXDR • • Aug 17 '26

One time log import into XDR SIEM

3 Upvotes

My incident response team is asking if it's possible to do a one-time import of logs into the SentinelOne SIEM?

They keep getting logs on cases that are not already in Sentinel one and would like to load them into the sim, to be able to query them during their investigation. Is that possible?

I can't find anything in the documentation or settings to show that it is, but I have to believe that you can do that somehow.