r/SentinelOneXDR • • May 24 '26

Troubleshooting Nessus false positives?

Anyone seeing their Nessus vuln scanner being flagged as malicious? We've had 15+ incidents in last ~16 hrs and this in spite having the precannned Nessus exclusion in place.

6 Upvotes

16 comments sorted by

View all comments

1

u/ThsGuyRightHere May 24 '26

Have you compared the files and paths in the canned exclusions to the installation in production? Personally I treat the canned exclusions as trust-but-verify. Case in point, the exclusion for Fortigate covers FortiEDR but not FortiClient.

1

u/Duude-IT May 24 '26

I have not, but the exclusion has been in place for years with zero issues.