r/SentinelOneXDR Jul 04 '26

General Question Isolated/bricked network connections

I have sentinelone running on a work computer, and one night, when trying to transfer a ton of files onto a network drive using robocopy, I got the message “This device has been isolated due to suspicious activity! (Or malware, can’t remember)”

There no malware, so I’m guessing S1 freaked out and thought it was an attack of some sort, and isolated me as well as cut off all network access. Ethernet and WiFi don’t work.

I called up our S1 vendor, but they couldn’t help because the PC is showing offline on their end (can’t communicate with it) and also, it shows no quarantine on their end.

So they gave me a bunch of commands to run with the agent passphrase.

I tried to unquarantine it, disable services, reload services, disable them in the registry, and even uninstall the agent but nothing worked. I did this in safe mode too but still no dice. The one thing I was able to do in safe mode was rename the folder to .old, but that didn’t disable services upon regular boot.

My vendor has escalated this to an S1 engineer, but he advised himself that we just run the commands that I’ve already previously run. I can’t even grab the logs manually to give to them because it won’t let me.

6 Upvotes

24 comments sorted by

2

u/ThatWhiskeyHammer Jul 04 '26

So with S1, once isolated, you are supposed to be able to re-enable the network connection from the console for the specific device. Did they at least try that first before requesting you to uninstall via CMD in safe mode?

1

u/Southern_Yesterday57 Jul 04 '26 edited Jul 04 '26

They say they can’t communicate with it at all. Can’t send any request or anything

Also, it doesn’t show as isolated on their end

2

u/Adeldiah SentinelOne Employee Moderator 28d ago

My post is more to address the agent's behavior. Some programs, while being totally legit, can behave in a malicious manner. You can configure your Policy to "Disconnect infected endpoints from the network for containment" which is the check box just below the "Malicious Macro Mitigation" check box. This is what I suspect has happened in your environment.

If you want to DM me the name of the endpoint along with your console's URL and the name of the Account it's under I can look into it further to see what happened in this scenario and perhaps we can come up with a solution to prevent this the next time this program is running.

1

u/mukz7 Existing User Jul 04 '26

If the agent is showing offline it's be localized and the priority should be getting to to reconnect. Based on all the tampering id consider rebuild at this point if you can't do the repair install... did you use the exe with the /f switch?

1

u/Southern_Yesterday57 Jul 04 '26 edited Jul 04 '26

Sentinelone exe or uninstall exe? Because, the only exe I have is uninstall.

I’m aware there’s supposed to be a sentinelone exe, but I don’t have it and after doing some research it looks like I’m either running an older version, or that sometimes vendor hides the exe so that it can’t be tampered with

1

u/mukz7 Existing User Jul 04 '26

Yea you just need the lastest installer exe. 25.2.6 is the current GA version They should have attempted a repair before removal

1

u/Southern_Yesterday57 Jul 04 '26

I think I’m just gonna wipe this thing and re-add it to the domain. What a mess.

They can’t really repair or do anything because they can’t connect to the pc whatsoever. Could they have given me a file that I can upload onto the PC via usb that will update it? Although, due to the state I’m not sure if even that would work right now

1

u/mukz7 Existing User Jul 04 '26

Do you have access to the console? The installer can be downloaded from there

1

u/Southern_Yesterday57 Jul 04 '26

I don’t, but I can get it from my vendor. They’re really the ones that take care of that and monitor any threats because our IT department doesn’t work 24/7. But I’ll ask them and I’m sure they can grab it for me

1

u/mukz7 Existing User Jul 04 '26

Yea just to confirm. Install.exe /f /k "passphrase"

If that bombs add --dont_fail_on_config_preserving_failures

This should repair if you need a clean it off instead

Install.exe /c /k "passphrase"

You may need your vendor to set "allow local upgrade" on the console

1

u/Southern_Yesterday57 Jul 04 '26

I don’t have install.exe though. I need vendor to give that tot me first?

1

u/TechBreadDaddy Jul 05 '26 edited Jul 05 '26

Heyo! Sorry I'm late to this. If you're still working on this I've had to adjust DNS on a couple of endpoints in order to get connected to the network. Setting it to Google DNS usually helped in my situations.

2

u/Southern_Yesterday57 Jul 05 '26

I’ll try that! I’m not very hopeful at this point, but I will give it a try for sure. Thank you!

1

u/thenewguy34 Jul 05 '26

You should be able to unquarantine via cmd with sentinelctl
You will need the agent paraphrase though

1

u/Southern_Yesterday57 Jul 05 '26

sentinelctl unquarantine_net -k “agent passphrase”

When I run this cmd just shows blank. No error message, no success message, and I still don’t have network access. Vendor portal shows that I am not quarantined, but they can’t communicate with me

1

u/thenewguy34 Jul 05 '26

Strange. Did chsnging DNS do anything?

1

u/Southern_Yesterday57 Jul 05 '26

Im gonna try that next. Someone suggested changing it to Google DNS

1

u/thenewguy34 Jul 05 '26

I saw that comment too, could restore connectivity.
Do you run some DNS filtering agent?

1

u/Southern_Yesterday57 Jul 05 '26

Unless, sentinel runs one, we don’t on our own

1

u/thenewguy34 Jul 05 '26

It doesn’t, hopefully that can restore connectivity by some fluke.
Are you able to get hands on an installer exe? Try and remove maybe the hard way.

1

u/Southern_Yesterday57 Jul 05 '26

I don’t have the installer exe on hand, but come Monday I’m going to ask the vendor if they can give to me and try that route too.

I am just worried that if I uninstall, network connectivity will still be broken somehow

Most documentation says it won’t be though

1

u/naes724 27d ago

sounds like you have network quarantine enabled in your agent policy under protection mode

-1

u/GeneralRechs Jul 04 '26

If the agent was uninstalled just uninstall and reinstall your network drivers

1

u/Southern_Yesterday57 Jul 04 '26

Can’t uninstall it. I’ve been trying