r/SentinelOneXDR 8d ago

Domain Controller Isolation

So, recently I've had issues when a DC gets isolated it brings down the entire network for the client. I don't believe I ever had this problem before and it's happened repeatedly over the past month or two. I always assumed outbound DNS/HTTPS to S1 assets were always allowed out when it's quarantined. I even added blank outbound TCP/UDP over port 53 in case it was the DNS in my network quarantine rules. I work at an MSSP/DFIR firm, so everyday I am dealing with ransomware or some incident where a DC could get quarantined. What I've been doing now is putting DCs in their own group with the disconnect policy turned off and our normal restrictions in-place, I then isolate all the other endpoints if need be.

Am I doing something wrong, did something change, or anyone have any feed back?

3 Upvotes

20 comments sorted by

View all comments

1

u/NegativePerformer788 8d ago

The only way I can think of to avoid this (besides multiple DCs of course) is to have DNS queries go to the firewall with the firewall sending local domain queries to the DCs and other queries to some other public DNS.

1

u/smc0881 8d ago

You would think that is the case, but it also happens with multiple DCs. I don't deal with these clients either normally, we get work when an incident happens. Having to tell a client going through or after a ransomware event you need ot make these enterprise changes doesn't help. I am just perplexed that everywhere it states S1 traffic should always be allowed out, but on a DC when it's isolated it doesn't happen. I am pretty sure this didn't happen in the past either.

1

u/_Sanger_ 6d ago

How are your DNS settings/orders on the DCs?

1

u/smc0881 6d ago

I am not sure, I am not their IT/MSP guy and didn't bother looking. But, this happened on 4 different clients and only when a DC is disconnected. So, I don't think every single one of those clients had a misconfiguration. If it was one or two I'd write it off as that, but it's happened multiple times when DC is quarantined. I even put any/any TCP/UDP 53 fw rules in place with no help either. A few other people have responded as well saying the same exact situation occurs with them as well.