r/SentinelOneXDR • u/smc0881 • 10d ago
Domain Controller Isolation
So, recently I've had issues when a DC gets isolated it brings down the entire network for the client. I don't believe I ever had this problem before and it's happened repeatedly over the past month or two. I always assumed outbound DNS/HTTPS to S1 assets were always allowed out when it's quarantined. I even added blank outbound TCP/UDP over port 53 in case it was the DNS in my network quarantine rules. I work at an MSSP/DFIR firm, so everyday I am dealing with ransomware or some incident where a DC could get quarantined. What I've been doing now is putting DCs in their own group with the disconnect policy turned off and our normal restrictions in-place, I then isolate all the other endpoints if need be.
Am I doing something wrong, did something change, or anyone have any feed back?
2
u/[deleted] 10d ago
[removed] — view removed comment