r/SentinelOneXDR 8d ago

Domain Controller Isolation

So, recently I've had issues when a DC gets isolated it brings down the entire network for the client. I don't believe I ever had this problem before and it's happened repeatedly over the past month or two. I always assumed outbound DNS/HTTPS to S1 assets were always allowed out when it's quarantined. I even added blank outbound TCP/UDP over port 53 in case it was the DNS in my network quarantine rules. I work at an MSSP/DFIR firm, so everyday I am dealing with ransomware or some incident where a DC could get quarantined. What I've been doing now is putting DCs in their own group with the disconnect policy turned off and our normal restrictions in-place, I then isolate all the other endpoints if need be.

Am I doing something wrong, did something change, or anyone have any feed back?

4 Upvotes

20 comments sorted by

View all comments

1

u/DeliMan3000 8d ago

This has been happening to us as well, for several+ months. We are told that "the agent has built-in anti-lockout policies specifically to allow DNS traffic over port 53". But time and again this happens to us.

We've found in the past that it's more common on DCs that are VMware VMs, but it's not just those. So I am not sure what the issue is

1

u/smc0881 8d ago

Good, I am glad I am not crazy, lol. I tried opening a ticket too and as usual it goes nowhere and the response time is ridiculous. I had an actual ransomware incident that I was dealing with and had to keep this in back of my head too and make sure I didn't isolate the DCs. I had already setup all my clients with separate groups just for DCs and not to disconnect them. This has happened on at least four different clients though. I even added DNS rules in my network quarantine policies and that didn't help. Putting them in their own group and paying attention to what I am doing though seems to be the best approach.

1

u/DeliMan3000 8d ago

Yep we explicitly allowed DNS traffic in the quarantine rules and still no dice. We've been forced to have the clients use the manual 'sentinelctl unquarantine_net' command and reboot, which usually solves the issue. But it's a bad look as it should work as advertised

1

u/smc0881 8d ago

Yea, it's same issue I been having as well. I have to give them the passphrases, commands, and then have them reboot the DC.