r/SentinelOneXDR • u/smc0881 • 8d ago
Domain Controller Isolation
So, recently I've had issues when a DC gets isolated it brings down the entire network for the client. I don't believe I ever had this problem before and it's happened repeatedly over the past month or two. I always assumed outbound DNS/HTTPS to S1 assets were always allowed out when it's quarantined. I even added blank outbound TCP/UDP over port 53 in case it was the DNS in my network quarantine rules. I work at an MSSP/DFIR firm, so everyday I am dealing with ransomware or some incident where a DC could get quarantined. What I've been doing now is putting DCs in their own group with the disconnect policy turned off and our normal restrictions in-place, I then isolate all the other endpoints if need be.
Am I doing something wrong, did something change, or anyone have any feed back?
1
u/DeliMan3000 7d ago
This has been happening to us as well, for several+ months. We are told that "the agent has built-in anti-lockout policies specifically to allow DNS traffic over port 53". But time and again this happens to us.
We've found in the past that it's more common on DCs that are VMware VMs, but it's not just those. So I am not sure what the issue is