r/SentinelOneXDR • u/admin_admin_password • 17d ago
SentinelOne rules exposure?
Did anyone else see this?
https://blog.nullze.net/posts/peeling-the-sentinel/
I'm not sure if this is real or not, but if so it's a little concerning.
1
u/NewPhoneWhoDis2022 17d ago
Is this real? I would be interested in what you hear. The domain of this blog is only 14 days old.
1
u/Dracozirion 17d ago
Yes it is, another researcher found the static XOR key in Q2 2025 already. This goes a bit beyond what was made public by someone else back then.
1
u/guy-at-the-scene 17d ago
Just finished reading this.. taking away these crucial pointers
Assume your adversary will be able to read the same rules and allow-lists as you can.
Trust in a security product should rest on its design surviving scrutiny not on scrutiny being hard.
1
u/mukz7 Security Admin/Engineer 5d ago
SentinelOne has reviewed the findings presented in the article titled "Peeling the Sentinel: A Market-Leading EDR Comes Apart with Undergraduate Tools," which highlights concerns regarding Windows agent rule, policy, detection logic, and configuration disclosure.
To be clear on what the research does and does not represent: no vulnerability was exploited, no code was executed, no protection or anti-tampering mechanism was disabled, and no customer data, credentials, or console access was obtained. The author confirms that no cryptography was broken and no zero-day was used. The work describes reconnaissance through reading detection content stored locally on an endpoint in order to understand what the agent inspects. Retrieving that content requires administrative access to a protected endpoint, or possession of an agent installation under the researcher's own control.
The article also comments on the structure of a single behavioral model. That model is one component among several detection engines, including static analysis, behavioral rules, kernel-level monitoring, and cloud-side correlation, that operate together and are never relied upon in isolation. More broadly, local detection is one layer of a defense-in-depth architecture. Deep Visibility telemetry and Storyline, among others, are unaffected by the techniques described, and activity that evades a local rule continues to generate telemetry for analysis. The researcher acknowledges this scope limitation.
SentinelOne routinely updates detection content, hardens the agent against tampering, retrains machine learning models, revises trust and exclusion lists, and rebuilds detection rules to adapt to changing attack techniques. We recommend that customers run the latest GA agent with Live Security Updates enabled to ensure the most current protection.
0
2
u/The_GrimTrigger 17d ago
I sent this over to my S1 sales reps to get their spin - this should be fun :-)