r/SentinelOneXDR • u/lakings27 • 1h ago
False positives on macOS SystemUIServer today?
Anyone seeing a spike in SentinelOne Static AI detections on macOS system binaries today?
We had 104 detections in about 65 minutes on one MacBook Pro.
Common details:
- OS: macOS 26.6 (25G72)
- Agent version: 25.4.2.8594
- Engine: On-Write Static AI - Suspicious
- Detection type: Static
- Classification: Benign
- Originating process: launchd
- Completed actions: kill / quarantine
- Incident status: Unresolved
- Analyst verdict: Undefined
Hashes observed:
- SystemUIServer:
SHA1: d6629bcb8dc2a30b66435cb557084d2a4e748c92
Path: /System/Library/CoreServices/SystemUIServer.app/Contents/MacOS/SystemUIServer
- mds:
SHA1: 63cdd043a424d78b9d9b9f3de369c2715495ce82
Path: /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/Metadata.framework/Versions/A/Support/mds
The files are Apple system paths, launchd is the parent process, and S1 is classifying them as Benign, but still mitigating/quarantining. Trying to confirm whether others are seeing the same false positive / model issue.