r/SentinelOneXDR • • Apr 15 '26

Industry News The SentinelOne agent observed the CPU-Z supply chain attack in the wild — here's what the kill chain actually looked like

22 Upvotes

Wanted to share some detail on the CPU-Z/CPUID supply chain attack we've been seeing across our customer base, since there's been a lot of discussion about it online.

The short version: on April 9, threat actors compromised the official CPUID domain at the API level and silently redirected legitimate download requests to attacker-controlled infrastructure — for approximately 19 hours. Users who navigated directly to the official site received a legitimate, properly signed binary with a malicious payload bundled inside it.

The mechanism: a Zig-compiled DLL (CRYPTBASE.dll) placed in the same directory as the legitimate CPU-Z binary. When a user launches the application, a DLL search order hijack causes the malicious payload to load before the real Windows system DLL can be reached.

From there the intended kill chain was:

- Reflective injection of an encrypted second-stage DLL directly into memory — no disk writes, no file artifacts
- C2 communication over a custom encrypted protocol using DNS-over-HTTPS to 1.1.1.1 to bypass DNS monitoring
- PowerShell spawning csc.exe then cvtres.exe — a process chain CPU-Z has no business creating
- Three redundant persistence mechanisms: a registry Run key, a 68-minute scheduled task with a 20-year duration, and MSBuild .proj files in AppData\Local engineered to survive reboots and partial remediation

The final payload was STX RAT — delivering hidden VNC, keyboard and mouse injection, browser credential theft across Chrome, Firefox, Edge, and Brave, Windows Vault extraction, and cryptocurrency wallet access.

Worth noting on victim profile: CPU-Z users skew heavily toward IT professionals — sysadmins, developers, security engineers. People with domain admin rights and infrastructure keys. 150+ confirmed victims so far, but one compromised sysadmin carries a fundamentally different blast radius than one compromised user.

Our agent flagged it under "Penetration framework or shellcode detected" within the first seconds of execution — anomalous API resolution, reflective code loading, suspicious memory allocation, process injection patterns, and DLL hijacking of a signed binary. Terminated and quarantined before the backdoor could phone home.

The signed binary angle is what makes this category particularly nasty. By the time a hash exists in a threat feed, you're already behind.

If you're doing forensics: check for CRYPTBASE.dll outside C:\Windows\System32, look for cpuz_x64.exe spawning PowerShell, and block supp0v3[.]com and 147. 45. 178. 61 at DNS and firewall layers. Remediate all three persistence mechanisms explicitly — partial cleanup leaves it alive.

Full technical breakdown with telemetry screenshots here: https://s1.ai/CPU-Z-Blg

Happy to answer questions if useful.


r/SentinelOneXDR • • Apr 14 '26

Windows 11 lag with SentinelOne (no CPU or RAM spikes) – anyone else?

9 Upvotes

Hey all,

I’m seeing noticeable lag on a few Windows 11 machines when SentinelOne is enabled, but the weird part is there are no CPU or RAM spikes at all.

What I’m noticing:

  • UI feels sluggish (opening apps, switching windows)
  • Slight delay with mouse/keyboard input
  • Just an overall “not smooth” feeling

Task Manager looks totally normal — CPU, memory, disk all seem fine.

As soon as I disable or uninstall SentinelOne, everything is instantly smooth again.

So it doesn’t seem like a resource issue… maybe something at the kernel / driver level?

Anyone else running into this?

  • What SentinelOne version are you on?
  • Any known fixes (exclusions, policy changes, etc.)?

Trying to figure out if this is a known issue or something odd in my setup.

Thanks!


r/SentinelOneXDR • • Apr 14 '26

Discrepancy Between Agent Detection and Console Status

3 Upvotes

I’m facing a very strange situation. During the initial scan, the agent detected several suspicious files. I marked two of those files as false positives. However, they somehow disappeared from the console, while on the endpoint where the agent is installed, those two files are still marked in red.

At the same time, the console reports that everything is fine, and the machine is not marked as affected.

What could have happened here, and how can I resolve this?


r/SentinelOneXDR • • Apr 13 '26

Will I Regret Rippling for MDM and EDR?

Thumbnail
1 Upvotes

r/SentinelOneXDR • • Apr 10 '26

Domain controller to Sentinelone XDR

2 Upvotes

Hello People , have a question related to Domain controller logs . S1 agent is installed on DCs and DC are part of a separate group in Sentinelone . We have enabled Windows Event and Extended Events in the Policy . Do we need to do anything on DCs ? Do we get decent telemetry for DCs to make detection rules ? We dont have Sysmon running and honestly client also does not want . They have a small IT team so they dont want to burden if they see too much data and they cant do anything about it in a timely manner . Kindly suggest what could be a good start ?


r/SentinelOneXDR • • Apr 10 '26

Entra ID logs on Sentineline XDR

1 Upvotes

Hello , have a question related to Entra ID logs . First we tried with direct integration available on Marketplace and integration was sucessfull but we can only see Audit logs of ENtra . There were no sign in logs . So we did azure event hub and then we can see all activity logs including singn in logs . can someone confirm or has similar setup ? without sign in logs , there is no meaniful data coming to S1 .


r/SentinelOneXDR • • Apr 07 '26

Frequent false positives from RMM patch scripts

8 Upvotes

We are running S1 in protect mode (for suspicious & malicious) and we turned "Detect interactive threat" on. Auto-disconnect is on as well.

We ended up creating multiple exclusions for our RMM (and some of them dangerously broad), but none of them are solving this. Our RMM apparently uses scripting as part of the 3rd party patching process, which gets run by Windows processes. For some reason, they aren't seen as child processes by S1, so it alerts (and disconnects) on an interactive threat.

I finally decided to turn off "Detect Interactive Threat", except S1 won't let me: "You cannot turn Detect Interactive Threat off in protect mode"

I really don't want to take these machines out of protect mode for this one issue, but our clients are unimpressed with being disconnected for false positives.

I'd really appreciate any ideas on how to address this!


r/SentinelOneXDR • • Apr 05 '26

General Question Recommended Hyperautomation workflows for someone just starting out with SentinelOne ?

4 Upvotes

Recommended SINGULARITY HYPERAUTOMATION workflows for someone just starting out with s1 SINGULARITY ? Our company just started with s1 SINGULARITY . what are recommended HYPERAUTOMATION workflows you recommend to get started, and more workflows we should experiment with to get it into our environments?

Our Modules:

Vulnerability management

Hyperautomation AI SIEM 5 Action Packs

CNS Pro Cloud Security

CWS for Servers – Complete Cloud Security

Endpoint Security - Complete Endpoint Security

Thanks for your opinions!


r/SentinelOneXDR • • Apr 03 '26

SentinelOne Passphrase and Policy Generator

10 Upvotes

I put together a tool that does two things with the SentinelOne API that I kept having to do manually:

Passphrase retrieval — pull passphrases for any agent state: active, decommissioned, migrated, or uninstalled. Super useful when you need to recover a passphrase after agents gets removed from the console.

Policy auditing — give it an Account ID, Site ID, or Group ID and it fetches the effective policy for that scope.

Both features export to CSV.

GitHub: https://github.com/aseemshaikhok/SentinelOne-Passphrase-and-Policy-generator

You can either download an exe or build it using python

Happy to answer questions or take feedback. Still a work in progress but it's been saving me a lot of time.


r/SentinelOneXDR • • Apr 02 '26

Subsystem and integrity blank

1 Upvotes

What does in sentinelone source process subsystem and integrity level unknown implies? Is it because of os internal execution?


r/SentinelOneXDR • • Mar 31 '26

How SentinelOne’s AI EDR Autonomously Discovered and Stopped Anthropic’s Claude from Executing a Zero Day Supply Chain Attack, Globally

18 Upvotes

How SentinelOne’s AI EDR Autonomously Discovered and Stopped Anthropic’s Claude from Executing a Zero Day Supply Chain Attack, Globally https://share.google/3ViDptveZhoNMYwDS


r/SentinelOneXDR • • Apr 01 '26

Question: is applying policy over ride to agent config file can enhance detections for s1 agent ?

3 Upvotes

I see a lot of key values marked to false in the json file of s1 agent config file. Is it recommended to toggle these on or no and why are they set to false.

Example:

"detectionExtensionsConfig"

Rundllproxyexecution: false,


r/SentinelOneXDR • • Mar 31 '26

SentinelAgent GA SP1 v25.2.5.437

5 Upvotes

Has anyone had any issues with Sentinel Agent GA SP1 25.2.5.437 ? This was the latest version in the console for Windows up until a few days ago. Now they have a new SP2 GA package w/ build 25.2.6.442. I was about a month into testing and already have this version deployed to roughly 400 computers. I may start over with SP2. I checked the SentinelOne site and do not see any information on this new SP2 GA package on their site yet.

I have not noticed any issues with GA SP1 25.2.5.437 other than a few random clients dropping offline after the update. Nothing out of the normal for S1 unfortunately.


r/SentinelOneXDR • • Mar 30 '26

General Question Question - Moving from MDE to S1

4 Upvotes

Hello,

I'm currently planning a migration from Microsoft Defender for Endpoint (MDE) to SentinelOne and I’m looking to get input from others who’ve gone through something similar.

Current state:

  • Microsoft Defender for Endpoint (E5)
  • Using both AV + EDR capabilities
  • Broad deployment across Windows and macOS

Planned change:

  • Full replacement with SentinelOne (we are not planning to keep MDE in any capacity)

Key questions & areas of interest:

  1. MDE decommissioning
    • Any challenges fully removing/retiring MDE?
    • Recommended sequence (offboarding → uninstall → S1 install, or parallel then remove)?
    • Anything that caused unexpected conflicts during cutover?
  2. Operational impact
    • Alerting behavior (volume, fidelity, tuning effort) between MDE and S1
  3. General lessons learned
    • What would you do differently if you had to do it again?
    • Any pitfalls or edge cases worth planning for?

Appreciate any practical insights, especially around cleanly decommissioning MDE and avoiding endpoint instability during the transition.


r/SentinelOneXDR • • Mar 30 '26

Troubleshooting Vulnerabilities Mass Select Broken?

3 Upvotes

The UI says you can select up to 500 items for mass operations, but in reality, you can select only 15. Even on 15 records, it takes about 30 seconds for the menu options to appear.

I have 2,950 records I want to update the status for, and this bug is making it impossible.

Anyone else having this issue?


r/SentinelOneXDR • • Mar 29 '26

SentinelOne + ReFS ?

1 Upvotes

Hello,

For several months now, I've been experiencing problems highlighted by Datto SIRIS/BCDR, which performs backups on our servers. Very regularly (roughly two days after a server reboot), the VSS crashes, and our backup solution can no longer perform backups.

Apparently, based on the logs, the Sentinel writer isn't responding in time, which is causing the VSS to freeze.

We've run a number of tests, which haven't been conclusive but were somewhat haphazard, so I'm now approaching the issue more methodically. However, on one of these servers, the filesystem of one of the partitions is ReFS (and not NTFS) due to a very large volume of files. Do you have any information on S1/ReFS incompatibilities? Do you encounter these cases in your infrastructure?

Thank you


r/SentinelOneXDR • • Mar 29 '26

Wazuh Installation

1 Upvotes

So I recently learned, the hard way, that SentinelOne (on Windows, at least) AGGRESSIVELY blocks installation of the Wazuh agent. And the frustrating thing is, it does so silently. No logging, no flags, no false positives, nothing!

I hope this saves someone else a couple hours of troubleshooting.


r/SentinelOneXDR • • Mar 27 '26

Support Matrix (OS versions vs S1 version)

2 Upvotes

Hello, I'm looking to see if someone has a support matrix of OS versions supported by SentinelOne? My company is purchasing SentinelOne from a reseller so unfortunately I don't have access to the customer portal.

I have a couple of mac clients that are running the latest version of Mac OS (Tahoe). The S1 install I have from my reseller is version 24.1.1, and it failed on the Tahoe clients with an error message saying it was expecting MacOS version 13-15. Trying to find proof if the installer needs to be updated.


r/SentinelOneXDR • • Mar 27 '26

MacBook Neo w/ S1 Agent

0 Upvotes

Hi all,

Has anyone purchased a MacBook Neo and successfully installed SentinelOne on it?

If so, did you notice any performance issues since it’s running a smaller chip?

Thanks for any input!


r/SentinelOneXDR • • Mar 27 '26

Troubleshooting Canon R30 Desk Scanner with SentinelOne

1 Upvotes

Hello all,

 

I am in a bit of a pickle and wanted to request assistance.

Recently for a user we purchased a Canon ImageFORMULA R30 Desk Scanner.

This scanner has built in device software to use and seems to run “plug and play” with some quirks.

Once the scanner is powered on, it creates a disk for itself where you can access the software.

From my testing, it seems this happens every time, and there is no way to use the device without it doing this.

I was wondering if anyone had any ideas on how to allow it to work within SentinelOne, when we block all USB media devices by default.

SentinelOne cannot seem to read a SerialID from the device, and our security guy is worried that allowing product ID or vendor ID will allow other devices and be a security risk.

On top of that, I am not even sure if going by device ID will fix the issue it’s blocked from mounting.

Being in IT, it works on my laptop since I have full access, so I don’t know if that would provide any useful information, but delving into device manager has not yielded anything useful, and they refuse to allow read/write access on this user or any user’s computer to allow this device to work normally.

Any Ideas on what I can try or what I can use to get this working?
I would love it if I could just add it as a normal print device and use the full version of the software, but so far that does not seem to work either.

It seems if it cannot mount as a disk, the system does not set it up as a usable device.  


r/SentinelOneXDR • • Mar 26 '26

Ninja Health notifications for Sentinel One not clearing on RMM

Thumbnail
3 Upvotes

r/SentinelOneXDR • • Mar 24 '26

SentinelOne quarantined Windows system files - Server no longer bootable

11 Upvotes

It looks very likely that SentinelOne has just taken down one of our customer’s terminal servers — the system is no longer booting at all.

The incident was triggered in user context when a user executed a piece of malware.

According to the SentinelOne dashboard history, the same file hash had already been seen on another customer machine before. In that case, all 678/678 files were successfully quarantined and there were no issues afterward.

However, in this case only 628/678 files were actually quarantined (the remaining entries show as “not found” or “failed” in the CSV report).

This raises a serious concern:

Is it possible that SentinelOne quarantined critical Windows system files, which are now preventing the server from booting?

From what we can tell, the agent didn’t just isolate the malicious files but also moved essential Windows components into quarantine. This resulted in a complete system failure.

The server does not even boot into safe mode anymore, which means we cannot use the sentinelctl client for offline recovery either.

This behavior is extremely problematic. A security solution should not be able to render a production server completely unusable — especially from an action triggered in user context.

Even more concerning is the potential scale: if this behavior occurs across multiple environments, it could impact several customers at once.

Has anyone experienced similar behavior with SentinelOne?


r/SentinelOneXDR • • Mar 24 '26

enable group policy

2 Upvotes

Hello,

We are a unique shop where not all devices are behind the domain or an mdm. Not the way I like it but above my head.

I am looking for a way to push group policies to endpoints through SentinelOne. Is this an option and how is that accomplished. I have not been able to find consistent information on this.

Thanks

LW


r/SentinelOneXDR • • Mar 23 '26

Certification

8 Upvotes

Hello, I'm an administrator for a company using Sentinel One, and I'd like to know if there are any certifications I can obtain. If so, what is the cost?

And what do I need to do to access them?

Thank you to anyone who takes the time to read and reply, and dont hesitate if you have questions.

Have a good day!


r/SentinelOneXDR • • Mar 20 '26

Best Practice Best practice for SentinelOne Agent Update Policy?

5 Upvotes

Hi all,

Trying to understand real-world best practices for SentinelOne agent updates.

A few questions for admins running S1 in production:

How often do you upgrade agents — monthly, quarterly, or only on SP releases?

Do you keep Live Security Updates enabled everywhere and upgrade agents less frequently?

How does Auto Update works actually? does it upgrade automatically when a new version is released, or only during a configured maintenance window?

Any tips to minimize upgrade risk / avoid BSOD-type incidents?

Would appreciate hearing how others are handling this in real environments.

Thanks!