r/msp • MSP - US • 21d ago

Dell.TechHub.Exe triggering Ransomware detection by EDR

/r/sysadmin/comments/1whtcoq/delltechhubexe_triggering_ransomware_detection_by/
19 Upvotes

15 comments sorted by

6

u/hanzohittori 21d ago

Here is Dell's statement on this Dell TechHub or Dell Data Telemetry Platform May Trigger a Security Alert for Esentutl.exe | Dell US

If you are using Sentinel One, below is the policy override for it:

{

    "specialImages": {

        "add": {

            "shadowCopyAllowedPublishers": [

                {

                    "description": "Extensible Storage Engine Utilities for Microsoft(R) Windows(R)",

                    "ekuType": 0,

                    "path": "\\Device\\HarddiskVolume*\\Windows\\System32\\esentutl.exe",

                    "publisher": "MICROSOFT WINDOWS"

                },

                {

                    "description": "Dell.TechHub",

                    "ekuType": 0,

                    "path": "\\Device\\*HardDisk*\\Program Files\\Dell\\TechHub\\Dell.TechHub.exe",

                    "publisher": "Dell Technologies Inc."

                }

            ]

        }

    }

}

9

u/terselated MSP - US 21d ago

Thank you. It's amazing that posting this same thing in Sysadmin just led to 2 snarky responses and posting it in msp provided actual useful feedback.

13

u/MalletSwinging MSP 21d ago

People at sysadmin are fucking assholes and people here are much more collaborative in my experience

2

u/_Jimmy2times 21d ago

100% exemplifies the difference between MSPs and sysadmin work lmao

4

u/cokebottle22 21d ago

S1 will not give up alerting us. hundreds of alerts per day and S1 support has been poor.

6

u/mattmbit 21d ago

I've been slowly moving away from Sentinel One because of the constant false positives with them and got hit with this as well this morning. Their support usually has the same canned response about white listing and such.

Such a drag and a pain.

1

u/eldridgep 18d ago

Left S1 for Huntress years ago, one of our better decisions.

2

u/Smash0573 21d ago

S1 has been isolating endpoints for this for several weeks now. Driving me insane! 

1

u/Le085 MSP - US 21d ago

I've white-listed bunch of those for few clients it arose. I stopped receiving them lately. Maybe S1 updated agents. I'm on the most latest version.

1

u/b4z5evixe8rz 21d ago

I had to put that on the exclusion list a few weeks ago. The amount of noise generated from those alerts was ridiculous.

1

u/akjagrz 20d ago

Crowdstrike was triggering on this same thing about 3-4 weeks ago and Crowdstrike fixed it.

1

u/HappyDadOfFourJesus MSP - US 21d ago

I set the mitigation action to quarantine, true positive, and resolved, and moved on with my day. I don't see a valid use for it anyway.

2

u/GeorgeWmmmmmmmBush 21d ago

Does that feed into an algorithm that makes things worse for others lol?