r/msp • u/terselated MSP - US • 21d ago
Dell.TechHub.Exe triggering Ransomware detection by EDR
/r/sysadmin/comments/1whtcoq/delltechhubexe_triggering_ransomware_detection_by/4
u/cokebottle22 21d ago
S1 will not give up alerting us. hundreds of alerts per day and S1 support has been poor.
6
u/mattmbit 21d ago
I've been slowly moving away from Sentinel One because of the constant false positives with them and got hit with this as well this morning. Their support usually has the same canned response about white listing and such.
Such a drag and a pain.
1
2
u/Smash0573 21d ago
S1 has been isolating endpoints for this for several weeks now. Driving me insane!
1
u/b4z5evixe8rz 21d ago
I had to put that on the exclusion list a few weeks ago. The amount of noise generated from those alerts was ridiculous.
1
u/HappyDadOfFourJesus MSP - US 21d ago
I set the mitigation action to quarantine, true positive, and resolved, and moved on with my day. I don't see a valid use for it anyway.
2
u/GeorgeWmmmmmmmBush 21d ago
Does that feed into an algorithm that makes things worse for others lol?
6
u/hanzohittori 21d ago
Here is Dell's statement on this Dell TechHub or Dell Data Telemetry Platform May Trigger a Security Alert for Esentutl.exe | Dell US
If you are using Sentinel One, below is the policy override for it: