<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SentinelOne on SolCyber Knowledgebase</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/</link><description>Recent content in SentinelOne on SolCyber Knowledgebase</description><generator>Hugo</generator><language>en</language><atom:link href="https://kb.solcyber.com/endpoint-setup-guides/sentinelone/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Agent Installation</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/windows-agent-installation/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/windows-agent-installation/</guid><description>&lt;blockquote class='book-hint warning' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;path d="M10.29 3.86 1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z"/&gt;&lt;path d="M12 9v4"/&gt;&lt;path d="M12 17h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;Installation of Windows agent version &lt;strong&gt;23.4 and above&lt;/strong&gt; DOES NOT require a system reboot. &lt;/p&gt;
&lt;p&gt;If you are installing any agent version before 23.4, a system reboot is required to complete installation.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;h2 id="install-with-interactive-gui-wizard"&gt;Install with interactive GUI wizard&lt;a class="anchor" href="#install-with-interactive-gui-wizard"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Run the installation package and enter the Site Token when prompted in the installation wizard.&lt;/p&gt;</description></item><item><title>Linux Agent Installation</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/linux-agent-installation/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/linux-agent-installation/</guid><description>&lt;blockquote class='book-hint note' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;circle cx="12" cy="12" r="10"/&gt;&lt;path d="M12 16v-4"/&gt;&lt;path d="M12 8h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;No reboot is required for installation on Linux endpoints&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;h2 id="option-1-deploy-agent-with-a-configuration-file"&gt;Option 1: Deploy Agent with a Configuration File&lt;a class="anchor" href="#option-1-deploy-agent-with-a-configuration-file"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Version 21.5+ of the Linux Agent supports an easier deployment. Rather than run the commands to install, associate, activate, and then set a proxy (if applicable), you can set one configuration file to use these variables.&lt;/p&gt;
&lt;p&gt;1. Create a configuration file with the installation parameters, each on a separate line.&lt;/p&gt;</description></item><item><title>Supported Operating Systems</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/supported-operating-systems/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/supported-operating-systems/</guid><description>&lt;h2 id="windows"&gt;Windows&lt;a class="anchor" href="#windows"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;h3 id="microsoft-windows-operating-system-versions"&gt;Microsoft Windows Operating System Versions&lt;a class="anchor" href="#microsoft-windows-operating-system-versions"&gt;#&lt;/a&gt;&lt;/h3&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Windows OS&lt;/th&gt;
 &lt;th&gt;Details&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Server Core&lt;/td&gt;
 &lt;td&gt;2019, 2016, 2012&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Server&lt;/td&gt;
 &lt;td&gt;2022, 2019, 2016, 2012 R2, 2012, 2008 R2 SP1&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Storage Server&lt;/td&gt;
 &lt;td&gt;2016, 2012 R2, 2012&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows 7 SP1, 8, 8.1, 10, 11&lt;/td&gt;
 &lt;td&gt;32/64-bit&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="minimum-hardware-requirements"&gt;Minimum Hardware Requirements&lt;a class="anchor" href="#minimum-hardware-requirements"&gt;#&lt;/a&gt;&lt;/h3&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Minimum&lt;/th&gt;
 &lt;th&gt;Recommended&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;1 GHz CPU or better&lt;/td&gt;
 &lt;td&gt;Dual-core. You can install on a single-core CPU, but performance will not be optimal.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;1 GB RAM or more&lt;/td&gt;
 &lt;td&gt;3 GB recommended&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;2 GB free disk space on the Windows partition&lt;/td&gt;
 &lt;td&gt;If you are taking VSS snapshots, add an additional 10%.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;blockquote class='book-hint warning' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;path d="M10.29 3.86 1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z"/&gt;&lt;path d="M12 9v4"/&gt;&lt;path d="M12 17h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;CPU micro-architectures such as x86_32, ARM, RISC, MIPS are not supported by SentinelOne components&lt;/p&gt;</description></item><item><title>Windows Agent Installer Command Line Options</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/windows-agent-installer-command-line-options/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/windows-agent-installer-command-line-options/</guid><description>&lt;blockquote class='book-hint note' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;circle cx="12" cy="12" r="10"/&gt;&lt;path d="M12 16v-4"/&gt;&lt;path d="M12 8h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;&lt;strong&gt;If you are installing an agent version 21.x or lower, please use the&lt;/strong&gt; &lt;a href="https://kb.solcyber.com/endpoint-setup-guides/sentinelone/windows-agent-installer-command-line-options/#legacy-installer-options"&gt;&lt;strong&gt;legacy command line options&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Example Usage:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;CMD&lt;/p&gt;
&lt;div class="kb-code" data-lang="text"&gt;
 &lt;div class="kb-code-head"&gt;
 &lt;span class="kb-code-lang"&gt;text&lt;/span&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#e6edf3;background-color:#0d1117;-moz-tab-size:2;-o-tab-size:2;tab-size:2;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;SentinelOneInstaller.exe -q -b -t &amp;lt;site_token&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;Powershell&lt;/p&gt;
&lt;div class="kb-code" data-lang="text"&gt;
 &lt;div class="kb-code-head"&gt;
 &lt;span class="kb-code-lang"&gt;text&lt;/span&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#e6edf3;background-color:#0d1117;-moz-tab-size:2;-o-tab-size:2;tab-size:2;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;./SentinelOneInstaller.exe -q -t &amp;lt;site_token&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;-b, --reboot_on_need&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Optional. Automatically reboot the endpoint when required to continue with the installation.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;-t`` &lt;/code&gt;&lt;em&gt;&lt;code&gt;site_Token or group_Token&lt;/code&gt;&lt;/em&gt; is the site token or group token.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;-q, --qn&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Optional unless you use a deployment tool to install the Agent (then it is mandatory).&lt;/p&gt;</description></item><item><title>Interoperability Exclusions</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/interoperability-exclusions/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/interoperability-exclusions/</guid><description>&lt;p&gt;The SentinelOne agent can sometimes present interoperability issues with other applications, either SentinelOne prevents another application from operating properly, or another application prevents the SentinelOne agent from operating properly. In the SentinelOne console, the SolCyber SOC can add exclusions that will prevent SentinelOne from interacting with certain files and directories to prevent such issues. &lt;/p&gt;
&lt;p&gt;The following list represents applications that SentinelOne provides some out-of-the-box interoperability exclusions for. Please let us know if you use any of the following applications on devices where you plan to install the S1 agent.&lt;/p&gt;</description></item><item><title>Uninstalling/Disabling SentinelOne</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/uninstalling-disabling-sentinelone/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/uninstalling-disabling-sentinelone/</guid><description>&lt;blockquote class='book-hint note' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;circle cx="12" cy="12" r="10"/&gt;&lt;path d="M12 16v-4"/&gt;&lt;path d="M12 8h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;Due to the tamper protection feature in the SentinelOne agent, the easiest way to uninstall or disable the agent is to open a ticket with the SolCyber SOC. We will send an &lt;code&gt;uninstall&lt;/code&gt;or &lt;code&gt;disable&lt;/code&gt; command to the device. In instances when the device in question is offline or otherwise unreachable by the SentinelOne console, local uninstalls/disable can be performed, but &lt;strong&gt;each device&amp;rsquo;s unique passphrase is required&lt;/strong&gt; to complete the action due to the tamper protection. The SolCyber SOC can provide you with the passphrase.&lt;/p&gt;</description></item><item><title>SentinelOne Data Collection List</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/sentinelone-data-collection-list/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/sentinelone-data-collection-list/</guid><description>&lt;h2 id="management-console-data-collection"&gt;Management Console Data Collection&lt;a class="anchor" href="#management-console-data-collection"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The SentinelOne Agent collects these datasets:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hardware data:
&lt;ul&gt;
&lt;li&gt;Machine type&lt;/li&gt;
&lt;li&gt;Architecture&lt;/li&gt;
&lt;li&gt;Memory&lt;/li&gt;
&lt;li&gt;CPU information&lt;/li&gt;
&lt;li&gt;Core count&lt;/li&gt;
&lt;li&gt;Mac address&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Solutions conﬁguration information: Customer instance settings (including users emails, phone numbers)&lt;/li&gt;
&lt;li&gt;User and device data:
&lt;ul&gt;
&lt;li&gt;Agent ID&lt;/li&gt;
&lt;li&gt;Endpoint Name&lt;/li&gt;
&lt;li&gt;Workgroup/domain&lt;/li&gt;
&lt;li&gt;User name&lt;/li&gt;
&lt;li&gt;Disk encryption state&lt;/li&gt;
&lt;li&gt;Installed applications - installation time, size, publisher and version.&lt;/li&gt;
&lt;li&gt;OS type&lt;/li&gt;
&lt;li&gt;OS version&lt;/li&gt;
&lt;li&gt;SentinelOne Agent version&lt;/li&gt;
&lt;li&gt;SMTP username&lt;/li&gt;
&lt;li&gt;User login/out time&lt;/li&gt;
&lt;li&gt;External devices control rules&lt;/li&gt;
&lt;li&gt;Firewall control rules, and event notiﬁcations (such as details of blocked application events)&lt;/li&gt;
&lt;li&gt;Notiﬁcation of interface connection (USB/Bluetooth) and hardware information&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Integrations to the Console and global conﬁguration of connected endpoints&lt;/li&gt;
&lt;li&gt;Process activity:
&lt;ul&gt;
&lt;li&gt;Time of machine activity&lt;/li&gt;
&lt;li&gt;Running processes (name, ID, CPU usage, memory)&lt;/li&gt;
&lt;li&gt;Full ﬁle path&lt;/li&gt;
&lt;li&gt;In cases of suspected threats, the SentinelOne Agent collects for each process:
&lt;ul&gt;
&lt;li&gt;File metadata&lt;/li&gt;
&lt;li&gt;Hash&lt;/li&gt;
&lt;li&gt;File type&lt;/li&gt;
&lt;li&gt;Certiﬁcate (for veriﬁed or not)&lt;/li&gt;
&lt;li&gt;Command-line arguments&lt;/li&gt;
&lt;li&gt;Network access metadata only: IP Address; protocol&lt;/li&gt;
&lt;li&gt;Registry: created keys; deleted keys; modiﬁed key names&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Network Data:
&lt;ul&gt;
&lt;li&gt;Internal network IP address&lt;/li&gt;
&lt;li&gt;Public IP address (if running cloud-based management)&lt;/li&gt;
&lt;li&gt;Inbound/Outbound connections, metadata only (source, target, port, and application)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Fetched Files:
&lt;ul&gt;
&lt;li&gt;Any ﬁle fetched by user (encrypted at rest, deleted after 72 hours)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="cloud-data"&gt;Cloud Data&lt;a class="anchor" href="#cloud-data"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;SentinelOne collects the data of the cloud service provider for each Linux and K8s Agent that is recognized as a server (Sentinels &amp;gt; Endpoints &amp;gt; &lt;strong&gt;Machine Type&lt;/strong&gt; = Server ).&lt;/p&gt;</description></item><item><title>Agent Troubleshooting</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/agent-troubleshooting/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/agent-troubleshooting/</guid><description>&lt;p&gt;When troubleshooting issues with SentinelOne agents, a SolCyber SOC engineer will usually open a ticket with SentinelOne support. To expedite resolution, we ask that some data or log collection be done on the device so that we can provide the details to SentinelOne support.&lt;/p&gt;
&lt;h2 id="windows"&gt;&lt;strong&gt;Windows&lt;/strong&gt;&lt;a class="anchor" href="#windows"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;h3 id="to-collect-installation-logs-from-windows-endpoints"&gt;To collect installation logs from Windows endpoints:&lt;a class="anchor" href="#to-collect-installation-logs-from-windows-endpoints"&gt;#&lt;/a&gt;&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;In File Explorer, enter:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;C:\Windows\Temp\&lt;/code&gt; &lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;%temp%&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;This redirects to &lt;code&gt;C:\Users\&amp;lt;USER&amp;gt;\AppData\Local\Temp\&lt;/code&gt; where &amp;lt;USER&amp;gt; is the logged-in user.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In each of these file paths, look for &lt;code&gt;sentinelinstaller&lt;/code&gt; files. The file path can be different configuration of your operating system.&lt;/p&gt;</description></item><item><title>SentinelOne Endpoint Actions</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/sentinelone-endpoint-actions/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/sentinelone-endpoint-actions/</guid><description>&lt;p&gt;In the SolCyber Customer Portal, you can run an Endpoint report to show any SentinelOne agents that are missing a necessary permission, or require an action (such as rebooting) to restore full functionality to the agent. Please use the chart below to find a description for the most common values found in the &amp;ldquo;&lt;strong&gt;Action Needed&lt;/strong&gt;&amp;rdquo; column of this report. If your report contains an action that is not listed here, please contact the SOC at &lt;a href="mailto:soc@SolCyber.com"&gt;soc@SolCyber.com&lt;/a&gt; so that we can assist.&lt;/p&gt;</description></item><item><title>VSS Writer Exclusions</title><link>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/vss-writer-exclusions/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/endpoint-setup-guides/sentinelone/vss-writer-exclusions/</guid><description>&lt;blockquote class='' &gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;⚠️ &lt;strong&gt;Important Security Notice&lt;/strong&gt;: Excluding VSS Writers removes SentinelOne protection from that data. Only exclude writers when absolutely necessary for backup compatibility.&lt;/p&gt;

&lt;/div&gt;
&lt;/blockquote&gt;
&lt;h2 id="overview"&gt;Overview&lt;a class="anchor" href="#overview"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This guide shows you how to exclude specific VSS Writers from SentinelOne protection to resolve compatibility issues with backup software using the SentinelCtl command line method.&lt;/p&gt;
&lt;p&gt;The SentinelOne agent protects VSS shadow copies from malicious changes and deletion. However, some backup applications may require specific VSS Writers to be excluded from SentinelOne monitoring to function properly.&lt;/p&gt;</description></item></channel></rss>