SentinelOne Blocking Atera

mikepage
mikepage Member Posts: 6

It looks like this may be a recurring issue but SentinelOne incorrectly labeled Atera as malicious today breaking my remote access to 100+ of my clients computers. I have created some exclusions in SentinelOne but I am still unable to use Atera with the affected clients. I have a ticket open with SentinelOne for this.

Any help is appreciated.

Comments

  • gilgi
    gilgi Administrator, Moderator, Internal Posts: 224 admin

    Hello, sorry for the late response -

    Indeed, this was a false positive, and has since been resolved and whitelisted by S1.
    Are you still having problem with offline endpoints?

  • mikepage
    mikepage Member Posts: 6

    Yes. Pretty much every endpoint still shows offline in Atera. There were some that I could still connect to via splashtop despite it showing Offline. However, I just tried a few again and I am still unable to connect.

  • tdillon
    tdillon Member Posts: 1

    the whitelisting by S1 has not resolved anything. Each endpoint must be individual processed in S1, you must unquaranine the endpoint, and force S1 to do a rollback, and if that fails you must surgically remove all traces of AteraAgent from the endpoint machine directly, including all file directories and registry entries, then redeploy your AteraAgent for the endpoint. After that you will now have two endpoints in your Atera with the same name, which I am sure will complicate the reports you generate going forward for your clients.

  • gilgi
    gilgi Administrator, Moderator, Internal Posts: 224 admin

    Hey,

    Please DM your ticket #s with S1, we can help escalate them to assist quicker.

    @Tdillon I'm also sharing what you said about the double-entries with my team

  • c.zaragoza
    c.zaragoza Member Posts: 1

    hi

    we Have a same issue with watchguard EPDR.
    my team works on it.

  • gilgi
    gilgi Administrator, Moderator, Internal Posts: 224 admin

    Thanks @c.zaragoza
    Flagged my security team, so far we only heard about SentinalOne.

    If anyone else is experiencing quarantine issues and blocks with any other service please flag me 🙏

    Really appreciate it, I'm sorry this is affecting your work and day2day, we're on this and are working to help.

  • gilgi
    gilgi Administrator, Moderator, Internal Posts: 224 admin

    Hey, please open a ticket with the vendor, and explain your issue, you can also try whitelisting yourself - for that it's best you open a ticket with our support team at support@atera.com

  • mikepage
    mikepage Member Posts: 6

    I think that I am able to get Atera working by disabling SentinelOne and so I don't believe it will require all the steps mentioned by tdillion to resolve.

    I have a ticket open with SentinelOne already. Do I need to open a ticket with support@atera.com?

  • gilgi
    gilgi Administrator, Moderator, Internal Posts: 224 admin

    Could you send me the ticket #? @mikepage
    Don't think you need to open a support ticket quite yet with us.

  • mikepage
    mikepage Member Posts: 6

    My ticket is actually with N-able who is reselling SentinelOne.

    The N-able ticket is: 02521427

  • kkajdan
    kkajdan Member Posts: 1

    I'm having the same issue since Friday. I created a hash exclusion and unquarantined the file, I was finally able to get the endpoint to show as online but, the alerts from S1 will not stop, I've gotten over 20,000 emails... My ticket with S1 is #01308431.

  • gilgi
    gilgi Administrator, Moderator, Internal Posts: 224 admin

    Hey gang,

    Some updates -
    1. ESET and Panda customers - we've been aware that the Atera version was also falsely picked up by those, Panda have confirmed they are aware and restoring where applicable.
    2. Thanks for sharing the ticket #s, I've forwarded with my security team.

    I'm once again really sorry about the troubles.

  • mikepage
    mikepage Member Posts: 6
    edited September 17

    I am just wondering if there are any updates for this?

    I just checked things out for one of my clients. This particular client has 4 reception computers. 3 of them are showing as online which is great. The fourth shows as offline. I had that computer rebooted and still shows offline. I tried to connect via splashtop despite it showing offline and it wouldn't connect. I was able to connect to some computers on Friday despite them showing as offline. I'm not sure if any of this information is useful.

    On Friday I think nearly 100% of computers for a couple of clients were showing as offline. Currently I suspect that about 50% have come back online. However, I feel that around 80% or more are actually online and showing as offline so the problem isn't quite resolved.

    I currently have n-able asking for boat loads of information for them to pass along to SentinelOne but I am assuming that Atera and the folks at SentinelOne are already all aware of this issue and working towards a resolution. I would like to avoid spending the afternoon gathering up all the requested data if I can.

    Thanks

  • gilgi
    gilgi Administrator, Moderator, Internal Posts: 224 admin

    Heya, I've opened a ticket on your behalf with our support to update you and assist with the remaining offline devices and data collection however they can, they might have additional questions so please check your email.

    I wish I could help, but I don't want you to fall between the cracks and support have the right funnels with these more elaborate cases.