Hey folks, been putting the new SentinelOne 23.x agent through its paces on our dev endpoints and I've got to say, the memory footprint is... noticeable. Like, consistently sitting at 500MB+ on idle Windows 10/11 systems noticeable.
I'm a huge fan of their behavioral AI engine and the whole story they tell about prevention, but this feels like a step back. We're running it alongside a fairly lightweight stack (just a standard corporate image with some internal tools). Compared to some other EDRs I've tested in beta (like CrowdStrike's last preview), S1 seems to be asking for a lot more from the host.
Has anyone else run into this, especially with the latest versions? I'm trying to pin down if it's:
* A known issue with a specific component (the Data Lake module? The network inspection?)
* Something in our policy config that's unintentionally aggressive
* Just the "cost of doing business" with their deep visibility and recording features
We're considering a wider rollout, but the help desk is already antsy about user complaints on older hardware. Any tuning tips or benchmarks from your own deployments would be awesome.
Beta tester at heart