Alright, I've been digging into SentinelOne for a potential rollout here, and I keep hitting the same wall in my research: **living-off-the-land (LOL) attacks**.
The marketing materials and datasheets are full of big claims, but I'm hunting for real-world, boots-on-the-ground numbers. We all know traditional malware gets caught pretty easily these days. The real test is stuff like:
* PowerShell scripts calling out to C2
* Legit admin tools (PsExec, WMI) being abused
* MS Office macros / DDE attacks
* Credential dumping via comsvcs.dll
So, for those of you running S1 in production:
* **What's your actual detection rate** for these behaviors? Not the EDR alert, but a full "block/story" completion.
* Does it reliably **block the process chain** early, or is it more of a post-execution forensics tool for these?
* How much tuning did you need? Are default behavior policies enough?
I'm trying to build a comparison sheet vs. other EDRs, and this is my biggest data gap. The "real" false positive/negative balance here is crucial.
Bonus points if you've seen it catch something truly novel that slipped past other layers. Those war stories are gold.
— alex
Data > opinions