'Bring Your Own Installer' Attack Targets SentinelOne EDR
ID: 162c89f0-b6e0-5a91-8eba-ac336a1a8ee6
STIX ID: report--162c89f0-b6e0-5a91-8eba-ac336a1a8ee6
Feed Name: Dark Reading
Threat Score
Date Published: 2025-05-07
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
...
...
Aon's Stroz Friedberg demonstrated a "Bring Your Own Installer" local upgrade/downgrade technique that can temporarily terminate SentinelOne processes and leave endpoints unprotected, enabling deployment of Babuk ransomware; SentinelOne released a mitigation (Local Upgrade Authorization) and notes properly configured agents are not vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
