logo

'Bring Your Own Installer' Attack Targets SentinelOne EDR

ID: 162c89f0-b6e0-5a91-8eba-ac336a1a8ee6

STIX ID: report--162c89f0-b6e0-5a91-8eba-ac336a1a8ee6

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-05-07

Date Updated: 2026-04-21

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

Aon's Stroz Friedberg demonstrated a "Bring Your Own Installer" local upgrade/downgrade technique that can temporarily terminate SentinelOne processes and leave endpoints unprotected, enabling deployment of Babuk ransomware; SentinelOne released a mitigation (Local Upgrade Authorization) and notes properly configured agents are not vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.