Interoperability with Sophos

Description

To learn how to exclude files and folders please see Capture Client Interoperability Issues with Third Party Applications.

Resolution

Items to exclude from the SentinelOne Management Console:

  • C:\ProgramData\Sophos\

  • C:\Program Files\Sophos\

  • C:\Program Files (x86)\Sophos\

  • C:\windows\system32\drivers\SophosBootTasks.exe

    OR

    C:\windows\system32\SophosBootTasks.exe

  • C:\windows\system32\drivers\sdccoinstaller.dll

    OR

    C:\windows\system32\sdccoinstaller.dll

To exclude SentinelOne from Sophos:

  1. Exclude these folders and the update file:

    • C:\Program Files\SentinelOne

    • C:\ProgramData\Sentinel

    • C:\Documents and Settings\All Users\Application Data\Sentinel (ProgramData for 2003 and legacy agents )

    • C:\Windows\Temp\SentinelInstaller.exe

    Note: Make sure to exclude subfolders. Some solutions automatically exclude subfolders, but others require explicit notation.

  2. Exclude the SentinelOne Agent kernel-mode driver, service, and dynamic library:

    • Kernel-Mode driver: SentinelMonitor.sys

    • Windows Service: SentinelAgent.exe

    • 32-bit DLL: InProcessClient32.dll

    • 64-bit DLL: InProcessClient64.dll

Related Articles

  • Integrating with 3rd Party Syslog and Threat Detection Platforms
    Read More
  • How to Generate a Capture Client (SentinelOne) API Key Using a Service User
    Read More
  • Integrating SonicWall Capture Client with SonicWall Firewalls
    Read More
not finding your answers?