Interoperability with Sophos

Description

To learn how to exclude files and folders please see Capture Client Interoperability Issues with Third Party Applications.

Resolution

Items to exclude from the SentinelOne Management Console:

  • C:\ProgramData\Sophos\

  • C:\Program Files\Sophos\

  • C:\Program Files (x86)\Sophos\

  • C:\windows\system32\drivers\SophosBootTasks.exe

    OR

    C:\windows\system32\SophosBootTasks.exe

  • C:\windows\system32\drivers\sdccoinstaller.dll

    OR

    C:\windows\system32\sdccoinstaller.dll

To exclude SentinelOne from Sophos:

  1. Exclude these folders and the update file:

    • C:\Program Files\SentinelOne

    • C:\ProgramData\Sentinel

    • C:\Documents and Settings\All Users\Application Data\Sentinel (ProgramData for 2003 and legacy agents )

    • C:\Windows\Temp\SentinelInstaller.exe

    Note: Make sure to exclude subfolders. Some solutions automatically exclude subfolders, but others require explicit notation.

  2. Exclude the SentinelOne Agent kernel-mode driver, service, and dynamic library:

    • Kernel-Mode driver: SentinelMonitor.sys

    • Windows Service: SentinelAgent.exe

    • 32-bit DLL: InProcessClient32.dll

    • 64-bit DLL: InProcessClient64.dll

Related Articles

  • Capture Client: Prevent macOS 26.6 False Positives with SentinelOne Policy Override
    Read More
  • Capture Client migration across consoles
    Read More
  • Best Practices Guide for SonicWall Endpoint Security (SES)
    Read More
not finding your answers?