Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Current »

SentinelOne (S1) is a next-generation anti-virus solution that detects and responds to cyber threats like malware and ransomware. S1 provides a lightweight single-agent approach with AI capabilities. (Source https://security.utoronto.ca/about/cyberstrategy/epp/sentinelone-project/ ).

The ITS Private Cloud recommends the deployment of S1 on your virtual instances for an additional layer of visibility and security to your virtual servers.

This how-to will guide you through installing S1 agent on Ubuntu, however we provide installers for Linux and Windows OS available at vskey-stor.eis.utoronto.ca:/ut-vss-lib/sentinelone.

(tick) Requirements

\uD83D\uDCD8 Instructions

  1. Login to the target server and promote as administrator/root.

  2. With your preferred SFTP client login to vskey-stor.eis.utoronto.ca using your VSS credentials and fetch any of the available installers based on the host operating system:

    sftp user@vskey-stor.eis.utoronto.ca
    (user@vskey-stor.eis.utoronto.ca) Password:
    Connected to vskey-stor.eis.utoronto.ca.
    sftp> get /ut-vss-lib/sentinelone/SentinelAgent_linux_x86_64_v24_1_2_6.deb
    Fetching /ut-vss-lib/sentinelone/SentinelAgent_linux_x86_64_v24_1_2_6.deb to SentinelAgent_linux_x86_64_v24_1_2_6.deb
    SentinelAgent_linux_x86_64_v24_1_2_6.deb                                                                       100%   45MB  51.8MB/s   00:00
    sftp>
  3. Run the installer:

    apt install ./SentinelAgent_linux_x86_64_v24_1_2_6.deb 
  4. Associate the instance with your department site token:

    /opt/sentinelone/bin/sentinelctl management token set {{ sentinelone_token }}
  5. Start the service

    /opt/sentinelone/bin/sentinelctl control start
  6. Note that the first run takes a few minutes until shown at the SentinelOne Management Console (https://cace1-201.sentinelone.net/login).

If you have any questions about S1, please reach out to the InfoSec Support teamhttps://security.utoronto.ca/about/cyberstrategy/epp/support/ .

  • No labels