Provider
SentinelOneIncident detail
Elevated False Positive Alert Activity
Timeline window
to
Outage alerts
Get alerted the next time SentinelOne breaks
Free email alerts for up to 5 providers — no card, live in about a minute. Paid plans add Slack, Discord, and webhook delivery across your whole stack, plus higher API quotas.
Timeline
Incident updates
Updates are normalized from the official source chronology so timeline changes remain easy to scan.
Monitoring
SentinelOne is monitoring a global false positive event caused by a third-party reputation feed misclassification of a benign file artifact. This resulted in elevated reputation-based detections, alert activity across multiple regions, and, for some customers, network quarantines where enforcement policies are enabled.
Mitigation actions have been implemented. Teams continue to monitor platform stability and assist customers with any remaining cleanup. Additional updates will be shared if conditions change.
Monitoring
SentinelOne has mitigated the third-party reputation misclassification of hash e89cb8f5b2a05b00e85a1f549b0d1e48d148ccbf. We have manually updated our global reputation feed and issued a fleet-wide allowlist to prevent further detections.
While infrastructure remains healthy, customers may experience temporary console performance degradation and brief false positive alerts as agents check in to receive the update. These symptoms will subside as the allowlist propagation completes. We will continue to monitor the environment for stability and provide updates should this change.
Resolved
All services have been fully restored and the incident is now resolved. We have validated that all systems are functioning normally. Thank you for your patience throughout this incident.