Bypass Record
Disable or Modify Tools × SentinelOne Agent
A publicly-reported instance of Disable or Modify Tools bypassing SentinelOne Agent, recorded with its original source. Factual record; no assessment of any specific deployment.
Mechanism
SilentButDeadly enumerates EDR/AV processes, then creates high-priority bidirectional WFP filters in a dynamic session to block all network traffic for those processes. This severs cloud connectivity, disabling telemetry, threat intelligence updates, and remote commands without terminating processes or using kernel manipulation. Filters are automatically removed when the tool exits, reducing forensic traces.
Detection & mitigation
Monitor for WFP filter additions via Event ID 5157 (Windows Filtering Platform) or ETW providers like Microsoft-Windows-WFP, especially dynamic sessions targeting security product processes. Mitigation: enforce least-privilege to limit admin rights, and use endpoint logging to alert on unexpected WFP rule creation.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.