Index / Vendors / SentinelOne
Product Record

SentinelOne

Publicly-reported techniques recorded as bypassing SentinelOne. Each entry is sourced to its original disclosure. This is a factual tally, maintained on the same basis for every vendor in the Index.

15
recorded bypasses
7
distinct techniques

Techniques recorded against SentinelOne

TechniqueEntriesHigh-confidenceMost recent
BYOVD (Vulnerable Driver) 542026-03-26
Disable or Modify Tools 432025-11-17
EDR Unhooking 212025-12-07
Tamper-Protection Bypass 112025-05-05
DLL Side-Loading 112026-05-14
AMSI Bypass 112024-02-12
Process Injection 112023-12-08

All entries

TechniqueConfidenceDisclosedSource
DLL Side-Loading high 2026-05-14cybersecuritynews.com record →
BYOVD (Vulnerable Driver) high 2026-03-26labs.cloudsecurityalliance.org record →
BYOVD (Vulnerable Driver) high 2026-02-24blog.silentforce.io record →
EDR Unhooking high 2025-12-07github.com record →
Disable or Modify Tools high 2025-11-17cyberpress.org record →
Disable or Modify Tools high 2025-08-28beierle.win record →
BYOVD (Vulnerable Driver) medium 2025-08-07mine2.io record →
EDR Unhooking medium 2025-07-13github.com record →
Tamper-Protection Bypass high 2025-05-05www.bleepingcomputer.com record →
BYOVD (Vulnerable Driver) high 2024-07-16trustedsec.com record →
AMSI Bypass high 2024-02-12www.linkedin.com record →
Process Injection high 2023-12-08securityaffairs.com record →
Disable or Modify Tools high 2023-09-13labs.infoguard.ch record →
Disable or Modify Tools medium 2023-06-01www.threatlocker.com record →
BYOVD (Vulnerable Driver) high 2023-05-31www.bleepingcomputer.com record →

Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file, not that a product is unaffected.