Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
SentinelOne Singularity XDR
FIN-237
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 09:04
Verified
What It Detects
An internet-facing asset with a public IP address has a SentinelOne agent that is offline and not communicating with the management console. The security team has lost visibility and remote management capability over a publicly exposed endpoint. Policy updates, threat intelligence feeds, and remote response actions cannot reach this asset, creating a blind spot on one of the most attack-prone assets in the environment.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Agent Status
not_equals
online
Public IP Address
not_empty
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum