Novel Attack Method Silently Neutralizes Endpoint Defenses
Cybersecurity specialists have uncovered an advanced technique that stealthily disables endpoint protection systems, giving attackers a clear path to deploy ransomware without detection.
This tactic, referred to as the “Bring Your Own Installer” strategy, emerged during a forensic investigation into a Babuk ransomware case led by Aon’s Stroz Friedberg Incident Response team.
The Exploit: SentinelOne’s Agent Upgrade Loophole
The attack hinges on a gap within the SentinelOne endpoint agent’s upgrade mechanism. By manipulating this update process, adversaries can sidestep built-in tamper protection—without requiring privileged access or custom exploit tools.
Attack Breakdown
At the heart of this technique is a timing-based flaw. Here’s how threat actors weaponize it:
- Launch a legitimate SentinelOne installer—such as
SentinelOneInstaller_windows_64bit_v23_4_4_223.exeorv23_4_6_347.msi. - The installer automatically halts existing SentinelOne processes to prepare for upgrade.
- Before the install completes, attackers terminate the installer service (msiexec.exe).
- As a result, the endpoint is left with no active security agents, effectively exposed and unmonitored.
This maneuver allows ransomware to be unleashed on systems that appear, from the outside, to still be protected.

Turning Trusted Installers into Attack Tools
Rather than exploiting outdated drivers or deploying questionable third-party utilities, this innovative bypass leverages SentinelOne’s own trusted installation packages—a strategy that repurposes legitimate tools to quietly dismantle endpoint defenses from within.
Clues Left Behind
Digital forensic analysis revealed clear signs of tampering. Among them:
- Event ID 93 in SentinelOne logs flagged a final entry reading “CommandType: unload”.
- Simultaneously, Event ID 1042 in Windows Application logs confirmed “MsiInstaller Exited”, pointing to an interrupted setup routine.
Enter Babuk: A Precision Encryption Threat
Once the EDR platform is sidelined, attackers unleash Babuk ransomware, a high-impact encryption tool known for its cross-platform capability—crippling systems running both Windows and Linux. First spotted in early 2020, Babuk is distributed through a Ransomware-as-a-Service (RaaS) model, enabling affiliates to carry out attacks without deep technical expertise.
Babuk locks files using AES-256 encryption, aggressively halts system processes that might interfere with encryption, and ultimately delivers a ransom demand to the victim, complete with payment instructions.
Reducing the Attack Surface
Following responsible disclosure from Stroz Friedberg, SentinelOne issued an advisory in January 2025. A key defensive measure involves enabling “Online Authorization” within policy configurations. This setting blocks local software modifications—including upgrades, rollbacks, or uninstalls—unless approved by the central management console.

Mitigation Awareness Is Critical, Experts Urge
“The default setting leaves organizations exposed. The priority now is broad awareness and rapid mitigation,” emphasized Ailes, stressing the urgency of proactive defense.
In a move to promote ecosystem-wide resilience, SentinelOne shared details of the flaw with leading EDR vendors. Palo Alto Networks has since verified that its own solution remains unaffected by this particular technique.
Recommended Defensive Actions from Stroz Friedberg:
- Activate “Online Authorization” to ensure that any agent changes require central approval.
- Continuously audit for SentinelOne version shifts, specifically looking for Event ID 1.
- Flag anomalies like frequent or inconsistent version updates over short time frames.
- Inspect system logs for signs of SentinelOne processes being halted unexpectedly or prematurely.
A Broader Message: Threat Tactics Are Evolving
This incident underscores a key reality: EDR evasion methods are becoming more refined, often blending legitimate tools with precise timing attacks. The discovery is a strong reminder that default configurations may not be enough, and that staying ahead requires both active tuning of security tools and vigilance for emerging threat vectors.




