<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uninstalling S1 agnet from XDR in Endpoint (Traps) Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1251964#M1199</link>
    <description>&lt;P&gt;Hi kiwi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Already tested&amp;nbsp; and you are right it needs anti tampering pass phrase. without it we cant do. Even we can uninstall any third party application by knowing its uninstall behavior like:- /qn , /s.&amp;nbsp; But before doing we have to understand what type of process it use for uninstalling. Then only we can create script.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Apr 2026 12:38:17 GMT</pubDate>
    <dc:creator>Jai_Prakas</dc:creator>
    <dc:date>2026-04-09T12:38:17Z</dc:date>
    <item>
      <title>Uninstalling S1 agnet from XDR</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1248108#M1194</link>
      <description>&lt;P&gt;Can we uninstall the S1 agent from cortex xdr script or automation features.&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 07:57:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1248108#M1194</guid>
      <dc:creator>Jai_Prakas</dc:creator>
      <dc:date>2026-02-13T07:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Uninstalling S1 agnet from XDR</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1249349#M1195</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/831392957"&gt;@Jai_Prakas&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;While Cortex XDR does not have a native "out-of-the-box" feature or pre-canned scripts to uninstall third-party agents like SentinelOne (S1).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kindly note that configuration requests are outside of our TAC scope since we only deal with break/fix issues of our product.&lt;/SPAN&gt;Reach Accounts team on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 22:01:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1249349#M1195</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-03-03T22:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Uninstalling S1 agnet from XDR</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1251950#M1196</link>
      <description>&lt;P&gt;Hello, You can uninstall the SentinelOne (S1) agent using Cortex XDR by creating a script or automation that runs the agent’s uninstall command on your endpoints.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 11:57:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1251950#M1196</guid>
      <dc:creator>stuart012broad</dc:creator>
      <dc:date>2026-04-09T11:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Uninstalling S1 agnet from XDR</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1251962#M1197</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Its achieved by the help of Endpoint script.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 12:30:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1251962#M1197</guid>
      <dc:creator>Jai_Prakas</dc:creator>
      <dc:date>2026-04-09T12:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Uninstalling S1 agnet from XDR</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1251963#M1198</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/831392957"&gt;@Jai_Prakas&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;The short answer is: Yes, it is possible, but it is rarely as simple as a single command.&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;Because SentinelOne is a security product, it is designed to protect itself from being uninstalled. If you attempt to run a generic uninstall command via a Cortex XDR script, SentinelOne will likely flag it as a "tamper" attempt and block it with its anti-tamper protectio.&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;If you want to use Cortex XDR for this automation you must first obtain the Uninstall Passphrase from your SentinelOne console. Without this, the agent will block any removal attempt sent via Cortex.&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;Then create a Custom Script in Cortex XDR. You can use the Script Library to build a script that calls the SentinelOne agent’s control utility.&amp;nbsp; Your script must include the specific uninstall flag and the passphrase. Because file paths and command-line arguments can vary between agent versions, you should verify the exact syntax in the SentinelOne documentation for the specific version you are running.&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;Before deploying this to a group, run the script on one test endpoint to ensure Cortex has the permissions to execute the removal and that the agent accepts the passphrase.&lt;/P&gt;
&lt;P data-path-to-node="9"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 12:31:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1251963#M1198</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-04-09T12:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Uninstalling S1 agnet from XDR</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1251964#M1199</link>
      <description>&lt;P&gt;Hi kiwi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Already tested&amp;nbsp; and you are right it needs anti tampering pass phrase. without it we cant do. Even we can uninstall any third party application by knowing its uninstall behavior like:- /qn , /s.&amp;nbsp; But before doing we have to understand what type of process it use for uninstalling. Then only we can create script.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 12:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/uninstalling-s1-agnet-from-xdr/m-p/1251964#M1199</guid>
      <dc:creator>Jai_Prakas</dc:creator>
      <dc:date>2026-04-09T12:38:17Z</dc:date>
    </item>
  </channel>
</rss>

