
Script di rilevamento e mitigazione per CVE-2021-36934 (HiveNightmare aka. SeriousSam)
.\Get-HiveNightmareStatus.ps1
.\Get-HiveNightmareStatus.ps1 -PostureCheck
# For initial SAM fixes and vss removal
.\Get-HiveNightmareStatus.ps1 -Remediate
# Remediate even if the checks say healthy or are partial
.\Get-HiveNightmareStatus.ps1 -Remediate -Force
.\Get-HiveNightmareStatus.ps1 -Exploit
sentinelone-policy-override.txt(.\sentinelctl.exe config | Select-String -Pattern "vssSnapshots|penetration")$ (.\sentinelctl.exe config | Select-String -Pattern "vssSnapshots|penetration")
agent.enginesWantedState.penetration off
agent.vssSnapshots false