False Positive Detections Related to N-sight Feature

N-able’s N‑sight component triggered false positive alerts from SentinelOne’s Behavioral AI, blocking internet access and disabling protection on some endpoints. SentinelOne confirmed the issue and N‑able added the file to an exclusion list to stop the alerts. No user action is needed, but contacts support for lingering problems.

A component of N‑sight was mistakenly identified by SentinelOne’s Behavioral AI engine as malicious. The engine then applied its mitigation steps, which included blocking internet traffic and turning off protection on several endpoints. SentinelOne’s investigation confirmed that the detections were false positives rather than genuine threats. Endpoints that run the N‑sight component together with SentinelOne Endpoint Detection & Response experienced the unintended blocks. The issue impacted devices where the flagged file was present, causing loss of connectivity and disabled security functions. The scope of affected systems is limited to those using this specific integration. SentinelOne has added the implicated file to an exclusion list, which stops the false alerts and restores normal operation. No direct remediation is required from administrators, although lingering connectivity problems should be reported to Support. The vendor’s knowledge‑base article provides additional context for the change.