ScreenConnect 25.9.10.9546 client Installer EXE getting flagged repeatedly by SentinelOne XDR
After upgrading our ScreenConnect instance to the new 25.9.10.9546 version to resolve "Client installer's SHA-256 hash changes on every download" (which we thought might be an issue with antivirus, among other things --note, when "Installer" is mentioned they don't say MSI or EXE), the new SentinelOne Client Installer .EXE file gets flagged repeatedly by SentinelOne XDR.
This causes a major issue for us. We are on-prem, and while we have a code-signing certificate which shows perfectly for the MSI installer, the EXE installer (which is called by the ScreenConnect program to update our technicians workstations) has no signer, and this is the file that is repeatedly flagged. Also, despite the fact that Connectwise is a partner with SentinelOne (indeed, the Connectwise Fortify Endpoint solution is just SentinelOne, which is what we're using), this makes it appear as if Connectwise is not engaging with SentinelOne to ensure their ScreenConnect installer doesn't run afoul of one of their security integration partners.
I could create a hash exception for the EXE file, but my concern is that our hash file and the hash file of other MSPs installs is the same, meaning a rogue installer .EXE looks the same as ours and would slip through. If this were the MSI file, I could create an exception by Publisher, but it isn't and there is no publisher. I need to keep this from happening every time we get a new version of ScreenConnect, and I need the
ScreenConnect //Connectwise team to use its contacts with SentinelOne to collaborate with them to prevent its future occurrence, as it causes significant issues. Or, I need your team to figure out how to use the MSI file for everything (including updates and rid us of the EXE file altogether, so we may rely on our signing certificate.