# Elastic Endpoint Restarted

**URL:** <https://discuss.elastic.co/t/elastic-endpoint-restarted/349375>\
**Category:** Elastic Security\
**Created:** [December 14, 2023, 2:26pm UTC](https://discuss.elastic.co/t/elastic-endpoint-restarted/349375 "2023-12-14T14:26:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sourcreamnormanbates](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Post date:** [December 14, 2023, 2:26pm UTC](https://discuss.elastic.co/t/elastic-endpoint-restarted/349375/1 "2023-12-14T14:26:40Z")

</div>

I'm trying to understand what happened recently where this command ran on a desktop "sc.exe start ElasticEndpoint restarted"

We also use SentinelOne, and SentinelOne detected that activity as malicious, so I'm trying to figure how to exclude this and prevent others from experiencing a random reboot.

---

<div class="post-metadata">

**Author:** ![Ben\_McNichols](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben_mcnichols/32/88135_2.png) [@Ben\_McNichols](https://discuss.elastic.co/u/Ben_McNichols)\
**Post date:** [December 14, 2023, 6:15pm UTC](https://discuss.elastic.co/t/elastic-endpoint-restarted/349375/2 "2023-12-14T18:15:01Z")

</div>

Hi Aaron,

The command "sc.exe start ElasticEndpoint restarted" would have been executed by the service control manager as a configured service recovery action, almost certainly as the result of the ElasticEndpoint service having crashed. This action restarts the Elastic Endpoint service to attempt to restore it to a functioning state. The action is not malicious.

However, it's concerning that the Endpoint crashed and needed to be restarted. We attempt to ensure that a crash dump file is produced if we crash, and it's likely you'd find a `.dmp` file either in `c:\Program Files\Elastic\Endpoint\cache\CrashDumps\` or `c:\Program Files\Elastic\Endpoint\cache\`. If you'd be willing to share that crash dump with us, it's possible we could determine why our Endpoint service crashed. If you'd be willing to do that, please message me directly and I can provide you with a mechanism to securely share the file.

Thanks,  
Ben

---

<div class="post-metadata">

**Author:** ![sourcreamnormanbates](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Post date:** [December 20, 2023, 2:51pm UTC](https://discuss.elastic.co/t/elastic-endpoint-restarted/349375/3 "2023-12-20T14:51:36Z")

</div>

Ben,  
I reviewed the dump file which was about 500MB.  
It looks like SentinelOne was probably the cause of the problem and I just needed to add the executable hash to the list of exclusions.  
Thanks for pointing me in the right direction.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2024, 2:52pm UTC](https://discuss.elastic.co/t/elastic-endpoint-restarted/349375/4 "2024-01-17T14:52:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
