I have a local competitor who offices right down the street from our office. Bigger MSP than us, fairly mature, we've had a few clients off board from them to us. But we have never met up or talked shop or anything like that.
We did a deployment on a client that moved from them to us and the first night our MDR team notified us of a threat on one of the PCs. Confirmed that the previous MSPs tools had been on the machine in question, including their security stack (I won't bad mouth which one), and the issue was not caught prior to changing to our stack.
My question is do I reach out to the competitor and let them know about it? That potentially their MDR/EDR is missing things. Do I keep it to myself in the hopes that it leads to more clients jumping ship? I feel like professional courtesy dictates that I let them know. What would you do and how would you start a conversation like that?
Here is the MDR alert (sanitized).
Hi Team,
Security Incident Report — DESKTOP-*********
Date: July 17, 2026
Severity: Critical
Status: Mitigated — Further action recommended
---
We are reaching out to inform you of a critical security incident detected on one of your endpoints that required manual intervention by our MDR team and may need further action on your side
to fully resolve.
Summary
On July 17, 2026 at 00:28 UTC, our Managed Detection and Response (MDR) team identified a malicious Python-based implant executing on the endpoint DESKTOP-*********. The threat was initially detected by SentinelOne's EDR engine with a "suspicious" confidence level, which means the agent flagged the activity but did not automatically remediate it. Our MDR team reviewed the detection, confirmed it as malicious, and manually initiated full mitigation (kill, quarantine, remediation, and rollback).
What Happened
A malicious file disguised as image.png was executed from a hidden persistence directory (C:\Users\*******\AppData\Roaming\Microsoft\WindowsUpdate\). This directory mimics a legitimate Windows path but is not used by genuine Windows Update processes. Upon execution, the malware:
Masqueraded as a legitimate Windows process (svchost.exe)
Established a command-and-control (C2) connection to an external IP address (176.125.243[.]136) on port 56001
Performed process injection into multiple running applications over a 43-minute window, including browsers (Edge, Chrome), productivity software (Excel, Slack, Acrobat), and the SentinelOne security agent itself
Why Automatic Remediation Did Not Occur
SentinelOne classifies detections with a confidence level — either "malicious" or "suspicious." Only detections classified as "malicious" are automatically mitigated by the agent. In this case, the behavioral detection was classified as "suspicious," so the agent alerted on the activity but waited for analyst review before taking action. Our MDR team confirmed the threat and manually triggered full remediation.
Response Actions Taken
- The threat was detected and flagged by SentinelOne EDR
- Our MDR team confirmed the detection as a true positive
- A full mitigation was manually executed: the malicious process was killed, the file was quarantined, and system changes were rolled back
- The C2 IP address 176.125.243[.]136 has been identified for network-level blocking
Recommended Actions
Network isolation of DESKTOP-********* until a full forensic review is completed, to prevent further C2 communication in the event of re-execution
Full forensic sweep of the endpoint to identify and remove any remaining persistence mechanisms, particularly within the C:\Users\*******\ user profile
Review the "*******" local user account — this account was used to stage the malware and may have been created by the attacker. If it is not a recognized account, it should be disabled and removed
Block C2 IP 176.125.243[.]136 at the firewall/network perimeter level
Review network logs for any other endpoints that may have communicated with 176.125.243[.]136
Please let us know if you would like to proceed with network isolation or if you have any questions.
Guardz MDR Team