Skip to content
Back to skills

Sentinelone

BSecurity

Expert agent for SentinelOne Singularity EDR platform. Covers Storyline technology, autonomous response, 1-click rollback, Deep Visibility threat hunting, Purple AI, Ranger network discovery, and STAR rules. WHEN: \"SentinelOne\", \"Singularity\", \"Storyline\", \"Deep Visibility\", \"Purple AI\", \"1-click rollback\", \"Ranger\", \"STAR rule\", \"S1 agent\".

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
devopsgoshellbashsqlexpresskubernetesawsgcpazuresecurity

Works with

  • cli

Security analysis

B88/100
  • criticalModifies startup scripts or system services for persistence

Pro scans all 2 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill sentinelone --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sentinelone?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Sentinelone
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-sentinelone/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-sentinelone)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: sentinelone
description: "Expert agent for SentinelOne Singularity EDR platform. Covers Storyline technology, autonomous response, 1-click rollback, Deep Visibility threat hunting, Purple AI, Ranger network discovery, and STAR rules. WHEN: \"SentinelOne\", \"Singularity\", \"Storyline\", \"Deep Visibility\", \"Purple AI\", \"1-click rollback\", \"Ranger\", \"STAR rule\", \"S1 agent\"."
license: MIT
---

# SentinelOne Singularity

This skill covers SentinelOne Singularity, the autonomous EDR/XDR platform. It has deep expertise in Storyline technology, autonomous response configuration, 1-click rollback, Deep Visibility threat hunting, Purple AI, STAR (Storyline Active Response) rules, and the Singularity platform architecture.

## How to Approach Tasks

When you receive a request:

1. **Determine the tier** — Core, Control, Complete, or Enterprise. Deep Visibility (90-day telemetry) and Purple AI require Complete+. Confirm tier before recommending features.

2. **Classify the request type:**
   - **Architecture / deployment** — Load `references/architecture.md`
   - **Policy configuration** — Use protection mode and policy guidance below
   - **Threat hunting** — Deep Visibility queries and Purple AI guidance
   - **Incident response** — Storyline investigation and rollback procedures
   - **STAR rules** — Custom detection/response rule authoring
   - **Ranger** — Network discovery and rogue device identification

3. **Load context** — Read `references/architecture.md` for deployment and Storyline deep knowledge.

4. **Analyze** — Apply SentinelOne-specific reasoning. Understand that Storyline automatically correlates events into attack narratives — investigation starts with the Storyline, not individual events.

## SentinelOne Platform Tiers

| Feature | Core | Control | Complete | Enterprise |
|---|---|---|---|---|
| NGAV (static + behavioral) | Yes | Yes | Yes | Yes |
| Storyline (behavioral EDR) | Basic | Yes | Yes | Yes |
| Autonomous response | Yes | Yes | Yes | Yes |
| 1-click rollback | Yes | Yes | Yes | Yes |
| Deep Visibility telemetry | 14 days | 14 days | 90 days | 90 days |
| Purple AI (natural language hunting) | No | No | Yes | Yes |
| Ranger (network discovery) | No | Yes | Yes | Yes |
| Singularity Data Lake | No | No | Limited | Yes |
| Vigilance MDR service | Add-on | Add-on | Add-on | Add-on |
| Remote Shell | No | Yes | Yes | Yes |

## Agent Deployment

### Supported Platforms

| Platform | Minimum Version |
|---|---|
| Windows | Windows 7 SP1 / Server 2008 R2 |
| macOS | macOS 10.14 (Mojave) |
| Linux | RHEL 6, Ubuntu 14.04, Debian 8 |
| Windows Server Core | Supported |
| Kubernetes | DaemonSet via Helm chart |
| Cloud (AWS/Azure/GCP) | Standard agent |

### Windows Installation

```powershell
# Silent install
msiexec /i SentinelOneInstaller.msi /quiet /norestart SITE_TOKEN="<site_token>"

# Verify installation
Get-Service -Name SentinelAgent | Select Status
# Should be: Running

# Check agent version
Get-ItemProperty "HKLM:\SOFTWARE\SentinelOne\Agent" | Select Version

# Check agent health via command line
"C:\Program Files\SentinelOne\Sentinel Agent <version>\SentinelCtl.exe" status
```

### Linux Installation

```bash
# RPM-based
sudo rpm -ivh SentinelAgent_linux_v<version>.rpm
sudo sentinelctl management token set --token <site_token>
sudo systemctl start sentinelagent
sudo systemctl enable sentinelagent

# DEB-based
sudo dpkg -i SentinelAgent_linux_v<version>.deb
sudo sentinelctl management token set --token <site_token>
sudo systemctl start sentinelagent

# Verify
sudo sentinelctl status
```

### macOS Installation

```bash
sudo installer -pkg SentinelOne.pkg -target /
# Approve System Extension in System Preferences > Security & Privacy
# Grant Full Disk Access to SentinelOne from MDM profile or manually

# Verify
sudo sentinelctl status
```

## Protection Modes

SentinelOne uses a dual-mode model: **Detect** and **Protect**.

### Agent Policy Modes

| Mode | Detection | Prevention | Use Case |
|---|---|---|---|
| Detect | Generates alerts | No blocking | Audit/rollout phase |
| Protect | Generates alerts | Blocks malicious activity | Production (recommended) |
| Detect + Protect | Both active per category | Mixed | Transitional configurations |

### Threat Engine Configuration

Within a policy, each detection engine can be independently configured:

| Engine | Description | Detect Mode | Protect Mode |
|---|---|---|---|
| Static AI (pre-execution) | ML analysis of files before execution | Alert | Block |
| Behavioral AI (post-execution) | Storyline-based behavioral analysis | Alert | Kill + Quarantine |
| Reputation | File hash lookup against S1 cloud | Alert | Block |
| Anti-Exploit | Memory-based exploit techniques | Alert | Block |
| Anti-Ransomware | Mass encryption + shadow copy deletion | Alert | Kill + Rollback |
| PUA/PUP | Potentially unwanted applications | Alert | Quarantine |

### Behavioral Protection Action Flow

When a threat is detected in Protect mode:
1. **Kill** — Malicious process tree is terminated
2. **Quarantine** — Malicious files moved to quarantine vault (`.s1q` files in quarantine folder)
3. **Remediate** — Automatically reverses attacker changes (registry, files, scheduled tasks)
4. **Rollback** — If ransomware detected, offers 1-click VSS rollback

## Storyline Investigation

### Understanding Storyline

Storyline is SentinelOne's core differentiator — an automatic correlation engine that tracks process relationships and constructs attack narratives (Storyline IDs) representing an entire attack chain.

**Each Storyline captures:**
- Root process (entry point of the attack)
- All descendant processes (full process tree)
- Files written by any process in the tree
- Network connections made
- Registry modifications
- Module loads
- User context changes

**Storyline ID (STID):** A unique identifier assigned to each attack narrative. All events in the same attack chain share the same STID. This eliminates the need for manual event correlation — the platform does it automatically.

### Investigating a Detection in Storyline View

1. Navigate to: Incidents > Threat > click the threat
2. View the **Storyline** tab:
   - Timeline of all related events
   - Process tree visualization (parent → child relationships)
   - File, network, registry activity per process
3. Review the **Evidence** tab:
   - Files written (with hashes)
   - Network destinations
   - Registry changes
4. Review **Attack Details**:
   - MITRE ATT&CK technique mapping
   - Severity assessment
   - Confidence level

### Storyline Forensic Queries

Useful queries in Deep Visibility for Storyline investigation:

```sql
-- Find all events for a specific Storyline ID
EventType = "Storyline" AND StorylineId = "STID_VALUE"

-- All processes in a Storyline
EventType = "Process" AND StorylineId = "STID_VALUE"
| columns Timestamp, ProcessName, CommandLine, User, ParentProcessName

-- All network connections in a Storyline
EventType = "IP" AND StorylineId = "STID_VALUE"
| columns Timestamp, ProcessName, RemoteIP, RemotePort, Direction

-- All file writes in a Storyline
EventType = "File" AND StorylineId = "STID_VALUE" AND EventCategory = "actions on object"
| columns Timestamp, ProcessName, FilePath, FileSHA256
```

## Deep Visibility Threat Hunting

Deep Visibility provides access to 14 (Core/Control) or 90 (Complete/Enterprise) days of raw endpoint telemetry.

### Deep Visibility Query Language

Deep Visibility uses a SQL-like query language:

**Basic syntax:**
```sql
EventType = "Process" AND ProcessName = "powershell.exe"
  AND CommandLine CONTAINS "-enc"
```

**Key operators:**
- `=`, `!=` — Exact match
- `CONTAINS` — Substring match
- `IN` — Match list
- `STARTS WITH`, `ENDS WITH`
- `>`, `<`, `>=`, `<=` — Numeric/date comparisons
- `AND`, `OR`, `NOT`

**Result columns:**
```sql
| columns Timestamp, AgentName, ProcessName, CommandLine, User, ParentProcessName, FilePath
```

**Aggregations:**
```sql
| group by ProcessName
| count
| sort by count desc
```

### Core Event Types

| EventType | Description |
|---|---|
| `Process` | Process create/terminate |
| `File` | File create/modify/delete |
| `IP` | Network connection |
| `DNS` | DNS query |
| `Registry` | Registry read/write |
| `Module` | DLL/module load |
| `Login` | Authentication events |
| `Task` | Scheduled task events |
| `Service` | Service install/start/stop |

### Deep Visibility Hunting Queries

**Suspicious PowerShell:**
```sql
EventType = "Process"
  AND ProcessName = "powershell.exe"
  AND (CommandLine CONTAINS "-enc"
    OR CommandLine CONTAINS "bypass"
    OR CommandLine CONTAINS "hidden"
    OR CommandLine CONTAINS "iex"
    OR CommandLine CONTAINS "invoke-expression")
| columns Timestamp, AgentName, User, CommandLine, ParentProcessName, StorylineId
| sort by Timestamp desc
```

**Office spawning scripting engines:**
```sql
EventType = "Process"
  AND ParentProcessName IN ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe")
  AND ProcessName IN ("cmd.exe", "powershell.exe", "wscript.exe", "cscript.exe",
                       "mshta.exe", "regsvr32.exe", "rundll32.exe")
| columns Timestamp, AgentName, User, ParentProcessName, ProcessName, CommandLine, StorylineId
| sort by Timestamp desc
```

**LSASS access:**
```sql
EventType = "Process"
  AND TgtProcessName CONTAINS "lsass"
  AND SrcProcessName NOT IN ("services.exe", "wininit.exe", "csrss.exe",
                               "werfault.exe", "taskmgr.exe", "MsMpEng.exe",
                               "SentinelAgent.exe")
| columns Timestamp, AgentName, User, SrcProcessName, SrcProcessCommandLine, TgtProcessName, StorylineId
```

**Ransomware pre-execution indicators:**
```sql
EventType = "Process"
  AND (CommandLine CONTAINS "vssadmin delete shadows"
    OR CommandLine CONTAINS "wmic shadowcopy delete"
    OR CommandLine CONTAINS "bcdedit /set recoveryenabled no"
    OR CommandLine CONTAINS "wbadmin delete catalog")
| columns Timestamp, AgentName, User, ProcessName, CommandLine, StorylineId
```

**DNS to suspicious high-entropy domains (DGA):**
```sql
EventType = "DNS"
  AND DnsType = "Query"
  AND DNS NOT ENDS WITH ".microsoft.com"
  AND DNS NOT ENDS WITH ".windows.com"
  AND DNS NOT ENDS WITH ".windowsupdate.com"
| group by DNS, AgentName
| count
| sort by count asc  // Low-count DNS = unique/DGA-like domains
| limit 100
```

## Purple AI (Natural Language Hunting)

Purple AI is SentinelOne's generative AI hunting interface available in Complete and Enterprise tiers.

### Capabilities

- **Natural language to query**: "Show me all PowerShell executions with encoded commands in the last 7 days"
- **Query explanation**: Explains what a Deep Visibility query does in plain English
- **Anomaly investigation**: "Why is this threat significant?"
- **Threat summarization**: Automatic narrative generation for detections
- **Guided investigation**: "What should I investigate next?"

### Effective Purple AI Prompts

```
Hunting:
- "Find all endpoints where a process ran from the Temp folder and made an outbound connection in the last 24 hours"
- "Show me any process that read LSASS memory that wasn't a security tool in the past week"
- "Which endpoints had encoded PowerShell executions yesterday?"

Investigation:
- "Summarize this Storyline and explain the attack chain"
- "What is the MITRE ATT&CK mapping for this detection?"
- "Is there any related activity on other endpoints?"

Context:
- "What is [hash]? Is it malicious?"
- "Who is the threat actor using this technique?"
```

## 1-Click Rollback

Rollback reverses filesystem changes made during a ransomware attack using VSS (Volume Shadow Service) snapshots.

### Rollback Prerequisites

- Windows only (macOS/Linux: separate remediation approach)
- VSS must be enabled and have available shadow copies
- SentinelOne must have tracked the Storyline from the point of infection
- Rollback available within the retention window of shadow copies

### Rollback Execution

1. Navigate to: Incidents > select the ransomware detection
2. Click **Actions > Rollback**
3. System presents files that will be restored
4. Confirm rollback scope (can target specific files or full rollback)
5. Rollback executes; encrypted files replaced with pre-encryption versions

**Rollback behavior:**
- Restores files modified by processes in the malicious Storyline
- Deletes files created by the malicious Storyline
- Does NOT restore files deleted before SentinelOne captured the pre-encryption state
- Takes effect immediately; does not require reboot for most files

### Remediation vs. Rollback

| Action | When to Use | What It Does |
|---|---|---|
| Remediate | Non-ransomware threats | Removes files, reverses registry/task changes made by attack |
| Rollback | Ransomware / mass file modification | VSS-based full restoration of encrypted/modified files |
| Kill | Stop active attack only | Terminates processes, does not reverse changes |

## STAR Rules (Storyline Active Response)

STAR rules are custom automated detection and response rules that trigger on telemetry patterns.

### STAR Rule Structure

```json
{
  "name": "Suspicious Encoded PowerShell",
  "query": "EventType = 'Process' AND ProcessName = 'powershell.exe' AND CommandLine CONTAINS '-enc'",
  "severity": "High",
  "treatAsThreat": "SUSPICIOUS",
  "network_status": "connected",
  "auto_actions": {
    "kill_process": true,
    "quarantine_file": false,
    "network_quarantine": false
  },
  "alert_on_match": true
}
```

### STAR Rule Action Options

| Action | Description | Use With |
|---|---|---|
| Kill process | Terminate matching process and descendants | Confident detections |
| Quarantine file | Move matched file to quarantine vault | File-based indicators |
| Network quarantine | Isolate endpoint from all network | Confirmed active compromise |
| Alert only | Generate alert for SOC review | Uncertain detections |

### STAR Rule Best Practices

1. **Test in Detect mode** before enabling auto-actions
2. **Use StorylineId correlation** — Rules matching within an active Storyline are higher confidence
3. **Layer with IOC watchlists** — STAR rules for behavioral, IOC watchlists for known-bad hashes/domains
4. **Review regularly** — Check STAR rule hit rates monthly; tune noisy rules

### Example STAR Rules

**Certutil download from internet:**
```
Query: EventType = "Process"
  AND ProcessName = "certutil.exe"
  AND (CommandLine CONTAINS "-urlcache" OR CommandLine CONTAINS "-split")
  AND (CommandLine CONTAINS "http" OR CommandLine CONTAINS "ftp")
Severity: High
Auto-actions: Kill process, Alert
```

**Suspicious scheduled task creation:**
```
Query: EventType = "Task"
  AND EventCategory = "TaskAction Created"
  AND TaskAction CONTAINS "powershell"
Severity: Medium
Auto-actions: Alert only
```

## Ranger (Network Discovery)

Ranger performs agentless network discovery from endpoints with SentinelOne agents (Control tier+).

### Ranger Capabilities

- Discovers unmanaged devices on network segments visible to managed endpoints
- Identifies device type, OS, open ports, running services
- Highlights rogue or unexpected devices
- Does NOT require credentials or network access to central scanner

### Ranger Configuration

1. Navigate to: Singularity > Ranger
2. Configure scanning scope (network ranges)
3. Enable on agent policy: Policy > Ranger > Enable
4. Review discovered devices: Ranger > Discovered Devices

**Ranger is passive on managed endpoints** — agents collect ARP tables and broadcast responses without active port scanning (active scanning is optional and must be explicitly enabled).

### Responding to Rogue Device Discoveries

When Ranger discovers unexpected devices:
1. Review device fingerprint (OS, MAC address, open ports)
2. Query Deep Visibility for communication from managed endpoints to the rogue device
3. If confirmed unauthorized: Network quarantine nearby managed endpoints
4. Escalate to network team for switch port isolation

## Reference Files

Load for deep knowledge:

- `references/architecture.md` — Storyline technology internals, autonomous response engine, Deep Visibility pipeline, rollback mechanism, agent architecture, cloud/on-prem deployment models

Files in this skill

  • SKILL.md15.9 KB
  • references/architecture.md12.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…