Skip to content

acquiredsecurity/SentinelOne-ThreatHunting-and-XDR-Guide

Repository files navigation

Welcome to my Threat Hunting and XDR Guide for SentinelOne!

Sections:

I. SentinelOne Threat Hunting Guide

II. Skylight-DeepViz2Skylight -- Dashboards and queries built around the traditional DeepVizibility indicator view with the new Skylight feature in SentinelOne. Provides basic queries and visualizations for the following:

a. Processes & Cross Processes
b. Indicators
c. Files & Drivers
d. Network and DNS
e. URL
f. Registry
g. Scheduled Tasks
h. Event Logs / Logins
i. Command Scripts
j. Named Pipes

III. Skylight-GeoLocations

IV. Skylight-PowerShell

V. XDR-O365

About

Beginners Guide to Hunting for Threats

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published