Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Sentinelone

BSecurity

Expert agent for SentinelOne Singularity EDR platform. Covers Storyline technology, autonomous response, 1-click rollback, Deep Visibility threat hunting, Purple AI, Ranger network discovery, and STAR rules. WHEN: \"SentinelOne\", \"Singularity\", \"Storyline\", \"Deep Visibility\", \"Purple AI\", \"1-click rollback\", \"Ranger\", \"STAR rule\", \"S1 agent\".

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
devopsgoshellbashsqlexpresskubernetesawsgcpazuresecurity

Works with

cli

Security Analysis

B88/100
criticalModifies startup scripts or system services for persistence

Pro scans all 2 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill sentinelone --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sentinelone?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Sentinelone
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-sentinelone/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-sentinelone)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: sentinelone
description: "Expert agent for SentinelOne Singularity EDR platform. Covers Storyline technology, autonomous response, 1-click rollback, Deep Visibility threat hunting, Purple AI, Ranger network discovery, and STAR rules. WHEN: \"SentinelOne\", \"Singularity\", \"Storyline\", \"Deep Visibility\", \"Purple AI\", \"1-click rollback\", \"Ranger\", \"STAR rule\", \"S1 agent\"."
license: MIT
---

# SentinelOne Singularity

This skill covers SentinelOne Singularity, the autonomous EDR/XDR platform. It has deep expertise in Storyline technology, autonomous response configuration, 1-click rollback, Deep Visibility threat hunting, Purple AI, STAR (Storyline Active Response) rules, and the Singularity platform architecture.

## How to Approach Tasks

When you receive a request:

1. **Determine the tier** — Core, Control, Complete, or Enterprise. Deep Visibility (90-day telemetry) and Purple AI require Complete+. Confirm tier before recommending features.

2. **Classify the request type:**
   - **Architecture / deployment** — Load `references/architecture.md`
   - **Policy configuration** — Use protection mode and policy guidance below
   - **Threat hunting** — Deep Visibility queries and Purple AI guidance
   - **Incident response** — Storyline investigation and rollback procedures
   - **STAR rules** — Custom detection/response rule authoring
   - **Ranger** — Network discovery and rogue device identification

3. **Load context** — Read `references/architecture.md` for deployment and Storyline deep knowledge.

4. **Analyze** — Apply SentinelOne-specific reasoning. Understand that Storyline automatically correlates events into attack narratives — investigation starts with the Storyline, not individual events.

## SentinelOne Platform Tiers

| Feature | Core | Control | Complete | Enterprise |
|---|---|---|---|---|
| NGAV (static + behavioral) | Yes | Yes | Yes | Yes |
| Storyline (behavioral EDR) | Basic | Yes | Yes | Yes |
| Autonomous response | Yes | Yes | Yes | Yes |
| 1-click rollback | Yes | Yes | Yes | Yes |
| Deep Visibility telemetry | 14 days | 14 days | 90 days | 90 days |
| Purple AI (natural language hunting) | No | No | Yes | Yes |
| Ranger (network discovery) | No | Yes | Yes | Yes |
| Singularity Data Lake | No | No | Limited | Yes |
| Vigilance MDR service | Add-on | Add-on | Add-on | Add-on |
| Remote Shell | No | Yes | Yes | Yes |

## Agent Deployment

### Supported Platforms

| Platform | Minimum Version |
|---|---|
| Windows | Windows 7 SP1 / Server 2008 R2 |
| macOS | macOS 10.14 (Mojave) |
| Linux | RHEL 6, Ubuntu 14.04, Debian 8 |
| Windows Server Core | Supported |
| Kubernetes | DaemonSet via Helm chart |
| Cloud (AWS/Azure/GCP) | Standard agent |

### Windows Installation

```powershell
# Silent install
msiexec /i SentinelOneInstaller.msi /quiet /norestart SITE_TOKEN="<site_token>"

# Verify installation
Get-Service -Name SentinelAgent | Select Status
# Should be: Running

# Check agent version
Get-ItemProperty "HKLM:\SOFTWARE\SentinelOne\Agent" | Select Version

# Check agent health via command line
"C:\Program Files\SentinelOne\Sentinel Agent <version>\SentinelCtl.exe" status
```

### Linux Installation

```bash
# RPM-based
sudo rpm -ivh SentinelAgent_linux_v<version>.rpm
sudo sentinelctl management token set --token <site_token>
sudo systemctl start sentinelagent
sudo systemctl enable sentinelagent

# DEB-based
sudo dpkg -i SentinelAgent_linux_v<version>.deb
sudo sentinelctl management token set --token <site_token>
sudo systemctl start sentinelagent

# Verify
sudo sentinelctl status
```

### macOS Installation

```bash
sudo installer -pkg SentinelOne.pkg -target /
# Approve System Extension in System Preferences > Security & Privacy
# Grant Full Disk Access to SentinelOne from MDM profile or manually

# Verify
sudo sentinelctl status
```

## Protection Modes

SentinelOne uses a dual-mode model: **Detect** and **Protect**.

### Agent Policy Modes

| Mode | Detection | Prevention | Use Case |
|---|---|---|---|
| Detect | Generates alerts | No blocking | Audit/rollout phase |
| Protect | Generates alerts | Blocks malicious activity | Production (recommended) |
| Detect + Protect | Both active per category | Mixed | Transitional configurations |

### Threat Engine Configuration

Within a policy, each detection engine can be independently configured:

| Engine | Description | Detect Mode | Protect Mode |
|---|---|---|---|
| Static AI (pre-execution) | ML analysis of files before execution | Alert | Block |
| Behavioral AI (post-execution) | Storyline-based behavioral analysis | Alert | Kill + Quarantine |
| Reputation | File hash lookup against S1 cloud | Alert | Block |
| Anti-Exploit | Memory-based exploit techniques | Alert | Block |
| Anti-Ransomware | Mass encryption + shadow copy deletion | Alert | Kill + Rollback |
| PUA/PUP | Potentially unwanted applications | Alert | Quarantine |

### Behavioral Protection Action Flow

When a threat is detected in Protect mode:
1. **Kill** — Malicious process tree is terminated
2. **Quarantine** — Malicious files moved to quarantine vault (`.s1q` files in quarantine folder)
3. **Remediate** — Automatically reverses attacker changes (registry, files, scheduled tasks)
4. **Rollback** — If ransomware detected, offers 1-click VSS rollback

## Storyline Investigation

### Understanding Storyline

Storyline is SentinelOne's core differentiator — an automatic correlation engine that tracks process relationships and constructs attack narratives (Storyline IDs) representing an entire attack chain.

**Each Storyline captures:**
- Root process (entry point of the attack)
- All descendant processes (full process tree)
- Files written by any process in the tree
- Network connections made
- Registry modifications
- Module loads
- User context changes

**Storyline ID (STID):** A unique identifier assigned to each attack narrative. All events in the same attack chain share the same STID. This eliminates the need for manual event correlation — the platform does it automatically.

### Investigating a Detection in Storyline View

1. Navigate to: Incidents > Threat > click the threat
2. View the **Storyline** tab:
   - Timeline of all related events
   - Process tree visualization (parent → child relationships)
   - File, network, registry activity per process
3. Review the **Evidence** tab:
   - Files written (with hashes)
   - Network destinations
   - Registry changes
4. Review **Attack Details**:
   - MITRE ATT&CK technique mapping
   - Severity assessment
   - Confidence level

### Storyline Forensic Queries

Useful queries in Deep Visibility for Storyline investigation:

```sql
-- Find all events for a specific Storyline ID
EventType = "Storyline" AND StorylineId = "STID_VALUE"

-- All processes in a Storyline
EventType = "Process" AND StorylineId = "STID_VALUE"
| columns Timestamp, ProcessName, CommandLine, User, ParentProcessName

-- All network connections in a Storyline
EventType = "IP" AND StorylineId = "STID_VALUE"
| columns Timestamp, ProcessName, RemoteIP, RemotePort, Direction

-- All file writes in a Storyline
EventType = "File" AND StorylineId = "STID_VALUE" AND EventCategory = "actions on object"
| columns Timestamp, ProcessName, FilePath, FileSHA256
```

## Deep Visibility Threat Hunting

Deep Visibility provides access to 14 (Core/Control) or 90 (Complete/Enterprise) days of raw endpoint telemetry.

### Deep Visibility Query Language

Deep Visibility uses a SQL-like query language:

**Basic syntax:**
```sql
EventType = "Process" AND ProcessName = "powershell.exe"
  AND CommandLine CONTAINS "-enc"
```

**Key operators:**
- `=`, `!=` — Exact match
- `CONTAINS` — Substring match
- `IN` — Match list
- `STARTS WITH`, `ENDS WITH`
- `>`, `<`, `>=`, `<=` — Numeric/date comparisons
- `AND`, `OR`, `NOT`

**Result columns:**
```sql
| columns Timestamp, AgentName, ProcessName, CommandLine, User, ParentProcessName, FilePath
```

**Aggregations:**
```sql
| group by ProcessName
| count
| sort by count desc
```

### Core Event Types

| EventType | Description |
|---|---|
| `Process` | Process create/terminate |
| `File` | File create/modify/delete |
| `IP` | Network connection |
| `DNS` | DNS query |
| `Registry` | Registry read/write |
| `Module` | DLL/module load |
| `Login` | Authentication events |
| `Task` | Scheduled task events |
| `Service` | Service install/start/stop |

### Deep Visibility Hunting Queries

**Suspicious PowerShell:**
```sql
EventType = "Process"
  AND ProcessName = "powershell.exe"
  AND (CommandLine CONTAINS "-enc"
    OR CommandLine CONTAINS "bypass"
    OR CommandLine CONTAINS "hidden"
    OR CommandLine CONTAINS "iex"
    OR CommandLine CONTAINS "invoke-expression")
| columns Timestamp, AgentName, User, CommandLine, ParentProcessName, StorylineId
| sort by Timestamp desc
```

**Office spawning scripting engines:**
```sql
EventType = "Process"
  AND ParentProcessName IN ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe")
  AND ProcessName IN ("cmd.exe", "powershell.exe", "wscript.exe", "cscript.exe",
                       "mshta.exe", "regsvr32.exe", "rundll32.exe")
| columns Timestamp, AgentName, User, ParentProcessName, ProcessName, CommandLine, StorylineId
| sort by Timestamp desc
```

**LSASS access:**
```sql
EventType = "Process"
  AND TgtProcessName CONTAINS "lsass"
  AND SrcProcessName NOT IN ("services.exe", "wininit.exe", "csrss.exe",
                               "werfault.exe", "taskmgr.exe", "MsMpEng.exe",
                               "SentinelAgent.exe")
| columns Timestamp, AgentName, User, SrcProcessName, SrcProcessCommandLine, TgtProcessName, StorylineId
```

**Ransomware pre-execution indicators:**
```sql
EventType = "Process"
  AND (CommandLine CONTAINS "vssadmin delete shadows"
    OR CommandLine CONTAINS "wmic shadowcopy delete"
    OR CommandLine CONTAINS "bcdedit /set recoveryenabled no"
    OR CommandLine CONTAINS "wbadmin delete catalog")
| columns Timestamp, AgentName, User, ProcessName, CommandLine, StorylineId
```

**DNS to suspicious high-entropy domains (DGA):**
```sql
EventType = "DNS"
  AND DnsType = "Query"
  AND DNS NOT ENDS WITH ".microsoft.com"
  AND DNS NOT ENDS WITH ".windows.com"
  AND DNS NOT ENDS WITH ".windowsupdate.com"
| group by DNS, AgentName
| count
| sort by count asc  // Low-count DNS = unique/DGA-like domains
| limit 100
```

## Purple AI (Natural Language Hunting)

Purple AI is SentinelOne's generative AI hunting interface available in Complete and Enterprise tiers.

### Capabilities

- **Natural language to query**: "Show me all PowerShell executions with encoded commands in the last 7 days"
- **Query explanation**: Explains what a Deep Visibility query does in plain English
- **Anomaly investigation**: "Why is this threat significant?"
- **Threat summarization**: Automatic narrative generation for detections
- **Guided investigation**: "What should I investigate next?"

### Effective Purple AI Prompts

```
Hunting:
- "Find all endpoints where a process ran from the Temp folder and made an outbound connection in the last 24 hours"
- "Show me any process that read LSASS memory that wasn't a security tool in the past week"
- "Which endpoints had encoded PowerShell executions yesterday?"

Investigation:
- "Summarize this Storyline and explain the attack chain"
- "What is the MITRE ATT&CK mapping for this detection?"
- "Is there any related activity on other endpoints?"

Context:
- "What is [hash]? Is it malicious?"
- "Who is the threat actor using this technique?"
```

## 1-Click Rollback

Rollback reverses filesystem changes made during a ransomware attack using VSS (Volume Shadow Service) snapshots.

### Rollback Prerequisites

- Windows only (macOS/Linux: separate remediation approach)
- VSS must be enabled and have available shadow copies
- SentinelOne must have tracked the Storyline from the point of infection
- Rollback available within the retention window of shadow copies

### Rollback Execution

1. Navigate to: Incidents > select the ransomware detection
2. Click **Actions > Rollback**
3. System presents files that will be restored
4. Confirm rollback scope (can target specific files or full rollback)
5. Rollback executes; encrypted files replaced with pre-encryption versions

**Rollback behavior:**
- Restores files modified by processes in the malicious Storyline
- Deletes files created by the malicious Storyline
- Does NOT restore files deleted before SentinelOne captured the pre-encryption state
- Takes effect immediately; does not require reboot for most files

### Remediation vs. Rollback

| Action | When to Use | What It Does |
|---|---|---|
| Remediate | Non-ransomware threats | Removes files, reverses registry/task changes made by attack |
| Rollback | Ransomware / mass file modification | VSS-based full restoration of encrypted/modified files |
| Kill | Stop active attack only | Terminates processes, does not reverse changes |

## STAR Rules (Storyline Active Response)

STAR rules are custom automated detection and response rules that trigger on telemetry patterns.

### STAR Rule Structure

```json
{
  "name": "Suspicious Encoded PowerShell",
  "query": "EventType = 'Process' AND ProcessName = 'powershell.exe' AND CommandLine CONTAINS '-enc'",
  "severity": "High",
  "treatAsThreat": "SUSPICIOUS",
  "network_status": "connected",
  "auto_actions": {
    "kill_process": true,
    "quarantine_file": false,
    "network_quarantine": false
  },
  "alert_on_match": true
}
```

### STAR Rule Action Options

| Action | Description | Use With |
|---|---|---|
| Kill process | Terminate matching process and descendants | Confident detections |
| Quarantine file | Move matched file to quarantine vault | File-based indicators |
| Network quarantine | Isolate endpoint from all network | Confirmed active compromise |
| Alert only | Generate alert for SOC review | Uncertain detections |

### STAR Rule Best Practices

1. **Test in Detect mode** before enabling auto-actions
2. **Use StorylineId correlation** — Rules matching within an active Storyline are higher confidence
3. **Layer with IOC watchlists** — STAR rules for behavioral, IOC watchlists for known-bad hashes/domains
4. **Review regularly** — Check STAR rule hit rates monthly; tune noisy rules

### Example STAR Rules

**Certutil download from internet:**
```
Query: EventType = "Process"
  AND ProcessName = "certutil.exe"
  AND (CommandLine CONTAINS "-urlcache" OR CommandLine CONTAINS "-split")
  AND (CommandLine CONTAINS "http" OR CommandLine CONTAINS "ftp")
Severity: High
Auto-actions: Kill process, Alert
```

**Suspicious scheduled task creation:**
```
Query: EventType = "Task"
  AND EventCategory = "TaskAction Created"
  AND TaskAction CONTAINS "powershell"
Severity: Medium
Auto-actions: Alert only
```

## Ranger (Network Discovery)

Ranger performs agentless network discovery from endpoints with SentinelOne agents (Control tier+).

### Ranger Capabilities

- Discovers unmanaged devices on network segments visible to managed endpoints
- Identifies device type, OS, open ports, running services
- Highlights rogue or unexpected devices
- Does NOT require credentials or network access to central scanner

### Ranger Configuration

1. Navigate to: Singularity > Ranger
2. Configure scanning scope (network ranges)
3. Enable on agent policy: Policy > Ranger > Enable
4. Review discovered devices: Ranger > Discovered Devices

**Ranger is passive on managed endpoints** — agents collect ARP tables and broadcast responses without active port scanning (active scanning is optional and must be explicitly enabled).

### Responding to Rogue Device Discoveries

When Ranger discovers unexpected devices:
1. Review device fingerprint (OS, MAC address, open ports)
2. Query Deep Visibility for communication from managed endpoints to the rogue device
3. If confirmed unauthorized: Network quarantine nearby managed endpoints
4. Escalate to network team for switch port isolation

## Reference Files

Load for deep knowledge:

- `references/architecture.md` — Storyline technology internals, autonomous response engine, Deep Visibility pipeline, rollback mechanism, agent architecture, cloud/on-prem deployment models

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Terraform Module Library

Build reusable Terraform modules for AWS, Azure, and GCP infrastructure following infrastructure-as-code best practices. Use when creating infrastructure modules, standardizing cloud provisioning, or implementing reusable IaC components.

401991 votes

sematext-otel

Wire a service's OpenTelemetry output to Sematext Cloud. Walks through region, App-type, instrumentation flow (managed OTLP endpoint vs Sematext Agent), and signal selection (traces/metrics/logs), then produces the exact env-var block and points at a runnable reference example in this repo. Invoke when instrumenting a new app for Sematext.

01 votes

Deployment Patterns

Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up deployment infrastructure or planning releases.

2699140 votes

Babysit

Watch a pull request or review cycle until it is ready to merge. Use when asked to babysit, monitor, or keep checking PR comments, reviews, and CI until all actionable issues are resolved.

971540 votes

V7 Roster

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953190 votes
View all in devops →