SentinelOne - IR Handbook - SentinelOne-IR-Handbook

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

SentinelOne

IR Handbook

IR Handbook
November 2021
Introduction 4

Preparation 5
General 5
Endpoints 5
Asset management 6
Network 6
Incident Information 6
Goals 6

Deployment 7
Prerequisites 7
Console Preparation 8
Groups and Policies 8
Exclusion Best Practices 12
Using Exclusion Catalog 12
Some of the most common recommended exclusions: 13
Rollout 16
Choose your deployment methodology 16
Choose your deployment strategy 17
Consider the actual status of the hosts 18
Land on Default and dispatch 18
Which machine should go first 18

Incident Response 20
Incidents Page 20
Threat Lifecycle 22
Threat Status 22
The Analyst Verdict 22
Incident Status 23
Responding to a threat 24
False Positives 26
Hunting with Deep Visibility 26
Syntax Notes 26
Query types 27
MITRE ATT&CK Indicators 28
Other useful KB Resources: 28
STAR Rules 29
Creating a STAR Rule 29
STAR Rules Examples 32

SentinelOne IR – Handbook Page 2

You might also like