Skip to main content
{ Security Operations }

SentinelOne Alert Triage

Triages new SentinelOne threats, contains the confirmed ones, closes the known-good ones, and escalates the rest to an analyst.

What this agent does

This agent triages the unresolved threats in a SentinelOne tenant. It looks up every file hash, domain, IP, and URL in open threat intelligence sources, and it checks how important the affected endpoint is. It then contains the threat, closes it as benign, or escalates it to an analyst. It leaves a note on each threat in SentinelOne explaining what it decided and why.

The challenge

SentinelOne raises more threats than a small team can investigate, and each one takes an analyst several lookups before they can decide what to do. Real malware keeps running on an endpoint while the analyst works through the queue. Closing a false alarm on known-good software takes as much effort as handling a real attack.

The solution

The agent does the lookups an analyst would do and applies a containment policy the team agrees on. It disconnects endpoints with confirmed malware from the network right away, and it closes alerts on files known to be safe. It sends anything uncertain to an analyst with the evidence already gathered. Analysts spend their time on the alerts that need judgment.

Workflow

  1. 01

    Pick up new threats

    Read the unresolved threats the agent has not triaged yet, most severe first.

  2. 02

    Gather evidence

    Look up each indicator in threat intelligence sources, and check the endpoint's importance and owner.

  3. 03

    Decide

    Contain, close as benign, or escalate, based on the verdicts and the endpoint.

  4. 04

    Act and record

    Quarantine the threat and disconnect the endpoint from the network when containing, set the verdict in SentinelOne, and leave a note on every threat.

Agent template

# SentinelOne Alert Triage

## Measurable outcomes

Every new SentinelOne threat is contained, closed as benign, or escalated to an analyst, with a note that explains why. Track how many threats were contained, closed, and escalated on each run.

## Procedure

Each run, pick up the unresolved threats in SentinelOne that have not been triaged yet, most severe first, up to a limit I set. Look up every file hash, domain, IP, and URL in the abuse.ch MalwareBazaar, URLhaus, and ThreatFox services and in AlienVault OTX. Check file hashes against CIRCL hashlookup for known-good files. When the threat or the endpoint's software is tied to a CVE, check CISA KEV and EPSS to judge how urgent it is. Include the MITRE ATT&CK techniques SentinelOne reports. Decide how important the endpoint is from its SentinelOne site, group, and tags, which I map to high-value or standard, and use my asset inventory for the owner when I provide one. If the agent cannot tell how important an endpoint is, treat it as standard. Contain anything confirmed malicious. Contain suspicious threats on high-value endpoints and escalate them everywhere else. Close a threat as benign when every indicator is known to be good. Escalate anything the agent cannot confirm. To contain, quarantine the threat and disconnect the endpoint from the network, then mark the threat as a true positive. When closing as benign, mark it as a false positive and resolve it. Leave a note on every threat with the decision and the evidence behind it. In reports outside SentinelOne, replace hostnames and user names with stable pseudonyms. Start in a report-only mode so I can review its decisions before it contains or closes anything.

## Requirements

It needs SentinelOne API access to read threats and endpoints, quarantine threats, disconnect endpoints from the network, and update threat verdicts, status, and notes. It needs nothing else in SentinelOne. It never deletes threats, changes policies, or adds exclusions.