SentinelOne Posture Report
Delivers a weekly report on SentinelOne agent coverage, what changed, and anything in the console that needs attention, from detect-only policies to license seats.
What this agent does
This read-only agent checks the health of a SentinelOne deployment every week. It finds endpoints whose agent is offline, out of date, or running in detect-only mode instead of protect. It summarizes the threats that appeared, were resolved, or are still open since last week, and any new exclusions. It flags anything that needs an admin, such as a policy weakened since last week, an API token about to expire, or license seats close to the limit.
The challenge
SentinelOne only protects endpoints where the agent is installed, current, and set to protect. Agents stop reporting or fall behind on versions. An admin sets an agent to detect-only mode to troubleshoot and never sets it back to protect. A broad exclusion added to fix one false positive can stop the agent from checking those files on every machine in a group. Admins find these gaps after an incident, not before.
The solution
The agent checks agent health, policy settings, exclusions, and license use in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check agents
Find endpoints whose agent is offline, out of date, detect-only, or waiting for a reboot.
- 02
Check policies
Compare site and group policies and exclusions with last week, and flag anything that weakens protection.
- 03
Check activity
Summarize threats that appeared, were resolved, or are still open since last week.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# SentinelOne Posture Report
## Measurable outcomes
Every week, the admin knows which endpoints SentinelOne is not fully protecting, what changed in the console, and what needs action before it matters. Track protected and unprotected endpoints and open action items on every run.
## Procedure
Once a week, check every agent in the SentinelOne console. Flag agents that have not reported in the last 7 days, agents more than one major version behind, agents in detect-only mode, and agents waiting for a reboot to finish an update or remediation, unless I set other values. When I give it an asset inventory, compare it with the console and list endpoints with no agent. Compare each site's and group's policy with last week's, and call out any change that weakens protection, such as moving from protect to detect. List exclusions added since the last report, with who added them, and call out broad ones such as whole folders or file types. Summarize the new threats, the threats resolved, and the threats still open, with the oldest first. Check the API token and each integration, and flag any that are failing or about to expire. Compare license seat use with the purchased count, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine. Replace hostnames and user names with stable pseudonyms in the report.
## Requirements
It needs read-only SentinelOne API access to agents, policies, exclusions, threats, licenses, API tokens, and integrations, and nothing more. It never changes agents, policies, exclusions, or threats. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools