T Techclick ← All lessons
SentinelOne · Singularity · Evidence desk · Interactive lesson

Prove SentinelOne is working — first tool + proof field

01:40. Slack: “Is the agent even working?” Then: “Why didn’t it block?” The CIO is already in the channel. A screenshot of update.exe is not proof. This desk is five official surfaces — Sentinels agent health, Threats / Threat Center (Analyst Verdict and AI Confidence Level), Storyline, Policy mode Detect vs Protect, Remote Shell / Fetch File — each mapped to one ticket, one first click, and one field you paste before you kill, disconnect, or flip a group to Protect.

~20 min read · L2 primary · Quiz at end · Blog 1 · Factory

⚡ Quick Answer

How you prove SentinelOne is working: Sentinels agent health, Threats Analyst Verdict / AI Confidence, Storyline, Policy Detect vs Protect, Remote Shell / fetch. Five tickets with first tool and one proof field.

After this page you can

Quick answer (say this out loud)

Sentinels answers “did this agent check in?” Threat Center answers “what is the Threat Status, AI Confidence Level, and Analyst Verdict?” Storyline (Explore) answers “what is the plot — process, file, persistence, network?” Policy Detect vs Protect answers “was this Group even allowed to mitigate?” Remote Shell / Fetch File answers “what is on this live host right now?” A green tray icon is not Last Reported. A Detect-mode Group is not a miss. Kill is not Remediate. Disconnect from Network is a separate lever.

1. Why “is the agent working?” is five questions

Operators collapse five failures into one sentence. The agent never checked in. The host is decommissioned or already disconnected. The Group policy is Detect, so the agent alerted and did not kill. The Storyline still has a Run key after mitigation = Kill. Remote Shell cannot start because Last Reported is fourteen hours ago. Those are five first clicks.

This page is the night-shift desk for proof. The factory taught Storyline, Kill vs Remediate, and Disconnect from Network. Here you learn the five console surfaces you actually open, in order, when someone asks you to prove SentinelOne is working — or to explain why it did not block.

Hero · five tiles, one ticket
Isometric laptop with a shield node and five proof steps on a night-shift desk
Notice: five tiles, not one “Singularity dashboard.” You pick the tile that matches the question, then you quote one field.
Interview line

If they say “prove SentinelOne is working,” do not say “I opened the console.” Say: “I prove the agent with Sentinels Last Reported and Network Status, the conviction with Threat Center AI Confidence Level and Analyst Verdict, the plot with Storyline on Explore, the block decision with Group policy Detect vs Protect, and the live host with Remote Shell or Fetch File.”

2. Mental model — five proof tools

Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you Disconnect a DC at 02:00 or flip the whole Site to Detect.

1 · Sentinels

Sentinels (agent inventory). Proves the agent: Last Reported, Network Status, Agent Version, online vs decommissioned. Does not prove a verdict or a policy mode.

2 · Threat Center

Incidents → a threat → Threat Center. Proves one conviction: Threat Status, AI Confidence Level, Analyst Verdict. Does not prove the Group can Protect.

3 · Storyline

Threat Center → Explore. Proves the plot: Storyline ID, process tree, files, registry, network. A filename in Slack is not the Storyline.

4 · Policy mode

Group card → assigned Policy. Proves Detect vs Protect for the engines on that Group. Detect is configuration, not a miss.

5 · Remote Shell / Fetch

Endpoint or Threat Center → Remote Shell or Fetch File. Proves live state. PowerShell on Windows, Bash on macOS/Linux. A dark Last Reported does not collect.

Hard words, once

Storyline = correlated attack story. AI Confidence = Malicious or Suspicious. Analyst Verdict = True Positive / False Positive / Suspicious / Undefined. Protect = policy may auto-mitigate. Disconnect from Network = isolate except the management console.

Flow 1 · five tools, one question each
Write hostname + Storyline ID + UTC first · then pick the tool Is the agent working? five questions, not one Sentinels Agent talking? Last Reported Network Status Sentinels inventory not a verdict Threat Center This conviction? AI Confidence Analyst Verdict Incidents → threat not a policy mode Storyline What is the plot? Explore · tree persistence Threat Center → Explore not live shell Policy mode Allowed to block? Detect vs Protect Group assign Sentinels → Policy Detect is not a miss Remote Shell Live host now? shell · Fetch File needs Last Reported Actions → Remote Shell dark host = no fetch Empty Incidents is data. It usually means the agent never landed or is decommissioned. Do not invent a miss from an empty queue. Start at Sentinels Last Reported.

Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing.

Say this out loud

I prove the agent, then the conviction, then the Storyline, then the assigned policy mode, then the live host. I do not Disconnect, Fetch, or flip Detect to Protect until I can quote the field that made me do it.

3. Decision flow — ticket → first tool

Flowchart first. Do not open Policy or start Remote Shell until a diamond says so.

Path · pick the branch before the menu
Abstract diamond splitting into five SentinelOne proof paths
Notice: the diamond is the ticket. The path is the tool. The field comes last. Do not reverse that order.
Flow 2 · first-tool diamond
Symptom first · tool second · field third What must we prove? Agent live? or already inside? “Is the agent up?” Sentinels Last Reported “Why no block?” Group Policy Detect vs Protect Live malicious plot Threats + Explore verdict · Storyline Need a file / shell Fetch / Remote Shell after Last Reported Blocked demo / VIP Group Policy scoped exclusion Last Reported hours ago / decommissioned = stop. There is no live shell and no “S1 miss.” Fix the agent (filter, token, offline, leftover row). Then re-open Incidents. Diamond = decision. Do not Disconnect from the bottom box. Do not flip Protect from an empty queue. Confirm current menu labels in the SentinelOne Customer Portal knowledge base on your console generation.

Read the diamond first. “Why didn’t it block?” never starts in Remote Shell. A dark Last Reported never starts in Policy. A blocked demo is often Protect success.

4. How to choose — first tool + proof field

Print this next to the Singularity console. If you cannot recite the proof field, you are not ready to Disconnect or change Detect to Protect.

If the ticket says…First tool (official path)Proof fieldDo not open first
Laptop / hotel / “is the agent even working?” Sentinels Last Reported (UTC) + Network Status + Agent Version + decommissioned filter A new STAR rule, or Remote Shell
“Why didn’t it block?” after a threat fired Endpoint card → assigned Policy (Group) Policy name + engine set to Detect (not Protect) Tenant-wide Protect-off
Malicious file / user still working / “mitigated” Incidents → Threat Center, then Explore Threat Status + AI Confidence Level + Analyst Verdict + Storyline persistence The filename argument in Slack
Need the sample, a running process, or a live command Threat Center Fetch File, or Actions → Remote Shell (after Last Reported is seconds) Fetch completed, or shell session + command output Remote Shell on a host Last Reported hours ago
Red team / VIP: “S1 broke the demo” Assigned Group Policy Policy name + Protect mode that matched + scoped exclusion / Group Global Detect for the Site
Console label caveat (official)

Singularity menu chrome moves by console generation. SentinelOne documents Sentinels for agent inventory, Incidents opening the Kauai-era Threat Center (Overview / Explore / Timeline), Group Policy with Detect vs Protect, Remote Shell, and Fetch File. Older tenants may still say Threats instead of Incidents. Confirm the click-path in the SentinelOne Customer Portal knowledge base for your console. The proof fields — Last Reported, Network Status, Threat Status, AI Confidence Level, Analyst Verdict, Storyline ID, Detect vs Protect — are the ones you paste.

5. Runbook Side A → B → C

Side A proves the agent is on the wire. Side B proves what Singularity saw and whether policy was allowed to mitigate. Side C proves live response. On a messy Sev-2, do them in this order until a field lights up.

Side A — Sentinels (agent health)

  1. Open Sentinels, not Incidents

    Path: Sentinels. Search hostname. If two rows appear, sort by Last Reported and work the live one — the stale row is often a leftover or a pending-decommission record. Source: SentinelOne FAQ (Management console manages agents); Customer Portal knowledge base for Sentinels filters including Decommissioned.

  2. Read the four agent columns that close “is the agent working?”

    Last Reported — most recent console check-in (UTC). Agent Version. Network Status — Connected or Disconnected (after Disconnect from Network). Decommissioned filter — offline agents drop out of the default view (commonly after 21 days unless your Site changed the aging). Source: Sentinels inventory columns; FAQ on remote agent management.

  3. If Last Reported is hours, stop. This is an agent ticket

    Do not start Remote Shell. Do not Fetch File and call it collected. Do not call it a miss. Check connectivity to the management console, install token / Site, pending uninstall, and whether you opened a decommissioned row. Then come back.

  4. If Network Status is already Disconnected, say that out loud

    Disconnect from Network cuts inbound and outbound except the management console. That is containment, not “agent down.” Quote Network Status before anyone “fixes S1” by reconnecting a live malicious host.

usea1-lab.sentinelone.net · Sentinels
Training mock · not live

Sentinels / Endpoints

Sentinels

ENDPOINT-LAB-41
Last 24 hours
EndpointSite / GroupLast ReportedNetwork StatusAgent Version
ENDPOINT-LAB-41Techclick-Lab / FIN-WS16s agoConnected24.1
ENDPOINT-LAB-41Techclick-Lab / FIN-WS12 days agoConnected23.4

Source: SentinelOne FAQ — Management console manages agents; Customer Portal knowledge base — Sentinels filters, Decommissioned agents. Two rows, one hostname — work the 16s row. Lab identities only. Training mock · not live.

Side B — Threat Center, Storyline, Policy Detect vs Protect

  1. Open the threat, not Slack’s filename

    Path: Incidents → the threat (older chrome: Threats). You land in Threat Center. Official status bar: Threat Status (mitigated by policy or not), AI Confidence Level (Suspicious or Malicious), Analyst Verdict and Incident Status. Source: Feature Spotlight — Introducing the New Threat Center.

  2. Read Threat Status, AI Confidence, Analyst Verdict

    Those three close “what did the agent think this was, and what did a human mark?” A Malicious / Undefined / Not mitigated threat is not a hash debate. Set Analyst Verdict (True Positive, False Positive, Suspicious). Do not leave it Undefined while you argue update.exe.

  3. Open Explore (Storyline) before you type Remote Shell

    Threat Center → Explore. Official: the entire attack Storyline — processes, files, registry, network, DNS — in Process Tree or the table. Quote Storyline ID and persistence. Explore is historical telemetry. Remote Shell is live. Do not skip the plot to go collect a file the tree already named.

  4. If the ticket is “why didn’t it block?”, open the assigned Group policy

    Path: endpoint card → Policy, or Policy on that Group. Read Detect vs Protect for the engine that convicted (Static AI / Behavioral AI). Official: the choice between Detect or Protect is governed by policies the customer controls; Protect takes the mitigation actions defined in the policy. Detect means the product did what that Group is configured to do. Promote to Protect under change control — do not call it a miss and do not flip the Site.

usea1-lab.sentinelone.net · Incidents → THR-1042 · Threat Center
Training mock · not live

Incidents / THR-1042 / Overview

Threat Center

Mitigated · Kill
Malicious
Undefined
SL-88
RoleObjectDetail (lab)State
Fileupdate.exeC:\Users\finance.user\Downloads\killed
PersistenceRun keyHKCU\...\Run · update.exepresent
Userfinance.userinteractive logonactive

Source: SentinelOne — Feature Spotlight: Introducing the New Threat Center (Threat Status, AI Confidence Level, Analyst Verdict, Explore Storyline, Fetch File, Remote Shell). Lab identities only. Training mock · not live.

Threat + policy — fields you write in the ticket
Path:            Incidents → threat → Threat Center
Quote:           Threat Status + AI Confidence Level + Analyst Verdict
Then:            Explore  (Storyline ID · process tree · persistence)
If “no block”:   Sentinels → endpoint → assigned Policy
Quote:           policy name + Detect vs Protect for that engine
If empty queue:  Sentinels Last Reported / decommissioned first
usea1-lab.sentinelone.net · Policy · FIN-WS-Detect
Training mock · not live

Policy / Group FIN-WS / FIN-WS-Detect

Policy mode

FIN-WS-Detect
Group · FIN-WS
Detect
Detect
Assigned policy on ENDPOINT-LAB-41: FIN-WS-Detect
Engine that convicted: Detect — not Protect
Product did what this Group is configured to do.
Promote to Protect under change control. Do not flip the Site.

Source: SentinelOne — Detect or Protect is governed by customer-controlled policies; Protect takes the mitigation actions defined in the policy (Static AI / Behavioral AI write-ups; Singularity Complete response set). Confirm engine labels on your build. Lab policy name only. Training mock · not live.

Side C — Remote Shell / Fetch File + Disconnect from Network

  1. Contain a live malicious workstation before you collect souvenirs

    Official action: Disconnect from Network (network isolation). The host keeps a path to the management console. That is the right 01:40 move on a finance laptop with a live Malicious Storyline. It is the wrong reflex on a DC / DNS / DHCP — those wait for change-control. Source: SentinelOne FAQ (network isolation); Singularity Complete (block incoming and outgoing network activity).

  2. Fetch File or start Remote Shell only after Last Reported is seconds

    Threat Center can fetch the threat file from the same view. Endpoint Actions → Remote Shell opens PowerShell on Windows and Bash on macOS and Linux, securely from the Management Console. A dark Last Reported does not give you a shell tonight — that is not evidence.

  3. Use the documented action that answers the ticket

    Fetch the file the Storyline already named. Use Remote Shell to confirm the process or persistence the Explore tab showed. Quote the action and the output. Remote Shell is change-control — you need the role and, in most shops, a change number before you delete or run unconstrained commands.

usea1-lab.sentinelone.net · Sentinels → ENDPOINT-LAB-41 → Remote Shell
Training mock · not live

Sentinels / ENDPOINT-LAB-41 / Actions / Remote Shell

Remote Shell

PowerShell · established
18s ago · Network Disconnected
remote shell: connected host=ENDPOINT-LAB-41
PS> Get-Item HKCU:\Software\Microsoft\Windows\CurrentVersion\Run
update.exe C:\Users\finance.user\Downloads\update.exe
Threat Center → Fetch File update.exe
fetch: complete · sha256=lab-only

Source: SentinelOne FAQ — Remote Shell (PowerShell on Windows, Bash on macOS and Linux from the Management Console); Threat Center spotlight — fetch the threat file from the same view; Singularity Complete — Full Remote Shell. Do this after Last Reported is live. Training mock · not live.

Green success on each side

6. Five tickets as full stories

These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only.

TicketSymptomFirst toolProof field
S1-ED-01WFH laptop: “S1 is down, icon looks installed”SentinelsLast Reported + Network Status + Agent Version — or the 12-day leftover row
S1-ED-02Threat fired; process still running; “why didn’t it block?”Group PolicyPolicy name + engine = Detect (not Protect)
S1-ED-03Mitigated = Kill; user still on the laptopThreat Center → ExploreAI Confidence + Analyst Verdict + Storyline persistence, then Disconnect if a workstation
S1-ED-04Need the sample / live Run-key proofFetch File / Remote ShellFetch complete, or shell output — after Last Reported is seconds
S1-ED-05Red team: “S1 broke the demo”Group PolicyProtect mode that matched + scoped exclusion / Group

S1-ED-01 — Prove the agent (Sentinels)

01:42 · P2. Priya on a hotel network. Phone photo of a SentinelOne tray icon. L1 already drafted “S1 missed the malware.” Incidents for her hostname are empty.

First tool: Sentinels. Search ENDPOINT-LAB-41.

If Last Reported is hours / the only row is decommissioned: quote that pair. Empty Incidents is expected. Next check is the agent — console connectivity, install token, Site, leftover row — not a new STAR rule.

If Last Reported is seconds and Network Status is Connected: the agent is talking. Now you are allowed to open Incidents for that endpoint and UTC window. A tray icon is not Last Reported.

Trap

Two rows, one hostname. The 12-day row is leftover. Disconnecting it does not touch the laptop on the desk. Sort Last Reported. Do not rebuild the fleet because status.sentinelone.com is green and this one host is dark.

S1-ED-02 — Prove why it did not block (Policy Detect vs Protect)

02:05 · P2. A threat fired. The process is still running. Someone typed “S1 failed” in the channel and wants Protect off for Finance so they can work.

First tool: endpoint card → assigned Policy, or Policy on Group FIN-WS. Confirm the Group that assigned it.

Proof field: policy name (lab: FIN-WS-Detect) and Behavioral AI / Static AI set to Detect. That is the ticket. The agent did what that Group is configured to do. Set Analyst Verdict. Disconnect if the Storyline is real. Promote the engine to Protect under change control. Do not flip the Site to Detect.

Close

I would not call this a miss. I would quote Detect on the assigned policy, Disconnect the live workstation if Confidence is Malicious, and open a change to move that one Group to Protect.

S1-ED-03 — Prove the conviction and the plot (Threat Center + Storyline)

02:20 · P1. THR-1042. User still in Outlook. L1 wants to close because mitigation = Kill.

First tool: Incidents → THR-1042 → Threat Center, then Explore.

Proof field: Threat Status = Mitigated (Kill), AI Confidence Level = Malicious, Analyst Verdict still Undefined; Explore shows Storyline SL-88 with a Run key under finance.user. Last Reported 16s, Network Status = Connected. Kill stopped a process. It did not finish the plot. Disconnect this workstation. Remediate the Storyline. Set the verdict. Filename later.

Close

Quote Confidence + Verdict + the persistence line on SL-88. Disconnect the live workstation. Do not spend the bridge on whether the file is named update.exe. Source: Threat Center status bar + Explore Storyline + FAQ kill / remediate / network isolation.

S1-ED-04 — Prove the live host (Fetch File / Remote Shell)

02:40 · P2. IR wants the sample on disk. Someone already opened Remote Shell against the 12-day row.

First tool: Sentinels Last Reported on the row you will session, then Threat Center Fetch File or Actions → Remote Shell.

Proof field: fetch complete for the path on Explore, or a PowerShell/Bash session showing the Run key / process the Storyline already named. If Last Reported is hours, you will not collect — that is not evidence in the ticket tonight.

Trap

Remote Shell needs a live agent. Fetch File from Threat Center is the shorter path when the object is already the threat file. Do not shell a decommissioned row and claim you collected. Do not reconnect Network Status just to make a download easier on a live Malicious host.

S1-ED-05 — Prove the block was policy (Protect mode)

03:00 · P3. Red team says SentinelOne broke the demo. Group policy on that host is Protect. L1 wants Detect for the Site until Monday.

First tool: Policy for the demo Group.

Proof field: policy name + Protect mode that matched the demo tool. A blocked demo can be policy success. Scope a time-boxed exclusion or move that one host to a Detect Group with an owner and an end time. Keep Protect on for everyone else.

Close

I would not set Detect for the Site. I would paste the policy name, the mode, and the exclusion / Group move + owner + expiry. Then re-read Incidents on the demo host after the change.

7. Traps + close-the-ticket proof

Proof · named field, then Closed
Operations desk with a verified check and one highlighted log row
Notice: the close is a named column on a timestamp, not a screenshot of the user’s tray icon.
You seeWeak closeStrong close
Empty Incidents“S1 missed it”Sentinels Last Reported + decommissioned filter first
Tray icon on a phone photo“The agent is working”You only proved a bitmap. Quote Last Reported on that row
Threat + process still running“S1 failed”Assigned Group policy = Detect
Mitigation = Kill“Mitigated, go to sleep”Explore SL-88 for persistence; Remediate is still required
Two rows, one hostnameDisconnect / shell the old oneSort Last Reported; work the live row
Last Reported 14 hoursStart Remote Shell / FetchAgent ticket. You will not collect tonight
Network Status = Connected + Malicious“Kill isolated the host”Disconnect the workstation; change-control for DC/DNS/DHCP
Blocked demo, Protect onDetect for the SiteScoped exclusion / Group + owner + end time
Filename in SlackBridge starts on update.exeConfidence + Storyline, then Disconnect
Proof checklist before you leave the bridge
Interview close

I name the question, then the first tool, then one official field. Sentinels proves the agent. Threat Center proves the conviction. Storyline proves the plot. Policy Detect vs Protect proves whether the agent was allowed to mitigate. Remote Shell / Fetch proves the live host. I Disconnect a live workstation. I do not start with “S1 missed it.” Factory model: Storyline is the S1 word — kill is not remediate.

Knowledge check

Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

Q1

WFH user: “Is the agent even working?” Incidents for her hostname are empty. You have not opened a policy yet. First proof?

Correct: b. Empty Incidents is data. Official first surface is Sentinels Last Reported / Network Status. Re-read Side A and S1-ED-01.
Q2

A threat fired an hour ago. The process is still running. Which proof field closes “why didn’t it block?”

Correct: a. Detect-only is configuration, not a miss. Remote Shell and the status page answer different tickets. Re-read Side B step 4 and S1-ED-02.
Q3

Last Reported on the row is 14 hours. IR wants Fetch File and Remote Shell. What do you do first?

Correct: c. Official Remote Shell / Fetch need a live agent. A dark Last Reported does not collect. Re-read Flow 2 bottom box and S1-ED-04.
Q4

THR-1042 shows Threat Status Mitigated (Kill), AI Confidence Malicious, Analyst Verdict Undefined. Last Reported is 16s. Network Status is Connected. Next?

Correct: d. Kill is not Remediate. Explore is the plot. Disconnect is a separate lever on a workstation. Re-read Side C step 1 and S1-ED-03.
Q5

You already have THR-1042. You need the sample on disk and confirmation of the Run key. First surface?

Correct: b. Fetch File is documented on Threat Center. Explore is historical. Remote Shell is live. Do not reconnect a Malicious host to “make Fetch work.” Re-read Side B step 3 and Side C.
Q6

Red team says SentinelOne broke their demo. The assigned Group policy is Protect. Best first reply?

Correct: a. A blocked demo can be policy success. Scope the exception; keep Protect on. Re-read S1-ED-05 and the How to choose table.

Sources

Related: Blog 1 · Storyline is the S1 word — kill is not remediate · SentinelOne dashboard · Dummy lab · Storyline, Ranger & Rollback