Sentinels answers “did this agent check in?” Threat Center answers “what is the Threat Status, AI Confidence Level, and Analyst Verdict?” Storyline (Explore) answers “what is the plot — process, file, persistence, network?” Policy Detect vs Protect answers “was this Group even allowed to mitigate?” Remote Shell / Fetch File answers “what is on this live host right now?” A green tray icon is not Last Reported. A Detect-mode Group is not a miss. Kill is not Remediate. Disconnect from Network is a separate lever.
1. Why “is the agent working?” is five questions
Operators collapse five failures into one sentence. The agent never checked in. The host is decommissioned or already disconnected. The Group policy is Detect, so the agent alerted and did not kill. The Storyline still has a Run key after mitigation = Kill. Remote Shell cannot start because Last Reported is fourteen hours ago. Those are five first clicks.
This page is the night-shift desk for proof. The factory taught Storyline, Kill vs Remediate, and Disconnect from Network. Here you learn the five console surfaces you actually open, in order, when someone asks you to prove SentinelOne is working — or to explain why it did not block.
If they say “prove SentinelOne is working,” do not say “I opened the console.” Say: “I prove the agent with Sentinels Last Reported and Network Status, the conviction with Threat Center AI Confidence Level and Analyst Verdict, the plot with Storyline on Explore, the block decision with Group policy Detect vs Protect, and the live host with Remote Shell or Fetch File.”
2. Mental model — five proof tools
Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you Disconnect a DC at 02:00 or flip the whole Site to Detect.
1 · Sentinels
Sentinels (agent inventory). Proves the agent: Last Reported, Network Status, Agent Version, online vs decommissioned. Does not prove a verdict or a policy mode.
2 · Threat Center
Incidents → a threat → Threat Center. Proves one conviction: Threat Status, AI Confidence Level, Analyst Verdict. Does not prove the Group can Protect.
3 · Storyline
Threat Center → Explore. Proves the plot: Storyline ID, process tree, files, registry, network. A filename in Slack is not the Storyline.
4 · Policy mode
Group card → assigned Policy. Proves Detect vs Protect for the engines on that Group. Detect is configuration, not a miss.
5 · Remote Shell / Fetch
Endpoint or Threat Center → Remote Shell or Fetch File. Proves live state. PowerShell on Windows, Bash on macOS/Linux. A dark Last Reported does not collect.
Hard words, once
Storyline = correlated attack story. AI Confidence = Malicious or Suspicious. Analyst Verdict = True Positive / False Positive / Suspicious / Undefined. Protect = policy may auto-mitigate. Disconnect from Network = isolate except the management console.
Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing.
I prove the agent, then the conviction, then the Storyline, then the assigned policy mode, then the live host. I do not Disconnect, Fetch, or flip Detect to Protect until I can quote the field that made me do it.
3. Decision flow — ticket → first tool
Flowchart first. Do not open Policy or start Remote Shell until a diamond says so.
Read the diamond first. “Why didn’t it block?” never starts in Remote Shell. A dark Last Reported never starts in Policy. A blocked demo is often Protect success.
4. How to choose — first tool + proof field
Print this next to the Singularity console. If you cannot recite the proof field, you are not ready to Disconnect or change Detect to Protect.
| If the ticket says… | First tool (official path) | Proof field | Do not open first |
|---|---|---|---|
| Laptop / hotel / “is the agent even working?” | Sentinels | Last Reported (UTC) + Network Status + Agent Version + decommissioned filter |
A new STAR rule, or Remote Shell |
| “Why didn’t it block?” after a threat fired | Endpoint card → assigned Policy (Group) | Policy name + engine set to Detect (not Protect) | Tenant-wide Protect-off |
| Malicious file / user still working / “mitigated” | Incidents → Threat Center, then Explore | Threat Status + AI Confidence Level + Analyst Verdict + Storyline persistence |
The filename argument in Slack |
| Need the sample, a running process, or a live command | Threat Center Fetch File, or Actions → Remote Shell (after Last Reported is seconds) | Fetch completed, or shell session + command output | Remote Shell on a host Last Reported hours ago |
| Red team / VIP: “S1 broke the demo” | Assigned Group Policy | Policy name + Protect mode that matched + scoped exclusion / Group | Global Detect for the Site |
Singularity menu chrome moves by console generation. SentinelOne documents Sentinels for agent inventory, Incidents opening the Kauai-era Threat Center (Overview / Explore / Timeline), Group Policy with Detect vs Protect, Remote Shell, and Fetch File. Older tenants may still say Threats instead of Incidents. Confirm the click-path in the SentinelOne Customer Portal knowledge base for your console. The proof fields — Last Reported, Network Status, Threat Status, AI Confidence Level, Analyst Verdict, Storyline ID, Detect vs Protect — are the ones you paste.
5. Runbook Side A → B → C
Side A proves the agent is on the wire. Side B proves what Singularity saw and whether policy was allowed to mitigate. Side C proves live response. On a messy Sev-2, do them in this order until a field lights up.
Side A — Sentinels (agent health)
-
Open Sentinels, not Incidents
Path: Sentinels. Search hostname. If two rows appear, sort by
Last Reportedand work the live one — the stale row is often a leftover or a pending-decommission record. Source: SentinelOne FAQ (Management console manages agents); Customer Portal knowledge base for Sentinels filters including Decommissioned. -
Read the four agent columns that close “is the agent working?”
Last Reported— most recent console check-in (UTC).Agent Version.Network Status— Connected or Disconnected (after Disconnect from Network). Decommissioned filter — offline agents drop out of the default view (commonly after 21 days unless your Site changed the aging). Source: Sentinels inventory columns; FAQ on remote agent management. -
If Last Reported is hours, stop. This is an agent ticket
Do not start Remote Shell. Do not Fetch File and call it collected. Do not call it a miss. Check connectivity to the management console, install token / Site, pending uninstall, and whether you opened a decommissioned row. Then come back.
-
If Network Status is already Disconnected, say that out loud
Disconnect from Network cuts inbound and outbound except the management console. That is containment, not “agent down.” Quote Network Status before anyone “fixes S1” by reconnecting a live malicious host.
Sentinels / Endpoints
Sentinels
| Endpoint | Site / Group | Last Reported | Network Status | Agent Version |
|---|---|---|---|---|
| ENDPOINT-LAB-41 | Techclick-Lab / FIN-WS | 16s ago | Connected | 24.1 |
| ENDPOINT-LAB-41 | Techclick-Lab / FIN-WS | 12 days ago | Connected | 23.4 |
Source: SentinelOne FAQ — Management console manages agents; Customer Portal knowledge base — Sentinels filters, Decommissioned agents. Two rows, one hostname — work the 16s row. Lab identities only. Training mock · not live.
Side B — Threat Center, Storyline, Policy Detect vs Protect
-
Open the threat, not Slack’s filename
Path: Incidents → the threat (older chrome: Threats). You land in Threat Center. Official status bar:
Threat Status(mitigated by policy or not),AI Confidence Level(Suspicious or Malicious),Analyst Verdictand Incident Status. Source: Feature Spotlight — Introducing the New Threat Center. -
Read Threat Status, AI Confidence, Analyst Verdict
Those three close “what did the agent think this was, and what did a human mark?” A Malicious / Undefined / Not mitigated threat is not a hash debate. Set Analyst Verdict (True Positive, False Positive, Suspicious). Do not leave it Undefined while you argue
update.exe. -
Open Explore (Storyline) before you type Remote Shell
Threat Center → Explore. Official: the entire attack Storyline — processes, files, registry, network, DNS — in Process Tree or the table. Quote Storyline ID and persistence. Explore is historical telemetry. Remote Shell is live. Do not skip the plot to go collect a file the tree already named.
-
If the ticket is “why didn’t it block?”, open the assigned Group policy
Path: endpoint card → Policy, or Policy on that Group. Read Detect vs Protect for the engine that convicted (Static AI / Behavioral AI). Official: the choice between Detect or Protect is governed by policies the customer controls; Protect takes the mitigation actions defined in the policy. Detect means the product did what that Group is configured to do. Promote to Protect under change control — do not call it a miss and do not flip the Site.
Incidents / THR-1042 / Overview
Threat Center
| Role | Object | Detail (lab) | State |
|---|---|---|---|
| File | update.exe | C:\Users\finance.user\Downloads\ | killed |
| Persistence | Run key | HKCU\...\Run · update.exe | present |
| User | finance.user | interactive logon | active |
Source: SentinelOne — Feature Spotlight: Introducing the New Threat Center (Threat Status, AI Confidence Level, Analyst Verdict, Explore Storyline, Fetch File, Remote Shell). Lab identities only. Training mock · not live.
Path: Incidents → threat → Threat Center Quote: Threat Status + AI Confidence Level + Analyst Verdict Then: Explore (Storyline ID · process tree · persistence) If “no block”: Sentinels → endpoint → assigned Policy Quote: policy name + Detect vs Protect for that engine If empty queue: Sentinels Last Reported / decommissioned first
Policy / Group FIN-WS / FIN-WS-Detect
Policy mode
Engine that convicted: Detect — not Protect
Product did what this Group is configured to do.
Promote to Protect under change control. Do not flip the Site.
Source: SentinelOne — Detect or Protect is governed by customer-controlled policies; Protect takes the mitigation actions defined in the policy (Static AI / Behavioral AI write-ups; Singularity Complete response set). Confirm engine labels on your build. Lab policy name only. Training mock · not live.
Side C — Remote Shell / Fetch File + Disconnect from Network
-
Contain a live malicious workstation before you collect souvenirs
Official action: Disconnect from Network (network isolation). The host keeps a path to the management console. That is the right 01:40 move on a finance laptop with a live Malicious Storyline. It is the wrong reflex on a DC / DNS / DHCP — those wait for change-control. Source: SentinelOne FAQ (network isolation); Singularity Complete (block incoming and outgoing network activity).
-
Fetch File or start Remote Shell only after Last Reported is seconds
Threat Center can fetch the threat file from the same view. Endpoint Actions → Remote Shell opens PowerShell on Windows and Bash on macOS and Linux, securely from the Management Console. A dark Last Reported does not give you a shell tonight — that is not evidence.
-
Use the documented action that answers the ticket
Fetch the file the Storyline already named. Use Remote Shell to confirm the process or persistence the Explore tab showed. Quote the action and the output. Remote Shell is change-control — you need the role and, in most shops, a change number before you delete or run unconstrained commands.
Sentinels / ENDPOINT-LAB-41 / Actions / Remote Shell
Remote Shell
PS> Get-Item HKCU:\Software\Microsoft\Windows\CurrentVersion\Run
update.exe C:\Users\finance.user\Downloads\update.exe
Threat Center → Fetch File update.exe
fetch: complete · sha256=lab-only
Source: SentinelOne FAQ — Remote Shell (PowerShell on Windows, Bash on macOS and Linux from the Management Console); Threat Center spotlight — fetch the threat file from the same view; Singularity Complete — Full Remote Shell. Do this after Last Reported is live. Training mock · not live.
- Side A: Sentinels
Last Reportedis seconds on the row you named; Network Status is stated; you said which row if the hostname duplicated. - Side B: Threat Center quotes
Threat Status+AI Confidence Level+Analyst Verdict; Explore names Storyline ID and persistence; “no block” quotes Detect on the assigned Group policy. - Side C: Network Status = Disconnected on a workstation (or change-control named on infra); Fetch File or Remote Shell output is pasted, or you documented why you did not start a shell.
6. Five tickets as full stories
These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only.
| Ticket | Symptom | First tool | Proof field |
|---|---|---|---|
| S1-ED-01 | WFH laptop: “S1 is down, icon looks installed” | Sentinels | Last Reported + Network Status + Agent Version — or the 12-day leftover row |
| S1-ED-02 | Threat fired; process still running; “why didn’t it block?” | Group Policy | Policy name + engine = Detect (not Protect) |
| S1-ED-03 | Mitigated = Kill; user still on the laptop | Threat Center → Explore | AI Confidence + Analyst Verdict + Storyline persistence, then Disconnect if a workstation |
| S1-ED-04 | Need the sample / live Run-key proof | Fetch File / Remote Shell | Fetch complete, or shell output — after Last Reported is seconds |
| S1-ED-05 | Red team: “S1 broke the demo” | Group Policy | Protect mode that matched + scoped exclusion / Group |
S1-ED-01 — Prove the agent (Sentinels)
01:42 · P2. Priya on a hotel network. Phone photo of a SentinelOne tray icon. L1 already drafted “S1 missed the malware.” Incidents for her hostname are empty.
First tool: Sentinels. Search ENDPOINT-LAB-41.
If Last Reported is hours / the only row is decommissioned: quote that pair. Empty Incidents is expected. Next check is the agent — console connectivity, install token, Site, leftover row — not a new STAR rule.
If Last Reported is seconds and Network Status is Connected: the agent is talking. Now you are allowed to open Incidents for that endpoint and UTC window. A tray icon is not Last Reported.
Two rows, one hostname. The 12-day row is leftover. Disconnecting it does not touch the laptop on the desk. Sort Last Reported. Do not rebuild the fleet because status.sentinelone.com is green and this one host is dark.
S1-ED-02 — Prove why it did not block (Policy Detect vs Protect)
02:05 · P2. A threat fired. The process is still running. Someone typed “S1 failed” in the channel and wants Protect off for Finance so they can work.
First tool: endpoint card → assigned Policy, or Policy on Group FIN-WS. Confirm the Group that assigned it.
Proof field: policy name (lab: FIN-WS-Detect) and Behavioral AI / Static AI set to Detect. That is the ticket. The agent did what that Group is configured to do. Set Analyst Verdict. Disconnect if the Storyline is real. Promote the engine to Protect under change control. Do not flip the Site to Detect.
I would not call this a miss. I would quote Detect on the assigned policy, Disconnect the live workstation if Confidence is Malicious, and open a change to move that one Group to Protect.
S1-ED-03 — Prove the conviction and the plot (Threat Center + Storyline)
02:20 · P1. THR-1042. User still in Outlook. L1 wants to close because mitigation = Kill.
First tool: Incidents → THR-1042 → Threat Center, then Explore.
Proof field: Threat Status = Mitigated (Kill), AI Confidence Level = Malicious, Analyst Verdict still Undefined; Explore shows Storyline SL-88 with a Run key under finance.user. Last Reported 16s, Network Status = Connected. Kill stopped a process. It did not finish the plot. Disconnect this workstation. Remediate the Storyline. Set the verdict. Filename later.
Quote Confidence + Verdict + the persistence line on SL-88. Disconnect the live workstation. Do not spend the bridge on whether the file is named update.exe. Source: Threat Center status bar + Explore Storyline + FAQ kill / remediate / network isolation.
S1-ED-04 — Prove the live host (Fetch File / Remote Shell)
02:40 · P2. IR wants the sample on disk. Someone already opened Remote Shell against the 12-day row.
First tool: Sentinels Last Reported on the row you will session, then Threat Center Fetch File or Actions → Remote Shell.
Proof field: fetch complete for the path on Explore, or a PowerShell/Bash session showing the Run key / process the Storyline already named. If Last Reported is hours, you will not collect — that is not evidence in the ticket tonight.
Remote Shell needs a live agent. Fetch File from Threat Center is the shorter path when the object is already the threat file. Do not shell a decommissioned row and claim you collected. Do not reconnect Network Status just to make a download easier on a live Malicious host.
S1-ED-05 — Prove the block was policy (Protect mode)
03:00 · P3. Red team says SentinelOne broke the demo. Group policy on that host is Protect. L1 wants Detect for the Site until Monday.
First tool: Policy for the demo Group.
Proof field: policy name + Protect mode that matched the demo tool. A blocked demo can be policy success. Scope a time-boxed exclusion or move that one host to a Detect Group with an owner and an end time. Keep Protect on for everyone else.
I would not set Detect for the Site. I would paste the policy name, the mode, and the exclusion / Group move + owner + expiry. Then re-read Incidents on the demo host after the change.
7. Traps + close-the-ticket proof
| You see | Weak close | Strong close |
|---|---|---|
| Empty Incidents | “S1 missed it” | Sentinels Last Reported + decommissioned filter first |
| Tray icon on a phone photo | “The agent is working” | You only proved a bitmap. Quote Last Reported on that row |
| Threat + process still running | “S1 failed” | Assigned Group policy = Detect |
| Mitigation = Kill | “Mitigated, go to sleep” | Explore SL-88 for persistence; Remediate is still required |
| Two rows, one hostname | Disconnect / shell the old one | Sort Last Reported; work the live row |
| Last Reported 14 hours | Start Remote Shell / Fetch | Agent ticket. You will not collect tonight |
| Network Status = Connected + Malicious | “Kill isolated the host” | Disconnect the workstation; change-control for DC/DNS/DHCP |
| Blocked demo, Protect on | Detect for the Site | Scoped exclusion / Group + owner + end time |
| Filename in Slack | Bridge starts on update.exe | Confidence + Storyline, then Disconnect |
- UTC window written next to the tool you opened.
- Agent proved:
Last Reported+Network Status+Agent Versionon the row you named. - One conviction quoted: Threat Center
Threat Status/AI Confidence Level/Analyst Verdict, or one Storyline persistence line, or one Fetch / Remote Shell output, or one Detect vs Protect mode. - If disconnected: Network Status = Disconnected and Last Reported still incrementing (console path up). Confirmed not DC/DNS/DHCP.
- If exclusion or Detect Group: owner, expiry. No Site-wide Detect.
- Remote Shell / Fetch only with a live Last Reported and, for unconstrained commands, a change number.
I name the question, then the first tool, then one official field. Sentinels proves the agent. Threat Center proves the conviction. Storyline proves the plot. Policy Detect vs Protect proves whether the agent was allowed to mitigate. Remote Shell / Fetch proves the live host. I Disconnect a live workstation. I do not start with “S1 missed it.” Factory model: Storyline is the S1 word — kill is not remediate.
Knowledge check
Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.
Sources
- SentinelOne Customer Portal / Knowledge Base (official console paths: Sentinels, Incidents / Threat Center, Policy, Remote Shell, Fetch File, Decommissioned filter — confirm labels on your generation)
- SentinelOne FAQ (Management console manages agents; kill, quarantine, remediate, rollback, network isolation; Remote Shell — PowerShell on Windows, Bash on macOS and Linux; AI Confidence Level on incidents)
- SentinelOne — Feature Spotlight: Introducing the New Threat Center (
Threat Status,AI Confidence Level,Analyst Verdict, Incident Status; Overview / Explore / Timeline; Fetch File; Remote Shell; endpoint online / quarantined snapshot) - SentinelOne — Singularity Complete (Storyline context; automated and manual remediation including 1-click rollback; block incoming and outgoing network; Full Remote Shell)
- SentinelOne — Singularity Endpoint
- SentinelOne — ActiveEDR feature spotlight (on-agent correlation that becomes the Storyline)
- SentinelOne — Deep Visibility (hunt from Threat Center network history / Storyline ID)
- SentinelOne — Detect or Protect is governed by customer-controlled policies (Protect takes the mitigation actions defined in the policy)
- SentinelOne — Storyline Active Response (STAR)
- SentinelOne — Threat hunting + auto-mitigate / network quarantine
- SentinelOne — What is EDR? + Storyline correlation
- SentinelOne Status (platform-wide console health — not a substitute for one host’s Last Reported)
Related: Blog 1 · Storyline is the S1 word — kill is not remediate · SentinelOne dashboard · Dummy lab · Storyline, Ranger & Rollback