# Prove SentinelOne is working — first tool + proof field

Source: https://ai.techclick.in/blog_sentinelone_evidence_desk
Markdown: https://ai.techclick.in/blog_sentinelone_evidence_desk.md
Publisher: Techclick Infosec Pvt Ltd

How you prove SentinelOne is working: Sentinels agent health, Threats Analyst Verdict / AI Confidence, Storyline, Policy Detect vs Protect, Remote Shell / fetch. Five tickets with first tool and one proof field.

Quick answer (say this out loud)

    Sentinels  answers “did this agent check in?”  Threat Center  answers “what is the Threat Status, AI Confidence Level, and Analyst Verdict?”  Storyline  (Explore) answers “what is the plot — process, file, persistence, network?”  Policy Detect vs Protect  answers “was this Group even allowed to mitigate?”  Remote Shell / Fetch File  answers “what is on this live host right now?” A green tray icon is not  Last Reported . A Detect-mode Group is not a miss. Kill is not Remediate. Disconnect from Network is a separate lever.

## 1. Why “is the agent working?” is five questions

 Operators collapse five failures into one sentence. The agent never checked in. The host is decommissioned or already disconnected. The Group policy is Detect, so the agent alerted and did not kill. The Storyline still has a Run key after mitigation = Kill. Remote Shell cannot start because Last Reported is fourteen hours ago. Those are five first clicks.

 This page is the night-shift desk for  proof . The factory taught Storyline, Kill vs Remediate, and Disconnect from Network. Here you learn the five console surfaces you actually open, in order, when someone asks you to prove SentinelOne is working — or to explain why it did not block.

   Hero · five tiles, one ticket

   Notice: five tiles, not one “Singularity dashboard.” You pick the tile that matches the question, then you quote one field.

   Interview line

   If they say “prove SentinelOne is working,” do not say “I opened the console.” Say: “I prove the agent with Sentinels  Last Reported  and  Network Status , the conviction with Threat Center  AI Confidence Level  and  Analyst Verdict , the plot with Storyline on Explore, the block decision with Group policy Detect vs Protect, and the live host with Remote Shell or Fetch File.”

## 2. Mental model — five proof tools

 Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you Disconnect a DC at 02:00 or flip the whole Site to Detect.

#### 1 · Sentinels

      Sentinels  (agent inventory). Proves the agent:  Last Reported ,  Network Status ,  Agent Version , online vs decommissioned. Does not prove a verdict or a policy mode.

#### 2 · Threat Center

      Incidents  → a threat → Threat Center. Proves one conviction:  Threat Status ,  AI Confidence Level ,  Analyst Verdict . Does not prove the Group can Protect.

#### 3 · Storyline

     Threat Center →  Explore . Proves the plot: Storyline ID, process tree, files, registry, network. A filename in Slack is not the Storyline.

#### 4 · Policy mode

     Group card → assigned  Policy . Proves Detect vs Protect for the engines on that Group. Detect is configuration, not a miss.

#### 5 · Remote Shell / Fetch

     Endpoint or Threat Center →  Remote Shell  or  Fetch File . Proves live state. PowerShell on Windows, Bash on macOS/Linux. A dark Last Reported does not collect.

#### Hard words, once

      Storyline  = correlated attack story.  AI Confidence  = Malicious or Suspicious.  Analyst Verdict  = True Positive / False Positive / Suspicious / Undefined.  Protect  = policy may auto-mitigate.  Disconnect from Network  = isolate except the management console.

   Flow 1 · five tools, one question each

       Five SentinelOne proof tools and the one question each is allowed to answer

- Write hostname + Storyline ID + UTC first · then pick the tool Is the agent working? five questions, not one Sentinels Agent talking? Last Reported Network Status Sentinels inventory not a verdict Threat Center This conviction? AI Confidence Analyst Verdict Incidents → threat not a policy mode Storyline What is the plot? Explore · tree persistence Threat Center → Explore not live shell Policy mode Allowed to block? Detect vs Protect Group assign Sentinels → Policy Detect is not a miss Remote Shell Live host now? shell · Fetch File needs Last Reported Actions → Remote Shell dark host = no fetch Empty Incidents is data. It usually means the agent never landed or is decommissioned. Do not invent a miss from an empty queue. Start at Sentinels Last Reported. Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing. Say this out loud I prove the agent, then the conviction, then the Storyline, then the assigned policy mode, then the live host. I do not Disconnect, Fetch, or flip Detect to Protect until I can quote the field that made me do it. ## 3. Decision flow — ticket → first tool Flowchart first. Do not open Policy or start Remote Shell until a diamond says so. Path · pick the branch before the menu Notice: the diamond is the ticket. The path is the tool. The field comes last. Do not reverse that order. Flow 2 · first-tool diamond Decision diamond from symptom to first SentinelOne proof tool Symptom first · tool second · field third What must we prove? Agent live? or already inside? “Is the agent up?” Sentinels Last Reported “Why no block?” Group Policy Detect vs Protect Live malicious plot Threats + Explore verdict · Storyline Need a file / shell Fetch / Remote Shell after Last Reported Blocked demo / VIP Group Policy scoped exclusion Last Reported hours ago / decommissioned = stop. There is no live shell and no “S1 miss.” Fix the agent (filter, token, offline, leftover row). Then re-open Incidents. Diamond = decision. Do not Disconnect from the bottom box. Do not flip Protect from an empty queue. Confirm current menu labels in the SentinelOne Customer Portal knowledge base on your console generation. Read the diamond first. “Why didn’t it block?” never starts in Remote Shell. A dark Last Reported never starts in Policy. A blocked demo is often Protect success. ## 4. How to choose — first tool + proof field Print this next to the Singularity console. If you cannot recite the proof field, you are not ready to Disconnect or change Detect to Protect. If the ticket says… First tool (official path) Proof field Do not open first Laptop / hotel / “is the agent even working?” Sentinels Last Reported (UTC) + Network Status + Agent Version + decommissioned filter A new STAR rule, or Remote Shell “Why didn’t it block?” after a threat fired Endpoint card → assigned Policy (Group) Policy name + engine set to Detect (not Protect) Tenant-wide Protect-off Malicious file / user still working / “mitigated” Incidents → Threat Center, then Explore Threat Status + AI Confidence Level + Analyst Verdict + Storyline persistence The filename argument in Slack Need the sample, a running process, or a live command Threat Center Fetch File , or Actions → Remote Shell (after Last Reported is seconds) Fetch completed, or shell session + command output Remote Shell on a host Last Reported hours ago Red team / VIP: “S1 broke the demo” Assigned Group Policy Policy name + Protect mode that matched + scoped exclusion / Group Global Detect for the Site Console label caveat (official) Singularity menu chrome moves by console generation. SentinelOne documents Sentinels for agent inventory, Incidents opening the Kauai-era Threat Center (Overview / Explore / Timeline), Group Policy with Detect vs Protect, Remote Shell , and Fetch File . Older tenants may still say Threats instead of Incidents. Confirm the click-path in the SentinelOne Customer Portal knowledge base for your console. The proof fields — Last Reported, Network Status, Threat Status, AI Confidence Level, Analyst Verdict, Storyline ID, Detect vs Protect — are the ones you paste. ## 5. Runbook Side A → B → C Side A proves the agent is on the wire. Side B proves what Singularity saw and whether policy was allowed to mitigate. Side C proves live response. On a messy Sev-2, do them in this order until a field lights up. ### Side A — Sentinels (agent health) #### Open Sentinels, not Incidents Path: Sentinels . Search hostname. If two rows appear, sort by Last Reported and work the live one — the stale row is often a leftover or a pending-decommission record. Source: SentinelOne FAQ (Management console manages agents); Customer Portal knowledge base for Sentinels filters including Decommissioned.

- #### Read the four agent columns that close “is the agent working?” Last Reported — most recent console check-in (UTC). Agent Version . Network Status — Connected or Disconnected (after Disconnect from Network ). Decommissioned filter — offline agents drop out of the default view (commonly after 21 days unless your Site changed the aging). Source: Sentinels inventory columns; FAQ on remote agent management.

- #### If Last Reported is hours, stop. This is an agent ticket Do not start Remote Shell. Do not Fetch File and call it collected. Do not call it a miss. Check connectivity to the management console, install token / Site, pending uninstall, and whether you opened a decommissioned row. Then come back.

- #### If Network Status is already Disconnected, say that out loud Disconnect from Network cuts inbound and outbound except the management console. That is containment, not “agent down.” Quote Network Status before anyone “fixes S1” by reconnecting a live malicious host.

     usea1-lab.sentinelone.net · Sentinels

     Training mock · not live

       Sentinels / Endpoints

### Sentinels

          Endpoint  ENDPOINT-LAB-41

          Last Reported  Last 24 hours

           Endpoint  Site / Group  Last Reported  Network Status  Agent Version

            ENDPOINT-LAB-41  Techclick-Lab / FIN-WS  16s ago   Connected   24.1
            ENDPOINT-LAB-41  Techclick-Lab / FIN-WS  12 days ago   Connected   23.4

        Show decommissioned  View endpoint

    Source:  SentinelOne FAQ — Management console manages agents; Customer Portal knowledge base — Sentinels filters, Decommissioned agents. Two rows, one hostname — work the 16s row. Lab identities only. Training mock · not live.

### Side B — Threat Center, Storyline, Policy Detect vs Protect

- #### Open the threat, not Slack’s filename Path: Incidents → the threat (older chrome: Threats ). You land in Threat Center. Official status bar: Threat Status (mitigated by policy or not), AI Confidence Level (Suspicious or Malicious), Analyst Verdict and Incident Status. Source: Feature Spotlight — Introducing the New Threat Center.

- #### Read Threat Status, AI Confidence, Analyst Verdict Those three close “what did the agent think this was, and what did a human mark?” A Malicious / Undefined / Not mitigated threat is not a hash debate. Set Analyst Verdict (True Positive, False Positive, Suspicious). Do not leave it Undefined while you argue update.exe .

- #### Open Explore (Storyline) before you type Remote Shell Threat Center → Explore . Official: the entire attack Storyline — processes, files, registry, network, DNS — in Process Tree or the table. Quote Storyline ID and persistence. Explore is historical telemetry. Remote Shell is live. Do not skip the plot to go collect a file the tree already named.

- #### If the ticket is “why didn’t it block?”, open the assigned Group policy Path: endpoint card → Policy, or Policy on that Group. Read Detect vs Protect for the engine that convicted (Static AI / Behavioral AI). Official: the choice between Detect or Protect is governed by policies the customer controls; Protect takes the mitigation actions defined in the policy. Detect means the product did what that Group is configured to do. Promote to Protect under change control — do not call it a miss and do not flip the Site.

     usea1-lab.sentinelone.net · Incidents → THR-1042 · Threat Center

     Training mock · not live

       Incidents / THR-1042 / Overview

### Threat Center

          Threat Status  Mitigated · Kill

          AI Confidence Level  Malicious

          Analyst Verdict  Undefined

          Storyline ID  SL-88

           Role  Object  Detail (lab)  State

            File  update.exe  C:\Users\finance.user\Downloads\  killed
            Persistence  Run key  HKCU\...\Run · update.exe  present
            User  finance.user  interactive logon  active

        Set verdict  Explore Storyline

    Source:  SentinelOne — Feature Spotlight: Introducing the New Threat Center ( Threat Status ,  AI Confidence Level ,  Analyst Verdict , Explore Storyline, Fetch File, Remote Shell). Lab identities only. Training mock · not live.

  Threat + policy — fields you write in the ticket  Path:            Incidents → threat → Threat Center
Quote:           Threat Status + AI Confidence Level + Analyst Verdict
Then:            Explore  (Storyline ID · process tree · persistence)
If “no block”:   Sentinels → endpoint → assigned Policy
Quote:           policy name + Detect vs Protect for that engine
If empty queue:  Sentinels Last Reported / decommissioned first

     usea1-lab.sentinelone.net · Policy · FIN-WS-Detect

     Training mock · not live

       Policy / Group FIN-WS / FIN-WS-Detect

### Policy mode

          Policy name  FIN-WS-Detect

          Assigned via  Group · FIN-WS

          Behavioral AI  Detect

          Static AI  Detect

 Assigned policy on ENDPOINT-LAB-41:  FIN-WS-Detect

 Engine that convicted:  Detect — not Protect

 Product did what this Group is configured to do.

Promote to Protect under change control. Do not flip the Site.

        Cancel  Save (change control)

    Source:  SentinelOne — Detect or Protect is governed by customer-controlled policies; Protect takes the mitigation actions defined in the policy (Static AI / Behavioral AI write-ups; Singularity Complete response set). Confirm engine labels on your build. Lab policy name only. Training mock · not live.

### Side C — Remote Shell / Fetch File + Disconnect from Network

- #### Contain a live malicious workstation before you collect souvenirs Official action: Disconnect from Network (network isolation). The host keeps a path to the management console. That is the right 01:40 move on a finance laptop with a live Malicious Storyline. It is the wrong reflex on a DC / DNS / DHCP — those wait for change-control. Source: SentinelOne FAQ (network isolation); Singularity Complete (block incoming and outgoing network activity).

- #### Fetch File or start Remote Shell only after Last Reported is seconds Threat Center can fetch the threat file from the same view. Endpoint Actions → Remote Shell opens PowerShell on Windows and Bash on macOS and Linux, securely from the Management Console. A dark Last Reported does not give you a shell tonight — that is not evidence.

- #### Use the documented action that answers the ticket Fetch the file the Storyline already named. Use Remote Shell to confirm the process or persistence the Explore tab showed. Quote the action and the output. Remote Shell is change-control — you need the role and, in most shops, a change number before you delete or run unconstrained commands.

     usea1-lab.sentinelone.net · Sentinels → ENDPOINT-LAB-41 → Remote Shell

     Training mock · not live

       Sentinels / ENDPOINT-LAB-41 / Actions / Remote Shell

### Remote Shell

          Session  PowerShell · established

          Last Reported  18s ago · Network Disconnected

 remote shell:  connected  host=ENDPOINT-LAB-41

 PS&gt; Get-Item HKCU:\Software\Microsoft\Windows\CurrentVersion\Run

  update.exe  C:\Users\finance.user\Downloads\update.exe

 Threat Center → Fetch File  update.exe

 fetch:  complete · sha256=lab-only

        End session  Run

    Source:  SentinelOne FAQ — Remote Shell (PowerShell on Windows, Bash on macOS and Linux from the Management Console); Threat Center spotlight — fetch the threat file from the same view; Singularity Complete — Full Remote Shell. Do this after Last Reported is live. Training mock · not live.

   Green success on each side

- Side A: Sentinels Last Reported is seconds on the row you named; Network Status is stated; you said which row if the hostname duplicated.

- Side B: Threat Center quotes Threat Status + AI Confidence Level + Analyst Verdict ; Explore names Storyline ID and persistence; “no block” quotes Detect on the assigned Group policy.

- Side C: Network Status = Disconnected on a workstation (or change-control named on infra); Fetch File or Remote Shell output is pasted, or you documented why you did not start a shell.

## 6. Five tickets as full stories

 These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only.

     Ticket  Symptom  First tool  Proof field

       S1-ED-01   WFH laptop: “S1 is down, icon looks installed”  Sentinels   Last Reported  + Network Status + Agent Version — or the 12-day leftover row
       S1-ED-02   Threat fired; process still running; “why didn’t it block?”  Group Policy  Policy name + engine = Detect (not Protect)
       S1-ED-03   Mitigated = Kill; user still on the laptop  Threat Center → Explore  AI Confidence + Analyst Verdict + Storyline persistence, then Disconnect if a workstation
       S1-ED-04   Need the sample / live Run-key proof  Fetch File / Remote Shell  Fetch complete, or shell output — after Last Reported is seconds
       S1-ED-05   Red team: “S1 broke the demo”  Group Policy  Protect mode that matched + scoped exclusion / Group

### S1-ED-01 — Prove the agent (Sentinels)

  01:42 · P2.  Priya on a hotel network. Phone photo of a SentinelOne tray icon. L1 already drafted “S1 missed the malware.” Incidents for her hostname are empty.

  First tool:   Sentinels . Search  ENDPOINT-LAB-41 .

  If Last Reported is hours / the only row is decommissioned:  quote that pair. Empty Incidents is expected. Next check is the agent — console connectivity, install token, Site, leftover row — not a new STAR rule.

  If Last Reported is seconds and Network Status is Connected:  the agent is talking. Now you are allowed to open Incidents for that endpoint and UTC window. A tray icon is not  Last Reported .

  Trap

 Two rows, one hostname. The 12-day row is leftover. Disconnecting it does not touch the laptop on the desk. Sort  Last Reported . Do not rebuild the fleet because  status.sentinelone.com  is green and this one host is dark.

### S1-ED-02 — Prove why it did not block (Policy Detect vs Protect)

  02:05 · P2.  A threat fired. The process is still running. Someone typed “S1 failed” in the channel and wants Protect off for Finance so they can work.

  First tool:  endpoint card → assigned  Policy , or  Policy  on Group  FIN-WS . Confirm the Group that assigned it.

  Proof field:  policy name (lab:  FIN-WS-Detect ) and Behavioral AI / Static AI set to  Detect . That is the ticket. The agent did what that Group is configured to do. Set Analyst Verdict. Disconnect if the Storyline is real. Promote the engine to Protect under change control. Do not flip the Site to Detect.

  Close

 I would not call this a miss. I would quote Detect on the assigned policy, Disconnect the live workstation if Confidence is Malicious, and open a change to move that one Group to Protect.

### S1-ED-03 — Prove the conviction and the plot (Threat Center + Storyline)

  02:20 · P1.  THR-1042. User still in Outlook. L1 wants to close because mitigation = Kill.

  First tool:   Incidents  → THR-1042 → Threat Center, then  Explore .

  Proof field:   Threat Status  = Mitigated (Kill),  AI Confidence Level  = Malicious,  Analyst Verdict  still Undefined; Explore shows Storyline  SL-88  with a Run key under  finance.user . Last Reported 16s, Network Status = Connected. Kill stopped a process. It did not finish the plot. Disconnect this workstation. Remediate the Storyline. Set the verdict. Filename later.

  Close

 Quote Confidence + Verdict + the persistence line on SL-88. Disconnect the live workstation. Do not spend the bridge on whether the file is named  update.exe . Source: Threat Center status bar + Explore Storyline + FAQ kill / remediate / network isolation.

### S1-ED-04 — Prove the live host (Fetch File / Remote Shell)

  02:40 · P2.  IR wants the sample on disk. Someone already opened Remote Shell against the 12-day row.

  First tool:  Sentinels  Last Reported  on the row you will session, then Threat Center  Fetch File  or Actions →  Remote Shell .

  Proof field:  fetch complete for the path on Explore, or a PowerShell/Bash session showing the Run key / process the Storyline already named. If Last Reported is hours, you will not collect — that is not evidence in the ticket tonight.

  Trap

 Remote Shell needs a live agent. Fetch File from Threat Center is the shorter path when the object is already the threat file. Do not shell a decommissioned row and claim you collected. Do not reconnect Network Status just to make a download easier on a live Malicious host.

### S1-ED-05 — Prove the block was policy (Protect mode)

  03:00 · P3.  Red team says SentinelOne broke the demo. Group policy on that host is Protect. L1 wants Detect for the Site until Monday.

  First tool:   Policy  for the demo Group.

  Proof field:  policy name + Protect mode that matched the demo tool. A blocked demo can be policy success. Scope a time-boxed exclusion or move that one host to a Detect Group with an owner and an end time. Keep Protect on for everyone else.

  Close

 I would not set Detect for the Site. I would paste the policy name, the mode, and the exclusion / Group move + owner + expiry. Then re-read Incidents on the demo host after the change.

## 7. Traps + close-the-ticket proof

   Proof · named field, then Closed

   Notice: the close is a named column on a timestamp, not a screenshot of the user’s tray icon.

     You see  Weak close  Strong close

      Empty Incidents  “S1 missed it”  Sentinels  Last Reported  + decommissioned filter first
      Tray icon on a phone photo  “The agent is working”  You only proved a bitmap. Quote  Last Reported  on that row
      Threat + process still running  “S1 failed”  Assigned Group policy = Detect
      Mitigation = Kill  “Mitigated, go to sleep”  Explore SL-88 for persistence; Remediate is still required
      Two rows, one hostname  Disconnect / shell the old one  Sort  Last Reported ; work the live row
      Last Reported 14 hours  Start Remote Shell / Fetch  Agent ticket. You will not collect tonight
      Network Status = Connected + Malicious  “Kill isolated the host”  Disconnect the workstation; change-control for DC/DNS/DHCP
      Blocked demo, Protect on  Detect for the Site  Scoped exclusion / Group + owner + end time
      Filename in Slack  Bridge starts on update.exe  Confidence + Storyline, then Disconnect

   Proof checklist before you leave the bridge

- UTC window written next to the tool you opened.

- Agent proved: Last Reported + Network Status + Agent Version on the row you named.

- One conviction quoted: Threat Center Threat Status / AI Confidence Level / Analyst Verdict , or one Storyline persistence line, or one Fetch / Remote Shell output, or one Detect vs Protect mode.

- If disconnected: Network Status = Disconnected and Last Reported still incrementing (console path up). Confirmed not DC/DNS/DHCP.

- If exclusion or Detect Group: owner, expiry. No Site-wide Detect.

- Remote Shell / Fetch only with a live Last Reported and, for unconstrained commands, a change number.

   Interview close

   I name the question, then the first tool, then one official field. Sentinels proves the agent. Threat Center proves the conviction. Storyline proves the plot. Policy Detect vs Protect proves whether the agent was allowed to mitigate. Remote Shell / Fetch proves the live host. I Disconnect a live workstation. I do not start with “S1 missed it.” Factory model:  Storyline is the S1 word — kill is not remediate .

## Knowledge check

   Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

       Q1
       WFH user: “Is the agent even working?” Incidents for her hostname are empty. You have not opened a policy yet. First proof?

           Write a new STAR rule so something fires
           Sentinels — quote Last Reported, Network Status, and which row if the name is duplicated
           Start Remote Shell and list processes
           Set the Site policy to Detect

       Correct:  b . Empty Incidents is data. Official first surface is Sentinels Last Reported / Network Status. Re-read Side A and S1-ED-01.

       Q2
       A threat fired an hour ago. The process is still running. Which proof field closes “why didn’t it block?”

           Assigned Group policy: the engine is Detect, not Protect
           Remote Shell session banner
           status.sentinelone.com only
           A phone photo of the tray icon

       Correct:  a . Detect-only is configuration, not a miss. Remote Shell and the status page answer different tickets. Re-read Side B step 4 and S1-ED-02.

       Q3
       Last Reported on the row is 14 hours. IR wants Fetch File and Remote Shell. What do you do first?

           Open Remote Shell anyway — Fetch always returns the file tonight
           Disconnect the dark row and call it done
           Treat it as an agent ticket. Quote Last Reported. Do not claim you collected
           Flip Protect off from Policy so the host can check in

       Correct:  c . Official Remote Shell / Fetch need a live agent. A dark Last Reported does not collect. Re-read Flow 2 bottom box and S1-ED-04.

       Q4
       THR-1042 shows Threat Status Mitigated (Kill), AI Confidence Malicious, Analyst Verdict Undefined. Last Reported is 16s. Network Status is Connected. Next?

           Set the Site to Detect so Finance can keep working
           Close the P1 — mitigated means clean
           Remote Shell the 12-day leftover row with the same hostname
           Open Explore on SL-88, quote persistence, Disconnect this workstation, then Remediate

       Correct:  d . Kill is not Remediate. Explore is the plot. Disconnect is a separate lever on a workstation. Re-read Side C step 1 and S1-ED-03.

       Q5
       You already have THR-1042. You need the sample on disk and confirmation of the Run key. First surface?

           Policy Detect/Protect — it lists every Run key
           Threat Center Fetch File for the threat object, then Remote Shell only after Last Reported is seconds — quote Explore first so you know the path
           status.sentinelone.com
           Reconnect Network Status so the tree can populate

       Correct:  b . Fetch File is documented on Threat Center. Explore is historical. Remote Shell is live. Do not reconnect a Malicious host to “make Fetch work.” Re-read Side B step 3 and Side C.

       Q6
       Red team says SentinelOne broke their demo. The assigned Group policy is Protect. Best first reply?

           Time-boxed exclusion or move that one host to a Detect Group with an owner and an end time — quote the policy name and Protect mode that matched
           Set Detect for the whole Site until Monday
           Agree S1 failed and close as a miss
           Decommission the host from Sentinels

       Correct:  a . A blocked demo can be policy success. Scope the exception; keep Protect on. Re-read S1-ED-05 and the How to choose table.

       Check answers
       Reset

## Sources

- SentinelOne Customer Portal / Knowledge Base (official console paths: Sentinels, Incidents / Threat Center, Policy, Remote Shell, Fetch File, Decommissioned filter — confirm labels on your generation)

- SentinelOne FAQ (Management console manages agents; kill, quarantine, remediate, rollback, network isolation; Remote Shell — PowerShell on Windows, Bash on macOS and Linux; AI Confidence Level on incidents)

- SentinelOne — Feature Spotlight: Introducing the New Threat Center ( Threat Status , AI Confidence Level , Analyst Verdict , Incident Status; Overview / Explore / Timeline; Fetch File; Remote Shell; endpoint online / quarantined snapshot)

- SentinelOne — Singularity Complete (Storyline context; automated and manual remediation including 1-click rollback; block incoming and outgoing network; Full Remote Shell)

- SentinelOne — Singularity Endpoint

- SentinelOne — ActiveEDR feature spotlight (on-agent correlation that becomes the Storyline)

- SentinelOne — Deep Visibility (hunt from Threat Center network history / Storyline ID)

- SentinelOne — Detect or Protect is governed by customer-controlled policies (Protect takes the mitigation actions defined in the policy)

- SentinelOne — Storyline Active Response (STAR)

- SentinelOne — Threat hunting + auto-mitigate / network quarantine

- SentinelOne — What is EDR? + Storyline correlation

- SentinelOne Status (platform-wide console health — not a substitute for one host’s Last Reported)

 Related:  Blog 1 · Storyline is the S1 word — kill is not remediate  ·  SentinelOne dashboard  ·  Dummy lab  ·  Storyline, Ranger &amp; Rollback

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
