T Techclick ← SentinelOne hub
SentinelOne · Singularity · Session factory · Interactive lesson

SentinelOne is an agent + storyline factory. Health, plot, then remote action.

The ticket says “S1 missed update.exe.” The tray icon is green. The filename is already in Slack. That is not a missing feature. The factory either never checked in, printed a Storyline you have not opened, stamped Detect instead of Protect, or is still waiting for a remote action. This lesson is the official line: agent health → threat / Storyline → Detect vs Protect policy → remote action. Proof is a live Last Reported, a Storyline ID, the assigned Group policy mode, and a Remote Shell or Fetch File — not a screenshot of a tray icon.

20 min read · L2 primary · Quiz at end · Dummy lab only · Blog 2 · Evidence desk

⚡ Quick Answer

SentinelOne is an agent + storyline factory: agent health → threat/storyline → Detect vs Protect policy → remote action. Official SentinelOne docs only.

After this page you can

Quick answer

SentinelOne is an agent + storyline factory. The autonomous agent on the host observes process, file, registry and network activity and stays protective even when offline. When it can talk, Sentinels writes Last Reported and Network Status. Related events become one Storyline ID — the plot, not the filename. The assigned Group Policy stamps Detect (alert, do not auto-mitigate) or Protect (kill, quarantine, remediate, rollback as the policy defines). Remote action is how you finish: Fetch File, Remote Shell, Disconnect from Network. Success is a live check-in, a Storyline you can quote, a policy mode you can name, and an action that actually ran — not “the icon is green.”

Say this out loud

I do not start with the filename. I ask whether this agent checked in, what Storyline the threat belongs to, whether that Group is Detect or Protect, and which remote action finishes the plot. A Detect stamp is not a miss. Kill is not Remediate. A dark Last Reported cannot take a Remote Shell or a Fetch.

1. Why a green tray is not a Storyline

Every other briefing starts with the filename. update.exe. “S1 missed it.” That is why students freeze in interviews. The real object is the Storyline the agent printed. Features are only stamps the factory puts on that plot before a human (or Protect policy) takes a remote action.

Official SentinelOne architecture: a single autonomous agent on the endpoint, a Management console that manages those agents, and on-agent Static AI plus Behavioral AI that classify before and during execution. Official FAQ: the agent protects while disconnected from the internet; administrative visibility in the console is lost until the device is back online. Official Sentinels field: Last Reported is the most recent console check-in. Hours old is a dark factory floor. Seconds old is a live worker.

Hero · the factory floor
Teaches: a host event becomes a SentinelOne Storyline ticket that walks agent health, plot, policy and remote action
Notice: SentinelOne does not “miss a file.” It tries to manufacture a Storyline, stamp it with Detect or Protect, and wait for a remote action.

What the ticket asked

“S1 missed update.exe.” That sentence is a hypothesis. The factory may already have Detect-stamped the Storyline and printed a live ticket you have not opened.

What you prove first

Identity of the endpoint row, then Last Reported, then the assigned Group policy, then the Storyline. The evidence desk is the night-shift version of this order.

The lie every L1 repeats

“The tray icon is green, so SentinelOne is working — we need a wider exclude.” A green icon only means an agent process is running on that laptop. If Last Reported is fourteen hours old, or the assigned Group is Detect, or the leftover Sentinels row is the one you opened, the factory did not print the ticket you think it printed. Widening an exclusion just stamps more events as invisible.

Hard words before the runbook

Agent / Sentinels

The software on the host. Sentinels is the inventory. Official fields: Last Reported, Network Status, Agent Version. One hostname can have two rows after a reimage. Work the live check-in.

Storyline

Official: each agent builds a model of the endpoint; a Storyline ID groups related processes, files, threads and events. Threat Center Explore is that plot. A filename in Slack is not the Storyline.

Detect vs Protect

Assigned on the Group Policy. Official: the choice is customer-controlled. Detect alerts and does not auto-mitigate. Protect takes the mitigation actions defined in the policy. A Detect stamp is configuration, not a miss.

Remote action

Official response set: alert, kill, quarantine, remediate unwanted changes, Windows rollback, network isolation, Remote Shell, Fetch File. Disconnect from Network is isolation except the management console. Kill is not Remediate.

Official Threat Center status bar (Kauai): Threat Status (mitigated by policy or not), AI Confidence Level (Suspicious or Malicious), Analyst Verdict and Incident Status. Official Remote Shell: PowerShell on Windows, Bash on macOS and Linux; must be enabled in the management policy; each session uses a dedicated encryption password; 2FA before access; every session is audited. Use those words in the ticket.

Console label caveat (official)

Singularity menu chrome moves by console generation. SentinelOne documents Sentinels for agent inventory, Incidents opening the Kauai-era Threat Center (Overview / Explore / Timeline), Group Policy with Detect vs Protect, Remote Shell, and Fetch File. Older tenants may still say Threats instead of Incidents. Confirm the click-path in the SentinelOne Customer Portal knowledge base for your console. The factory fields — Last Reported, Network Status, Threat Status, AI Confidence Level, Analyst Verdict, Storyline ID, Detect vs Protect — are the ones you paste.

2. Mental model — four factory stations

Hold four parts. Interviews fail when people mix them. Skipping a station is how you Disconnect a leftover row or argue a miss on a Group that was never allowed to Protect.

1. The worker is the agent

One autonomous agent. It sees the host. Last Reported is the heartbeat. Network Status Connected vs Disconnected is containment state, not “agent down.” A green tray is not Last Reported.

2. The ticket is the Storyline

Process, file, registry, network, DNS. The first event of a new plot is setup. Later events of the same Storyline ID ride that story. No Storyline = nothing for policy to stamp.

3. The stamp is Detect or Protect

Policy on the assigned Group. Detect writes the threat and lets the process run. Protect writes the threat and may kill / quarantine / remediate / rollback. STAR custom rules sit on the same Storyline.

4. The finish is a remote action

Fetch File, Remote Shell, Disconnect from Network, or a mitigation you can name. Official: analysts want to know what the Agent did — processes killed, files quarantined, items rolled back. “Mitigated” without that list is a slogan.

Path · first event vs later events
Teaches: a Last Reported diamond splits a live factory path from a dark-agent rebuild path
Notice: the diamond is not “did S1 miss it?” It is “did this agent print a Storyline the console could stamp?”
Flow 1 · one ticket, four stations
ENDPOINT-LAB-41 · THR-1042 · SL-88 · Last Reported 16s 1 Agent health Sentinels inventory Last Reported · Version Network Status dark = no ticket 2 Threat / Storyline Incidents → Center Explore · Storyline ID AI Confidence · Verdict filename ≠ plot 3 Detect vs Protect Group Policy assign Static AI / Behavioral STAR on same Storyline Detect ≠ miss 4 Remote action Fetch File · Shell Kill ≠ Remediate Disconnect from Network needs Last Reported Policy stamp Detect lets it run Protect may auto-mitigate Storyline stamp plot, not the hash Explore · process / file / Run Disconnect is a network stamp not isolate · console path stays Connected → Disconnected Duplicate-row check lives inside station 1. Sort Last Reported. Work the live agent. Sentinels is the live table. Threat Center is the plot. Policy is the recipe. Remote action is the finish. A saved Detect slider is not a miss.

Read left → right. Station 1 is Last Reported plus the live row. Remote action is last, and only on a live host. Disconnect is a network stamp, not a replacement for Remediate.

Concept: SentinelOne manufactures Storylines on an agent and stamps them with Detect or Protect. Path: agent health → threat / Storyline → Group policy → remote action. Do: never open the filename first.

Agent health answers “is this endpoint talking?” Official: Management console manages agents; protection continues offline; console visibility returns when the device is back. Fields: Last Reported, Network Status, Agent Version. Source: SentinelOne FAQ + Customer Portal Sentinels inventory.

Storyline answers “what is the plot?” Official: a Storyline ID groups related events in the agent’s model; Explore shows processes, files, registry, network and DNS. Threat Status, AI Confidence Level, Analyst Verdict sit on the status bar. Source: Threat Center feature spotlight + Storylines / Deep Visibility spotlight.

Detect vs Protect answers “was this Group allowed to block?” Official: the choice is governed by customer-controlled policies; Protect takes the mitigation actions defined in the policy (Static AI / Behavioral AI). Source: SentinelOne detection-engine write-up + Singularity Complete response set.

Remote action answers “what did we do on this live host?” Official: alert, kill, quarantine, remediate, Windows rollback, network isolation, Remote Shell, Fetch File. Remote Shell is native PowerShell or Bash from the Management Console. A dark Last Reported does not collect. Source: FAQ + Full Remote Shell spotlight + Threat Center (Fetch File).

3. First event vs later events of the Storyline

The first event of a new process has no Storyline yet. It walks the factory: agent observes → events are grouped under a Storyline ID → assigned Group policy stamps Detect or Protect → Threat Center writes Threat Status / AI Confidence. Later events of the same Storyline ride that plot. That is why “I flipped Detect to Protect” sometimes does nothing until the next new process, and why “I Disconnected the leftover row” does nothing to the laptop on the desk.

Flow 2 · official factory order (student labels)
Agent → Last Reported? → print Storyline → Detect/Protect → remote action 1 Agent observe host Last Reported? seconds? yes SETUP — first event of this Storyline print ticket · stamp policy · wait for Threat Center Print Storyline proc / file / net Policy lookup Group assign Detect or Protect? Threat Center status · confidence Remote action only if Last Reported live Hours old agent ticket LATER EVENTS — same Storyline ID, same agent more telemetry on the existing plot · policy already stamped · Explore updates · Remote Shell still needs a live check-in Official facts students invert 1. Last Reported is console check-in, not a tray icon. Hours old = Remote Shell and Fetch sit pending. Offline still protects. 2. Policy is assigned to a Group. Read the assigned Detect vs Protect, not the Site default. 3. Detect writes a threat and lets the process run. Protect writes a threat and may auto-mitigate. Both are stamps. 4. Remote Shell must be enabled in policy; session is password-encrypted; 2FA; full audit. Dark host does not collect. 5. Disconnect from Network isolates except the management console. It is not Remediate and not a DC reflex. Source: FAQ · Threat Center spotlight · Full Remote Shell · Storylines / Deep Visibility · Customer Portal Two Sentinels rows = leftover install. Sort Last Reported. Confirm labels on your console generation.

Read left → right, then the green later-events bar. Decision diamond = “is Last Reported seconds?” Detect vs Protect sits on the live branch only.

#1 student trap — Detect called a miss

The first events of a living-off-the-land chain are still just process creates. The factory may write a threat with AI Confidence Malicious, Threat Status not mitigated, and leave the process running. That is the assigned Group policy doing what you configured. Official: Detect or Protect is governed by customer-controlled policies; Protect takes the mitigation actions defined in the policy. If the engine is Detect, promoting it or Disconnecting the workstation is a change — writing “S1 missed it” is a lie.

4. How to choose the stamps

You are not choosing a product. You are choosing what the factory is allowed to write on the Storyline, and which remote action finishes it.

ChoiceUse whenDo not use whenProof you were right
Protect on the assigned Group Production Groups that must auto-mitigate (kill, quarantine, remediate, rollback as the policy defines). A detect-only pilot you have not finished. Promoting the Site mid-incident without change control. Threat Status shows mitigated by policy. Process is not still running on Remote Shell.
Detect on the assigned Group Pilot, noisy app, or a documented exception with an owner. You treat Detect as “S1 failed” on the bridge. Policy name + Detect quoted. Threat exists. Process may still be running — that is the mode.
Kill Active process, no persistence yet on Explore. Storyline already shows a Run key / service / task and you stop at Kill. Threat Center counters: processes killed. Explore no longer shows the live process.
Quarantine / Remediate / Rollback Quarantine cages the executable. Remediate also removes persistence and restores OS/app changes. Rollback (Windows, VSS) restores files after ransomware. You say “mitigated” and mean only Kill. You Rollback a Mac/Linux host as if it were VSS. Official counters: files quarantined, items remediates / rolled back. Explore persistence gone.
Disconnect from Network Live workstation, Malicious Storyline, Network Status still Connected. Last Reported is days old. You would only Disconnect the leftover row. DC / DNS / DHCP without change-control. Network Status = Disconnected. Last Reported still incrementing. Remote Shell still opens.
Remote Shell / Fetch File You need live proof or the sample. Last Reported is seconds. Policy has Remote Shell enabled. Host is dark. You treat the shell as a scratch pad and delete first. Fetch completed, or shell session + command output + audit trail. Dedicated session password set.

Detect versus Protect is a contract for the factory, not a vibe. Official wording: the choice is governed by policies the customer controls; Protect takes the mitigation actions defined in the policy. Official response features: alert, kill, quarantine, remediate unwanted changes, Windows rollback, network isolation, remote shell. Source: SentinelOne detection-engine write-up + FAQ + Singularity Complete.

Interview phrasing

I say Last Reported, then the Storyline ID, then the assigned Detect vs Protect stamp. I Disconnect a live workstation. I do not start with “S1 missed it,” and I do not say isolate when the console says Disconnect from Network.

5. Runbook Side A → B → C

Lab values only. Site Techclick-Lab, hostname ENDPOINT-LAB-41, live row Last Reported 16s, leftover row Last Reported 12 days, user finance.user, client 192.0.2.25, threat THR-1042, Storyline SL-88, file C:\Users\finance.user\Downloads\update.exe, Group FIN-WS, policy FIN-WS-Detect. Nothing here is a live tenant. Confirm console labels on your Singularity generation. Primary source for each block is named under the steps.

Side A — Sentinels (building the factory floor)

Primary source: SentinelOne FAQ (Management console manages agents; protection while offline) + Customer Portal knowledge base — Sentinels filters, Decommissioned agents.

  1. Filter hostname, then sort Last Reported

    Sentinels. Search ENDPOINT-LAB-41. Official fields: Last Reported, Network Status, Agent Version, Site / Group. If two rows share the hostname, you have a leftover-install problem before you have a Storyline problem. Work the row with Last Reported in seconds.

  2. Read Network Status and the decommissioned filter

    Network Status Disconnected means someone already ran Disconnect from Network — the host can still talk to the management console. That is containment, not “agent down.” Offline / decommissioned agents drop out of the default view (Customer Portal: commonly after aging unless your Site changed it). Quote the filter you used.

  3. If Last Reported is hours, stop. This is an agent ticket

    Do not start Remote Shell. Do not Fetch File and call it collected. Do not call it a miss. Check connectivity to the management console, install token / Site, pending uninstall, and whether you opened the leftover row. Official FAQ: console visibility is lost until the device is back online. Then come back.

Side B — Storyline and Detect vs Protect (printing the ticket, choosing stamps)

Primary source: Feature Spotlight — Introducing the New Threat Center + SentinelOne detection-engine write-up (Detect or Protect is customer-controlled; Protect takes the mitigation actions defined in the policy).

  1. Open the threat, not Slack’s filename

    Path: Incidents → the threat (older chrome: Threats). You land in Threat Center. Official status bar: Threat Status (mitigated by policy or not), AI Confidence Level (Suspicious or Malicious), Analyst Verdict and Incident Status. Source: Feature Spotlight — Introducing the New Threat Center.

  2. Open Explore (Storyline) before you type Remote Shell

    Threat Center → Explore. Official: the entire attack Storyline — processes, files, registry, network, DNS — in Process Tree or the table. Quote Storyline ID and persistence. Explore is historical telemetry. Remote Shell is live. Do not skip the plot to go collect a file the tree already named.

  3. If the ticket is “why didn’t it block?”, quote the assigned Group policy

    Path: endpoint card → Policy, or Policy on that Group. Read Detect vs Protect for the engine that convicted (Static AI / Behavioral AI). Detect means the product did what that Group is configured to do. Promote to Protect under change control — do not call it a miss and do not flip the Site.

  4. Set Analyst Verdict. Do not leave Undefined

    True Positive, False Positive, Suspicious, Undefined. Official Threat Center: mark the threat so the rest of the team knows whether it is in progress. A Malicious / Undefined / Not mitigated threat is not a hash debate in Slack.

Predicted factory state — Techclick dummy lab
endpoint             : ENDPOINT-LAB-41
last_reported        : 16s
network_status       : Connected
agent_version        : 24.1
group / policy       : FIN-WS / FIN-WS-Detect
engine_stamp         : Behavioral AI = Detect
threat               : THR-1042
storyline            : SL-88
ai_confidence        : Malicious
analyst_verdict      : Undefined
threat_status        : Not mitigated
explore_persistence  : HKCU\...\Run · update.exe  PRESENT
remote_action        : none yet

Say the word predicted until you have opened Explore. A Detect stamp plus a live process is a printed ticket, not a miss. Compare this block to Threat Center and Remote Shell in Side C.

Side C — prove the Storyline and take a remote action

Primary source: Threat Center feature spotlight (Fetch File, Remote Shell, mitigation window, agent counters) + Full Remote Shell spotlight + FAQ (network isolation; PowerShell / Bash).

  1. Baseline the live row again

    Sentinels: hostname ENDPOINT-LAB-41, Last Reported still seconds, Network Status still Connected, you are not on the 12-day leftover. Half of “Remote Shell failed” is the leftover row. Half of empty Incidents is a decommissioned filter.

  2. Read the stamps on Threat Center

    You need Threat Status, AI Confidence Level, Analyst Verdict, Storyline SL-88, Explore persistence named. Copy the Storyline ID into the ticket before you click Mitigate.

  3. Contain a live malicious workstation before you collect souvenirs

    Official action: Disconnect from Network (network isolation). The host keeps a path to the management console. That is the right 01:40 move on a finance laptop with a live Malicious Storyline. It is the wrong reflex on a DC / DNS / DHCP — those wait for change-control.

  4. Fetch File or start Remote Shell only after Last Reported is seconds

    Threat Center can fetch the threat file from the same view. Endpoint Actions → Remote Shell opens PowerShell on Windows and Bash on macOS and Linux. Official: enable Remote Shell in the management policy; set a dedicated session password; 2FA; every session is audited. A dark Last Reported does not give you a shell tonight.

  5. Use the documented action that answers the ticket

    Kill stops processes. Quarantine cages the executable. Remediate also removes persistence and restores OS/app changes. Rollback (Windows, VSS) restores files. Official Threat Center counters tell you what the Agent actually did. If Explore still shows the Run key after Kill, you stopped too early.

# Dummy lab Remote Shell — not a customer tenant
remote shell: connected host=ENDPOINT-LAB-41 last_reported=18s network=Disconnected
PS> Get-Item HKCU:\Software\Microsoft\Windows\CurrentVersion\Run
  update.exe C:\Users\finance.user\Downloads\update.exe
Threat Center → Fetch File update.exe status=completed
# Kill would stop the process. Explore still shows the Run key. Remediate next.
Green success on this runbook

Predicted host = ENDPOINT-LAB-41 16s row, Last Reported still incrementing. Assigned policy = FIN-WS-Detect. Storyline SL-88 quoted with persistence. If you Disconnected: Network Status = Disconnected and Last Reported still incrementing. If you used Remote Shell or Fetch: session opened or fetch completed, output pasted. Action Detect with a live process is a printed ticket, not a miss. Last Reported 14 hours with an empty shell is not IR.

6. Runtime — Disconnect, dark hosts, leftover rows

After the slot exists, later events of the same Storyline skip the “is this a new plot?” question and ride the existing threat. Official Disconnect from Network: inbound and outbound are cut except the management console, so Remote Shell and Fetch File can still work. Official Remote Shell: enabled in policy, dedicated session password, 2FA, full audit. Official FAQ: if the device is offline, the agent still protects; the console just cannot see it.

If you moved Detect to Protect after the process already started, the running process may keep the old stamp until it dies. That is the later-events bar in Flow 2. Do not call it a failed save. Wait for a new process, or Disconnect this workstation now because the Storyline is real.

If Last Reported goes stale after you click Disconnect, Network Status sits where it was. That is a sensor / network problem, not a console bug. The worker never picked the action up. Fix Last Reported. Do not Disconnect the leftover 12-day row and celebrate.

HA for SentinelOne is not two firewalls. The factory is every agent plus the Management console. A green tray on a laptop whose Last Reported is Monday is one worker who clocked out. Decommission or hide the leftover row after change control so threats stop attaching to a ghost.

Proof · the live ticket
Teaches: proof is Last Reported, Storyline, Detect vs Protect, and a remote action that ran
Notice: four stamps on one ticket. A tray icon is none of them. Night-shift field map: evidence desk.
Flow 3 · Disconnect + Remote Shell runtime
Host disconnected Network Status Management console path stays open Remote Shell / Fetch needs Last Reported Everything else blocked · C2 / lateral Disconnect is not Remediate. The Run key can still be present. Explore, then Remediate. Remote Shell still works because the console channel stays open. Dark Last Reported = session never starts. Source: FAQ — network isolation · Full Remote Shell — policy enable, session password, 2FA, audit

Disconnect is a network decision. The agent stays up on purpose so you can keep investigating. Remote Shell is not free — policy, password, 2FA, audit.

7. Traps + factory proof

SymptomLooks likeActuallyFirst move
Green tray, empty Incidents S1 is fine / silent miss Last Reported stale, leftover row, or decommissioned filter — no Storyline reached the console Sentinels Last Reported + decommissioned filter
Threat fired, process still running S1 missed it Assigned Group engine is Detect Read Policy Detect vs Protect
Flipped Detect → Protect, nothing changed Save failed Later events of the same Storyline ride the old stamp Wait for a new process, or Disconnect this host
Kill done, user infected at login Product failure Explore still shows persistence. Kill is not Remediate Explore Storyline, then Remediate / Rollback
Remote Shell will not connect Permissions / console bug Dark Last Reported, leftover row, or Remote Shell not enabled in policy Last Reported, then policy Remote Ops, then session password / 2FA
Disconnect stuck / still Connected API failed Agent never checked in to apply the action Fix Last Reported. Do not Disconnect the leftover row
Two Sentinels rows, one hostname Duplicate threats Reimage / leftover install Sort Last Reported. Decommission the leftover after change control
Red-team demo blocked Product failure Protect stamp doing its job Time-boxed Group exception or scoped exclusion
Ticket says “isolate it” Same as Falcon contain / Defender isolate Console action is Disconnect from Network. Network Status = Disconnected Write Disconnect / Reconnect Network, not isolate
Proof checklist — the factory actually printed this ticket
Interview close you can steal

SentinelOne is an agent + storyline factory. I prove agent health with Last Reported and Network Status. I open the Storyline on Explore, not the filename. Detect vs Protect is the assigned Group stamp — Detect is not a miss. I finish with a remote action I can name: Fetch File, Remote Shell, Disconnect from Network, Remediate. Kill is not Remediate. A green tray is not a plot.

Related: The evidence desk · SentinelOne hub · Dummy lab

Knowledge check

Six judgment questions. Map each miss back to the section named in the reason.

Q1

A ticket says SentinelOne missed update.exe. What is the factory’s first object you must prove?

Correct: b. Agent health is station 1. A dark or leftover row cannot manufacture the ticket. Re-read Why a green tray is not a Storyline and Side A.
Q2

On the SentinelOne factory floor, what are Detect and Protect?

Correct: b. One Storyline, policy stamps. Detect is not a miss. Re-read Mental model and How to choose the stamps.
Q3

THR-1042 shows AI Confidence Malicious, the process is still in Remote Shell, and the assigned Behavioral AI engine is Detect. What happened?

Correct: a. Conviction exists. Policy stamp is Detect. Disconnect if the plot is real; promote the engine under change control. Re-read Side B and Side C.
Q4

You need live proof from ENDPOINT-LAB-41. Official Remote Shell fact you must not invert?

Correct: d. Official Full Remote Shell: policy enable, session password, 2FA, full audit. Official FAQ: console visibility is lost while offline. Re-read First event vs later events and Side C.
Q5

Sentinels shows two rows for ENDPOINT-LAB-41. First factory move?

Correct: b. Duplicate row lives inside station 1. Disconnecting the 12-day leftover does not touch the laptop on the desk. Re-read Side A and the Sentinels mock.
Q6

What proves the SentinelOne factory actually printed a working ticket for THR-1042?

Correct: c. Agent, Storyline, policy, remote action. Tray and save are not proof. Re-read Side C and the proof checklist. Field map: evidence desk.

Sources

Related: The SentinelOne evidence desk — first tool + proof field · SentinelOne hub · Dummy lab · Storyline, Ranger & Rollback