Elastic medium stable kql

SentinelOne Threat External Alerts

Generates a detection alert for each SentinelOne threat written to the configured indices. Enabling this rule allows you to immediately begin investigating SentinelOne threat alerts in the app.

View Source

Detection Logic

event.kind: alert and data_stream.dataset: sentinel_one.threat

Field Validations

Loading…

Comments (0)

Loading comments...