SentinelOneGroups_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (16 columns)

Source: Connector definition

Column Name Type Description
CreatedAt datetime The timestamp (UTC) when the object was created.
Creator string The name of the creator.
CreatorId string The unique identifier of the creator.
FilterId string The unique identifier of the filter.
FilterName string The name of the filter applied.
GroupType string The type of the object.
Id string The unique identifier for the object.
Inherits string Indicates whether the object inherits properties.
IsDefault string Indicates whether this is the default setting.
Name string The name of the object.
Rank real The rank of the object.
RegistrationToken string The token used for registration.
SiteId string The unique identifier of the site.
TimeGenerated datetime The timestamp (UTC) reflecting the time in which the event was generated.
TotalAgents string The total number of agents.
UpdatedAt datetime The timestamp (UTC) when the object was last updated.

Solutions (1)

This table is used by the following solutions:

Connectors (2)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] SentinelOne (using Azure Function)
SentinelOne (via Codeless Connector Framework)

Content Items Using This Table (22)

Analytic Rules (11)

In solution SentinelOne:

Analytic Rule Selection Criteria
Sentinel One - Admin login from new location
Sentinel One - Agent uninstalled from multiple hosts
Sentinel One - Alert from custom rule
Sentinel One - Blacklist hash deleted
Sentinel One - Exclusion added
Sentinel One - Multiple alerts on host
Sentinel One - New admin created
Sentinel One - Rule deleted
Sentinel One - Rule disabled
Sentinel One - Same custom rule triggered on different hosts
Sentinel One - User viewed agent's passphrase

Hunting Queries (10)

In solution SentinelOne:

Hunting Query Selection Criteria
Sentinel One - Agent not updated
Sentinel One - Agent status
Sentinel One - Alert triggers (files, processes, strings)
Sentinel One - Deleted rules
Sentinel One - Hosts not scanned recently
Sentinel One - New rules
Sentinel One - Scanned hosts
Sentinel One - Sources by alert count
Sentinel One - Uninstalled agents
Sentinel One - Users by alert count

Workbooks (1)

In solution SentinelOne:

Workbook Selection Criteria
SentinelOne

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
SentinelOne SentinelOne

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index