An endpoint security evaluation needs to establish whether analysts can investigate, contain and recover from an incident in the environment they operate. I contributed to the SentinelOne evaluation for server and legacy estates through structured demonstrations, testing and SOC success-criteria reviews.
I reviewed behavioural and signature detection, custom STAR rules, Storyline correlation, process and file evidence, quarantine, process termination, network isolation and remediation. I distinguished capabilities demonstrated in the sessions from those still requiring configuration or synthetic-attack testing.
Recovery and integration needed particular scrutiny. I examined ransomware rollback dependencies on Volume Shadow Copy and the implications for critical servers and databases. I also questioned how alerts, storylines, severity and verdicts would map into Microsoft Sentinel and ServiceNow incident workflows.
The evaluation brought API token scope, policy visibility, duplicate SIEM data, selective CloudFunnel export and automation licensing into the decision. I supplied operational requirements and evaluation evidence for the go/no-go process, with demonstrated capabilities distinguished from items requiring further validation.
Methods, evidence & technical decisions
Follow the analyst’s investigation and response path
The review covered behavioural and signature detection, STAR rules, Storyline correlation, process and file evidence, quarantine, process termination, isolation and remediation. I assessed these against operational SOC requirements and kept demonstrated behaviour separate from features requiring further configuration or testing.
Open this detail ↗Check recovery dependencies and incident mappings
I examined rollback’s dependency on Volume Shadow Copy and the risk of applying it to critical servers or databases. Integration discussions covered how SentinelOne alerts and storylines would map to Sentinel and ServiceNow statuses, verdicts, severity and aggregation.
Open this detail ↗Include the constraints behind the feature list
I reviewed API token scope, Marketplace integration options, policy versioning and synchronisation visibility. I also raised duplicate-data concerns across SIEM platforms, discussed selective CloudFunnel export and examined the licensing boundary between built-in automation and Hyperautomation.
Open this detail ↗Skills used in this work