Endpoint Security & Technical Evaluation

Evaluate EDR against real incident-response needs

Assessed SentinelOne investigation, containment and recovery capabilities against SOC requirements, including Sentinel/ServiceNow integration, rollback dependencies and automation licensing.

UK Water UtilitySOC capability evaluation and success-criteria review2 min read

An endpoint security evaluation needs to establish whether analysts can investigate, contain and recover from an incident in the environment they operate. I contributed to the SentinelOne evaluation for server and legacy estates through structured demonstrations, testing and SOC success-criteria reviews.

I reviewed behavioural and signature detection, custom STAR rules, Storyline correlation, process and file evidence, quarantine, process termination, network isolation and remediation. I distinguished capabilities demonstrated in the sessions from those still requiring configuration or synthetic-attack testing.

Recovery and integration needed particular scrutiny. I examined ransomware rollback dependencies on Volume Shadow Copy and the implications for critical servers and databases. I also questioned how alerts, storylines, severity and verdicts would map into Microsoft Sentinel and ServiceNow incident workflows.

The evaluation brought API token scope, policy visibility, duplicate SIEM data, selective CloudFunnel export and automation licensing into the decision. I supplied operational requirements and evaluation evidence for the go/no-go process, with demonstrated capabilities distinguished from items requiring further validation.

Methods, evidence & technical decisions

Follow the analyst’s investigation and response path

The review covered behavioural and signature detection, STAR rules, Storyline correlation, process and file evidence, quarantine, process termination, isolation and remediation. I assessed these against operational SOC requirements and kept demonstrated behaviour separate from features requiring further configuration or testing.

Open this detail ↗
Check recovery dependencies and incident mappings

I examined rollback’s dependency on Volume Shadow Copy and the risk of applying it to critical servers or databases. Integration discussions covered how SentinelOne alerts and storylines would map to Sentinel and ServiceNow statuses, verdicts, severity and aggregation.

Open this detail ↗
Include the constraints behind the feature list

I reviewed API token scope, Marketplace integration options, policy versioning and synchronisation visibility. I also raised duplicate-data concerns across SIEM platforms, discussed selective CloudFunnel export and examined the licensing boundary between built-in automation and Hyperautomation.

Open this detail ↗

Skills used in this work

This work connects to

Security engineering & assuranceSOC & incident response

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Ask about an investigation, a technology or my contribution. Answers link to the relevant case and technical detail.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.