Collection of SentinelOne STAR Queries for Hunting and Creating Custom Rules
STAR (Storyline Active Response) Rules are part of the Feature "Deep Visibility" of the SentinelOne EDR Product.
They represent customizable rules to detect and either kill or alarm if matching processes are started or configurations are applied on endpoints.
- More about the feature - SentinelOne Product Sheet
- How-To for creating STAR Rules in the Product - SentinelOne Blog
- S1QL Cheatsheet for Security Analysis - SentinelOne Blog
There are already other repositories that collect SentinelOne STAR Rules like:
- Sentinel-One-STAR-Rules-Threat-Hunts - Detecting different specific or general malicious activities
- Sentinelone-Queries - Queries with Mapping to Mire Att@ck TTPs
- SentinelOne-Query-Navigator - A Python Flask based web application for loading the SentinelOne-Queries repository into a browseable database
This repository here contains Queries, that I found or created myself based on different sources.
the first attempt is to put them in to different md-Files based on something like "categories".
Maybe this will change over time.