SentinelOne in practice: hunting, custom rules, remote scripts and coverage
A deeper SentinelOne course built from SentinelOne's public feature spotlights and announcements: threat hunting in Deep Visibility with Storyline IDs, hashes and MITRE technique IDs, turning hunts into watchlists and STAR custom detection rules, running RemoteOps scripts safely at scale, finding unprotected devices with Ranger, tightening controls automatically with Conditional Policy, and giving people least-privilege custom roles.
- Level
- Advanced
- Length
- About 45 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- SentinelOne
Skills you'll practise
- Use a Storyline ID, a file hash or a MITRE ATT&CK technique ID to scope a Deep Visibility hunt across all operating systems
- Explain how STAR custom rules differ from saved watchlists and when an automated response is appropriate
- Plan a RemoteOps script run that is targeted, tested on a subset, permitted by role and auditable
- Interpret Ranger's Secured, Unsecured, Unsupported and Unknown device states and close a coverage gap
- Describe how Conditional Policy moves a threatened endpoint to a risky group and back
- Design a custom role on the principle of least privilege without altering the predefined roles
Course outline
- 1.SentinelOne in practice: hunting, custom rules, remote scripts and coverageVideo · 2 min
- 2.Hunting in Deep Visibility and turning hunts into rulesLesson · 16 min
- 3.RemoteOps: running scripts on many endpoints safelyLesson · 15 min
- 4.Coverage and access: Ranger, Conditional Policy and custom rolesLesson · 14 min
- 5.SentinelOne in practice: hunting, custom rules, remote scripts and coverage: knowledge checkKnowledge check · 16 questions
- 6.Final exam12 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- SentinelOne feature spotlight: Rapid Threat Hunting with Storylines (Deep Visibility, Storyline ID, query language, MITRE search, watchlists)
- SentinelOne blog: Deep Visibility Watchlists
- SentinelOne press release: Storyline Active Response (STAR), custom detection rules with automated responses
- SentinelOne blog: Remote Script Orchestration for incident response and endpoint management
- SentinelOne feature spotlight: RemoteOps Custom Script Actions (script library, RBAC, auditing, targeting)
- SentinelOne feature spotlight: Ranger Pro (device inventory states, peer-to-peer agent deployment)
- SentinelOne feature spotlight: Singularity Conditional Policy (risky endpoint group)
- SentinelOne feature spotlight: Fully Custom Role-Based Access Control (predefined and custom roles)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.