SentinelOne Power Query UI

Jan 1, 0001 • 1 min read

  • EDR
  • Security Operations

A user interface for SentinelOne query operations to streamline common investigations and hunting workflows.

Features

  • Quick query templates
  • Saved searches
  • Export and sharing

Installation

  1. Clone the repository
  2. Follow setup instructions in the README

Usage

EDR Query (s1)
ProcessName = "powershell.exe" and Tactic = "Execution"

Security Considerations

  • No credentials are stored in the client
  • Follow principle of least privilege for any API tokens (if used by backend components)

SentinelOne Power Query UI

EDR

User interface for SentinelOne query operations

Updated