Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SentinelOne-ATTACK-Queries — MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity | Kitploit
Tools/GitHubGitHub/keyboardcrunch/sentinelone-attack-queries
Defensive ToolsThreat IntelligenceIntrusion DetectionLog Analysis
GitHubkeyboardcrunch/sentinelone-attack-queries

SentinelOne-ATTACK-Queries

MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
96205 years agoReviewed by Kitploit

ATT&CK Mapped SentinelOne Queries

MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity

DISCONTINUED

This project has been replaced by the SentinelOne-Queries repository which moves towards shareable signatures and for use in tooling. New repo is built of the work within this repository and most testing is still performed against Atomic Red Team. These queries will not be updated as detections change between Agent versions etc.

This project aims to document SentinelOne Deep Visibility queries for detecting Windows TTPs generated by Red Canary Co's Atomic Red Team framework. Not all techniques documented within the Atomic Red Team project will have matching queries, due to limited data sources within SentinelOne some detections will be limited; we'll eventually expand beyond A.R.T. and just call these ATT&CK mapped queries, but I like the idea of having a framework to test these detections.

These queries have been crafted and tested on Liberty console release and should support Deep Visibility 3.0. Recommending that your Sentinel Agents be on 4.2.x or newer, as some of the indicator data being queried is only collected by newer agents.

Tactics (COMPLETED)

Privilege Escalation

Initial Access

Persistence

Execution

Lateral Movement

Impact

Exfiltration

Tactics (IN PROGRESS)

Defense Evasion

Discovery

Command and Control

Collection

Credential Access

Download Tool