Threat hunt across endpoints with SentinelOne Deep Visibility
Build a workflow that accepts a Deep Visibility query or IOC via a page or Send-to-Story. Submit the query to SentinelOne, poll for completion, and return the matching endpoints and events. Support common IOC types by templating queries, paginate large result sets, handle query timeouts, and rate-limit calls. Output the hunt results with affected hosts and event detail.
What this prompt builds
Run SentinelOne Deep Visibility queries from a page or Send-to-Story to hunt IOCs across the fleet.
The problem
Threat hunting in SentinelOne requires crafting Deep Visibility queries in the console, which is slow and gatekept to a few experts. Reusable, on-demand hunts rarely happen.
Solution and impact
This workflow runs Deep Visibility queries via a page, letting anyone hunt for IOCs across endpoints. Hunting becomes self-serve and repeatable instead of locked in the console.