sentinelone-singularity
SentinelOne Singularity detection engineering — explicit distinction from Microsoft Sentinel, surface map across STAR Custom Logic (sensor-side behavioural rules), Deep Visibility (DVQL), Singularity Data Lake / PowerQuery (SDL alert configuration, scheduled queries, geo/math functions), exclusions and policies, Storyline ID-based correlation, AI Engine policy modes (detect / protect), SIEM ingestion patterns, and entity alignment for cross-platform correlation. Distilled from Sentinel-One/ai-siem community detection library. Use for sentinel_one-keyed configurations in OpenTide MDR objects — never confuse with microsoft-sentinel.
Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/sentinelone-singularity/SKILL.md
- skills/sentinelone-singularity/references/DVQL-Field-Reference.md
Every link opens the file at its source, pinned to the revision this page describes.