
Learn to manage SentinelOne endpoint protection by navigating the console, deploying agents, and detecting and mitigating threats, including ransomware rollback, through practical demos.
Explore sentinelone versions from singularity core to control and complete, highlighting EDR and XDR, 14 days data retention, plus commercial options like threat hunting and digital forensics.
Compare legacy antiviruses with SentinelOne, contrasting signature-based detection with the behavioral, auto-detect and auto-respond EDR/XDR, data lake, and the single pane of the glass.
Create and manage multiple sites to organize devices for multiple customers on an enterprise grade SentinelOne platform, then group devices to apply different security policies by membership.
Explore a customizable SentinelOne dashboard with unresolved threats, infected endpoints, and built-in vulnerability scanning, plus threat detection using behavioral AI, cloud detection, and static AI.
Explore the visibility tab to search logs with powerful queries in sentinel one's data lake. Learn to use edr, process graphs, and threat details for threat hunting and root-cause analysis.
Discover how network discovery scans your local area network to identify devices without a SentinelOne agent and flag rogue devices or rogue access points in on premise environments.
Examine the sentinels tab to view devices enrolled with the SentinelOne agent; filter data by groups and sites, with three devices shown on the default site.
Learn to view and manage endpoint details, app inventory, tags, and actions in SentinelOne, including remote shell, file fetch, script execution, and disconnecting devices from the network.
Create tags to identify group devices and detect cloud rogues by connecting cloud accounts, such as an AWS account, to monitor your cloud environment.
Configure and tailor endpoint protection policies with sentinelone, choosing protection modes, remediation levels, and detection engines to secure devices and manage policies across groups.
Explore how SentinelOne uses pre-populated block lists to block threats with custom rules. Add specific block lists by OS and sha values to block new malware throughout your organization.
Identify false positives when legitimate software is flagged by SentinelOne and create an exclusion to prevent disruptions; then exclude the file from quarantine by specifying the OS and sha-1.
Enable the endpoint firewall, configure block rules for OS versions, protocols, applications, ports, and locations, and manage outbound/inbound filtering, remote scripts, remote shell, and USB device control.
Explore device control to manage usb, thunderbolt, and bluetooth ports, create rules to allow read/write, read-only, or block devices, and integrate with firewall controls.
Discover how group info provides a private group token to enroll a device in SentinelOne, binding that device to your SentinelOne agents and displaying in your dashboard.
Navigate the SentinelOne incidents tab to filter and analyze threats, see true positives like chrome path x malware across endpoints, and review threat details, VirusTotal results, and mitigation actions.
Explore how SentinelOne's applications tab performs automatic weekly vulnerability scans and on-demand checks, shows CVEs with MITRE and NVD references, and supports OS-level scans via Ranger Insights.
Explore the activities tab to view and filter activity logs by date, malware, threat management verdicts, and incident status. Export logs for audits and administrative review.
Create executive reports in SentinelOne, scheduling or one-time runs for last 30 days, exportable as pdf or html showing key findings and 3 threats mitigated.
Explore the SentinelOne settings, covering configuration, timeouts, password expiration, licenses, add-ons, and data retention. Learn to configure notifications, rules, integrations, site management, and the Singularity operation center interface.
Install the SentinelOne agent on endpoints, enroll devices into a chosen group using a group token, then verify the device appears online in the SentinelOne console.
Install the macOS SentinelOne agent from the console by downloading the stable package, entering the token, granting full disk access, and verifying the device shows secure online in the console.
Learn to identify and remediate threats in the SentinelOne console by viewing infected endpoints and unresolved threats, and manually remediate Chrome parsecs by adjusting security policies from detect to protect.
Isolate compromised endpoints by disconnecting them from the production network to prevent threat propagation, while maintaining connection to the SentinelOne console for troubleshooting and remediation.
SentinelOne surfaces threat details like endpoint name, file path, originating process (WinRAR), and static malware detection, with VirusTotal corroboration to guide mitigation in a SOC.
Learn how to identify and remediate threats with SentinelOne by killing malicious processes, quarantining threats, and adding them to the block list, with notes, VirusTotal checks, and incident timeline.
See how SentinelOne's rollback feature restores a computer to a pre-infection state during ransomware scenarios, and learn why ransomware encrypts data and demands payment for decryption.
this lab demonstrates simulating the WannaCry ransomware on a Windows 10 test VM, showing sentinelone in detect only mode detecting and remediating threats and illustrating the protection wall.
Identify and rollback ransomware infections with SentinelOne, using hash grouping and VirusTotal checks to confirm threats, then perform a full rollback to restore encrypted files and reboot the machine.
Learn how to use the SentinelOne customer portal to access the knowledge base, community webinars, slides, and the SentinelOne University learning paths to earn certifications in the Singularity Enterprise.
Congratulations on completing your SentinelOne essentials course. Apply the knowledge to become a better SentinelOne security administrator, and consider leaving a review to help the Udemy community.
In today's digital landscape, endpoint protection is critical for safeguarding an organization's assets from cyber threats. SentinelOne is a leading solution in the cybersecurity industry, providing advanced protection for devices and networks. This "SentinelOne: Endpoint Protection for Beginners" course is designed to help you master the essentials of endpoint security, from understanding key concepts to deploying and managing SentinelOne agents.
Whether you're an IT professional, a system administrator, or someone looking to transition into cybersecurity, this course will guide you through the step-by-step process of using SentinelOne to protect your organization's endpoints. You will learn how to navigate the SentinelOne console, configure policies, and deploy agents across various devices. In addition, you'll explore how to detect, analyze, and respond to security threats using SentinelOne’s real-time threat intelligence and response capabilities.
No prior experience with SentinelOne is required, making this course perfect for beginners. The teaching style is a mixture of over the shoulder videos, combined with quizzes,ensuring you get all the practical knowledge you need. By the end of the course, you'll have a strong understanding of how to effectively use SentinelOne for endpoint protection, ensuring that you're equipped with the skills needed to secure your organization against cyber attacks. Join us and take the first step toward mastering endpoint security with SentinelOne!