ExploreGalaxyMy PathSettingsGive Feedback

New here?

A quick look at how MySkillGap works. Close it any time.

Security & Compliance

SentinelOne

Autonomous endpoint defence that can roll back an attack, not just alert on it

What it is

About SentinelOne

SentinelOne is an AI-driven endpoint detection and response (EDR/XDR) security platform used by security operations teams to detect, investigate and automatically respond to threats on laptops, servers and cloud workloads. It uses behavioural AI on the endpoint itself to detect malicious activity in real time and can automatically isolate a device and even roll back files/system changes caused by ransomware.

What you can do with it

Capabilities

1

Detect and automatically contain malware/ransomware activity on an endpoint

2

Roll back files and system state after a ransomware incident without manual restore

3

Investigate an attack's full timeline via the Storyline feature

4

Hunt for threats across the fleet using built-in query tools

5

Integrate EDR telemetry into a broader SIEM/SOAR workflow

How to learn it

Learning Resources

SentinelOne's official documentation and SentinelOne University training/certifications

Vendor webinars and the SentinelOne YouTube channel

Hands-on practice in a SOC analyst role or a home-lab trial instance where available

General EDR/threat-hunting courses (e.g. via TryHackMe's SOC modules) to build transferable skills

Pro Tip

Tune detection policies (Detect versus Protect mode) deliberately per device group — leaving everything in full auto-block during rollout can cause disruptive false-positive quarantines before the baseline is properly tuned