-
Notifications
You must be signed in to change notification settings - Fork 191
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
SentinelOne bidirectional actions - response console & history (class…
…ic/ESS) (#4885) * Reorder & rename pages for flow Also matches newer organization scheme in serverless * More reordering and renaming for flow Also matches newer organization scheme in serverless * First (mostly complete) draft Create new page, update related other pages * Apply suggestions from review Co-authored-by: Ash <[email protected]> * Use "third-party" vs. "bidirectional" * Follow-up resolve merge conflict Add new page (automated-response-actions) to the TOC --------- Co-authored-by: Ash <[email protected]> (cherry picked from commit 6cf5f34)
- Loading branch information
1 parent
a149509
commit 93df7a7
Showing
7 changed files
with
66 additions
and
17 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,28 @@ | ||
[[third-party-actions]] | ||
= Third-party response actions | ||
|
||
:frontmatter-description: Perform response actions on hosts protected by third-party endpoint security systems. | ||
:frontmatter-tags-products: [security] | ||
:frontmatter-tags-content-type: [reference] | ||
:frontmatter-tags-user-goals: [manage] | ||
|
||
preview::[] | ||
|
||
[discrete] | ||
[[sentinelone-response-actions]] | ||
== SentinelOne response actions | ||
|
||
You can direct SentinelOne to perform response actions on protected hosts without leaving the {elastic-sec} UI. Prior <<response-actions-config,configuration>> is required to connect {elastic-sec} with SentinelOne. | ||
|
||
The following response actions and related features are supported for SentinelOne-protected hosts: | ||
|
||
* **Isolate and release a host** using any of these methods: | ||
+ | ||
-- | ||
** From a detection alert | ||
** From the response console | ||
-- | ||
+ | ||
Refer to the instructions on <<isolate-a-host,isolating>> and <<release-a-host,releasing>> hosts for more details. | ||
|
||
* **View past response action activity** in the <<response-actions-history,response actions history>> log. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters