A community‑driven, SentinelOne‑assisted library of parsers, dashboards, detections & response playbooks that supercharge the Singularity Platform.
-
Updated
Sep 17, 2026 - Lua
A community‑driven, SentinelOne‑assisted library of parsers, dashboards, detections & response playbooks that supercharge the Singularity Platform.
Multi-EDR & SIEM mock server. SentinelOne, CrowdStrike, Defender, Elastic, Cortex XDR, Splunk, M365 and Sentinel — 8 platforms in one process. Real API paths, real auth, deterministic seed data, fault injection, scenario engine, SPL parser. GitHub Action + one-click Render deploy. BSL-1.1
PowerShell module for SentinelOne API
This collection provides several unofficial ansible modules and roles to use with SentinelOne management consoles
A userscript that enhances the SentinelOne PowerQuery interface with a custom threat hunting button that follow the website UI / UX design interface.
Scripts played by GitHub Actions that converts Sigma rules to SentinelOne PowerQuery via PySigma.
PowerShell wrapper for the SentinelOne API
This project shows a graphical view of the process executions relationship in a tree format (HTML version)
Deep-dive forensic threat analysis from a single SentinelOne Storyline ID — generates HTML dashboard, Markdown report, CSV and terminal output with MITRE ATT&CK mapping, IOC extraction and SOC recommendations.
Complete syslog toolkit for SentinelOne SDL; Three solutions: Simple collector; 3-in-1 pipeline; rootless high-performance; Choose based on complexity needs; Docker + official S1 support
Security tools for purple team, AI security, and M365/GWS. Authorized use only.
Local AI-powered security incident triage. Connect it to your SIEM, point it at a local Ollama model, and get instant analysis on every alert — nothing leaves your machine.
Power Query collection for SentinelOne - KQL queries, data transformations, and analysis templates for security operations and threat hunting
Parallax — a self-hosted toolkit for SentinelOne AI-SIEM engineers: map parser & detection-library coverage, visualize MITRE ATT&CK gaps, and validate that detection rules actually fire by generating synthetic test logs from each rule's own logic and verifying the resulting alerts.
Monitoring plugin (Icinga/Nagios compatible) to check the presence of threats on the SentinelOne Cloud service
n8n node for SentinelOne API
SentinelOne Deep Visibility Forensic Analyzer — Automated SOC triage tool with 22+ analyzers, normalized threat scoring (0-20), and self-contained HTML dashboard
SOC/NOC correlation engine (PowerShell) aligning EDR, RMM, and backup signals with escalation precedence and remediation controls.
To associate your repository with the sentinelone topic, visit your repo's landing page and select "manage topics."