Tag: SentinelOne

Visualizing Insider Threat Detection with Uncoder AI’s Decision Tree for SentinelOne Queries
Visualizing Insider Threat Detection with Uncoder AI’s Decision Tree for SentinelOne Queries

Detecting insider access to sensitive data—like password documents—is a challenge for even mature SOC teams, especially when the activity is wrapped in benign processes like Notepad or triggered via Windows Explorer. While SentinelOne provides robust telemetry, interpreting detection rules often requires navigating multi-condition logic. That’s where Uncoder AI’s AI-generated Decision Tree transforms the workflow. Instead […]

Read More
Investigating Curl-Based TOR Proxy Access with Uncoder AI and SentinelOne Query Language
Investigating Curl-Based TOR Proxy Access with Uncoder AI and SentinelOne Query Language

Detecting stealthy command-line activity that may indicate dark web access or anonymized traffic is a growing challenge for security teams. Tools like curl.exe—while entirely legitimate—can be leveraged by advanced threats to route traffic through proxy networks or TOR. This is where Uncoder AI’s Full Summary capability provides crucial context. When applied to SentinelOne Query Language […]

Read More