RCA / SENTINELONE / DETECTION
Detection investigation
without guesswork.
A repeatable investigation path for validating whether a SentinelOne detection represents malicious behavior, an expected activity or an investigation gap.
Establish execution context
Identify the process, parent process, command line, user, path and execution time.
Build the sequence
Correlate related processes and endpoint events rather than treating one alert as the complete story.
Determine blast radius
Check whether the same indicator, process or behavior appears on additional endpoints.
01Alert
02Context
03Timeline
04Scope
05Contain
06Verify
Root-cause rule
Classify the behavior from correlated evidence: process ancestry, command line, user context, file/network activity and affected scope. Avoid declaring a false positive solely because the executable is known or signed.