Sentinel-OneSentinel-OneOfficialยท8 Agent Skills Included

ai-siem

SentinelOne SIEM parsers, dashboards, detections, and SOC automation

Builds and deploys SentinelOne Singularity Data Lake content: log parsers, dashboards, detection rules, and response playbooks. Runs PowerQuery threat hunts, alert triage, DFIR investigations, and Hyperautomation workflows directly against a live tenant. Eliminates manual parser writing, schema guessing, and repetitive console clicking for security operations teams.
npx skills add Sentinel-One/ai-siem --all -g -y
Available:

Instructs the agent to act as a principal SOC analyst, mandating cached schema discovery, evidence-based verdicts, threat-intel enrichment, and strict confidence rules before running any SentinelOne query or investigation.

All Skills in This Repository (8)

Pure Emerald Level Indicators

Frequently Asked Questions

FAQPage Schema
How to install ai-siem?โ–ผ

Run `npx skills add Sentinel-One/ai-siem --all -g -y` in your terminal to install all eight SecOps skills globally.

What does the ai-siem repository include?โ–ผ

It ships 165+ log parsers, 79 dashboards, detection rules, Observo pipeline templates, and eight skills covering PowerQuery hunting, console API actions, dashboard building, parser authoring, and automated DFIR investigations.

Can it investigate SentinelOne alerts automatically?โ–ผ

Yes. The soc-investigator skill runs short, medium, or full forensic investigations with IOC enrichment, MITRE mapping, and a calibrated verdict report.

Do I need a SentinelOne tenant to use it?โ–ผ

Yes. You need a Singularity console URL and API token, which the skills read from a credentials.json file or environment variables.

Can I use it without writing code?โ–ผ

Yes. Describe the task in plain English, such as building a dashboard or triaging an alert, and the skills generate and deploy the required queries, parsers, and workflows.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’