threat-hunting

Execute PowerQuery language queries against SentinelOne Singularity Data Lake for threat hunting.

39|17|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill threat-hunting-wyre-technology
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-hunting
Source: https://github.com/wyre-technology/msp-claude-plugins/tree/main/msp-claude-plugins/sentinelone/sentinelone/skills/threat-hunting
Command: npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill threat-hunting-wyre-technology

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill empowers security analysts to proactively search for and investigate threats within the SentinelOne Singularity Data Lake using its powerful PowerQuery language.

Core Features & Use Cases

  • Execute PowerQueries: Run custom or generated PowerQuery strings against the Singularity Data Lake to find specific security events.
  • Time Range Management: Utilize tools to get available data ranges and convert timestamps for precise querying.
  • Use Case: Investigate suspicious PowerShell activity by executing a PowerQuery to find all instances of PowerShell executing with encoded commands, specifying a custom time range for the investigation.

Quick Start

Use the threat-hunting skill to find all PowerShell network connections in the last 24 hours.

Frequently Asked Questions about threat-hunting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I execute PowerQuery strings against the SentinelOne Singularity Data Lake for threat hunting?

You can run custom PowerQuery strings against the Singularity Data Lake to investigate endpoint telemetry, including process events, network connections, and file operations, using specialized query execution tools.

What is threat hunting in endpoint telemetry and how does it work with SentinelOne?

Threat hunting in endpoint telemetry involves proactively searching for security threats within process events, network connections, and file operations using PowerQuery to query the Singularity Data Lake for forensic analysis.

Can I investigate suspicious PowerShell activity using SentinelOne Data Lake queries?

Yes, you can investigate suspicious PowerShell activity by executing a PowerQuery to find instances of PowerShell executing with encoded commands, specifying a custom time range for the investigation within the Data Lake.

How do I manage time ranges and convert timestamps when querying the Singularity Data Lake?

You manage time ranges and convert timestamps using specialized tools that retrieve available data ranges and convert timestamps to facilitate precise querying during security incident response.

Does threat hunting in the Data Lake support forensic analysis of network connections and file operations?

Yes, threat hunting supports detailed forensic analysis of endpoint telemetry by executing PowerQuery language queries against the Singularity Data Lake to investigate network connections and file operations.

What are the limitations of using PowerQuery for forensic analysis in SentinelOne?

Forensic analysis using PowerQuery is limited to available data ranges within the Singularity Data Lake. Querying relies on accurate timestamp conversion and time range retrieval to successfully investigate endpoint telemetry.