Skip to main content

SentinelOne Complete

Updated today

Overview

By default Ultimate plan provides SentinelOne Control, for service providers who require advanced EDR capabilities, SentinelOne Complete is available option.

SentinelOne Complete provides enhanced protection, automated response capabilities, and extended visibility compared to the Control package. In practice, it’s about taking endpoint security to the next level while delivering full EDR protection and stronger overall defense.


What does it Provide?

SentinelOne Complete is best suited for security teams seeking full EDR capabilities, advanced threat hunting, and deep forensic visibility. It includes two primary additional capabilities:

1. Deep Visibility

  • Full telemetry coverage (process, file, script, network, and DNS activity) across all events

  • Deep data access that enables thorough and forensic investigations

2. Custom Detection Rules (IOA / Behavior-Based)

  • Pre-defined library of rules on top of the “Control” automated protection

  • Ability to create custom detection rules / modify and fine-tune existing rules:

    • Guardz creates and manages (MDR) default detection rules across all Guardz-managed agents.

    • The SentinelOne console also allows admins to create additional custom rules as needed.

Additionally, SentinelOne Complete enables the following capabilities to be utilized via the SentinelOne Console:

  • Threat Storyline with full kill chain reconstruction

  • Manual hunting (SQL-style queries)

  • Full logs export Syslog and API


Detection & Response Aspects:

  • Any detection rule (custom or library) activated by Guardz that is triggered will generate an incident within the Guardz platform, and will be handled by the Guardz MDR team.

  • Custom detection rules activated by admins within the SentinelOne console will generate an issue within the Guardz platform and must be handled by the admins.

    • Please be cautious that custom detection roles can generate a large volume of issues.

Please note:
If your agents are on the BYO plan and custom rules are configured, they will be supported and will appear as an issue in Guardz.


How to Upgrade to Complete?

  1. Raising the Request:

    • Contact your Account Manager or CSM for pricing information and to enable the service

    • Please note that this is available for 'Ultimate' customers only

  2. Automatic Procedure:

    • There is no impact on endpoint performance.

    • The agent version remains exactly the same, with no changes to the installation or binaries.

    • The functionality is activated via an API call that instructs the agent to begin collecting additional telemetry.

Please note:
Customers currently operating under a BYO (Bring Your Own) SentinelOne Complete deployment who wish to transition to the Guardz fully managed program should contact Guardz Support to facilitate proper migration of existing rules.

Did this answer your question?