SentinelOne: Group in Detect Mode
submitted
C
Christopher Towle
This metric will find if a Group has it's policy set to detect mode. Will be useful for alerting if this client should be in protect mode.
Groups[?GroupPolicyInformation.mitigationMode==
detect
|| GroupPolicyInformation.mitigationModeSuspicious=='detect'].{GroupName: name, mitigationMode: GroupPolicyInformation.mitigationMode, mitigationModeSuspicious: GroupPolicyInformation.mitigationModeSuspicious}