Skip to content

Minor readme.md changes + workflow refactor#66

Open
jacob-kraniak wants to merge 14 commits into
Sentinel-One:mainfrom
jacob-kraniak:main
Open

Minor readme.md changes + workflow refactor#66
jacob-kraniak wants to merge 14 commits into
Sentinel-One:mainfrom
jacob-kraniak:main

Conversation

@jacob-kraniak

Copy link
Copy Markdown
Contributor
  1. Tweaked the top-level Readme to include the new structure under workflows/.
  2. Continue refactor of Workflow documentation.

…de Policy.json to workflows/community/sentinelone/management/n-1 Automatic Upgrade Policy/n-1 Automatic Upgrade Policy.json
Adds metadata for the n-1 Automatic Upgrade Policy workflow, detailing its purpose, schedule, and requirements.
Updated workflow logic and formatting in the readme.
Added sections for community workflows and documentation guides.
@jacob-kraniak

jacob-kraniak commented Jun 18, 2026

Copy link
Copy Markdown
Contributor Author

@nate-smalls-s1 @josh-at-s1 ?

From SentinelOne official Query Library
Custom STAR Detection rule for KMS Activator tools, often used to bypass Windows Licensing Activation.
Updated MITRE tactics and techniques for better classification of KMS activator detection. Enhanced use case and expected alert scenarios to improve clarity on risk management.
@jacob-kraniak

jacob-kraniak commented Jun 18, 2026

Copy link
Copy Markdown
Contributor Author

Added a few of my custom Detection Rules, as well as a directory to house queries obtained through the S1 Library

@josh-at-s1

Copy link
Copy Markdown
Contributor

@nate-smalls-s1 @josh-at-s1 ?

Hey, Jacob - Nate owns the repo and will have to approve the PR as I am just a contributor.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants