Category: S1 & MITRE ATT&CK / How can I use MITRE ATT&CK framework for threat hunting?


You can create queries out-of-the-box and search for MITRE ATT&CK characteristics across your scope of endpoints. With SentinelOne, all you need is the MITRE ID or another string in the description, the category, the name, or the metadata.