SentinelOne

Download 31
Last updated May 5, 2026

sentinelone-star-custom-rules

Enumerate STAR custom detection rules in the SentinelOne service.

sentinelone-star-custom-rules [profile=PROFILE]
profile=PROFILE
Connect profile code of SentinelOne

Output Fields

FieldTypeNameDescription
profileStringConnect profilee.g. sentinelone
rule_idStringRule IDe.g. 1234567890123456789
rule_nameStringRule namee.g. AI Assistant Detected
severityStringSeveritye.g. Critical, High, Medium, Low
statusStringStatuse.g. Active, Draft, Activating, Disabled
status_reasonStringStatus reasone.g. Rule was activated by admin@example.com
query_typeStringQuery typee.g. events, processes
query_langStringQuery languagee.g. 1.0, 2.0
s1qlStringS1QL querye.g. event.type = 'Process Creation' and (src.process.cmdline ...
descriptionStringDescriptione.g. AI Assistant Behavioral Detection
scope_hierarchyStringScope hierarchye.g. global, account, site, group
scope_nameStringScope name
account_idStringAccount ID
account_nameStringAccount name
site_idStringSite ID
site_nameStringSite name
generated_alertsIntegerGenerated alertse.g. 2
last_alert_timeDateLast alert timee.g. 2026-05-05 22:22:22+0900
treat_as_threatStringTreat as threate.g. Malicious
network_quarantineBooleanNetwork quarantinee.g. false
active_responseBooleanActive responsee.g. true
expiration_modeStringExpiration modee.g. Permanent, Temporary
expiration_dateDateExpiration datee.g. 2025-10-28 00:00:00+0900
is_expiredBooleanExpirede.g. false
is_editableBooleanEditablee.g. false
reached_limitBooleanReached alert limite.g. false
creatorStringCreatore.g. admin@example.com
creator_idStringCreator IDe.g. 1234567890123456789
updater_idStringUpdater IDe.g. 1234567890123456789
template_rule_idStringTemplate rule ID
createdDateCreated timee.g. 2026-02-12 09:29:58+0900
updatedDateUpdated timee.g. 2026-04-28 16:52:59+0900