SentinelOne

Download 31
Last updated May 5, 2026

sentinelone-threat-timeline

Enumerate timeline events for a specific threat in the SentinelOne service.

sentinelone-threat-timeline [profile=PROFILE] id=ID
profile=PROFILE
Connect profile code of SentinelOne
id=ID
Required. Target threat ID

Output Fields

FieldTypeNameDescription
_timeDateEvent timee.g. 2026-05-05 16:07:37+0900
profileStringConnect profilee.g. sentinelone
event_idStringEvent IDe.g. 1234567890123456789
activity_typeIntegerActivity typeNumeric SentinelOne activity code
primary_descriptionStringPrimary descriptione.g. The management user Demo User (admin@example.com...
secondary_descriptionStringSecondary descriptione.g. \Device\HarddiskVolume3\WINDOWS\System32\drivers\PROCEXP1...
os_familyStringOS family
hashStringHash (SHA1)
agent_updated_versionStringAgent updated version
user_idStringUser IDActor management user ID
threat_idStringThreat IDe.g. 1234567890123456789
agent_idStringAgent IDe.g. 1234567890123456789
account_idStringAccount IDe.g. 1234567890123456789
site_idStringSite IDe.g. 1234567890123456789
group_idStringGroup IDe.g. 1234567890123456789
createdDateCreation timee.g. 2026-05-05 16:07:37+0900
updatedDateUpdated timee.g. 2026-05-05 16:07:37+0900