Kent, UK

Interface reference

What SentinelOne is

SentinelOne is an enterprise endpoint security platform that uses AI and behavioural analysis to detect, prevent and respond to threats in real time. Unlike traditional antivirus that relies on signature databases, SentinelOne monitors endpoint behaviour — process execution, file modifications, network connections, registry changes — and can autonomously contain threats without waiting for a human analyst.

It provides endpoint detection and response (EDR), extended detection and response (XDR), and forensic investigation capabilities. SentinelOne agents run on Windows, macOS and Linux, giving security teams visibility across the entire endpoint estate from a single console.

How I used it

I deployed SentinelOne agents across client systems during my time at ITHQ Ltd. This involved installing agents on Windows, Mac and Linux machines, configuring policy groups, and monitoring the console for detections and incidents. SentinelOne was a core part of the managed-services security stack alongside Rapid7 for vulnerability management and Zabbix for infrastructure monitoring.

Deploying EDR commercially taught me the practical side of endpoint security — not just what the tool does in theory, but how to roll it out across a mixed estate, handle false positives, and explain security findings to clients who are not technical.

Why this matters

Endpoint protection is no longer optional in any organisation. Having hands-on experience deploying and managing a commercial EDR platform like SentinelOne — across multiple client environments, not just a single test machine — is directly relevant to any infrastructure, IT support or security-adjacent role.

How to deploy or reproduce it

Use the organisation's approved console and deployment package, assign the endpoint to a test policy and confirm it reports healthy before enabling stricter controls.

Agent packages, site tokens and customer policy details must remain private.