Skip to main content
Apply a mitigation action to a group of threats that match the filter. Your user role must have permissions to mitigate threats - Admin, IR Team, SOC. Only threats which you have permission to mitigate are countedas “affected” in response field. You must use one of the filters before executing the action.

Basic Parameters

Advanced Parameters

Example Output

Workflow Library Example

Mitigate Threats with Sentinelone and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop