redcanaryco / surveyor

A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.
MIT License
169 stars 59 forks source link

Implement PowerQuery support for SentinelOne #94

Closed jholtmann closed 1 year ago

jholtmann commented 1 year ago

This PR implements PowerQuery support for the SentinelOne product.

Benefits of PowerQuery (PQ) over Deep Visibility (DV):

Discussion Points:

Testing:

xC0uNt3r7hr34t commented 1 year ago

PowerQuery is still in Beta. I would recommend that DV be set to default until PowerQuery is released to GA and more stable. I agree with all the other benefits. If we want to keep PowerQuery as the default for the future to limit code changes, then we need to make it very obvious in documentation and help guide that PowerQuery is default.

rc-csmith commented 1 year ago

Because of the benefits of using PQ (more accurate results and faster runtime), I think we should go ahead and keep it as defaul. But, as @xC0uNt3r7hr34t said, we'll need to make sure documentation and release notes are in place when the changes go live so users are aware.