SentinelOne
SentinelOne is an enterprise cybersecurity platform specializing in autonomous endpoint protection, detection, and response (EDR). It provides advanced threat detection, prevention, investigation, and remediation capabilities across endpoints, containers, and cloud workloads. The platform uses artificial intelligence and machine learning to identify and neutralize malware, ransomware, exploits, fileless attacks, and other sophisticated cyber threats in real-time.
| Category | EDR |
| Direction | Query source |
| Sign-in | API Token |
| Query languages | STIX |
| Website | sentinelone.com |
Before you start
Huntbase signs in to SentinelOne with API Token. Create the credential in SentinelOne first, then keep it to hand for the Connect step.
- In the SentinelOne Management Console, go to Settings › Users › Service Users, open the Actions menu, and select Create New Service User.
- Enter a Name and an Expiration Date, then click Next.
- Choose the Access Level (Global, Account or Site) and the account or site, then select the minimum Role you need.
- Generate the API token and copy it right away. It is shown only once.
- The token has the role and scope of the service user it belongs to.
For the vendor's own instructions, see Creating a SentinelOne service user API token (SonicWall guide).
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect SentinelOne
- Go to Connections and click New connection, or click New connection on the SentinelOne product page.
- On Product, pick SentinelOne and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your SentinelOne lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname of your SentinelOne management console, without https://. |
| Port | Yes | Set the port number that is associated with the hostname or IP address. Defaults to 443. |
Credentials
The only Method is API Token. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| API Token | Yes | API Token with access to the search API. Secret — not shown again after you save it. |
Query it
Once connected, SentinelOne can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog