Skip to main content

SentinelOne

SentinelOne is an enterprise cybersecurity platform specializing in autonomous endpoint protection, detection, and response (EDR). It provides advanced threat detection, prevention, investigation, and remediation capabilities across endpoints, containers, and cloud workloads. The platform uses artificial intelligence and machine learning to identify and neutralize malware, ransomware, exploits, fileless attacks, and other sophisticated cyber threats in real-time.

CategoryEDR
DirectionQuery source
Sign-inAPI Token
Query languagesSTIX
Websitesentinelone.com

Before you start​

Huntbase signs in to SentinelOne with API Token. Create the credential in SentinelOne first, then keep it to hand for the Connect step.

  1. In the SentinelOne Management Console, go to Settings › Users › Service Users, open the Actions menu, and select Create New Service User.
  2. Enter a Name and an Expiration Date, then click Next.
  3. Choose the Access Level (Global, Account or Site) and the account or site, then select the minimum Role you need.
  4. Generate the API token and copy it right away. It is shown only once.
Watch out for
  • The token has the role and scope of the service user it belongs to.

For the vendor's own instructions, see Creating a SentinelOne service user API token (SonicWall guide).

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect SentinelOne​

  1. Go to Connections and click New connection, or click New connection on the SentinelOne product page.
  2. On Product, pick SentinelOne and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your SentinelOne lives:

FieldRequiredNotes
Server AddressYesThe hostname of your SentinelOne management console, without https://.
PortYesSet the port number that is associated with the hostname or IP address. Defaults to 443.

Credentials​

The only Method is API Token. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
API TokenYesAPI Token with access to the search API. Secret — not shown again after you save it.

Query it​

Once connected, SentinelOne can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​