Sentinel One Connector

how to connect and use SentinelOne integration

Updated over a week ago

Reach greater network visibility with SentinelOne and Vulcan Cyber. Retrieve vulnerability information from SentinelOne application data to automate notifications and ticket system integrations. In this article, you will find how to connect, locate, and automate SentinelOne with Vulcan Cyber.

  1. First, log in to your account-specific SentinelOne dashboard.

  2. Click on your user profile icon and the My User link.

  3. Generate an API Token as Admin user by clicking the Generate hyperlink within the user details section.

  4. Once presented with the API Token, choose to download or copy the token as the value is hidden upon leaving the screen.

    The generated token expires in 6 months. You will need to regenerate the token and update your Vulcan system before the expiration time

  5. Log in to your Vulcan Cyber platform and click on Connectors.

  6. Click on the Add a Connector button.

  7. Click on the SentinelOne icon.

  8. Enter the following information into the connector setup page.

    • Server URL - Your specific instance of SentinelOne.

    • Api Key - The previously generated API key.

    • Fetch Decommissioned Assets - Here the value is kept un-checked to avoid syncing decommissioned assets.

    • Inactive Assets - In this example, the default value of 30 days is used. To remove inactive assets quicker or keep them longer, as seen by SentinelOne, change this value to suit your needs.

  9. Once all information has been entered, click the Test Connectivity button to verify that Vulcan Cyber can connect to your SentinelOne instance, as shown below, and finally click the Create button.

  10. Navigate to the Connectors page and once the SentinelOne icon shows as Connected, the connection is complete.

Locating SentinelOne Vulnerabilities in Vulcan Cyber

As SentinelOne discovers vulnerabilities, the Vulcan Cyber connector will import those vulnerabilities for reporting and action. With a large number of assets and potential vulnerabilities discovering specific vulnerabilities via source is made easy with filters.

  1. Open the Vulcan Cyber dashboard and navigate to the Vulnerabilities section. Click on the Search or filter vulnerabilities search box, scroll to the Vulnerability Source option, and click to filter by the vulnerability source.

  2. Locate SentinelOne on the vulnerability source list and click to filter results by SentinelOne.

    The risk score is assessed from a base score of 8.1 in SentinelOne combined with Vulcan threat intelligence and asset impact.

  3. Click on any vulnerability to view further information and potentially take action by clicking the Take Action drop-down and choosing an option, as shown below.

Screenshot below is for asset comparison, but currently this asset does not exist in Vulcan anymore that I can find. Therefore, waiting on update to decide on a course of action.

Automating SentinelOne Vulnerability Actions in Vulcan Cyber

Large environments quickly become unmanageable if constant manual attention and action are necessary to remediate vulnerabilities. Take advantage of the automation capabilities of Vulcan Cyber and the SentinelOne connector.

  1. Open the Vulcan Cyber dashboard and navigate to the Automation section. Once there, click the Create new Playbook button.

  2. First, give your automation playbook a name, here the name given is, "Assign Critical SentinelOne Vulnerabilities to Email".

  3. Choose SentinelOne for the source of vulnerabilities and add the risk is critical vulnerability condition, leaving the rest as defaults.

  4. Click on the Assign via Email as the Remediate Action button.

  5. Choose how the separation of tickets is handled, here up to 200 vulnerabilities are aggregated into a single email. Then add the recipient emails to be notified.

  6. Leave all other steps as default and click on Save and Run.

Did this answer your question?