SentinelOne
Version: SentinelOne
SentinelOne is a next-generation endpoint security product used to protect against all threat vectors. Keep known and unknown malware and other bad programs out of endpoints.
Netsurion Open XDR collects the events from SentinelOne API and filters it out to get some critical event types for creating reports, dashboards, and alerts. These are considered as Data Source Integrations and helps you to analyze and manage the SentinelOne easily.
Flex reports will contain detailed overview of activities like login/ logout, firewall block activity, threat detection activity, and user management activities.
Alerts will be triggered when critical security events like threat detected, an external device connected, suspicious process detected, etc.
The dashboard provides a visual representation of all the activities like top user login, top threat activities, device control activities by the system, etc.
Once events are received into Netsurion Open XDR, Reports, Knowledge Objects, Categories and Dashboards can be configured into Netsurion Open XDR.
Netsurion monitors all the SentinelOne events, they are given as below.
- Security –Threat detection, Non-Mitigated threat detection, Suspicious process detection, Device control activities.
- Operation – Login and logout details, User-Management activity, and other management activities on the SentinelOne console.
The following are the key Data Source Integration available in Netsurion Open XDR.
Alerts
Type | Name | Description |
---|---|---|
Security | SentinelOne – Threat Activity Detected | This alert will be triggered in the event of any threat related activity (like new threat detected, suspicious process dejected) that has been detected. |
Security | SentinelOne – USB Activity Detected | This alert will be triggered when external devices have been connected to the systems which have been detected by the device control. |
Security | SentinelOne – Threat Not Mitigated | This alert will be triggered in the event of any threat action have been failed. |
Reports
Type | Name | Description |
---|---|---|
Security | SentinelOne – Firewall control activity | This report will generate a detailed view of activity related to firewall activity like firewall rule applied on the traffic. |
Security | SentinelOne – Threat activity details | This report will generate a detailed view on activities related to the threat activities like (New Threat Mitigated, New Threat Suspicious, Process marked as a threat, Threat Killed by Policy). |
Security | SentinelOne – Device control activity | This report will generate a detailed view on activities related to the external device connected or disconnected and the rule applied to the event and their action. |
Operations | SentinelOne – Management activity | This report will generate a detailed view of activities that happened in the SentinelOne by the Users. |
Operations | SentinelOne – User login and logout details | This report will generate a detailed view of activities related to user login and logout on SentinelOne console. |
Operations | SentinelOne – User management details | This report will generate a detailed view on activities related to user management, i.e. user added, user deleted, user modified, etc. |
Documentation
The configuration details are consistent with Netsurion Open XDR 9.x and later, and SentinelOne.
Download Integration Guide for configuration instructions and more information.