> ## Documentation Index
> Fetch the complete documentation index at: https://docs.threataware.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SentinelOne

> Connect ThreatAware to SentinelOne for endpoint protection and threat visibility

## Overview

The SentinelOne integration enables ThreatAware to collect endpoint protection and threat detection data from your SentinelOne Management Console, providing visibility into endpoint security status and threat detection across your organisation.

<Info>
  **Connection Method**: API
  **Setup Time**: 15 minutes
  **Access Required**: SentinelOne Administrator account
</Info>

## Data collected

The SentinelOne integration provides:

* Endpoint inventory and protection status
* Threat detection and incident data
* Remediation and quarantine information
* System health and compliance status

## Use cases

<CardGroup cols={2}>
  <Card title="Endpoint Protection Monitoring" icon="shield">
    Monitor SentinelOne protection status across all managed endpoints
  </Card>

  <Card title="Threat Detection" icon="triangle-exclamation">
    Track detected threats and remediation actions
  </Card>

  <Card title="Incident Response" icon="fire">
    Monitor and respond to detected incidents
  </Card>

  <Card title="Compliance Verification" icon="clipboard-check">
    Verify all endpoints have active SentinelOne protection
  </Card>
</CardGroup>

## Setup instructions

<Steps>
  <Step title="Log in to SentinelOne Management Console">
    * Access your [SentinelOne Management Console](https://sentinelone.com/)
    * Log in with an account that has administrator privileges
    * Note the **Platform URL** from your console's address bar (e.g., `https://euce1-110-nfr.sentinelone.net`)

    <Tip>
      The Platform URL is critical for API authentication. Make sure to use the exact URL from your console.
    </Tip>
  </Step>

  <Step title="Create Dedicated Admin Account">
    * Navigate to **Settings** > **Users** or **User Management** in the SentinelOne console
    * Click **Add User** to create a new administrator account
    * Create an account specifically for API access (e.g., "threataware-api")
    * Assign **Admin** permissions to the account
    * Set a strong, unique password for this account
    * Note the username and password for later use

    <Warning>
      This account will be used specifically for the ThreatAware integration. Keep the credentials secure and do not share them.
    </Warning>
  </Step>

  <Step title="Generate API Token">
    * Log in to the SentinelOne console with the newly created admin account
    * Navigate to **My User** > **API Token** or **Account Settings** > **API Token**
    * Click **Generate** to create a new API Token
    * Copy the **API Token** that is displayed
    * Note the token expiry date for your records

    <Warning>
      API tokens are displayed only once. Copy and securely store the token in your password manager before closing this screen.
    </Warning>
  </Step>

  <Step title="Configure in ThreatAware">
    Complete the integration setup in ThreatAware:

    * Open ThreatAware and navigate to **Settings** > **Integrations**
    * Search for and select **SentinelOne**
    * Enter the required information:
      * **Management Console URL**: The Platform URL from your SentinelOne console (e.g., `https://euce1-110-nfr.sentinelone.net`)
      * **API Token**: The API token generated in the previous step
    * Click **Authorize** to establish the integration
  </Step>

  <Step title="Verify Connection">
    After connecting, verify the integration is working:

    * Check that the **Integration Status** shows as **Active**
    * Wait up to 5 minutes for the initial endpoint data sync
    * Verify endpoint protection data appears in ThreatAware
    * Confirm threat and incident data is being collected
  </Step>
</Steps>

## Required credentials

<AccordionGroup>
  <Accordion title="Management Console URL" icon="link">
    **Field Name**: SentinelOne Management Console URL
    **Type**: String
    **Description**: The URL of your SentinelOne Management Console

    This is the base URL from your console's address bar. Include the protocol (https).

    **Format**: `https://region-platform.sentinelone.net`
    **Examples**:

    * `https://euce1-110-nfr.sentinelone.net`
    * `https://usea1-180-nfr.sentinelone.net`
    * `https://api.sentinelone.net`

    <Tip>
      The console URL is displayed in your browser's address bar when you log in. Copy it exactly as shown.
    </Tip>
  </Accordion>

  <Accordion title="API Token" icon="key">
    **Field Name**: SentinelOne API Token
    **Type**: Password (encrypted)
    **Description**: Authentication token for API access to SentinelOne

    Generated in **My User** > **API Token** section of the SentinelOne console.

    <Tip>
      Store this credential securely in your organisation's password manager. The token is only displayed once during generation.
    </Tip>
  </Accordion>
</AccordionGroup>

## Verification and testing

After setup, verify the integration is working correctly:

1. **Check Integration Status**
   * Navigate to **Settings** > **Integrations** in ThreatAware
   * Confirm the SentinelOne integration shows **Active** status
   * Check the last sync timestamp

2. **Verify Data Collection**
   * Wait up to 5 minutes for initial endpoint collection
   * Search for a known endpoint in ThreatAware
   * Verify SentinelOne protection status appears in endpoint details

3. **Test Queries**
   * Create a test query to filter endpoints by SentinelOne protection status
   * Verify the results match your SentinelOne console data

## Troubleshooting

<AccordionGroup>
  <Accordion title="Invalid Token Error" icon="triangle-exclamation">
    **Symptoms**: Integration fails to authenticate

    **Solutions**:

    * Verify the **API Token** was copied correctly without extra spaces
    * Confirm the API Token has not expired (check the expiry date)
    * Check if the API Token was revoked or disabled in SentinelOne
    * Generate a new API Token if necessary
    * Ensure the API Token is for the correct user account
  </Accordion>

  <Accordion title="Incorrect Console URL" icon="link-exclamation">
    **Symptoms**: Integration fails due to URL issues

    **Solutions**:

    * Verify the **Management Console URL** matches exactly what appears in your browser
    * Ensure the URL includes the protocol (https) and the region identifier
    * Remove any trailing slashes or paths from the URL
    * Test the URL in a browser to verify it's accessible
    * Confirm you're using the correct console URL for your region
  </Accordion>

  <Accordion title="Permission Issues" icon="ban">
    **Symptoms**: Integration connects but no endpoint data appears

    **Solutions**:

    * Verify the admin account has sufficient permissions in SentinelOne
    * Confirm the API Token is associated with an admin account
    * Check that the account has not been restricted to specific sites or groups
    * Review SentinelOne user permissions for the API account
    * Ensure the account is active and not disabled
  </Accordion>

  <Accordion title="Connection Timeout" icon="clock">
    **Symptoms**: Integration fails to connect or times out

    **Solutions**:

    * Verify the **Management Console URL** is accessible from your network
    * Test the URL in a browser to ensure it loads correctly
    * Check firewall rules allow outbound HTTPS (443) to SentinelOne
    * Confirm your internet connection is stable
    * Verify SentinelOne service is online and responsive
  </Accordion>

  <Accordion title="No Data After 5 Minutes" icon="database">
    **Symptoms**: Integration shows active but no endpoint data appears

    **Solutions**:

    * Verify you have endpoints enrolled in SentinelOne
    * Confirm the API Token has proper permissions to view endpoints
    * Wait up to 10 minutes for the initial data sync
    * Check SentinelOne console to verify data exists
    * Review ThreatAware integration logs for specific errors
    * Verify the admin account can access all required endpoints
  </Accordion>

  <Accordion title="API Token Expiration" icon="calendar-exclamation">
    **Symptoms**: Integration was working but stops collecting data

    **Solutions**:

    * Check the API Token expiry date in your SentinelOne console
    * Generate a new API Token if the current one has expired
    * Update the token in ThreatAware with the new API Token
    * Set a reminder to rotate API tokens before expiry
    * Consider setting tokens to not expire if your policy allows
  </Accordion>
</AccordionGroup>

## Additional resources

<CardGroup cols={2}>
  <Card title="SentinelOne API Documentation" icon="book" href="https://developer.sentinelone.com/">
    Official SentinelOne API documentation and reference materials
  </Card>

  <Card title="SentinelOne Support" icon="life-ring" href="https://support.sentinelone.com/">
    SentinelOne support portal for technical assistance
  </Card>
</CardGroup>

## Best practices

<Tip>
  **Credential Management**

  * Create a dedicated admin account specifically for ThreatAware API access
  * Store the API Token securely in your organisation's password manager
  * Rotate API tokens regularly (annually or per security policy)
  * Document the API Token generation date and expiry date
  * Monitor integration status to catch authentication failures early
</Tip>

<Tip>
  **Security Considerations**

  * Only use the API Token for ThreatAware integration
  * Do not share API tokens with unauthorized users
  * Monitor SentinelOne audit logs for API account activity
  * Review endpoint protection status regularly
  * Keep integration status monitoring in place for continuity
</Tip>
