Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up
SentinelOne Incidents logo

SentinelOne Incidents

Supported by community
Detection & Response Enablement

Overview

Imports SentinelOne EDR alerts as STIX Incidents into OpenCTI, with linked endpoint observables, MITRE ATT&CK patterns, file hash indicators, and incident notes.

SentinelOne delivers passive and active EDR security via AI threat detection and autonomous response.

The OpenCTI SentinelOne Incidents connector will ingest alert data from SentinelOne into the OpenCTI threat intelligence platform. This integration enables security teams to centralise and enrich incident data from SentinelOne, facilitating comprehensive threat analysis and response.

This version of the connector creates the following objects in correspondence with a SentinelOne Incident:

  • An Incident with all pivotal information
  • Observable of the affected endpoint
  • Attack Patterns corresponding to the MITRE Attack Patterns identified for the Incident
  • Notes based on the actual notes made for the Incident
  • Indicators for any hashes of malicious files
  • An external reference to the Incident in SentinelOne if deeper analysis is required.

Basic information

SentinelOne Incidents
Vendor Contact
Connectors
6.8.13
2

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".