SentinelOne Threats
Supported by community
Detection & Response Enablement
Overview
Imports malware artifacts detected by SentinelOne EDR from BinaryVault into OpenCTI as STIX observables and indicators.
The SentinelOne Threats connector imports malware artifacts and threat data from SentinelOne BinaryVault into OpenCTI. It retrieves malicious file samples detected by SentinelOne's EDR platform and creates corresponding STIX observables and indicators. Note: SentinelOne API tokens expire every 6 months and must be renewed before expiration.