XTM Hub by Filigran
SentinelOne Incidents logo

SentinelOne Incidents

Supporté par la communauté
Detection & Response Enablement

Aperçu

Imports SentinelOne EDR alerts as STIX Incidents into OpenCTI, with linked endpoint observables, MITRE ATT&CK patterns, file hash indicators, and incident notes.

SentinelOne delivers passive and active EDR security via AI threat detection and autonomous response.

The OpenCTI SentinelOne Incidents connector will ingest alert data from SentinelOne into the OpenCTI threat intelligence platform. This integration enables security teams to centralise and enrich incident data from SentinelOne, facilitating comprehensive threat analysis and response.

This version of the connector creates the following objects in correspondence with a SentinelOne Incident:

  • An Incident with all pivotal information
  • Observable of the affected endpoint
  • Attack Patterns corresponding to the MITRE Attack Patterns identified for the Incident
  • Notes based on the actual notes made for the Incident
  • Indicators for any hashes of malicious files
  • An external reference to the Incident in SentinelOne if deeper analysis is required.

Informations de base

SentinelOne Incidents
Contact vendeur
Connecteurs
6.8.13
2

    Nous utilisons des cookies pour assurer le fonctionnement de XTM Hub. Les cookies nécessaires sont toujours activés ; les cookies facultatifs (fonctionnels, d'analyse, de marketing) ne sont utilisés qu'avec votre consentement. Vous pouvez accepter tous les cookies, les refuser tous ou gérer vos préférences à tout moment dans la rubrique « Paramètres des cookies ».