OpenCTI または OpenAEV プラットフォームを 30 日間お試しいただけます。 無料トライアル
XTMハブ by フィリグラン
サインアップ
SentinelOne Incidents logo

SentinelOne Incidents

コミュニティの提供による
Detection & Response Enablement

概要

Imports SentinelOne EDR alerts as STIX Incidents into OpenCTI, with linked endpoint observables, MITRE ATT&CK patterns, file hash indicators, and incident notes.

SentinelOne delivers passive and active EDR security via AI threat detection and autonomous response.

The OpenCTI SentinelOne Incidents connector will ingest alert data from SentinelOne into the OpenCTI threat intelligence platform. This integration enables security teams to centralise and enrich incident data from SentinelOne, facilitating comprehensive threat analysis and response.

This version of the connector creates the following objects in correspondence with a SentinelOne Incident:

  • An Incident with all pivotal information
  • Observable of the affected endpoint
  • Attack Patterns corresponding to the MITRE Attack Patterns identified for the Incident
  • Notes based on the actual notes made for the Incident
  • Indicators for any hashes of malicious files
  • An external reference to the Incident in SentinelOne if deeper analysis is required.

基本情報

SentinelOne Incidents
ベンダー連絡先
コネクター
6.8.13
2

    XTM Hubの運営にはクッキーを使用しています。必須のクッキーは常に有効になっていますが、オプションのクッキー(機能、分析、マーケティング)は、お客様の同意を得た上で使用されます。「クッキー設定」から、いつでも「すべて受け入れる」、「すべて拒否する」、または設定を管理することができます。