SentinelOne integration
Pull endpoint security data and threat intelligence into service management; automate incident response and agent management at scale.
What it connects
- Endpoint agents with OS, hardware inventory, active threat counts, and network status.
- Organizational sites, groups, and deployment structure for hierarchical asset mapping.
- Installed software inventory across all endpoints to track applications and vulnerabilities.
- Threats, detections, and activities logs for security event correlation and incident investigation.
What it automates
- Scan endpoints and fetch agent logs for diagnostics and threat containment verification.
- Quarantine or kill threats to contain malicious files and processes automatically.
- Disconnect agents from network or move them to isolation groups during active incidents.
- Update agent software and manage endpoint group assignments for policy-driven remediation.
In practice
SentinelOne detects malware on a production server; STLabs immediately quarantines the threat, initiates a forensic scan, creates a critical incident ticket, and isolates the agent from the network.
Security team discovers endpoints running outdated SentinelOne agents; STLabs automatically generates patching tickets and triggers software updates on non-compliant agents.
A suspicious file detection arrives; STLabs correlates it with digital twin data to identify which business unit is affected, escalates priority if production, and logs the full forensic activities.
After a threat is mitigated, STLabs broadcasts status messages to affected endpoints, schedules full-system scans, and documents mitigation actions in the incident audit trail.