SentinelOne is an endpoint protection solution that prevents, detects, and responds to attacks across all major vectors. The Balbix integration with SentinelOne ingests IT infrastructure assets and software vulnerabilities discovered by SentinelOne.
Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.
Integration Summary
This table provides a summary of the Balbix integration for the SentinelOne connector.
Integration Type | Fetch: An inbound API integration used to fetch IT infrastructure assets and software vulnerabilities. |
Types of Assets Fetched | Host devices (includes servers, virtual machines, desktops, laptops. |
Types of Data Fetched | Asset names, hardware information, interface information (MAC address, IP address), OS information, BIOS information, system information, software information, vulnerability information, user information, and all relevant timestamps (e.g., software install time, CVE last observed). |
Prerequisites
To configure the Balbix connector, you must first create SentinelOne API credentials with the appropriate permissions. These credentials are required for completing the configuration process.
Create an API Token
To generate an API token from SentinelOne:
Log in to the SentinelOne online console with your user account.
Click your username in the top-right corner of the console and select My User.
Go to Actions > API Token Operations > Generate API Token. The API token and its expiration date will be displayed.
Copy the token and securely save it for later use when setting up the SentinelOne connector in Balbix.
Click Close.
Create and Configure the Connector
After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for SentinelOne.
Field Mapping
Fields from API | Balbix Fields |
id | Asset ID |
uuid | Asset UUID |
computerName | Asset Name |
ip | IP Address |
mac | Mac Address |
machineType | Asset Type |
osName | Operating System Name |
osArch | Operating System Architecture |
osRevision | Operating System Version |
domain | Windows Domain |
domain_joined | Domain Joined |
uptime_mins | Uptime |
networkInterfaces → gatewayIp | IP Address, Interfaces - IP Address |
networkInterfaces → gatewayMacAddress | MAC Address, Interfaces - MAC Address |
externalIp | External IP (mapped, but not used yet) |
coreCount | CPU Cores |
cpuId | CPU Model Name |
totalMemory | Total Physical Memory (MB) |
tags | Tags |
modelName | System Product Name |
serialNumber | Serial Number |
threatRebootRequired | Is Reboot Pending |
API Reference Documentation
To learn more about the SentinelOne API, see the reference listed below: