Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

SentinelOne Connector Guide

Prev Next

SentinelOne is an endpoint protection solution that prevents, detects, and responds to attacks across all major vectors. The Balbix integration with SentinelOne ingests IT infrastructure assets and software vulnerabilities discovered by SentinelOne.

Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.

Integration Summary

This table provides a summary of the Balbix integration for the SentinelOne connector.

Integration Type

Fetch: An inbound API integration used to fetch IT infrastructure assets and software vulnerabilities.

Types of Assets Fetched

Host devices (includes servers, virtual machines, desktops, laptops.

Types of Data Fetched

Asset names, hardware information, interface information (MAC address, IP address), OS information, BIOS information, system information, software information, vulnerability information, user information, and all relevant timestamps (e.g., software install time, CVE last observed).

Prerequisites

To configure the Balbix connector, you must first create SentinelOne API credentials with the appropriate permissions. These credentials are required for completing the configuration process.

Create an API Token

To generate an API token from SentinelOne:

  1. Log in to the SentinelOne online console with your user account.

  2. Click your username in the top-right corner of the console and select My User.

  3. Go to Actions > API Token Operations > Generate API Token. The API token and its expiration date will be displayed.

  4. Copy the token and securely save it for later use when setting up the SentinelOne connector in Balbix.

  5. Click Close.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for SentinelOne.

Field Mapping

Fields from API

Balbix Fields

id

Asset ID

uuid

Asset UUID

computerName

Asset Name

ip

IP Address

mac

Mac Address

machineType

Asset Type

osName

Operating System Name

osArch

Operating System Architecture

osRevision

Operating System Version

domain

Windows Domain

domain_joined

Domain Joined

uptime_mins

Uptime

networkInterfaces → gatewayIp

IP Address, Interfaces - IP Address

networkInterfaces → gatewayMacAddress

MAC Address, Interfaces - MAC Address

externalIp

External IP (mapped, but not used yet)

coreCount

CPU Cores

cpuId

CPU Model Name

totalMemory

Total Physical Memory (MB)

tags

Tags

modelName

System Product Name

serialNumber

Serial Number

threatRebootRequired

Is Reboot Pending

API Reference Documentation

To learn more about the SentinelOne API, see the reference listed below: