SentinelOne delivers autonomous security for endpoints, data centers, and cloud environments to help organizations secure their assets.
Use the SentinelOne integration to interact with core aspects directly from Torq workflows. SentinelOne steps within Torq include:
Add Note to Threats
Broadcast Message
Cancel Deep Visibility Query
Connect to Network
Create Blacklist Item
Create Custom Detection Rules
Create Deep Visibility Power Query
Create Exclusion
Delete Blacklist Item
Get Agents
+45 more...
Trigger a Torq Workflow from SentinelOne Events
Create a SentinelOne Trigger Integration in Torq
Go to Build > Integrations > Triggers > SentinelOne and click Add.
Give the trigger a meaningful and unique name.
You will not be able to change this later.
Under Authentication Headers click Add.
Click Generate Random Secret and save the secret created.
Click Add.
Create a SentinelOne Singularity Marketplace App
In SentinelOne, log in to your Management Console and click Singularity Marketplace.
Search for Singularity Webhook and click Install.
Fill out the relevant details:
Toggle the Response Actions to
Make Response Actions available as "Manual Response Actions" from Threats
.Give the threat response action a unique and meaningful name, such as Torq Webhook.
Give the threat response action a meaningful description such as
Send response to Torq
.Under the Automated Trigger Option, select which threats you want to be sent to the webhook.
In the URL parameter, paste the webhook generated earlier in Torq.
Under Action, select POST.
In the Webhook Request Body parameter, select Full Threat Details.
Click Next and select the access level for the app: Global, Account, or Site.
Click Install.
Use SentinelOne Steps in a Torq Workflow
Create a SentinelOne API Key
Log in to your SentinelOne portal.
In the upper-right corner, click the arrow next to your user name and select My User.
Click Generate next to the API token.
Download and copy the API key for later use.
Create a SentinelOne Steps Integration in Torq
Go to Build > Integrations > Steps > SentinelOne and click Add.
Give the integration a meaningful name. This cannot be changed later.
Enter the API key you created earlier.
Enter your management URL without the
https://
prefix. For example,<company-name>.sentineleone.net
Click Add.