This article is for teams who want to connect their SentinelOne instance to Tenacy to automate the collection of security indicators for their workstations and servers.
SentinelOne EDR is a comprehensive asset security solution that provides businesses with advanced real-time threat detection and response capabilities.
SentinelOne EDR automates incident response processes, reducing detection and response times for security incidents, and offers forensic investigation capabilities, enabling security teams to conduct in-depth investigations into security incidents.
SentinelOne EDR offers comprehensive asset security, protecting against a wide range of cyber threats, including malware, ransomware, and phishing attacks.
This connector queries the SentinelOne API to generate indicators on threats and updates for workstations and servers.
This connector allows the following information to be retrieved for workstations and servers separately:
Total number of assets, up-to-date assets, infected assets, and protected assets.
Detected, confirmed, untreated, and unresolved threats.
Adding and configuring the connector
To add this connector, go to Catalog > Connectors > SentinelOne > Add a connector.
After adding, you need to configure:
Operator perimeter: the perimeter that operates and prescribes asset protection rules, to which indicators will be attached by default.
Frequency: the frequency at which the SentinelOne API is queried and the frequency of the metrics. This can be daily, weekly, monthly, semi-annual, or annual.
Once the connector is created, the configuration continues:
SentinelOne Namespace URL: corresponds to the connection URL for the SentinelOne dashboard.
SentinelOne API Key: API key generated in the SentinelOne management console (Settings > Users, select a user with the required permissions, then click Options > Generate API key).
Malware types: by default, the value is "Malware, Trojan, Virus, Infostealer", but you can add or remove categories by separating them with commas.
💡 By default, reporting is done in mono mapping: a single global value is attached to the operator perimeter. To report different values across several perimeters (multi mapping), use the Beneficiary perimeter dropdown menu: associate each desired Tenacy perimeter with one or more SentinelOne group(s) or site(s) values, separated by commas.
⚠️ By default, API tokens created on users are only valid for 30 days, and this duration cannot be changed. We therefore recommend creating a Service User dedicated to Tenacy, so you can granularly control what TENACY accesses and what rights the associated token has. Here are the steps to do this:
Select Settings > Users > Service Users.
Select Actions > Create a new service user.
Enter a name, a description, and an expiration date (more comfortable than 30 days).
Select Next.
Select the perimeter(s) the user will have access to, as well as the role for each perimeter.
Select Create user.
Copy the token and paste it into the connector configuration window in TENACY.
Run your first test
Once the connector is properly configured, test the integration by running an initial execution.
Go to ⚙️ > Connectors > Click on the SentinelOne connector > Run now:
💡 Feel free to contact Tenacy support if you have any questions about this.
Expected result
Once the test has run successfully, the connector automatically queries the SentinelOne API according to the chosen periodicity. Indicators for workstations and servers start updating separately, with threat and asset values reported for the configured perimeter(s).
Frequently asked questions
What happens if I don't enter any group or site values in "Beneficiary perimeter"?
Only the global value of your SentinelOne instance is reported, attached to the operator perimeter.
What happens when my API token expires after 30 days?
The connector can no longer query the SentinelOne API: indicators stop updating until a new valid token is entered in the configuration. This is why we recommend using a Service User with a more comfortable expiration date.
Can I change the list of tracked malware types after the connector has been created?
Yes, you can add or remove categories at any time in the connector's configuration, separating them with commas.
Are the reported indicators different for workstations and servers?
Yes, the connector reports distinct indicators for each of these two asset types.




