Sentinelone
SentinelOne provides AI-powered endpoint protection, detection, and response to autonomously prevent, detect, and remediate cyber threats across enterprise environments.
SentinelOne is a leading endpoint security platform that provides advanced threat detection, response, and endpoint management across enterprise environments. This connector enables Swimlane Turbine users to automate a wide range of SentinelOne operations, including threat investigation, mitigation, agent management, vulnerability assessment, and alert enrichment. By integrating SentinelOne with Swimlane Turbine, security teams can orchestrate rapid response actions, streamline incident workflows, and gain deeper visibility into endpoint activityβall without writing code. This integration empowers organizations to accelerate threat response, reduce manual effort, and unify security operations across their technology stack.
Prerequisites
Before using the SentinelOne connector, ensure you have the following prerequisites:
- API Key Authentication is required to access SentinelOne APIs:
- URL: The base URL of your SentinelOne management console or cloud instance.
- API Token: A valid SentinelOne API token with sufficient permissions to perform desired actions.
Obtaining an API Token
- Navigate to the SentinelOne Portal. Select your user in the upper right corner of the menu.
- Select the menu by your user account name, then select My User.
- A modal will pop up displaying your account information.
- Select Generate to generate a new API Token and copy the value into the Swimlane asset.
Capabilities
The SentinelOne integration provides the following capabilities:
- Add Threat Note
- Broadcast Message
- Connect Agents
- Create Blacklist Item
- Create Exclusion
- Create Long Running Query
- Create Power Query And Get Query ID
- Decommission Agent List
- Deep Visibility Create Query and Get Query ID
- Deep Visibility Get Events By Query ID
- Delete Blocklist Item
- Delete Remote Script
- Delete Threat Note
- Disconnect Agents
- Download From Cloud ... and so on
Remote Script Orchestration
These actions wrap the Management API /web/api/v2.1/remote-scripts surface (upload β execute β poll β retrieve output β delete). They require Remote Script Orchestration on the site plus the matching RBAC (Remote Script Orchestration.upload, runDataCollectionScript / runArtifactCollectionScript / runActionScript, and Task Management.view). upload_remote_script uploads generated script text. fetch_remote_script_files returns a zip downloadUrl. retrieve_script_output returns the same fetch-files path as scan JSON in json_body.data (no zip). Neither is the host-path Fetch Files action.
Typical order β Upload Remote Script β Execute Remote Script β Get Remote Script Status until completed β Retrieve Script Output β Delete Remote Script.
Initiate Scan Action
- Full Disk Scan finds dormant suspicious activity, threats, and compliance violations, that are then mitigated according to the policy. It scans the local file system.
- Full Disk Scan does not inspect drives that require user credentials (such as network drives) or external drives.
- Full Disk Scan does not work on hashes. It does not check each file against the blacklist.
- If the Static AI determines a file is suspicious, the Agent calculates its hash and sees if the hash is in the blacklist. If a file is executed, all aspects of the process are inspected, including hash-based analysis and blacklist checks. Full Disk Scan can run when the endpoint is offline, but when it is connected to the Management, it can use the most updated Cloud data to improve detection.
Create Firewall Rule
To keep it simple for the user, this action currently only supports adding remote hosts to a firewall rule. Should this action need to be expanded to support others, please contact Swimlane Support.
About Deep Visibility Queries
For complete query syntax, see Query Syntax in the Knowledge Base or the Console Help.
Notes
The API documentation can be found on your SentinelOne Instance by doing the following:
- Select the arrow next to your user in the top right of the navigation bar.
- Select API Doc and a new tab of the API documentation will open.
This connector was last tested against product version: API v2.1
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
api_token | API Token | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Add Threat Note
Add a custom note to identified threats in SentinelOne using specified data and filters for targeted annotation.
Endpoint
- URL: web/api/v2.1/threats/notes
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
data.text | string | Required | Response data |
filter | object | Optional | Parameter for Add Threat Note |
filter.ids | array | Required | Unique identifier |
Input Example
{"json_body":{"data":{"text":"this is a text"},"filter":{"ids":["1312010475659095549"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Nov 2022 21:12:44 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"f71d36aa-c8c9-4fdd-8df6-86c97d631c69","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Broadcast Message
Send a custom message to SentinelOne agents using specified data and filter criteria.
Endpoint
- URL: web/api/v2.0/agents/actions/broadcast
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Broadcast Message |
filter.updatedAt__gte | string | Optional | Parameter for Broadcast Message |
filter.operationalStates | array | Optional | Parameter for Broadcast Message |
filter.operationalStates.type | string | Optional | Type of the resource |
filter.locationIdsNin | array | Optional | Unique identifier |
filter.locationIdsNin.type | string | Optional | Unique identifier |
filter.locationIdsNin.minimum | number | Optional | Unique identifier |
filter.locationIdsNin.example | string | Optional | Unique identifier |
filter.lastSuccessfulScanDate__between | string | Optional | Whether the operation was successful |
filter.externalIp__contains | array | Optional | Parameter for Broadcast Message |
filter.externalIp__contains.type | string | Optional | Type of the resource |
filter.externalIp__contains.minLength | number | Optional | Parameter for Broadcast Message |
filter.groupIds | array | Optional | Unique identifier |
filter.groupIds.type | string | Optional | Unique identifier |
filter.groupIds.minimum | number | Optional | Unique identifier |
filter.groupIds.example | string | Optional | Unique identifier |
filter.threatRebootRequired | array | Optional | Parameter for Broadcast Message |
filter.threatRebootRequired.type | string | Optional | Type of the resource |
filter.missingPermissions | array | Optional | Parameter for Broadcast Message |
filter.missingPermissions.type | string | Optional | Type of the resource |
filter.missingPermissions.example | string | Optional | Parameter for Broadcast Message |
filter.missingPermissions.enum | array | Optional | Parameter for Broadcast Message |
filter.adUserName__contains | array | Optional | Name of the resource |
filter.adUserName__contains.type | string | Optional | Name of the resource |
filter.adUserName__contains.minLength | number | Optional | Name of the resource |
Input Example
{"filter":{"updatedAt__gte":"string","operationalStates":[{"type":"string"}],"locationIdsNin":[{"type":"string","minimum":123,"example":"string"}],"lastSuccessfulScanDate__between":"string","externalIp__contains":[{"type":"string","minLength":123}],"groupIds":[{"type":"string","minimum":123,"example":"string"}],"threatRebootRequired":[{"type":"string"}],"missingPermissions":[{"type":"string","example":"string","enum":["string"]}],"adUserName__contains":[{"type":"string","minLength":123}],"cloudTags__contains":[{"type":"string","minLength":123}],"filterId":"string","machineTypesNin":[{"type":"string","example":"string","enum":["string"]}],"cloudInstanceSize__contains":[{"type":"string","minLength":123}],"missingPermissionsNin":[{"type":"string","example":"string","enum":["string"]}],"liveUpdateId__contains":[{"type":"string","minLength":123}],"siteIds":[{"type":"string","minimum":123,"example":"string"}],"uuids":[{"type":"string"}],"adUserMember__contains":[{"type":"string","minLength":123}],"k8sVersion__contains":[{"type":"string","minLength":123}],"agentVersionsNin":[{"type":"string","example":"string"}],"lastLoggedInUserName__contains":[{"type":"string","minLength":123}],"machineTypes":[{"type":"string","example":"string","enum":["string"]}],"consoleMigrationStatusesNin":[{"type":"string","example":"string","enum":["string"]}],"appsVulnerabilityStatuses":[{"type":"string","example":"string","enum":["string"]}],"adComputerMember__contains":[{"type":"string","minLength":123}],"lastActiveDate__gte":"string","threatResolved":"string","isPendingUninstall":"string","cloudProviderNin":[{"type":"string"}],"updatedAt__gt":"string","lastSuccessfulScanDate__lte":"string","userActionsNeeded":[{"type":"string","example":"string","enum":["string"]}],"threatCreatedAt__gte":"string","createdAt__between":"string","osTypesNin":[{"type":"string","description":"string","example":"string","enum":["string"]}],"rsoLevel":"string","agentNamespace__contains":[{"type":"string","minLength":123}],"serialNumber__contains":[{"type":"string","minLength":123}],"tagsData":"string","activeThreats":123,"adComputerQuery__contains":[{"type":"string","minLength":123}],"awsSubnetIds__contains":[{"type":"string","minLength":123}],"remoteProfilingStates":[{"type":"string"}],"decommissionedAt__gte":"string","coreCount__lte":"string","cpuCount__gt":"string","isUninstalled":[{"type":"string"}],"lastActiveDate__lte":"string","networkQuarantineEnabled":[{"type":"string"}],"hasLocalConfiguration":"string"},"data":{"message":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
errors | array | Error message if any |
errors.type | string | Type of the resource |
data | object | Response data |
data.affected | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"errors":[{}],"data":{"affected":"integer"}}}
Connect Agents
Reconnect disconnected SentinelOne endpoints by applying a filter to target specific agents and restore their connectivity.
Endpoint
- URL: web/api/v2.1/agents/actions/connect
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Connect Agents |
filter.ids | array | Required | Unique identifier |
Input Example
{"json_body":{"filter":{"ids":["1550901640146865256","1286438987267469377"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 19:32:07 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"d448b9e3-ca4d-4bf2-b828-10a74f33c3be","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Create Blacklist Item
Add a SHA1 or SHA256 hash to the SentinelOne blacklist by specifying the hash in the data field to strengthen threat prevention.
Endpoint
- URL: web/api/v2.1/restrictions
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Create Blacklist Item |
filter.tenant | boolean | Optional | Parameter for Create Blacklist Item |
filter.siteIds | array | Optional | Unique identifier |
data | object | Optional | Response data |
data.osType | string | Required | Response data |
data.type | string | Required | Response data |
data.description | string | Optional | Response data |
data.value | string | Optional | SHA1 hash for the blacklist item (use this or sha256Value). |
data.sha256Value | string | Optional | SHA256 hash for the blacklist item (use this or value). |
data.source | string | Optional | Response data |
Input Example
{"json_body":{"filter":{"tenant":true,"siteIds":["1286405255257023125"]},"data":{"osType":"windows_legacy","type":"black_hash","description":"string","value":"eb571ebfa53742df0e2e8375b7d15f94ab436a09","source":"string"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
errors | array | Error message if any |
errors.file_name | string | Name of the resource |
errors.file | string | Error message if any |
data | array | Response data |
data.scope | object | Response data |
data.scope.siteIds | array | Response data |
data.scope.tenant | boolean | Response data |
data.scope.groupIds | array | Response data |
data.scope.accountIds | array | Response data |
data.userName | string | Response data |
data.userId | string | Response data |
data.updatedAt | string | Response data |
data.createdAt | string | Response data |
data.notRecommended | string | Response data |
data.osType | string | Response data |
data.source | string | Response data |
data.description | string | Response data |
data.value | string | Response data |
data.sha256Value | string | Response data |
data.type | string | Response data |
data.scopeName | string | Response data |
data.id | string | Response data |
Output Example
{"status_code":400,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 18:21:30 GMT","Content-Type":"application/json","Content-Length":"152","Connection":"keep-alive","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Security-Policy":"default-src 'self' ; connect-src 'self'...
Create Exclusion
Establish exclusions in SentinelOne to suppress alerts and mitigate benign items by specifying data and filter parameters.
Endpoint
- URL: /web/api/v2.1/exclusions
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
data.osType | string | Required | OS type. |
data.type | string | Required | Exclusion item type. |
data.value | string | Required | Value for the item type. |
data.actions | array | Optional | Actions to perform. |
data.description | string | Optional | Description. |
data.mode | string | Optional | Exclusion mode (path exclusion only). |
data.pathExclusionType | string | Optional | Excluded path for a path exclusion list. |
data.source | string | Optional | Source. |
filter | object | Optional | Parameter for Create Exclusion |
filter.accountIds | array | Optional | List of Account IDs to filter by. |
filter.groupIds | array | Optional | List of Group IDs to filter by. |
filter.siteIds | array | Optional | List of Site IDs to filter by. |
filter.tenant | boolean | Optional | Indicates a tenant scope request. |
Input Example
{"data":{"osType":"string","type":"string","value":"string","actions":["string"],"description":"string","mode":"string","pathExclusionType":"string","source":"string"},"filter":{"accountIds":["string"],"groupIds":["string"],"siteIds":["string"],"tenant":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.scope | object | Response data |
data.scope.accountIds | array | Response data |
data.scope.groupIds | array | Response data |
data.scope.siteIds | array | Response data |
data.scope.tenant | boolean | Response data |
data.actions | array | Response data |
data.createdAt | string | Response data |
data.description | string | Response data |
data.id | string | Response data |
data.mode | string | Response data |
data.notRecommended | string | Response data |
data.osType | string | Response data |
data.pathExclusionType | string | Response data |
data.scopeName | string | Response data |
data.source | string | Response data |
data.type | string | Response data |
data.updatedAt | string | Response data |
data.userId | string | Response data |
data.userName | string | Response data |
data.value | string | Response data |
errors | array | Error message if any |
Output Example
{"data":{"scope":{"accountIds":[],"groupIds":[],"siteIds":[],"tenant":true},"actions":["string"],"createdAt":"string","description":"string","id":"12345678-1234-1234-1234-123456789abc","mode":"string","notRecommended":"string","osType":"string","pathExclusionType":"string","scopeName":"Example Name","source":"string","type":"string","updatedAt":"string","userId":"string","userName":"Example Name"},"errors":[]}
Create Long Running Query
Submit a PowerQuery or S1QL log search to the SentinelOne Singularity Data Lake and retrieve results for a specified tenant and time range.
Endpoint
- URL: /sdl/v2/api/queries
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
queryType | string | Optional | Use PQ for PowerQuery or LOG for a raw S1QL log search. |
tenant | boolean | Optional | Query the current tenant. Set true for tenant-wide searches. |
startTime | string | Optional | Inclusive ISO-8601 UTC start time. |
endTime | string | Optional | Exclusive ISO-8601 UTC end time. |
pq | object | Optional | PowerQuery request. Required when queryType is PQ. |
pq.query | string | Required | Executable SentinelOne PowerQuery text. |
pq.resultType | string | Required | Return tabular query results. |
log | object | Optional | Raw S1QL log search. Required when queryType is LOG. |
log.filter | string | Required | S1QL log filter expression. |
log.limit | integer | Required | Maximum raw log events to return. |
Input Example
{"queryType":"string","tenant":true,"startTime":"string","endTime":"string","pq":{"query":"string","resultType":"string"},"log":{"filter":"string","limit":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Create Power Query And Get Query ID
Execute a Deep Visibility Power Query in SentinelOne with specified date range and query, returning a unique query ID for result tracking.
Endpoint
- URL: /web/api/v2.1/dv/events/pq
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
query | string | Optional | Events matching the query search term will be returned. |
accountIds | string | Optional | List of Account IDs to filter by. |
siteIds | string | Optional | List of Site IDs to filter by. |
toDate | string | Optional | Events created before or at this timestamp. |
limit | number | Optional | Limit number of returned items (1-100000). |
fromDate | string | Optional | Events created after this timestamp. |
Input Example
{"json_body":{"query":"event.time = * | columns eventTime = event.time, agentUuid = agent.uuid, siteId = site.id","accountIds":"1286405255240245908,1286405255240245978","siteIds":"1758952600032266153,1758952600032266135","toDate":"2024-04-21T04:49:26.257525Z","limit":10,"fromDate":"2024-04-15T04:49:26.257525Z"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.columns | array | Response data |
data.columns.file_name | string | Response data |
data.columns.file | string | Response data |
data.data | array | Response data |
data.data.file_name | string | Response data |
data.data.file | string | Response data |
data.externalId | string | Response data |
data.progress | number | Response data |
data.queryId | string | Response data |
data.recommendations | array | Response data |
data.recommendations.file_name | string | Response data |
data.recommendations.file | string | Response data |
data.status | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 22 Apr 2024 08:49:49 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"32b46d87-e912-4ed0-9012-4e617cc9a015","Access-Control-Allow-Origin":"https://cns.na1.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Secu...
Decommission Agent List
Decommission SentinelOne agents that match specified filter criteria. Requires Endpoints.decommission permission.
Endpoint
- URL: web/api/v2.1/agents/actions/decommission
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Filter identifying agents to decommission. |
filter.ids | array | Optional | Agent IDs to target. |
filter.uuids | array | Optional | Agent UUIDs to target. |
filter.accountIds | array | Optional | Limit to agents in these accounts. |
filter.siteIds | array | Optional | Limit to agents in these sites. |
filter.groupIds | array | Optional | Limit to agents in these groups. |
filter.filteredGroupIds | array | Optional | Filter by dynamic group IDs. |
filter.uuid | string | Optional | Filter by a single agent UUID. |
filter.computerName | string | Optional | Filter by exact computer name. |
filter.computerName__contains | array | Optional | Free-text filter by computer name (min 2 characters). |
filter.computerName__like | string | Optional | SQL-like pattern filter on computer name. |
filter.query | string | Optional | Free-text search across applicable agent attributes. |
filter.domains | array | Optional | Included network domains. |
filter.externalIp__contains | array | Optional | Free-text filter by external IP (min 2 characters). |
filter.externalId__contains | array | Optional | Free-text filter by external ID. |
filter.infected | boolean | Optional | Filter by infection status. |
filter.isActive | boolean | Optional | Filter by whether the agent is active. |
filter.isDecommissioned | boolean | Optional | Filter by decommissioned status. |
filter.isUninstalled | boolean | Optional | Filter by uninstalled status. |
filter.isPendingUninstall | boolean | Optional | Filter by pending uninstall status. |
filter.networkStatuses | array | Optional | Filter by network status (e.g. connected, disconnected). |
filter.operationalStates | array | Optional | Filter by operational states. |
filter.operationalStatesNin | array | Optional | Exclude these operational states. |
filter.osTypes | array | Optional | Filter by OS types (linux, macos, windows, windows_legacy). |
filter.osTypesNin | array | Optional | Exclude these OS types. |
Input Example
{"json_body":{"filter":{"ids":["1286438987267469377"]},"data":{}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code returned by the API. |
reason | string | HTTP reason phrase (e.g. OK). |
errors | array | API error objects, if any were returned. |
data | object | Response payload containing the number of affected agents. |
data.affected | number | Number of agents decommissioned. |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"errors":[],"data":{"affected":1}}}
Deep Visibility Create Query and Get Query ID
Execute a Deep Visibility query in SentinelOne with specified parameters and receive a unique query ID for tracking and retrieving results.
Endpoint
- URL: web/api/v2.1/dv/init-query
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
query | string | Optional | Parameter for Deep Visibility Create Query and Get Query ID |
fromDate | string | Optional | Date value |
toDate | string | Optional | Date value |
queryType | array | Optional | Type of the resource |
tenant | boolean | Optional | Parameter for Deep Visibility Create Query and Get Query ID |
siteIds | array | Optional | Unique identifier |
groupIds | array | Optional | Unique identifier |
accountIds | array | Optional | Unique identifier |
limit | number | Optional | Parameter for Deep Visibility Create Query and Get Query ID |
isVerbose | boolean | Optional | Show all fields or just priority fields. |
timeFrame | string | Optional | Time frame that the query was performed on, when omitted defaults to "Last 48 Hours". |
Input Example
{"json_body":{"query":"AgentName IS NOT EMPTY","fromDate":"2022-11-14T22:01:32.962480Z","toDate":"2022-11-14T22:01:32.962480Z","queryType":["events"],"tenant":true,"siteIds":["1286405255257023125"],"groupIds":["1286405255265411734"],"accountIds":["1286405255240245908"],"limit":10}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.queryId | string | Response data |
data.queryModeInfo | object | Response data |
data.queryModeInfo.lastActivatedAt | string | Response data |
data.queryModeInfo.mode | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 20:26:37 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"6b98f9cc-a555-4fe3-8b6e-ccf55ec6eacf","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Deep Visibility Get Events By Query ID
Retrieve all Deep Visibility events in SentinelOne for a specified query ID after an 'init-query' operation, using the required parameters and queryId.
Endpoint
- URL: web/api/v2.1/dv/events
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.queryId | string | Required | Parameters for the Deep Visibility Get Events By Query ID action |
parameters.limit | number | Optional | Parameters for the Deep Visibility Get Events By Query ID action |
parameters.sortOrder | string | Optional | Parameters for the Deep Visibility Get Events By Query ID action |
parameters.cursor | string | Optional | Cursor position returned by the last request. Should be used instead of skip. cursor currently supports sort by with createdAt, pid, processStartTime. |
parameters.skip | string | Optional | Skip first number of items (0-1000). To iterate over more than 1000 items, use "cursor". |
parameters.sortby | string | Optional | Events sorted by field. |
parameters.subquery | string | Optional | Create a sub query to run on the data that was already pulled. |
Input Example
{"parameters":{"queryId":"1286405255240245908","limit":10,"sortOrder":"asc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.networkMethod | string | Response data |
data.indicatorCategory | string | Response data |
data.agentVersion | string | Response data |
data.agentUuid | string | Response data |
data.createdAt | string | Response data |
data.agentMachineType | string | Response data |
data.forensicUrl | string | Response data |
data.fileSize | string | Response data |
data.parentProcessUniqueKey | string | Response data |
data.fileType | string | Response data |
data.taskPath | string | Response data |
data.oldFileMd5 | string | Response data |
data.fileMd5 | string | Response data |
data.trueContext | string | Response data |
data.verifiedStatus | string | Response data |
data.processIsRedirectedCommandProcessor | string | Response data |
data.agentIsDecommissioned | boolean | Response data |
data.oldFileName | string | Response data |
data.indicatorMetadata | string | Response data |
data.dstIp | string | Response data |
data.parentProcessName | string | Response data |
data.processImagePath | string | Response data |
Output Example
{"status_code":400,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 20:00:44 GMT","Content-Type":"application/json","Content-Length":"97","Connection":"keep-alive","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Security-Policy":"default-src 'self' ; connect-src 'self' ...
Delete Blocklist Item
Remove a specified item from the SentinelOne blocklist to restore agent access to previously restricted files using provided JSON data.
Endpoint
- URL: /web/api/v2.1/restrictions
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
data.ids | array | Optional | Response data |
data.type | string | Optional | Type. |
Input Example
{"data":{"ids":["string"],"type":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
errors | array | Error message if any |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":{"affected":1},"errors":[{}]}}
Delete Remote Script
Remove scripts from the Script Library by ID in SentinelOne. Requires appropriate permissions such as Remote Script Orchestration.upload or console delete access.
Endpoint
- URL: /web/api/v2.1/remote-scripts
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
data.ids | array | Required | Script Library ids to delete. Example β 225494730938493804. |
Input Example
{"json_body":{"data":{"ids":["225494730938493804"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
errors | array | Error message if any |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":{"affected":1}}}
Delete Threat Note
Remove a specific note from a threat in SentinelOne by providing the required threat and note IDs.
Endpoint
- URL: web/api/v2.1/threats/{{threat_id}}/notes/{{note_id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.threat_id | string | Required | Parameters for the Delete Threat Note action |
path_parameters.note_id | string | Required | Parameters for the Delete Threat Note action |
Input Example
{"path_parameters":{"threat_id":"1311010475659095549","note_id":"1553834980127175650"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.success | boolean | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 14:50:43 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"d005d0b4-d6c5-43f2-9a96-25ce505a3c7c","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Disconnect Agents
Quarantine SentinelOne agents by applying a specified filter to isolate endpoints as defined in the JSON body.
Endpoint
- URL: web/api/v2.1/agents/actions/disconnect
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Disconnect Agents |
filter.ids | array | Required | Unique identifier |
Input Example
{"json_body":{"filter":{"ids":["1550901640146865256","1286438987267469377"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 19:37:27 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"1c2a1804-99be-4b04-98ec-502396e71534","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Download From Cloud
Download a specific threat file from SentinelOne Cloud using the unique threat ID provided.
Endpoint
- URL: /web/api/v2.1/threats/{{threat_id}}/download-from-cloud
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.threat_id | string | Required | Threat ID. |
Input Example
{"path_parameters":{"threat_id":"1724638395443766805"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.downloadUrl | string | Response data |
data.fileName | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Sun, 21 Apr 2024 17:19:47 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"6774d02e-05e6-4a51-8c4c-168411f6fd66","Access-Control-Allow-Origin":"https://cns.na1.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Secu...
Execute Remote Script
Execute a script from the Script Library on selected SentinelOne agents and receive a parentTaskId to track execution status and results.
Endpoint
- URL: /web/api/v2.1/remote-scripts/execute
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
data.scriptId | string | Required | Script Library id from upload_remote_script (data.id) or the console. Example β 225494730938493804. |
data.outputDestination | string | Optional | Where script output is stored. Allowed values β SentinelCloud, Local, None, SingularityXDR. Use SentinelCloud to retrieve results via retrieve_script_output or fetch_remote_script_files. |
data.taskDescription | string | Optional | Label shown on the RemoteOps task. Example β Swimlane credential scan. |
data.inputParams | string | Optional | Argument string passed to the script (scan depth, paths). Example β standard. |
data.scriptRuntimeTimeoutSeconds | integer | Optional | Max runtime on the endpoint. Example β 3600. |
data.password | string | Optional | Optional password if the console encrypts collected output. |
filter | object | Optional | Agents to run on. Provide ids and/or uuids (same filter shape as other agent actions). |
filter.ids | array | Optional | SentinelOne agent IDs. Example β 1550901640146865256. |
filter.uuids | array | Optional | Agent UUIDs. Example β 2e24b3bf-5769-e031-35af-7ebaf2f3dcf3. |
filter.computerName | string | Optional | Exact computer name filter. |
Input Example
{"json_body":{"data":{"scriptId":"225494730938493804","outputDestination":"SentinelCloud","taskDescription":"Swimlane credential scan","scriptRuntimeTimeoutSeconds":3600},"filter":{"ids":["1550901640146865256"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.parentTaskId | string | Response data |
data.affected | number | Response data |
errors | array | Error message if any |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":{"parentTaskId":"225494730938493915","affected":1}}}
Fetch Files
Fetch files up to 10 MB from specified SentinelOne endpoints using agent ID and file data for detailed threat analysis.
Endpoint
- URL: /web/api/v2.1/agents/{{agent_id}}/actions/fetch-files
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.agent_id | string | Required | Agent ID. |
data | object | Optional | Response data |
data.password | string | Required | File encryption password. |
data.files | string | Optional | List of files to fetch (absolute paths, up to 10 files). |
Input Example
{"json_body":{"data":{"password":"MySecretPass123!","files":["/Users/saikumar.kondapalli/Desktop/Screenshot 2024-04-17.png"]}},"path_parameters":{"agent_id":"1286438987267469377"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.success | boolean | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Sun, 21 Apr 2024 10:42:26 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"00326c00-9064-4459-b5cd-56ea0fd24ae2","Access-Control-Allow-Origin":"https://cns.na1.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Secu...
Fetch Remote Script Files
Download the output files from a completed SentinelOne RemoteOps task as a ZIP archive using the child task ID.
Endpoint
- URL: /web/api/v2.1/remote-scripts/fetch-files
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
data.taskIds | array | Optional | Child task ids from get_remote_script_status data[].id. Example β 225494730938493999. |
data.taskId | string | Optional | Single child task id when the console expects a scalar instead of taskIds. |
data.parentTaskId | string | Optional | Parent task id from execute_remote_script when fetching by parent instead of child task ids. |
Input Example
{"json_body":{"data":{"taskIds":["225494730938493999"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
file | object | Present when SentinelOne returns the zip as the response body instead of a JSON downloadUrl. |
data | object | Response data |
data.downloadUrl | string | Response data |
data.fileName | string | Response data |
errors | array | Error message if any |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":{"downloadUrl":"https://mgmt-file-upload.sentinelone.net/proxy/output.zip","fileName":"remote-script-output.zip"}}}
Fetch Threat File
Retrieve a file linked to a specific threat in SentinelOne using provided data and filter parameters. Requires 'Fetch Threat File' permissions.
Endpoint
- URL: /web/api/v2.1/threats/fetch-file
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
data.password | string | Required | File encryption password. |
filter | object | Optional | Use any of the filtering options to control the list of affected threats. You can use any combination of filters to narrow down the list (For example "apply to only active threats from Linux endpoints"). You can also leave this field empty to apply to all available threats. Note - Filter must match exactly one threat. Bulk operations are not supported. |
filter.accountIds | string | Optional | List of Account IDs to filter by. |
filter.agentIds | string | Optional | List of Agent IDs. |
filter.agentIsActive | boolean | Optional | Include Agents currently connected to the Management Console. |
filter.agentMachineTypes | string | Optional | Include Agent machine types. |
filter.agentMachineTypesNin | string | Optional | Excluded Agent machine types. |
filter.agentTagsData | string | Optional | Filter threats by assigned tags to the related agent. Given in form of a JSON where each key represents a tag key, and each value represents a list of string values to filter by. To filter by unassigned tag values, use __nin suffix in the tag key. |
filter.agentVersions | string | Optional | Include Agent versions. |
filter.agentVersionsNin | string | Optional | Excluded Agent versions. |
filter.analystVerdicts | string | Optional | Filter threats by a specific analyst verdict. |
filter.analystVerdictsNin | string | Optional | Exclude threats with specific analyst verdicts. |
filter.awsRole__contains | string | Optional | Free-text filter by aws role(supports multiple values). |
filter.awsSecurityGroups__contains | string | Optional | Free-text filter by aws securityGroups(supports multiple values). |
filter.awsSubnetIds__contains | string | Optional | Free-text filter by aws subnet ids (supports multiple values). |
filter.azureResourceGroup__contains | string | Optional | Free-text filter by azure resource group(supports multiple values). |
filter.classifications | string | Optional | List of threat classifications to search. |
filter.classificationsNin | string | Optional | List of threat classifications not to search. |
filter.classificationSources | string | Optional | Classification sources list. |
filter.classificationSourcesNin | string | Optional | Classification sources list to exclude. |
filter.cloudAccount__contains | string | Optional | Free-text filter by cloud account (supports multiple values). |
filter.cloudImage__contains | string | Optional | Free-text filter by cloud image (supports multiple values). |
filter.cloudInstanceId__contains | string | Optional | Free-text filter by cloud instance id(supports multiple values). |
filter.cloudInstanceSize__contains | string | Optional | Free-text filter by cloud instance size(supports multiple values). |
Input Example
{"data":{"password":"string"},"filter":{"accountIds":"string","agentIds":"string","agentIsActive":true,"agentMachineTypes":"string","agentMachineTypesNin":"string","agentTagsData":"string","agentVersions":"string","agentVersionsNin":"string","analystVerdicts":"string","analystVerdictsNin":"string","awsRole__contains":"string","awsSecurityGroups__contains":"string","awsSubnetIds__contains":"string","azureResourceGroup__contains":"string","classifications":"string","classificationsNin":"string","classificationSources":"string","classificationSourcesNin":"string","cloudAccount__contains":"string","cloudImage__contains":"string","cloudInstanceId__contains":"string","cloudInstanceSize__contains":"string","cloudLocation__contains":"string","cloudNetwork__contains":"string","cloudProvider":"string","cloudProviderNin":"string","collectionIds":"string","commandLineArguments__contains":"string","computerName__contains":"Example Name","confidenceLevels":"string","confidenceLevelsNin":"string","containerImageName__contains":"Example Name","containerLabels__contains":"string","containerName__contains":"Example Name","contentHash__contains":"string","contentHashes":"string","countsFor":"string","createdAt__gt":"string","createdAt__gte":"string","createdAt__lt":"string","createdAt__lte":"string","detectionAgentDomain__contains":"string","detectionAgentVersion__contains":"string","detectionEngines":"string","detectionEnginesNin":"string","displayName":"Example Name","engines":"string","enginesNin":"string","externalTicketExists":true,"externalTicketId__contains":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"data":{"affected":1}}
Get Accounts
Retrieve account details from SentinelOne that match the specified filter criteria and return relevant account information.
Endpoint
- URL: web/api/v2.1/accounts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountIds | string | Optional | List of Account IDs to filter by. |
parameters.accountType | string | Optional | Account type. |
parameters.activeLicenses | string | Optional | Active licenses. |
parameters.billingMode | string | Optional | Billing mode. |
parameters.countOnly | boolean | Optional | f true, only total number of items will be returned, without any of the actual objects. |
parameters.createdAt | string | Optional | Timestamp of Account creation. |
parameters.cursor | string | Optional | Cursor position returned by the last request. Use to iterate over more than 1000 items. |
parameters.expiration | string | Optional | Expiration. |
parameters.features | string | Optional | Filter the list of Accounts for those that support this feature. |
parameters.ids | string | Optional | A list of Account IDs. |
parameters.isDefault | boolean | Optional | Is default. |
parameters.limit | string | Optional | Limit number of returned items (1-1000). |
parameters.name | string | Optional | Name of the Account. |
parameters.query | string | Optional | Full text search for fields - name. (Note - on single-Account Consoles, the Account name will not be matched). |
parameters.skip | string | Optional | Skip first number of items (0-1000). To iterate over more than 1000 items, use "cursor". |
parameters.skipCount | boolean | Optional | If true, total number of items will not be calculated, which speeds up execution time. |
parameters.sortBy | string | Optional | The column to sort the results by. |
parameters.sortOrder | string | Optional | Sort direction. |
parameters.states | string | Optional | Filter by state, such as active or expired. |
parameters.totalLicenses | string | Optional | Total Licenses. |
parameters.updatedAt | string | Optional | Timestamp of last update. |
parameters.usageType | string | Optional | Filter by usage type, such as customer or trial. |
Input Example
{"parameters":{"accountIds":"1286405255240245908,1286405255240245978","accountType":"Trail","activeLicenses":"test licenses","billingMode":"subscription","countOnly":true,"createdAt":"2018-02-27T04:49:26.257525Z","cursor":"YWdlbnRfaWQ6NTgwMjkzODE=","expiration":"2018-02-27T04:49:26.257525Z","features":"firewall-control","ids":"225494730938493804,225494730938493915","isDefault":true,"limit":"10","name":"My Account","query":"test query","skip":"150","skipCount":true,"sortBy":"id","sortOrder":"asc","states":"active","totalLicenses":"total licenses","updatedAt":"2018-02-27T04:49:26.257525Z","usageType":"customer"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Get Activities
Obtain filtered activity data from SentinelOne for targeted analysis and concise reporting.
Endpoint
- URL: /web/api/v2.1/activities
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountIds | string | Optional | List of Account IDs to filter by. |
parameters.activityTypes | string | Optional | Return only these activity codes (comma-separated list). Select a code from the dropdown, or see the id field from the Get activity types command. |
parameters.activityUuids | string | Optional | Return activities by specific activity UUIDs. |
parameters.agentIds | string | Optional | Return activities related to specified agents. |
parameters.alertIds | string | Optional | Return activities related to specified alerts. |
parameters.countOnly | boolean | Optional | If true, only total number of items will be returned, without any of the actual objects. |
parameters.createdAt__between | string | Optional | Get activities created in this range (inclusive) of a start timestamp and an end timestamp. |
parameters.createdAt__gt | string | Optional | Get activities created after this timestamp. |
parameters.createdAt__gte | string | Optional | Get activities created after or at this timestamp. |
parameters.createdAt__lt | string | Optional | Get activities created before this timestamp. |
parameters.createdAt__lte | string | Optional | Get activities created before or at this timestamp. |
parameters.cursor | string | Optional | Cursor position returned by the last request. Use to iterate over more than 1000 items. |
parameters.groupIds | string | Optional | List of Group IDs to filter by. |
parameters.ids | string | Optional | Filter activities by specific activity IDs. |
parameters.includeHidden | boolean | Optional | Include internal activities hidden from display. |
parameters.limit | number | Optional | Limit number of returned items (1-1000). |
parameters.ruleIds | string | Optional | Return activities related to specified rules. |
parameters.siteIds | string | Optional | List of Site IDs to filter by. |
parameters.skip | number | Optional | Skip first number of items (0-1000). To iterate over more than 1000 items, use "cursor". |
parameters.skipCount | boolean | Optional | If true, total number of items will not be calculated, which speeds up execution time. |
parameters.sortBy | string | Optional | The column to sort the results by. |
parameters.sortOrder | string | Optional | Sort direction. |
parameters.threatIds | string | Optional | Return activities related to specified threats. |
parameters.userEmails | string | Optional | Email of the user who invoked the activity (If applicable). |
parameters.userIds | string | Optional | The user who invoked the activity (If applicable). |
Input Example
{"parameters":{"accountIds":"string","activityTypes":"string","activityUuids":"string","agentIds":"string","alertIds":"string","countOnly":true,"createdAt__between":"string","createdAt__gt":"string","createdAt__gte":"string","createdAt__lt":"string","createdAt__lte":"string","cursor":"string","groupIds":"string","ids":"string","includeHidden":true,"limit":123,"ruleIds":"string","siteIds":"string","skip":123,"skipCount":true,"sortBy":"string","sortOrder":"string","threatIds":"string","userEmails":"string","userIds":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.accountId | string | Response data |
data.accountName | string | Response data |
data.activityType | number | Response data |
data.activityUuid | string | Response data |
data.agentId | object | Response data |
data.agentUpdatedVersion | object | Response data |
data.comments | object | Response data |
data.createdAt | string | Response data |
data.data | object | Response data |
data.data.accountName | string | Response data |
data.data.fileName | string | Response data |
data.data.fullScopeDetails | string | Response data |
data.data.fullScopeDetailsPath | string | Response data |
data.data.groupName | object | Response data |
data.data.ipAddress | string | Response data |
data.data.majorVersion | string | Response data |
data.data.minorVersion | string | Response data |
data.data.osArch | string | Response data |
data.data.packageId | number | Response data |
data.data.platformType | string | Response data |
data.data.realUser | object | Response data |
data.data.scopeLevel | string | Response data |
Output Example
{"data":[{"accountId":"string","accountName":"Example Name","activityType":123,"activityUuid":"string","agentId":{},"agentUpdatedVersion":{},"comments":{},"createdAt":"string","data":{},"description":{},"groupId":{},"groupName":{},"hash":{},"id":"12345678-1234-1234-1234-123456789abc","osFamily":{}}],"pagination":{"nextCursor":"string","totalItems":123}}
Get Agent Applications
Retrieve a list of installed applications for a specified SentinelOne agent by providing the unique agent ID.
Endpoint
- URL: web/api/v2.1/agents/applications
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ids | array | Required | Parameters for the Get Agent Applications action |
Input Example
{"parameters":{"ids":["1286438987267469377"]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.installedDate | string | Response data |
data.name | string | Response data |
data.publisher | string | Response data |
data.size | number | Response data |
data.version | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 15:25:40 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"7bef9a86-f973-47ea-83b6-41f61dd8510b","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Query for Agent Packages
Retrieve available agent update packages from the SentinelOne management console, including package metadata and IDs for use in upgrade workflows.
Endpoint
- URL: web/api/v2.1/update/agent/packages
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountIds | string | Optional | List of Account IDs to filter by. |
parameters.countOnly | boolean | Optional | If true, only total number of items will be returned, without any of the actual objects. |
parameters.cursor | string | Optional | Cursor position returned by the last request. Use to iterate over more than 1000 items. |
parameters.fileExtension | string | Optional | File extension filter. |
parameters.ids | string | Optional | Package ID list. |
parameters.limit | string | Optional | Limit number of returned items (1-1000). |
parameters.minorVersion | string | Optional | Package minor version. |
parameters.osArches | string | Optional | Package OS architecture (32/64 bit), applicable to Windows packages only. |
parameters.osTypes | string | Optional | OS type filter. |
parameters.packageType | string | Optional | Package type. |
parameters.packageTypes | string | Optional | Package type filter (comma-separated). |
parameters.platformTypes | string | Optional | Platform type filter. |
parameters.query | string | Optional | Free-text search term matching applicable package attributes. |
parameters.rangerVersion | string | Optional | Ranger version. |
parameters.sha1 | string | Optional | Package hash. |
parameters.siteIds | string | Optional | List of Site IDs to filter by. |
parameters.skip | string | Optional | Skip first number of items (0-1000). To iterate over more than 1000 items, use cursor. |
parameters.skipCount | boolean | Optional | If true, total number of items will not be calculated, which speeds up execution time. |
parameters.sortBy | string | Optional | Column to sort results by. |
parameters.sortOrder | string | Optional | Sort direction. |
parameters.status | string | Optional | Status filter. |
parameters.version | string | Optional | Agent version. |
Input Example
{"parameters":{"accountIds":"string","countOnly":true,"cursor":"string","fileExtension":"string","ids":"string","limit":"string","minorVersion":"string","osArches":"string","osTypes":"string","packageType":"string","packageTypes":"string","platformTypes":"string","query":"string","rangerVersion":"string","sha1":"string","siteIds":"string","skip":"string","skipCount":true,"sortBy":"string","sortOrder":"string","status":"active","version":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code returned by the API. |
reason | string | HTTP reason phrase (e.g. OK). |
data | array | Response data payload. |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":[]}}
Get Agents
Obtain detailed information on SentinelOne agents, with filtering options to target specific Agent IDs and streamline agent management.
Endpoint
- URL: web/api/v2.1/agents
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.computerName | string | Optional | Parameters for the Get Agents action |
parameters.infected | boolean | Optional | Parameters for the Get Agents action |
parameters.isActive | boolean | Optional | Parameters for the Get Agents action |
parameters.activeThreats | array | Optional | Parameters for the Get Agents action |
parameters.domains | array | Optional | Parameters for the Get Agents action |
parameters.networkStatuses | array | Optional | Parameters for the Get Agents action |
parameters.externalIp__contains | string | Optional | Parameters for the Get Agents action |
parameters.ids | array | Optional | Parameters for the Get Agents action |
parameters.accountIds | array | Optional | Parameters for the Get Agents action |
parameters.uuids | array | Optional | Parameters for the Get Agents action |
Input Example
{"parameters":{"computerName":"ubuntu","infected":false,"isActive":false,"activeThreats":[0,1,2],"domains":["unknown","OLYMPIA"],"networkStatuses":["connected"],"externalIp__contains":"96.79","ids":["1550901640146865256"],"accountIds":["1286405255240245908"],"uuids":["2e24b3bf-5769-e031-35af-7ebaf2f3dcf3"]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.accountId | string | Response data |
data.accountName | string | Response data |
data.activeDirectory | object | Response data |
data.activeDirectory.computerDistinguishedName | object | Response data |
data.activeDirectory.computerMemberOf | array | Response data |
data.activeDirectory.computerMemberOf.file_name | string | Response data |
data.activeDirectory.computerMemberOf.file | string | Response data |
data.activeDirectory.lastUserDistinguishedName | object | Response data |
data.activeDirectory.lastUserMemberOf | array | Response data |
data.activeDirectory.lastUserMemberOf.file_name | string | Response data |
data.activeDirectory.lastUserMemberOf.file | string | Response data |
data.activeThreats | number | Response data |
data.agentVersion | string | Response data |
data.allowRemoteShell | boolean | Response data |
data.appsVulnerabilityStatus | string | Response data |
data.cloudProviders | object | Response data |
data.cloudProviders.ESXI | object | Response data |
data.computerName | string | Response data |
data.consoleMigrationStatus | string | Response data |
data.coreCount | number | Response data |
data.cpuCount | number | Response data |
data.cpuId | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 17:35:13 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"bd078c0d-1020-461b-885a-0028c992ac70","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Get Alerts
Retrieve a list of SentinelOne alerts to identify potential security threats within a specified scope.
Endpoint
- URL: /web/api/v2.1/cloud-detection/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountIds | string | Optional | List of Account IDs to filter by. |
parameters.analystVerdict | string | Optional | Filter threats by a analyst verdict. |
parameters.containerImageName__contains | string | Optional | Free-text filter by the endpoint container image name (supports multiple values). |
parameters.containerLabels__contains | string | Optional | Free-text filter by the endpoint container labels (supports multiple values). |
parameters.containerName__contains | string | Optional | Free-text filter by the endpoint container name (supports multiple values). |
parameters.countOnly | boolean | Optional | If true, only total number of items will be returned, without any of the actual objects. |
parameters.createdAt__gt | string | Optional | Created at greater than. |
parameters.createdAt__gte | string | Optional | Created at greater or equal than. |
parameters.createdAt__lt | string | Optional | Created at lesser than. |
parameters.createdAt__lte | string | Optional | Created at lesser or equal than. |
parameters.cursor | string | Optional | Cursor position returned by the last request. Use to iterate over more than 1000 items. |
parameters.disablePagination | boolean | Optional | If true, all rules for requested scope will be returned. |
parameters.groupIds | string | Optional | List of Group IDs to filter by. |
parameters.ids | array | Optional | A list of Alert IDs. |
parameters.incidentStatus | string | Optional | Filter threats by a incident status. |
parameters.k8sCluster__contains | string | Optional | Free-text filter by the endpoint Kubernetes cluster name (supports multiple values). |
parameters.k8sControllerLabels__contains | string | Optional | Free-text filter by the endpoint Kubernetes controller labels (supports multiple values). |
parameters.k8sControllerName__contains | string | Optional | Free-text filter by the endpoint Kubernetes controller name (supports multiple values). |
parameters.k8sNamespaceLabels__contains | string | Optional | Free-text filter by the endpoint Kubernetes namespace labels (supports multiple values). |
parameters.k8sNamespaceName__contains | string | Optional | Free-text filter by the endpoint Kubernetes namespace name (supports multiple values). |
parameters.k8sNode__contains | string | Optional | Free-text filter by the endpoint Kubernetes node name (supports multiple values). |
parameters.k8sPod__contains | string | Optional | Free-text filter by the endpoint Kubernetes pod name (supports multiple values). |
parameters.k8sPodLabels__contains | string | Optional | Free-text filter by the endpoint Kubernetes pod labels (supports multiple values). |
parameters.limit | number | Optional | Limit number of returned items (1-1000). |
parameters.machineType | string | Optional | agent machine type. |
Input Example
{"parameters":{"accountIds":"string","analystVerdict":"string","containerImageName__contains":"Example Name","containerLabels__contains":"string","containerName__contains":"Example Name","countOnly":true,"createdAt__gt":"string","createdAt__gte":"string","createdAt__lt":"string","createdAt__lte":"string","cursor":"string","disablePagination":true,"groupIds":"string","ids":["string"],"incidentStatus":"active","k8sCluster__contains":"string","k8sControllerLabels__contains":"string","k8sControllerName__contains":"Example Name","k8sNamespaceLabels__contains":"Example Name","k8sNamespaceName__contains":"Example Name","k8sNode__contains":"string","k8sPod__contains":"string","k8sPodLabels__contains":"string","limit":123,"machineType":"string","origAgentName__contains":"Example Name","origAgentOsRevision__contains":"string","origAgentUuid__contains":"string","origAgentVersion__contains":"string","osType":"string","query":"string","reportedAt__gt":"string","reportedAt__gte":"string","reportedAt__lt":"string","reportedAt__lte":"string","ruleName__contains":"Example Name","scopes":"string","severity":"string","siteIds":"string","skip":123,"skipCount":true,"sortBy":"string","sortOrder":"string","sourceProcessCommandline__contains":"string","sourceProcessFileHashMd5__contains":"string","sourceProcessFileHashSha1__contains":"string","sourceProcessFileHashSha256__contains":"string","sourceProcessFilePath__contains":"string","sourceProcessName__contains":"Example Name","sourceProcessStoryline__contains":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.agentDetectionInfo | object | Response data |
data.agentDetectionInfo.accountId | string | Response data |
data.agentDetectionInfo.machineType | object | Response data |
data.agentDetectionInfo.name | object | Response data |
data.agentDetectionInfo.osFamily | object | Response data |
data.agentDetectionInfo.osName | string | Response data |
data.agentDetectionInfo.osRevision | string | Response data |
data.agentDetectionInfo.siteId | object | Response data |
data.agentDetectionInfo.uuid | object | Response data |
data.agentDetectionInfo.version | object | Response data |
data.alertInfo | object | Response data |
data.alertInfo.alertId | string | Response data |
data.alertInfo.analystVerdict | string | Response data |
data.alertInfo.createdAt | string | Response data |
data.alertInfo.dnsRequest | object | Response data |
data.alertInfo.dnsResponse | object | Response data |
data.alertInfo.dstIp | object | Response data |
data.alertInfo.dstPort | object | Response data |
data.alertInfo.dvEventId | object | Response data |
data.alertInfo.eventType | object | Response data |
data.alertInfo.hitType | string | Response data |
data.alertInfo.incidentStatus | string | Response data |
Output Example
{"data":[{"agentDetectionInfo":{},"alertInfo":{},"containerInfo":{},"kubernetesInfo":{},"ruleInfo":{},"sourceParentProcessInfo":{},"sourceProcessInfo":{},"targetProcessInfo":{}}],"pagination":{"nextCursor":{},"totalItems":123}}
Get Blocklist Items
Retrieve all items from the SentinelOne blocklist, with optional filters for hash values or threat IDs.
Endpoint
- URL: /web/api/v2.1/restrictions
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountids | string | Optional | List of Account IDs to filter by. |
parameters.countonly | boolean | Optional | If true, only total number of items will be returned, without any of the actual objects. |
parameters.createdat__between | string | Optional | Date range for creation time (format - <from_timestamp> - <to_timestamp>, inclusive) |
parameters.createdat__gt | string | Optional | Created after this timestamp. |
parameters.createdat__gte | string | Optional | Created after or at this timestamp. |
parameters.createdat__lt | string | Optional | Created before this timestamp. |
parameters.createdat__lte | string | Optional | Created before or at this timestamp. |
parameters.cursor | string | Optional | Cursor position returned by the last request. Use to iterate over more than 1000 items. |
parameters.description__contains | string | Optional | Free-text filter by description. |
parameters.groupids | string | Optional | List of Group IDs to filter by. |
parameters.ids | string | Optional | List of IDs to filter by. |
parameters.imported | boolean | Optional | Indication whether the hash was imported by a bulk operation or not. |
parameters.includechildren | boolean | Optional | Return filters from children scope levels. |
parameters.includeparents | boolean | Optional | Return filters from parent scope levels. |
parameters.limit | string | Optional | Limit number of returned items (1-1000). |
parameters.modes | string | Optional | List of modes to filter by (Path exclusions only). |
parameters.ostypes | string | Optional | List of OS types to filter by. |
parameters.query | string | Optional | A free-text search term, will match applicable attributes |
parameters.recommendations | string | Optional | List of recommendations to filter by. |
parameters.siteids | string | Optional | List of Site IDs to filter by. |
parameters.skip | string | Optional | Skip first number of items (0-1000). To iterate over more than 1000 items, use "cursor". |
parameters.skipcount | boolean | Optional | If true, total number of items will not be calculated, which speeds up execution time. |
parameters.sortby | string | Optional | The column to sort the results by. |
parameters.sortorder | string | Optional | Sort direction. |
parameters.source | string | Optional | List sources to filter by. |
Input Example
{"parameters":{"skip":10,"sortorder":"asc","includeparents":false,"limit":10,"includechildren":false,"skipcount":true,"countonly":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.createdAt | string | Response data |
data.description | string | Response data |
data.id | string | Response data |
data.imported | boolean | Response data |
data.includeChildren | boolean | Response data |
data.includeParents | boolean | Response data |
data.notRecommended | string | Response data |
data.osType | string | Response data |
data.scope | object | Response data |
data.scope.accountIds | array | Response data |
data.scope.groupIds | array | Response data |
data.scope.siteIds | array | Response data |
data.scope.tenant | boolean | Response data |
data.scopeName | string | Response data |
data.scopePath | string | Response data |
data.source | string | Response data |
data.type | string | Response data |
data.updatedAt | string | Response data |
data.userId | string | Response data |
data.userName | string | Response data |
data.value | string | Response data |
errors | array | Error message if any |
Output Example
{"data":[{"createdAt":"string","description":"string","id":"12345678-1234-1234-1234-123456789abc","imported":true,"includeChildren":true,"includeParents":true,"notRecommended":"string","osType":"string","scope":{},"scopeName":"Example Name","scopePath":"string","source":"string","type":"string","updatedAt":"string","userId":"string"}],"errors":[],"pagination":{"nextCursor":"string","totalItems":123}}
Get Groups
Retrieve detailed information about groups in SentinelOne, with optional filters for targeted management and analysis.
Endpoint
- URL: /web/api/v2.1/groups
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountids | string | Optional | List of Account IDs to filter by. |
parameters.countonly | boolean | Optional | If true, only total number of items will be returned, without any of the actual objects. |
parameters.cursor | string | Optional | Cursor position returned by the last request. Use to iterate over more than 1000 items. |
parameters.description | string | Optional | The description for the Group. |
parameters.groupids | string | Optional | List of Group IDs to filter by. |
parameters.id | string | Optional | ID. |
parameters.isdefault | boolean | Optional | If true, default group is set. |
parameters.limit | string | Optional | Limit number of returned items (1-300). |
parameters.name | string | Optional | Name. |
parameters.query | string | Optional | Free text search on fields name, description. |
parameters.rank | string | Optional | The rank sets the priority of a dynamic group over others. |
parameters.registrationtoken | string | Optional | Registration token. |
parameters.siteids | string | Optional | List of Site IDs to filter by. |
parameters.skip | string | Optional | Skip first number of items (0-1000). To iterate over more than 1000 items, use "cursor". |
parameters.skipcount | boolean | Optional | If true, total number of items will not be calculated, which speeds up execution time. |
parameters.sortby | string | Optional | The column to sort the results by. |
parameters.sortorder | string | Optional | Sort direction. |
parameters.type | string | Optional | Group type. |
parameters.types | string | Optional | A list of Group types. |
parameters.updatedat__gt | string | Optional | Updated at greater than. |
parameters.updatedat__gte | string | Optional | Updated at greater or equal than. |
parameters.updatedat__lt | string | Optional | Updated at lesser than. |
parameters.updatedat__lte | string | Optional | Updated at lesser or equal than. |
Input Example
{"parameters":{"skip":100,"limit":10,"skipcount":true,"countonly":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.createdAt | string | Response data |
data.creator | string | Response data |
data.creatorId | string | Response data |
data.filterId | object | Response data |
data.filterName | object | Response data |
data.id | string | Response data |
data.inherits | boolean | Response data |
data.isDefault | boolean | Response data |
data.name | string | Response data |
data.rank | object | Response data |
data.registrationToken | string | Response data |
data.siteId | string | Response data |
data.totalAgents | number | Response data |
data.type | string | Response data |
data.updatedAt | string | Response data |
pagination | object | Output field: pagination |
pagination.nextCursor | object | Output field: pagination.nextCursor |
pagination.totalItems | number | Output field: pagination.totalItems |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Tue, 11 Jun 2024 11:26:21 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"112653fa-4329-4f71-a7a6-5dc163b97fd2","Access-Control-Allow-Origin":"https://cns.na1.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Secu...
Get Hash
Retrieve classification details for a specified hash from SentinelOne by providing the hash value as a path parameter.
Endpoint
- URL: /web/api/v2.1/hashes/{{hash}}/reputation
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.hash | string | Required | Parameters for the Get Hash action |
Input Example
{"path_parameters":{"hash":"3395856ce81f2b7382dee72602f798b642f14140"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.rank | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Nov 2022 20:17:39 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"64e8155a-3841-4681-a3c7-27a64ebebf5a","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Get Long Running Query
Retrieve the current state, metrics, and results page of a long-running query in SentinelOne Singularity Data Lake using a specified query ID.
Endpoint
- URL: /sdl/v2/api/queries/{{query_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.query_id | string | Required | Identifier returned by Create Long Running Query. |
parameters.limit | integer | Optional | Maximum number of result rows to return. |
parameters.cursor | string | Optional | Opaque cursor returned by a previous result page. |
headers | object | Required | HTTP headers for the request |
headers.X-Dataset-Query-Forward-Tag | string | Required | Value returned by the create response; echo it on every poll. |
Input Example
{"path_parameters":{"query_id":"string"},"parameters":{"limit":123,"cursor":"string"},"headers":{"X-Dataset-Query-Forward-Tag":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Get Remote Script Status
Retrieve the status of a RemoteOps task in SentinelOne using parentTaskId or parentTaskId__in. Requires Task Management.view permission.
Endpoint
- URL: /web/api/v2.1/remote-scripts/status
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.parentTaskId | string | Optional | Parent task id returned by execute_remote_script. Example β 225494730938493915. |
parameters.parentTaskId__in | string | Optional | Comma-separated parent task ids when polling more than one execute. |
parameters.ids | string | Optional | Child task ids to filter (comma-separated). |
parameters.status | string | Optional | Filter by task status. Example β completed. |
parameters.computerName__contains | string | Optional | Free-text agent computer name filter. |
parameters.accountIds | string | Optional | Comma-separated account ids. |
parameters.siteIds | string | Optional | Comma-separated site ids. |
parameters.groupIds | string | Optional | Comma-separated group ids. |
parameters.detailedStatus__contains | string | Optional | Free-text detailedStatus filter. |
parameters.limit | integer | Optional | Page size. Example β 100. |
parameters.cursor | string | Optional | Pagination cursor from the previous response. |
parameters.skip | integer | Optional | Number of items to skip. |
Input Example
{"parameters":{"parentTaskId":"225494730938493915","limit":100}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.id | string | Response data |
data.parentTaskId | string | Response data |
data.status | string | Response data |
data.detailedStatus | string | Response data |
pagination | object | Output field: pagination |
pagination.nextCursor | string | Output field: pagination.nextCursor |
pagination.totalItems | number | Output field: pagination.totalItems |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":[{}],"pagination":{"nextCursor":null,"totalItems":1}}}
Get Rogues Settings
Retrieve the current configuration settings for rogue devices from SentinelOne to view how unidentified or unauthorized devices are managed.
Endpoint
- URL: /web/api/v2.1/rogues/settings
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountIds | array | Optional | Parameters for the Get Rogues Settings action |
parameters.siteIds | array | Optional | Parameters for the Get Rogues Settings action |
Input Example
{"parameters":{"accountIds":["string"],"siteIds":["string"]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.minAgentsInNetworkToScan | number | Response data |
data.accountId | string | Response data |
data.enabled | boolean | Response data |
data.useSpecificPorts | boolean | Response data |
data.restrictions | array | Response data |
data.restrictions.annotation | string | Response data |
data.restrictions.values | array | Response data |
data.restrictions.type | string | Response data |
data.specificPorts | array | Response data |
data.specificPorts.values | array | Response data |
data.specificPorts.type | string | Response data |
errors | array | Error message if any |
errors.code | number | Error message if any |
errors.detail | object | Error message if any |
errors.title | string | Error message if any |
Output Example
{"data":{"minAgentsInNetworkToScan":123,"accountId":"string","enabled":true,"useSpecificPorts":true,"restrictions":[{}],"specificPorts":[{}]},"errors":[{"code":123,"detail":{},"title":"string"}]}
Get Sites
Retrieve a list of SentinelOne sites with optional filters to help manage and organize your network topology.
Endpoint
- URL: /web/api/v2.1/sites
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountId | string | Optional | Account ID |
parameters.accountIds | array | Optional | List of Account IDs to filter by. |
parameters.accountName__contain | array | Optional | Free-text filter by account name (supports multiple values). |
parameters.activeLicenses | number | Optional | Active licenses. |
parameters.adminOnly | boolean | Optional | Show sites the user has Admin privileges to. |
parameters.availableMoveSites | boolean | Optional | Only return sites the user can move agents through. |
parameters.countOnly | boolean | Optional | If true, only total number of items will be returned, without any of the actual objects. |
parameters.createdAt | string | Optional | Timestamp of site creation. |
parameters.cursor | string | Optional | Cursor position returned by the last request. Use to iterate over more than 1000 items. |
parameters.description | string | Optional | The description for the Site. |
parameters.description__contains | array | Optional | Free-text filter by site description (supports multiple values). |
parameters.expiration | string | Optional | Expiration. |
parameters.externalId | string | Optional | Id in a CRM external system. |
parameters.features | array | Optional | If sent return only sites that support this features. |
parameters.healthStatus | boolean | Optional | Health status. |
parameters.isDefault | boolean | Optional | Is default. |
parameters.limit | number | Optional | Limit number of returned items (1-1000) |
parameters.module | string | Optional | Module. |
parameters.name | string | Optional | Name. |
parameters.name__contains | array | Optional | Free-text filter by site name (supports multiple values). |
parameters.query | string | Optional | Full text search for fields - name, account_name, description. (Note - on single-account consoles account name will not be matched). |
parameters.registrationToken | string | Optional | Registration token. |
parameters.siteIds | array | Optional | List of Site IDs to filter by. |
parameters.siteType | string | Optional | Site type. |
parameters.skip | number | Optional | Skip first number of items (0-1000). To iterate over more than 1000 items, use "cursor". |
Input Example
{"parameters":{"accountId":"string","accountIds":["string"],"accountName__contain":["string"],"activeLicenses":123,"adminOnly":true,"availableMoveSites":true,"countOnly":true,"createdAt":"string","cursor":"string","description":"string","description__contains":["string"],"expiration":"string","externalId":"string","features":["string"],"healthStatus":true,"isDefault":true,"limit":123,"module":"string","name":"Example Name","name__contains":["string"],"query":"string","registrationToken":"string","siteIds":["string"],"siteType":"string","skip":123,"skipCount":true,"sku":"string","sortBy":"string","sortOrder":"string","state":"string","states":["string"],"totalLicenses":123,"updatedAt":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.allSites | object | Response data |
data.allSites.activeLicenses | number | Response data |
data.allSites.totalLicenses | number | Response data |
data.sites | array | Response data |
data.sites.accountId | string | Response data |
data.sites.accountName | string | Response data |
data.sites.activeLicenses | number | Response data |
data.sites.createdAt | string | Response data |
data.sites.creator | string | Response data |
data.sites.creatorId | string | Response data |
data.sites.description | object | Response data |
data.sites.expiration | object | Response data |
data.sites.externalId | object | Response data |
data.sites.healthStatus | boolean | Response data |
data.sites.id | string | Response data |
data.sites.isDefault | boolean | Response data |
data.sites.licenses | object | Response data |
data.sites.licenses.bundles | array | Response data |
data.sites.licenses.bundles.displayName | string | Response data |
data.sites.licenses.bundles.majorVersion | number | Response data |
data.sites.licenses.bundles.minorVersion | number | Response data |
data.sites.licenses.bundles.name | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 28 Aug 2023 10:07:53 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"fb4ea2f2-3f64-4aa0-817d-7f77429fd646","Access-Control-Allow-Origin":"https://usea1-identity.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Conte...
Get Threat Analysis
Retrieve detailed information about a detected threat in SentinelOne using the provided threat ID.
Endpoint
- URL: web/api/v2.1/private/threats/{{threat_id}}/analysis
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.threat_id | string | Required | Parameters for the Get Threat Analysis action |
Input Example
{"path_parameters":{"threat_id":"1311010474425970168"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.agentDetectionInfo | object | Response data |
data.agentDetectionInfo.accountId | string | Response data |
data.agentDetectionInfo.accountName | string | Response data |
data.agentDetectionInfo.agentDetectionState | object | Response data |
data.agentDetectionInfo.agentDomain | string | Response data |
data.agentDetectionInfo.agentIpV4 | string | Response data |
data.agentDetectionInfo.agentIpV6 | string | Response data |
data.agentDetectionInfo.agentLastLoggedInUpn | object | Response data |
data.agentDetectionInfo.agentLastLoggedInUserMail | object | Response data |
data.agentDetectionInfo.agentLastLoggedInUserName | string | Response data |
data.agentDetectionInfo.agentMitigationMode | string | Response data |
data.agentDetectionInfo.agentOsName | string | Response data |
data.agentDetectionInfo.agentOsRevision | string | Response data |
data.agentDetectionInfo.agentRegisteredAt | string | Response data |
data.agentDetectionInfo.agentUuid | string | Response data |
data.agentDetectionInfo.agentVersion | string | Response data |
data.agentDetectionInfo.cloudProviders | object | Response data |
data.agentDetectionInfo.externalIp | string | Response data |
data.agentDetectionInfo.groupId | string | Response data |
data.agentDetectionInfo.groupName | string | Response data |
data.agentDetectionInfo.siteId | string | Response data |
data.agentDetectionInfo.siteName | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Nov 2022 21:44:11 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"fbaffde6-2d29-4834-946d-d3c77ee169f9","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Get Threat Appearances
Retrieve infected endpoints and appearance frequency for a specific threat in SentinelOne using the provided threat ID.
Endpoint
- URL: /web/api/v2.1/private/threats/{{threat_id}}/appearances
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.threat_id | string | Required | Parameters for the Get Threat Appearances action |
Input Example
{"path_parameters":{"threat_id":"1311010475659095549"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.accounts | number | Response data |
data.agents | number | Response data |
data.firstSeen | string | Response data |
data.groups | number | Response data |
data.lastSeen | string | Response data |
data.sites | number | Response data |
data.timesSeen | number | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 19:02:30 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"73e105d3-22fa-4f21-9985-f088bc4f75f4","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Get Threat Events
Retrieve all threat events associated with a specified threat ID in SentinelOne to support comprehensive incident analysis and investigation.
Endpoint
- URL: /web/api/v2.1/threats/{{threat_id}}/explore/events
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.threat_id | string | Required | Parameters for the Get Threat Events action |
parameters.eventId | string | Optional | Parameters for the Get Threat Events action |
parameters.sortBy | string | Optional | Parameters for the Get Threat Events action |
parameters.limit | number | Optional | Parameters for the Get Threat Events action |
parameters.skip | number | Optional | Parameters for the Get Threat Events action |
parameters.sortOrder | string | Optional | Parameters for the Get Threat Events action |
parameters.skipCount | boolean | Optional | Parameters for the Get Threat Events action |
parameters.countOnly | boolean | Optional | Parameters for the Get Threat Events action |
parameters.cursor | string | Optional | Parameters for the Get Threat Events action |
parameters.eventSubTypes | array | Optional | Parameters for the Get Threat Events action |
parameters.processName__like | string | Optional | Parameters for the Get Threat Events action |
parameters.eventTypes | array | Optional | Parameters for the Get Threat Events action |
Input Example
{"path_parameters":{"threat_id":"1311010475659095549"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.activeContentFileId | object | Response data |
data.activeContentHash | object | Response data |
data.activeContentPath | object | Response data |
data.agentDomain | string | Response data |
data.agentGroupId | string | Response data |
data.agentId | string | Response data |
data.agentInfected | boolean | Response data |
data.agentIp | string | Response data |
data.agentIsActive | boolean | Response data |
data.agentIsDecommissioned | boolean | Response data |
data.agentMachineType | string | Response data |
data.agentName | string | Response data |
data.agentNetworkStatus | string | Response data |
data.agentOs | string | Response data |
data.agentUuid | string | Response data |
data.agentVersion | string | Response data |
data.connectionStatus | object | Response data |
data.createdAt | string | Response data |
data.direction | object | Response data |
data.dnsRequest | object | Response data |
data.dnsResponse | object | Response data |
data.dstIp | object | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Tue, 06 Dec 2022 20:12:03 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"19f65f98-24e9-42e2-b9bc-d1c075019219","Access-Control-Allow-Origin":"https://usea1-attivo.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content...
Get Threat Notes
Retrieve all notes associated with a specific threat in SentinelOne using the provided threat_id.
Endpoint
- URL: web/api/v2.1/threats/{{threat_id}}/notes
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.threat_id | string | Required | Parameters for the Get Threat Notes action |
Input Example
{"path_parameters":{"threat_id":"1311010475659095549"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.createdAt | string | Response data |
data.creator | string | Response data |
data.creatorId | string | Response data |
data.edited | boolean | Response data |
data.id | string | Response data |
data.text | string | Response data |
data.updatedAt | string | Response data |
pagination | object | Output field: pagination |
pagination.nextCursor | object | Output field: pagination.nextCursor |
pagination.totalItems | number | Output field: pagination.totalItems |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Nov 2022 21:30:46 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"2cc914c5-8abc-4253-8d67-eccaa991bc06","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Get Threat Timeline
Retrieve a detailed timeline of events and activities for a specific threat in SentinelOne using the unique threat ID.
Endpoint
- URL: web/api/v2.1/threats/{{threat_id}}/timeline
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.threat_id | string | Required | Parameters for the Get Threat Timeline action |
parameters.sortOrder | string | Optional | Parameters for the Get Threat Timeline action |
parameters.skipCount | boolean | Optional | Parameters for the Get Threat Timeline action |
parameters.activityTypes | number | Optional | Parameters for the Get Threat Timeline action |
parameters.sortBy | string | Optional | Parameters for the Get Threat Timeline action |
parameters.countOnly | boolean | Optional | Parameters for the Get Threat Timeline action |
Input Example
{"parameters":{"sortOrder":"asc","skipCount":false,"activityTypes":4003,"sortBy":"hash","countOnly":false},"path_parameters":{"threat_id":"1503989642042428880"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.accountId | string | Response data |
data.activityType | number | Response data |
data.agentId | string | Response data |
data.agentUpdatedVersion | object | Response data |
data.createdAt | string | Response data |
data.data | object | Response data |
data.data.accountName | string | Response data |
data.data.computerName | string | Response data |
data.data.fileContentHash | string | Response data |
data.data.fileDisplayName | string | Response data |
data.data.filePath | string | Response data |
data.data.fullScopeDetails | string | Response data |
data.data.fullScopeDetailsPath | string | Response data |
data.data.groupName | string | Response data |
data.data.newStatus | object | Response data |
data.data.originalStatus | string | Response data |
data.data.siteName | string | Response data |
data.data.threatClassification | string | Response data |
data.data.threatClassificationSource | string | Response data |
data.data.username | string | Response data |
data.groupId | string | Response data |
data.hash | object | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Nov 2022 22:05:11 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"2a863e30-2f72-4519-9162-4e198dcb768d","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Get Threats
Retrieve a comprehensive list of all identified threats from SentinelOne, providing detailed threat information for further analysis or response.
Endpoint
- URL: web/api/v2.1/threats
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountIds | array | Optional | Parameters for the Get Threats action |
parameters.agentIds | array | Optional | Parameters for the Get Threats action |
parameters.agentIsActive | boolean | Optional | Parameters for the Get Threats action |
parameters.agentMachineTypes | array | Optional | Parameters for the Get Threats action |
parameters.agentMachineTypesNin | array | Optional | Parameters for the Get Threats action |
parameters.agentVersions | array | Optional | Parameters for the Get Threats action |
parameters.agentVersionsNin | array | Optional | Parameters for the Get Threats action |
parameters.analystVerdicts | array | Optional | Parameters for the Get Threats action |
parameters.analystVerdictsNin | array | Optional | Parameters for the Get Threats action |
parameters.awsRole__contains | array | Optional | Parameters for the Get Threats action |
parameters.awsSecurityGroups__contains | array | Optional | Parameters for the Get Threats action |
parameters.awsSubnetIds__contains | array | Optional | Parameters for the Get Threats action |
parameters.azureResourceGroup__contains | array | Optional | Parameters for the Get Threats action |
parameters.classifications | array | Optional | Parameters for the Get Threats action |
parameters.classificationsNin | array | Optional | Parameters for the Get Threats action |
parameters.classificationSources | array | Optional | Parameters for the Get Threats action |
parameters.classificationSourcesNin | array | Optional | Parameters for the Get Threats action |
parameters.cloudAccount__contains | array | Optional | Parameters for the Get Threats action |
parameters.cloudImage__contains | array | Optional | Parameters for the Get Threats action |
parameters.cloudInstanceId__contains | array | Optional | Parameters for the Get Threats action |
parameters.cloudInstanceSize__contains | array | Optional | Parameters for the Get Threats action |
parameters.cloudLocation__contains | array | Optional | Parameters for the Get Threats action |
parameters.cloudNetwork__contains | array | Optional | Parameters for the Get Threats action |
parameters.cloudProvider | array | Optional | Parameters for the Get Threats action |
parameters.cloudProviderNin | array | Optional | Parameters for the Get Threats action |
Input Example
{"parameters":{"accountIds":["225494730938493804"],"agentIds":["225494730938493804"],"agentIsActive":true,"agentMachineTypes":["unknown"],"agentMachineTypesNin":["unknown"],"agentVersions":["2.5.1.1320"],"agentVersionsNin":["2.5.1.1320"],"analystVerdicts":["true_positive,suspicious"],"analystVerdictsNin":["true_positive,suspicious"],"awsRole__contains":["aws role"],"awsSecurityGroups__contains":["aws securityGroups"],"awsSubnetIds__contains":["aws subnet ids"],"azureResourceGroup__contains":["azure resource group"],"classifications":["classification"],"classificationsNin":["classificationsNin"],"classificationSources":["Cloud"],"classificationSourcesNin":["Cloud"],"cloudAccount__contains":["cloud account"],"cloudImage__contains":["cloud image"],"cloudInstanceId__contains":["225494730938493915"],"cloudInstanceSize__contains":["cloud instance size"],"cloudLocation__contains":["cloud location"],"cloudNetwork__contains":["cloud network"],"cloudProvider":["cloud provider"],"cloudProviderNin":["cloud provider"],"collectionIds":["225494730938493804"],"commandLineArguments__contains":["/usr/sbin/,wget"],"computerName__contains":["john-office,WIN"],"confidenceLevels":["malicious"],"confidenceLevelsNin":["malicious"],"containerImageName__contains":["container image name"],"containerLabels__contains":["container labels"],"containerName__contains":["container name"],"contentHash__contains":["5f09bcff3"],"contentHashes":["d"],"countOnly":true,"countsFor":"osTypes,machineTypes","createdAt__gt":"2018-02-27T04:49:26.257525Z","createdAt__gte":"2018-02-27T04:49:26.257525Z","createdAt__lt":"2018-02-27T04:49:26.257525Z","createdAt__lte":"2018-02-27T04:49:26.257525Z","cursor":"YWdlbnRfaWQ6NTgwMjkzODE=","detectionAgentDomain__contains":["sentinel,sentinelone.com"],"detectionAgentVersion__contains":["1.1.1.1,2.2."],"detectionEngines":["reputation"],"detectionEnginesNin":["reputation"],"displayName":"Display name","engines":["reputation"],"enginesNin":["reputation"],"externalTicketExists":true,"externalTicketId__contains":["threat external ticket ID"],"externalTicketIds":["225494730938493918"],"failedActions":true,"filePath__contains":["MyUser"],"gcpServiceAccount__contains":["gcp service account"],"groupIds":["225494730938493804,225494730938493915"],"ids":["225494730938493804,225494730938493915"],"incidentStatuses":["unresolved,in_progress"],"incidentStatusesNin":["unresolved,in_progress"],"initiatedBy":["agent_policy,dv_command"],"initiatedByNin":["agent_policy,dv_command"],"initiatedByUsername__contains":["John,John Doe"],"k8sClusterName__contains":["Kubernetes cluster name"],"k8sControllerLabels__contains":["Kubernetes controller labels"],"k8sControllerName__contains":["Kubernetes controller name"],"k8sNamespaceLabels__contains":["Kubernetes namespace labels"],"k8sNamespaceName__contains":["Kubernetes namespace name"],"k8sNodeLabels__contains":["Kubernetes node labels"],"k8sNodeName__contains":["Kubernetes node name"],"k8sPodLabels__contains":["Kubernetes pod labels"],"k8sPodName__contains":["Kubernetes pod name"],"limit":10,"mitigatedPreemptively":true,"mitigationStatuses":["not_mitigated"],"mitigationStatusesNin":["not_mitigated"],"noteExists":true,"originatedProcess__contains":["process name of the threat"],"osArchs":["32 bit"],"osNames":["osNames"],"osNamesNin":["osNamesNin"],"osTypes":["linux"],"osTypesNin":["linux"],"pendingActions":true,"publisherName__contains":["GOOGLE,Apple Inc."],"query":"threat_details","realtimeAgentVersion__contains":["1.1.1.1,2.2."],"rebootRequired":true,"resolved":true,"siteIds":["225494730938493804,225494730938493915"],"skip":150,"skipCount":true,"sortBy":"iD","sortOrder":"asc","storyline__contains":["0000C2E97648,0006FC73-77B4-470F-AAC7-"],"storylines":["List of Agent context to search for"],"tenant":true,"threatDetails__contains":["malware.exe,virus.exe"],"updatedAt__gt":"2018-02-27T04:49:26.257525Z","updatedAt__gte":"2018-02-27T04:49:26.257525Z","updatedAt__lt":"2018-02-27T04:49:26.257525Z","updatedAt__lte":"2018-02-27T04:49:26.257525Z","uuid__contains":["e92-01928,b055"]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
errors | array | Error message if any |
errors.type | string | Type of the resource |
pagination | object | Output field: pagination |
pagination.totalItems | number | Output field: pagination.totalItems |
pagination.nextCursor | string | Output field: pagination.nextCursor |
data | array | Response data |
data.mitigationStatus | array | Response data |
data.mitigationStatus.lastUpdate | string | Response data |
data.mitigationStatus.agentSupportsReport | string | Response data |
data.mitigationStatus.latestReport | string | Response data |
data.mitigationStatus.groupNotFound | string | Response data |
data.mitigationStatus.mitigationEndedAt | string | Response data |
data.mitigationStatus.action | string | Response data |
data.mitigationStatus.actionsCounters | object | Response data |
data.mitigationStatus.actionsCounters.pendingReboot | string | Response data |
data.mitigationStatus.actionsCounters.failed | string | Response data |
data.mitigationStatus.actionsCounters.total | string | Response data |
data.mitigationStatus.actionsCounters.notFound | string | Response data |
data.mitigationStatus.actionsCounters.success | string | Response data |
data.mitigationStatus.status | string | Response data |
data.mitigationStatus.mitigationStartedAt | string | Response data |
data.kubernetesInfo | object | Response data |
data.kubernetesInfo.controllerKind | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 03 Jul 2023 03:42:11 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"96f7b37b-0e6b-4cb7-ba52-1c6bffa6d0fe","Access-Control-Allow-Origin":"https://usea1-identity.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Conte...
Get Unified Alerts
Retrieve SentinelOne unified alerts to identify potential security threats within a specified scope.
Endpoint
- URL: web/api/v2.1/unifiedalerts/graphql?opName=GetAlerts
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
variables | object | Optional | Parameter for Get Unified Alerts |
variables.skipName | boolean | Optional | Name of the resource |
variables.skipAsset | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipResult | boolean | Optional | Result of the operation |
variables.skipStatus | boolean | Optional | Status value |
variables.skipProcess | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipAssignee | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipSeverity | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipTicketId | boolean | Optional | Unique identifier |
variables.skipRealTime | boolean | Optional | Time value |
variables.skipAnalytics | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipNoteExists | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipExternalId | boolean | Optional | Unique identifier |
variables.skipDetectedAt | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipCreatedAt | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipUpdatedAt | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipLastSeenAt | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipDescription | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipStorylineId | boolean | Optional | Unique identifier |
variables.skipFirstSeenAt | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipDetectionTime | boolean | Optional | Time value |
variables.skipAttackSurfaces | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipAnalystVerdict | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipClassification | boolean | Optional | Parameter for Get Unified Alerts |
variables.skipDetectionSource | boolean | Optional | Parameter for Get Unified Alerts |
Input Example
{"variables":{"skipName":false,"skipAsset":false,"skipResult":false,"skipStatus":false,"skipProcess":false,"skipAssignee":false,"skipSeverity":false,"skipTicketId":false,"skipRealTime":false,"skipAnalytics":false,"skipNoteExists":false,"skipExternalId":false,"skipDetectedAt":false,"skipCreatedAt":false,"skipUpdatedAt":false,"skipLastSeenAt":false,"skipDescription":false,"skipStorylineId":false,"skipFirstSeenAt":false,"skipDetectionTime":false,"skipAttackSurfaces":false,"skipAnalystVerdict":false,"skipClassification":false,"skipDetectionSource":false,"skipConfidenceLevel":false,"viewType":"ALL","scope":{"scopeType":"ACCOUNT","scopeIds":["2068398282156670959"]},"first":100}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.alerts | object | Response data |
data.alerts.edges | array | Response data |
data.alerts.edges.node | object | Response data |
data.alerts.edges.node.id | string | Response data |
data.alerts.edges.node.name | string | Response data |
data.alerts.edges.node.result | string | Response data |
data.alerts.edges.node.status | string | Response data |
data.alerts.edges.node.severity | string | Response data |
data.alerts.edges.node.ticketId | object | Response data |
data.alerts.edges.node.noteExists | boolean | Response data |
data.alerts.edges.node.detectedAt | string | Response data |
data.alerts.edges.node.createdAt | string | Response data |
data.alerts.edges.node.updatedAt | string | Response data |
data.alerts.edges.node.lastSeenAt | string | Response data |
data.alerts.edges.node.externalId | string | Response data |
data.alerts.edges.node.description | string | Response data |
data.alerts.edges.node.firstSeenAt | string | Response data |
data.alerts.edges.node.storylineId | object | Response data |
data.alerts.edges.node.attackSurfaces | array | Response data |
data.alerts.edges.node.analystVerdict | string | Response data |
data.alerts.edges.node.classification | string | Response data |
data.alerts.edges.node.confidenceLevel | string | Response data |
Output Example
{"status_code":200,"response_headers":{"server":"envoy","date":"Wed, 04 Feb 2026 07:25:48 GMT","content-type":"application/json","cache-control":"no-cache, no-store, max-age=0, must-revalidate,no-store","expires":"0,-1","pragma":"no-cache, no-cache","strict-transport-security":"max-age=31536000 ; includeSubDomains, max-age=31536000; includeSubDomains","vary":"Origin,Access-Control-Request-Method,Access-Control-Request-Headers,Origin","x-content-type-options":"nosniff, nosniff, nosniff","x-frame-...
Get Upgrade Policies
Retrieve a paginated list of agent auto-upgrade policies from SentinelOne, using the limit parameter to control the number of results returned.
Endpoint
- URL: web/api/v2.1/upgrade-policy/policies
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.limit | string | Required | Limit number of returned items. Should be more than 1. |
parameters.osType | string | Optional | OS type filter. |
parameters.scopeLevel | string | Optional | Scope level for policies. |
parameters.scopeId | string | Optional | Scope ID matching the requested scope level. |
parameters.skip | string | Optional | Skip first number of items. |
parameters.sortBy | string | Optional | The column to sort the results by. |
parameters.sortOrder | string | Optional | Sort direction. |
Input Example
{"parameters":{"limit":"string","osType":"string","scopeLevel":"string","scopeId":"string","skip":"string","sortBy":"string","sortOrder":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code returned by the API. |
reason | string | HTTP reason phrase (e.g. OK). |
data | object | Policy data including inherited flag and policy list. |
data.isInherited | boolean | Whether policies are inherited from a parent scope. |
data.policiesInChildScope | boolean | Whether child scopes have their own policies. |
data.policies | array | List of auto-upgrade policies for the requested scope. |
data.policies.description | string | Policy or resource description. |
data.policies.id | string | Unique identifier. |
data.policies.name | string | Policy or resource name. |
data.policies.osType | string | OS type filter β linux, macos, or windows. |
data.policies.scopeLevel | string | Scope level (account, site, group, tenant). |
data.policies.scopeId | string | ID of the scope. |
data.policies.isActive | boolean | Whether the policy is active. |
data.policies.isScheduled | boolean | Whether the policy is scheduled. |
data.policies.priority | number | Policy priority order. |
data.policies.maxRetries | number | Maximum upgrade retry attempts. |
data.policies.allEndpoints | boolean | Whether the policy applies to all endpoints. |
data.policies.createdAt | string | Creation timestamp. |
data.policies.updatedAt | string | Last update timestamp. |
data.policies.activatedAt | string | Policy activation timestamp. |
data.policies.package | object | Target agent package for upgrade. |
data.policies.package.major | string | Package major version number. |
data.policies.package.minor | string | Package minor version. |
data.policies.package.build | string | Package build identifier. |
data.policies.package.fileId | string | Package file ID for use in upgrade commands. |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":{"isInherited":false,"policiesInChildScope":false,"policies":[]},"pagination":{"totalItems":1}}}
Ingest Unified Alerts
Ingest and process SentinelOne Unified Alerts with incremental polling, normalization, and enrichment using configurable variables.
Endpoint
- URL: web/api/v2.1/unifiedalerts/graphql?opName=GetAlerts
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
variables | object | Required | Configuration for alert ingestion including scope, polling, and filtering |
variables.scope | object | Required | Required. Define the scope for alert ingestion. Can be ACCOUNT, SITE, or GROUP level. Example: {"scopeType": "ACCOUNT", "scopeIds": [" ο»Ώ |
variables.scope.scopeType | string | Required | Type of scope - ACCOUNT, SITE, or GROUP |
variables.scope.scopeIds | array | Required | Array of scope IDs to include |
variables.lastUpdatedAt | string | Optional | ISO 8601 timestamp of the last processed alert's updatedAt field. Used for incremental polling to fetch only new/updated alerts since last run. Leave empty for initial ingestion or backfill. |
variables.backfillHours | number | Optional | Optional. Number of hours to look back for initial ingestion or backfill. Fetches alerts updated in the last N hours. Ignored if lastUpdatedAt or backfillTimeString is provided. |
variables.backfillTimeString | string | Optional | Optional. Human-readable time for backfill instead of backfillHours. Examples: "24 hours ago", "5 minutes ago", "1 week ago", "now". Ignored if lastUpdatedAt is provided. Takes precedence over backfillHours if both set. |
variables.pageSize | number | Optional | Number of alerts per page. Capped at 1000 by the API. |
variables.maxPages | number | Optional | Optional. Maximum number of pages to fetch in one run (safety limit). Default 1000. Pagination stops when this limit is reached or no more pages. |
variables.cursor | string | Optional | Optional. Cursor from previous page. Pagination is handled automatically; only set this if resuming a specific page. |
variables.viewType | string | Optional | Filter alerts by view type |
variables.filtersJson | string | Optional | Optional. JSON array of additional filter objects for advanced filtering. Each filter must have a "fieldId" key. See API documentation for filter options. |
variables.sorts | array | Optional | Optional. GraphQL sort spec. If omitted, defaults to updatedAt DESC for incremental polling. Example: [{"fieldPath": "updatedAt", "direction": "DESC"}]. |
variables.sorts.fieldPath | string | Optional | Parameter for Ingest Unified Alerts |
variables.sorts.direction | string | Optional | Parameter for Ingest Unified Alerts |
variables.enableEnrichment | boolean | Optional | Optional. Enable automatic enrichment of alerts with timeline, history, notes, mitigation actions, AI investigations, and raw indicators. Defaults to true. When enabled, all enrichment data is automatically fetched and included in the alert structure. No additional playbook actions needed. |
Input Example
{"variables":{"scope":{"scopeType":"string","scopeIds":["string"]},"lastUpdatedAt":"string","backfillHours":123,"backfillTimeString":"string","pageSize":100,"maxPages":1000,"cursor":"string","viewType":"ALL","filtersJson":"string","sorts":[{"fieldPath":"string","direction":"string"}],"enableEnrichment":true}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response containing alerts with teds_object and alert_metadata. Each alert node contains: teds_object (TEDS format for "Process as TEDS alert") and alert_metadata (enrichment data: timeline, history, notes, mitigation, AI, indicators). |
data.alerts | object | GraphQL response structure with edges array. Each edge contains a normalized alert in TEDS format. This structure is compatible with workflow conditions and loops that check/iterate over edges. |
data.alerts.edges | array | Array of alert edges. Each edge contains a normalized alert node in TEDS format. The workflow condition checks if edges is not empty, and the loop iterates over edges[].node. Parse Alert ID extracts node.id. |
data.alerts.edges.node | object | Alert with teds_object (TEDS format for schema conversion) and alert_metadata (enrichment data). Ready for "Process as TEDS alert". |
data.alerts.edges.node.id | string | Alert ID for use in Parse Alert ID action |
data.alerts.edges.node.teds_object | object | Complete TEDS-formatted alert ready for "Process as TEDS alert" action. Contains all standard TEDS fields for schema conversion. |
data.alerts.edges.node.alert_metadata | object | Enrichment data automatically fetched for each alert. Contains timeline, history, notes, mitigation actions, AI investigations, and raw indicators. |
data.alerts.edges.cursor | string | Pagination cursor |
data.alerts.edges.__typename | string | Response data |
data.alerts.pageInfo | object | Pagination information |
data.alerts.pageInfo.hasNextPage | boolean | Response data |
data.alerts.pageInfo.endCursor | string | Response data |
data.alerts.pageInfo.hasPreviousPage | boolean | Response data |
data.alerts.pageInfo.startCursor | string | Response data |
data.alerts.totalCount | number | Total number of alerts |
data.total_count | number | Total number of alerts ingested in this run |
data.last_updated_at | string | ISO 8601 timestamp of the most recent alert's updatedAt field. Use this value as lastUpdatedAt in the next run for incremental polling. |
data.pages_processed | number | Number of pages processed in this run |
data.has_more | boolean | Whether there are more alerts to fetch (if max pages limit reached) |
Output Example
{"data":{"alerts":{"edges":[],"pageInfo":{},"totalCount":1},"total_count":1,"last_updated_at":"2025-12-27T09:52:26.907Z","pages_processed":1,"has_more":false}}
Initiate Scan
Execute a full or targeted disk scan on SentinelOne agents to identify potential threats using customizable filters.
Endpoint
- URL: web/api/v2.1/agents/actions/initiate-scan
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
filter | object | Optional | Parameter for Initiate Scan |
filter.uuids | array | Optional | Unique identifier |
Input Example
{"json_body":{"data":{},"filter":{"uuids":["33b3a892-d388-d3e6-6ead-a98acb5d054c"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Nov 2022 20:10:56 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"39073fc2-f1d8-4ac6-880f-2f2c372ff37b","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Tag a SentinelOne Agent
Apply, remove, or override tags on SentinelOne agents by specifying data and filter in the JSON body. Requires Endpoints.manageEndpointTags permission.
Endpoint
- URL: web/api/v2.1/agents/actions/manage-tags
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Filter identifying agents to apply tag operations to. |
filter.ids | array | Optional | Agent IDs to target. |
filter.uuids | array | Optional | Agent UUIDs to target. |
filter.accountIds | array | Optional | Limit to agents in these accounts. |
filter.siteIds | array | Optional | Limit to agents in these sites. |
filter.groupIds | array | Optional | Limit to agents in these groups. |
filter.filteredGroupIds | array | Optional | Filter by dynamic group IDs. |
filter.uuid | string | Optional | Filter by a single agent UUID. |
filter.computerName | string | Optional | Filter by exact computer name. |
filter.computerName__contains | array | Optional | Free-text filter by computer name (min 2 characters). |
filter.computerName__like | string | Optional | SQL-like pattern filter on computer name. |
filter.query | string | Optional | Free-text search across applicable agent attributes. |
filter.domains | array | Optional | Included network domains. |
filter.externalIp__contains | array | Optional | Free-text filter by external IP (min 2 characters). |
filter.externalId__contains | array | Optional | Free-text filter by external ID. |
filter.infected | boolean | Optional | Filter by infection status. |
filter.isActive | boolean | Optional | Filter by whether the agent is active. |
filter.isDecommissioned | boolean | Optional | Filter by decommissioned status. |
filter.isUninstalled | boolean | Optional | Filter by uninstalled status. |
filter.isPendingUninstall | boolean | Optional | Filter by pending uninstall status. |
filter.networkStatuses | array | Optional | Filter by network status (e.g. connected, disconnected). |
filter.operationalStates | array | Optional | Filter by operational states. |
filter.operationalStatesNin | array | Optional | Exclude these operational states. |
filter.osTypes | array | Optional | Filter by OS types (linux, macos, windows, windows_legacy). |
filter.osTypesNin | array | Optional | Exclude these OS types. |
Input Example
{"json_body":{"data":[{"tagId":"225494730938493804","operation":"add"}],"filter":{"ids":["1286438987267469377"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code returned by the API. |
reason | string | HTTP reason phrase (e.g. OK). |
errors | array | API error objects, if any were returned. |
data | object | Response payload containing the number of affected agents. |
data.affected | number | Number of agents affected by the tag operation. |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"errors":[],"data":{"affected":1}}}
Mitigate Threats
Apply a specified mitigation action to targeted threats in SentinelOne using the 'action' and 'filter' parameters for precise threat response.
Endpoint
- URL: /web/api/v2.1/threats/mitigate/{{action}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.action | string | Required | Parameters for the Mitigate Threats action |
filter | object | Optional | Parameter for Mitigate Threats |
filter.k8sPodLabels__contains | array | Optional | Parameter for Mitigate Threats |
filter.updatedAt__gte | string | Optional | Parameter for Mitigate Threats |
filter.awsSubnetIds__contains | array | Optional | Unique identifier |
filter.agentMachineTypes | array | Optional | Type of the resource |
filter.cloudAccount__contains | array | Optional | Parameter for Mitigate Threats |
filter.agentVersions | array | Optional | Parameter for Mitigate Threats |
filter.siteIds | array | Optional | Unique identifier |
filter.classificationSourcesNin | array | Optional | Parameter for Mitigate Threats |
filter.storylines | array | Optional | Parameter for Mitigate Threats |
filter.detectionAgentVersion__contains | array | Optional | Parameter for Mitigate Threats |
filter.createdAt__lt | string | Optional | Parameter for Mitigate Threats |
filter.resolved | boolean | Optional | Parameter for Mitigate Threats |
filter.mitigatedPreemptively | boolean | Optional | Parameter for Mitigate Threats |
filter.detectionEngines | array | Optional | Parameter for Mitigate Threats |
filter.threatDetails__contains | array | Optional | Parameter for Mitigate Threats |
filter.storyline__contains | array | Optional | Parameter for Mitigate Threats |
filter.agentVersionsNin | array | Optional | Parameter for Mitigate Threats |
filter.originatedProcess__contains | array | Optional | Parameter for Mitigate Threats |
filter.tenant | boolean | Optional | Parameter for Mitigate Threats |
filter.cloudProvider | array | Optional | Unique identifier |
filter.pendingActions | boolean | Optional | Parameter for Mitigate Threats |
filter.agentIds | array | Optional | Unique identifier |
filter.detectionAgentDomain__contains | array | Optional | Parameter for Mitigate Threats |
Input Example
{"json_body":{"filter":{"k8sPodLabels__contains":["string"],"updatedAt__gte":"2018-02-27T04:49:26.257525Z","awsSubnetIds__contains":["string"],"agentMachineTypes":["string"],"cloudAccount__contains":["string"],"agentVersions":["2.5.1.1320"],"siteIds":["225494730938493804"],"classificationSourcesNin":["Cloud"],"storylines":["string"],"detectionAgentVersion__contains":["string"],"createdAt__lt":"2018-02-27T04:49:26.257525Z","resolved":true,"mitigatedPreemptively":true,"detectionEngines":["reputation"],"threatDetails__contains":["string"],"storyline__contains":["string"],"agentVersionsNin":["2.5.1.1320"],"originatedProcess__contains":["string"],"tenant":true,"cloudProvider":["string"],"pendingActions":true,"agentIds":["225494730938493804"],"detectionAgentDomain__contains":["string"],"incidentStatusesNin":["unresolved"],"updatedAt__gt":"2018-02-27T04:49:26.257525Z","gcpServiceAccount__contains":["string"],"k8sNodeName__contains":["string"],"classifications":["string"],"ids":["225494730938493804"],"classificationsNin":["string"],"confidenceLevels":["malicious"],"classificationSources":["Cloud"],"osArchs":["32 bit"],"limit":10,"k8sClusterName__contains":["string"],"publisherName__contains":["string"],"k8sControllerLabels__contains":["string"],"externalTicketId__contains":["string"],"cloudInstanceSize__contains":["string"],"cloudInstanceId__contains":["string"],"k8sNamespaceLabels__contains":["string"],"noteExists":true,"k8sNodeLabels__contains":["string"],"uuid__contains":["string"],"updatedAt__lt":"2018-02-27T04:49:26.257525Z","osNames":["string"],"azureResourceGroup__contains":["string"],"confidenceLevelsNin":["malicious"],"createdAt__gt":"2018-02-27T04:49:26.257525Z","enginesNin":["reputation"],"groupIds":["225494730938493804"],"collectionIds":["225494730938493804"],"k8sPodName__contains":["string"],"accountIds":["225494730938493804"],"analystVerdicts":["true_positive"],"k8sControllerName__contains":["string"],"cloudProviderNin":["string"],"mitigationStatusesNin":["not_mitigated"],"osTypes":["linux"],"detectionEnginesNin":["reputation"],"initiatedByNin":["agent_policy"],"k8sNamespaceName__contains":["string"],"cloudImage__contains":["string"],"query":"string","containerImageName__contains":["string"],"osTypesNin":["linux"],"contentHash__contains":["string"],"agentMachineTypesNin":["desktop"],"rebootRequired":true,"commandLineArguments__contains":["string"],"realtimeAgentVersion__contains":["string"],"createdAt__lte":"2018-02-27T04:49:26.257525Z","initiatedByUsername__contains":["string"],"failedActions":true,"containerLabels__contains":["string"],"cloudLocation__contains":["string"],"mitigationStatuses":["not_mitigated"],"createdAt__gte":"2018-02-27T04:49:26.257525Z","awsSecurityGroups__contains":["string"],"agentIsActive":true,"engines":["reputation"],"awsRole__contains":["string"],"updatedAt__lte":"2018-02-27T04:49:26.257525Z","containerName__contains":["string"],"cloudNetwork__contains":["string"],"displayName":"string","filePath__contains":["string"],"osNamesNin":["string"],"analystVerdictsNin":["true_positive"],"incidentStatuses":["unresolved"],"countsFor":"osTypes,machineTypes","externalTicketIds":["string"],"contentHashes":["string"],"initiatedBy":["agent_policy"],"computerName__contains":["string"],"externalTicketExists":true},"data":{}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 11 Sep 2023 08:58:22 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"ca215f22-b23f-4683-a984-d5283635fed4","Access-Control-Allow-Origin":"https://usea1-identity.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Conte...
New Firewall Rule
Create a SentinelOne firewall rule to control network traffic for specified scopes and operating systems using defined JSON body parameters.
Endpoint
- URL: web/api/v2.1/firewall-control
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for New Firewall Rule |
filter.accountIds | array | Optional | Unique identifier |
filter.siteIds | array | Optional | Unique identifier |
filter.tenant | boolean | Optional | Parameter for New Firewall Rule |
filter.groupIds | array | Optional | Unique identifier |
data | object | Optional | Response data |
data.protocol | string | Optional | Response data |
data.application | object | Optional | Response data |
data.application.type | string | Optional | Response data |
data.application.values | array | Optional | Response data |
data.localHost | object | Optional | Response data |
data.localHost.type | string | Optional | Response data |
data.localHost.values | array | Optional | Response data |
data.remoteHost | object | Optional | Response data |
data.remoteHost.type | string | Optional | Response data |
data.remoteHost.values | array | Optional | Response data |
data.osTypes | array | Optional | Response data |
data.action | string | Optional | Response data |
data.localPort | object | Optional | Response data |
data.localPort.type | string | Optional | Response data |
data.localPort.values | array | Optional | Response data |
data.status | string | Optional | Response data |
data.remotePort | object | Optional | Response data |
data.remotePort.type | string | Optional | Response data |
data.remotePort.values | array | Optional | Response data |
Input Example
{"json_body":{"filter":{"accountIds":["225494730938493915"],"siteIds":["1286405255257023125"],"tenant":true,"groupIds":["1286405255265411734"]},"data":{"protocol":"string","application":{"type":"any","values":["libpcap"]},"localHost":{"type":"any","values":["string"]},"remoteHost":{"type":"any","values":["string"]},"osTypes":["windows_legacy"],"action":"Allow","localPort":{"type":"any","values":[80,443]},"status":"Enabled","remotePort":{"type":"any","values":[80,443]},"osType":"windows_legacy","location":{"type":"all","values":[{"name":"office1","id":"225494730938493804"}]},"description":"string","direction":"any","remoteHosts":[{"type":"any","values":["string"]}],"tagIds":["225494730938493804","225494730938493915"],"tag":"string","name":"string"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.protocol | string | Response data |
data.createdAt | string | Response data |
data.location | object | Response data |
data.location.type | string | Response data |
data.location.values | array | Response data |
data.location.values.name | string | Response data |
data.location.values.scope | string | Response data |
data.location.values.id | string | Response data |
data.tagIds | array | Response data |
data.order | number | Response data |
data.name | string | Response data |
data.productId | string | Response data |
data.creatorId | string | Response data |
data.updatedAt | string | Response data |
data.ruleCategory | string | Response data |
data.description | string | Response data |
data.direction | string | Response data |
data.localPort | object | Response data |
data.status | string | Response data |
data.scopeId | string | Response data |
data.id | string | Response data |
data.application | object | Response data |
Output Example
{"status_code":403,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 17:50:40 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Security-Policy":"default-src 'self' ; connect-src...
Ping A Power Query
Initiate a follow-up ping on a SentinelOne Deep Visibility Power Query to check for results using the specified queryId.
Endpoint
- URL: /web/api/v2.1/dv/events/pq-ping
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.queryId | string | Optional | Query ID query param. |
Input Example
{"parameters":{"queryId":"pq280e9119257107b9b6a8f5991f6ecb91"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.columns | array | Response data |
data.columns.name | string | Response data |
data.columns.type | string | Response data |
data.data | array | Response data |
data.data.file_name | string | Response data |
data.data.file | string | Response data |
data.externalId | string | Response data |
data.progress | number | Response data |
data.queryId | string | Response data |
data.recommendations | array | Response data |
data.status | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 22 Apr 2024 09:18:00 GMT","Content-Type":"application/json","Content-Length":"94","Connection":"keep-alive","Access-Control-Allow-Origin":"https://cns.na1.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Security-Policy":"default-src 'self' ; connect-src 'self' *....
Query for Vulnerabilities
Retrieve CVE vulnerability data from SentinelOne, filtered by account, site, detection date, and severity, with pagination support.
Endpoint
- URL: web/api/v2.1/application-management/risks
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.accountIds | string | Optional | Account ID(s) to filter by. |
parameters.analystVerdict | string | Optional | Include Default (not edited), False Positives, or Added CVEs for vulnerabilities. |
parameters.application__contains | string | Optional | Free-text filter by application name and version (supports multiple values). |
parameters.applicationNames | string | Optional | Included application names. |
parameters.applicationVendor__contains | string | Optional | Free-text filter by vendor (supports multiple values). |
parameters.countOnly | boolean | Optional | If true, only total number of items will be returned, without any of the actual objects. |
parameters.cursor | string | Optional | Cursor position returned by the last request. Use to iterate over more than 1000 items. |
parameters.cveId__contains | string | Optional | Free-text filter by CVE id (supports multiple values). |
parameters.daysFromCveDetection | string | Optional | Days from CVE detection, e.g. 12 days or more. |
parameters.detectionDate__between | string | Optional | Date range for CVE detection date (format from_timestamp-to_timestamp, inclusive). |
parameters.detectionDate__gt | string | Optional | CVE detection date after this timestamp. |
parameters.detectionDate__gte | string | Optional | CVE detection date after or at this timestamp. |
parameters.detectionDate__lt | string | Optional | CVE detection date before this timestamp. |
parameters.detectionDate__lte | string | Optional | CVE detection date before or at this timestamp. |
parameters.domain__contains | string | Optional | Free-text filter by domain (supports multiple values). |
parameters.domains | string | Optional | Included network domains. |
parameters.endpointName__contains | string | Optional | Free-text filter by endpoint name (supports multiple values). |
parameters.endpointTypes | string | Optional | Included endpoint types. |
parameters.exploitCodeMaturity | string | Optional | Included exploit code maturity values. Available for Singularity Vulnerability Management SKU. |
parameters.exploitedInTheWild | string | Optional | Included exploited in the wild values. Available for Singularity Vulnerability Management SKU. |
parameters.groupIds | string | Optional | Group ID(s) to filter by. |
parameters.includeRemovals | boolean | Optional | Include also removed CVEs in the results. |
parameters.lastScanResults | string | Optional | Included last scan results. |
parameters.limit | string | Optional | Limit number of returned items (1-1000). |
parameters.mitigationStatus | string | Optional | Filter by application mitigation status. Available for Singularity Vulnerability Management SKU. |
Input Example
{"parameters":{"accountIds":"string","analystVerdict":"string","application__contains":"string","applicationNames":"Example Name","applicationVendor__contains":"string","countOnly":true,"cursor":"string","cveId__contains":"string","daysFromCveDetection":"string","detectionDate__between":"string","detectionDate__gt":"string","detectionDate__gte":"string","detectionDate__lt":"string","detectionDate__lte":"string","domain__contains":"string","domains":"string","endpointName__contains":"Example Name","endpointTypes":"string","exploitCodeMaturity":"string","exploitedInTheWild":"string","groupIds":"string","includeRemovals":true,"lastScanResults":"string","limit":"string","mitigationStatus":"active","osTypes":"string","osVersions":"string","publishedDate__between":"string","publishedDate__gt":"string","publishedDate__gte":"string","publishedDate__lt":"string","publishedDate__lte":"string","remediationLevels":"string","reportConfidence":"string","riskScore__between":"string","riskUpdatedDate__between":"string","riskUpdatedDate__gt":"string","riskUpdatedDate__gte":"string","riskUpdatedDate__lt":"string","riskUpdatedDate__lte":"string","severities":"string","siteIds":"string","skip":"string","skipCount":true,"sortBy":"string","sortOrder":"string","vendors":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code returned by the API. |
reason | string | HTTP reason phrase (e.g. OK). |
data | array | Response data payload. |
data.id | string | Unique identifier. |
data.cveId | string | CVE identifier (e.g. CVE-2024-0001). |
data.severity | string | CVE severity level. |
data.detectionDate | string | Timestamp when the CVE was detected on the endpoint. |
data.publishedDate | string | CVE published date. |
data.status | string | CVE or agent status. |
data.endpointName | string | Name of the affected endpoint. |
data.endpointId | string | ID of the affected endpoint. |
data.endpointType | string | Type of the affected endpoint. |
data.application | string | Application identifier or name. |
data.applicationName | string | Name of the vulnerable application. |
data.applicationVersion | string | Version of the vulnerable application. |
data.applicationVendor | string | Vendor of the vulnerable application. |
data.osType | string | OS type filter β linux, macos, or windows. |
data.baseScore | string | CVSS base score. |
data.riskScore | string | Calculated risk score. |
data.cvssVersion | string | CVSS version used for scoring. |
data.nvdBaseScore | string | NVD CVSS base score. |
data.nvdCvssVersion | string | NVD CVSS version. |
data.mitigationStatus | string | Current mitigation status for the vulnerability. |
data.mitigationStatusReason | string | Reason for the current mitigation status. |
data.mitigationStatusChangedBy | string | User who last changed mitigation status. |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":[{}],"pagination":{"totalItems":580,"nextCursor":"YWdlbnRfaWQ6NTgwMjkzODE="}}}
Reset User Password
Force selected SentinelOne users to reset their password at next login by applying a specified filter in the request body.
Endpoint
- URL: web/api/v2.1/users/login/force-reset-password-on-login
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Filter to identify users who must reset password on next login. |
filter.ids | array | Required | List of user IDs to force password reset on next login. |
Input Example
{"json_body":{"filter":{"ids":["2010000000000000000","2010000000000000001"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data from reset password on next login. |
errors | array | Errors if any. |
Output Example
{"status_code":200,"response_headers":{"Content-Type":"application/json"},"reason":"OK","json_body":{"data":{},"errors":[]}}
Retrieve Script Output
Retrieve the completed RemoteOps script output as JSON using the child task ID and scan object data, without returning a zip file.
Endpoint
- URL: /web/api/v2.1/remote-scripts/fetch-files
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
data.taskIds | array | Optional | Child task ids from get_remote_script_status data[].id. Example β 225494730938493999. |
data.taskId | string | Optional | Single child task id when the console expects a scalar instead of taskIds. |
data.parentTaskId | string | Optional | Parent task id from execute_remote_script when fetching by parent instead of child task ids. |
Input Example
{"json_body":{"data":{"taskIds":["225494730938493999"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.collection_version | string | Response data |
data.collection_timestamp | string | Response data |
data.hostname | string | Response data |
data.os | string | Response data |
data.collecting_user | string | Response data |
data.scan_depth | string | Response data |
data.files_scanned | number | Response data |
data.errors | array | Response data |
data.findings | array | Response data |
data.output | object | Nested scan JSON when the console wraps the payload. |
errors | array | Error message if any |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":{"collection_version":"1.0","collection_timestamp":"2026-09-22T03:10:00Z","hostname":"wkstn-fin-01","os":"windows","collecting_user":"SYSTEM","scan_depth":"standard","files_scanned":42,"errors":[],"findings":[]}}}
Revoke User Tokens
Revoke API tokens for specified SentinelOne users based on filter criteria to prevent further authentication with those tokens.
Endpoint
- URL: web/api/v2.1/private/agents/support-actions/revoke-token
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Filter to identify users whose tokens should be revoked. |
filter.ids | array | Required | List of user IDs for which to revoke API tokens. |
Input Example
{"json_body":{"filter":{"ids":["2010000000000000000","2010000000000000001"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Number of users whose tokens were revoked. |
Output Example
{"status_code":200,"response_headers":{"Content-Type":"application/json"},"reason":"OK","json_body":{"data":{"affected":2}}}
Update Alert Analyst Verdict
Update the analyst's verdict on SentinelOne alerts by specifying data and filter criteria to target relevant alerts.
Endpoint
- URL: /web/api/v2.1/cloud-detection/alerts/analyst-verdict
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Update Alert Analyst Verdict |
filter.containerImageName__contains | string | Optional | Free-text filter by the endpoint container image name (supports multiple values). |
filter.limit | number | Optional | Limit. |
filter.reportedAt__gte | string | Optional | Reported at greater or equal than. |
filter.tenant | boolean | Optional | Indicates a tenant scope request. |
filter.reportedAt__lte | string | Optional | Reported at lesser or equal than. |
filter.sourceProcessName__contains | string | Optional | Free-text filter by source process name. |
filter.incidentStatus | string | Optional | Filter threats by a incident status. |
filter.sourceProcessCommandline__contains | string | Optional | Free-text filter by source commandline. |
filter.createdAt__lte | string | Optional | Created at lesser or equal than. |
filter.k8sNamespaceLabels__contains | string | Optional | Free-text filter by the endpoint Kubernetes namespace labels (supports multiple values). |
filter.k8sPod__contains | string | Optional | Free-text filter by the endpoint Kubernetes pod name (supports multiple values). |
filter.reportedAt__gt | string | Optional | Reported at greater than. |
filter.sourceProcessFileHashSha1__contains | string | Optional | Free-text filter by source SHA1. |
filter.k8sNode__contains | string | Optional | Free-text filter by the endpoint Kubernetes node name (supports multiple values). |
filter.createdAt__gt | string | Optional | Created at greater than. |
filter.origAgentUuid__contains | string | Optional | Free-text filter by agent UUID. |
filter.sourceProcessFileHashMd5__contains | string | Optional | Free-text filter by source MD5 |
filter.query | string | Optional | Full text search for all fields. |
filter.osType | string | Optional | Included OS types. |
filter.containerName__contains | string | Optional | Free-text filter by the endpoint container name (supports multiple values). |
filter.analystVerdict | string | Optional | Filter threats by a analyst verdict. |
filter.createdAt__lt | string | Optional | Created at lesser than. |
filter.origAgentName__contains | string | Optional | Free-text filter by agent name. |
filter.ruleName__contains | string | Optional | Free-text filter by rule name. |
Input Example
{"filter":{"containerImageName__contains":"Example Name","limit":123,"reportedAt__gte":"string","tenant":true,"reportedAt__lte":"string","sourceProcessName__contains":"Example Name","incidentStatus":"active","sourceProcessCommandline__contains":"string","createdAt__lte":"string","k8sNamespaceLabels__contains":"Example Name","k8sPod__contains":"string","reportedAt__gt":"string","sourceProcessFileHashSha1__contains":"string","k8sNode__contains":"string","createdAt__gt":"string","origAgentUuid__contains":"string","sourceProcessFileHashMd5__contains":"string","query":"string","osType":"string","containerName__contains":"Example Name","analystVerdict":"string","createdAt__lt":"string","origAgentName__contains":"Example Name","ruleName__contains":"Example Name","origAgentOsRevision__contains":"string","sourceProcessFilePath__contains":"string","k8sControllerLabels__contains":"string","siteIds":"string","containerLabels__contains":"string","k8sNamespaceName__contains":"Example Name","groupIds":"string","accountIds":"string","machineType":"string","k8sControllerName__contains":"Example Name","severity":"string","k8sCluster__contains":"string","ids":"string","scopes":"string","createdAt__gte":"string","sourceProcessStoryline__contains":"string","origAgentVersion__contains":"string","reportedAt__lt":"string","k8sPodLabels__contains":"string","sourceProcessFileHashSha256__contains":"string"},"data":{"analystVerdict":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"data":{"affected":0}}
Update Alert Incident
Update incident details for a specific alert in SentinelOne using provided data and filter criteria.
Endpoint
- URL: /web/api/v2.1/cloud-detection/alerts/incident
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Update Alert Incident |
filter.containerImageName__contains | array | Optional | Free-text filter by the endpoint container image name (supports multiple values). |
filter.limit | number | Optional | Limit. |
filter.reportedAt__gte | string | Optional | Reported at greater or equal than. |
filter.tenant | boolean | Optional | Indicates a tenant scope request. |
filter.reportedAt__lte | string | Optional | Reported at lesser or equal than. |
filter.sourceProcessName__contains | array | Optional | Free-text filter by source process name. |
filter.incidentStatus | array | Optional | Filter threats by a incident status. |
filter.sourceProcessCommandline__contains | array | Optional | Free-text filter by source commandline. |
filter.createdAt__lte | string | Optional | Created at lesser or equal than. |
filter.k8sNamespaceLabels__contains | array | Optional | Free-text filter by the endpoint Kubernetes namespace labels (supports multiple values). |
filter.k8sPod__contains | array | Optional | Free-text filter by the endpoint Kubernetes pod name (supports multiple values). |
filter.reportedAt__gt | string | Optional | Reported at greater than. |
filter.sourceProcessFileHashSha1__contains | array | Optional | Free-text filter by source sha1. |
filter.k8sNode__contains | array | Optional | Free-text filter by the endpoint Kubernetes node name (supports multiple values). |
filter.createdAt__gt | string | Optional | Created at greater than. |
filter.origAgentUuid__contains | array | Optional | Free-text filter by agent UUID. |
filter.sourceProcessFileHashMd5__contains | array | Optional | Free-text filter by source MD5. |
filter.query | string | Optional | Full text search for all fields. |
filter.osType | array | Optional | Included OS types. |
filter.containerName__contains | array | Optional | Free-text filter by the endpoint container name (supports multiple values). |
filter.analystVerdict | array | Optional | Filter threats by a analyst verdict. |
filter.createdAt__lt | string | Optional | Created at lesser than. |
filter.origAgentName__contains | array | Optional | Free-text filter by agent name. |
filter.ruleName__contains | array | Optional | Free-text filter by rule name |
Input Example
{"filter":{"containerImageName__contains":["string"],"limit":123,"reportedAt__gte":"string","tenant":true,"reportedAt__lte":"string","sourceProcessName__contains":["string"],"incidentStatus":["string"],"sourceProcessCommandline__contains":["string"],"createdAt__lte":"string","k8sNamespaceLabels__contains":["string"],"k8sPod__contains":["string"],"reportedAt__gt":"string","sourceProcessFileHashSha1__contains":["string"],"k8sNode__contains":["string"],"createdAt__gt":"string","origAgentUuid__contains":["string"],"sourceProcessFileHashMd5__contains":["string"],"query":"string","osType":["string"],"containerName__contains":["string"],"analystVerdict":["string"],"createdAt__lt":"string","origAgentName__contains":["string"],"ruleName__contains":["string"],"origAgentOsRevision__contains":["string"],"sourceProcessFilePath__contains":["string"],"k8sControllerLabels__contains":["string"],"siteIds":["string"],"containerLabels__contains":["string"],"k8sNamespaceName__contains":["string"],"groupIds":["string"],"accountIds":["string"],"machineType":["string"],"k8sControllerName__contains":["string"],"severity":["string"],"k8sCluster__contains":["string"],"ids":["string"],"scopes":["string"],"createdAt__gte":"string","sourceProcessStoryline__contains":["string"],"origAgentVersion__contains":["string"],"reportedAt__lt":"string","k8sPodLabels__contains":["string"],"sourceProcessFileHashSha256__contains":["string"]},"data":{"incidentStatus":"active"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Thu, 18 Apr 2024 00:12:38 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"d281729a-04f6-40d4-aeef-5f0add7d40a3","Access-Control-Allow-Origin":"https://cns-us-east-1-prod.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","C...
Update Threat Analyst Verdict
Modify an analyst's verdict on a threat in SentinelOne by applying filter criteria and updating with specified data.
Endpoint
- URL: /web/api/v2.1/threats/analyst-verdict
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Update Threat Analyst Verdict |
filter.k8sPodLabels__contains | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.updatedAt__gte | string | Optional | Parameter for Update Threat Analyst Verdict |
filter.awsSubnetIds__contains | array | Optional | Unique identifier |
filter.agentMachineTypes | array | Optional | Type of the resource |
filter.cloudAccount__contains | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.agentVersions | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.siteIds | array | Optional | Unique identifier |
filter.classificationSourcesNin | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.storylines | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.detectionAgentVersion__contains | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.createdAt__lt | string | Optional | Parameter for Update Threat Analyst Verdict |
filter.resolved | boolean | Optional | Parameter for Update Threat Analyst Verdict |
filter.mitigatedPreemptively | boolean | Optional | Parameter for Update Threat Analyst Verdict |
filter.detectionEngines | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.threatDetails__contains | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.storyline__contains | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.agentVersionsNin | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.originatedProcess__contains | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.tenant | boolean | Optional | Parameter for Update Threat Analyst Verdict |
filter.cloudProvider | array | Optional | Unique identifier |
filter.pendingActions | boolean | Optional | Parameter for Update Threat Analyst Verdict |
filter.agentIds | array | Optional | Unique identifier |
filter.detectionAgentDomain__contains | array | Optional | Parameter for Update Threat Analyst Verdict |
filter.incidentStatusesNin | array | Optional | Unique identifier |
Input Example
{"json_body":{"filter":{"k8sPodLabels__contains":["string"],"updatedAt__gte":"2018-02-27T04:49:26.257525Z","awsSubnetIds__contains":["string"],"agentMachineTypes":["string"],"cloudAccount__contains":["string"],"agentVersions":["2.5.1.1320"],"siteIds":["225494730938493804"],"classificationSourcesNin":["Cloud"],"storylines":["string"],"detectionAgentVersion__contains":["string"],"createdAt__lt":"2018-02-27T04:49:26.257525Z","resolved":true,"mitigatedPreemptively":true,"detectionEngines":["reputation"],"threatDetails__contains":["string"],"storyline__contains":["string"],"agentVersionsNin":["2.5.1.1320"],"originatedProcess__contains":["string"],"tenant":true,"cloudProvider":["string"],"pendingActions":true,"agentIds":["225494730938493804"],"detectionAgentDomain__contains":["string"],"incidentStatusesNin":["unresolved"],"updatedAt__gt":"2018-02-27T04:49:26.257525Z","gcpServiceAccount__contains":["string"],"k8sNodeName__contains":["string"],"classifications":["string"],"ids":["225494730938493804"],"classificationsNin":["string"],"confidenceLevels":["malicious"],"classificationSources":["Cloud"],"osArchs":["32 bit"],"limit":10,"k8sClusterName__contains":["string"],"publisherName__contains":["string"],"k8sControllerLabels__contains":["string"],"externalTicketId__contains":["string"],"cloudInstanceSize__contains":["string"],"cloudInstanceId__contains":["string"],"k8sNamespaceLabels__contains":["string"],"noteExists":true,"k8sNodeLabels__contains":["string"],"uuid__contains":["string"],"updatedAt__lt":"2018-02-27T04:49:26.257525Z","osNames":["string"],"azureResourceGroup__contains":["string"],"confidenceLevelsNin":["malicious"],"createdAt__gt":"2018-02-27T04:49:26.257525Z","enginesNin":["reputation"],"groupIds":["225494730938493804"],"collectionIds":["225494730938493804"],"k8sPodName__contains":["string"],"accountIds":["225494730938493804"],"analystVerdicts":["true_positive"],"k8sControllerName__contains":["string"],"cloudProviderNin":["string"],"mitigationStatusesNin":["not_mitigated"],"osTypes":["linux"],"detectionEnginesNin":["reputation"],"initiatedByNin":["agent_policy"],"k8sNamespaceName__contains":["string"],"cloudImage__contains":["string"],"query":"string","containerImageName__contains":["string"],"osTypesNin":["linux"],"contentHash__contains":["string"],"agentMachineTypesNin":["desktop"],"rebootRequired":true,"commandLineArguments__contains":["string"],"realtimeAgentVersion__contains":["string"],"createdAt__lte":"2018-02-27T04:49:26.257525Z","initiatedByUsername__contains":["string"],"failedActions":true,"containerLabels__contains":["string"],"cloudLocation__contains":["string"],"mitigationStatuses":["not_mitigated"],"createdAt__gte":"2018-02-27T04:49:26.257525Z","awsSecurityGroups__contains":["string"],"agentIsActive":true,"engines":["reputation"],"awsRole__contains":["string"],"updatedAt__lte":"2018-02-27T04:49:26.257525Z","containerName__contains":["string"],"cloudNetwork__contains":["string"],"displayName":"string","filePath__contains":["string"],"osNamesNin":["string"],"analystVerdictsNin":["true_positive"],"incidentStatuses":["unresolved"],"countsFor":"osTypes,machineTypes","externalTicketIds":["string"],"contentHashes":["string"],"initiatedBy":["agent_policy"],"computerName__contains":["string"],"externalTicketExists":true},"data":{"analystVerdict":"undefined"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 08 Sep 2023 06:49:11 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"5d8a267b-7a4c-4666-819e-54f3ae329128","Access-Control-Allow-Origin":"https://usea1-identity.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Conte...
Update Threat External Ticket ID
Change the external ticket ID for a specified threat in SentinelOne using a provided JSON body input.
Endpoint
- URL: web/api/v2.1/threats/external-ticket-id
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Update Threat External Ticket ID |
filter.accountIds | array | Optional | Unique identifier |
filter.osArchs | array | Optional | Parameter for Update Threat External Ticket ID |
filter.agentMachineTypes | array | Optional | Type of the resource |
filter.commandLineArguments__contains | array | Optional | Parameter for Update Threat External Ticket ID |
filter.cloudImage__contains | array | Optional | Parameter for Update Threat External Ticket ID |
filter.limit | number | Optional | Parameter for Update Threat External Ticket ID |
filter.contentHashes | string | Optional | Response content |
filter.tenant | boolean | Optional | Parameter for Update Threat External Ticket ID |
filter.ids | array | Optional | Unique identifier |
filter.createdAt__lte | string | Optional | Parameter for Update Threat External Ticket ID |
filter.noteExists | boolean | Optional | Parameter for Update Threat External Ticket ID |
filter.k8sPodName__contains | array | Optional | Name of the resource |
filter.updatedAt__gte | string | Optional | Parameter for Update Threat External Ticket ID |
filter.updatedAt__lt | string | Optional | Parameter for Update Threat External Ticket ID |
filter.containerImageName__contains | array | Optional | Name of the resource |
filter.classificationSources | array | Optional | Parameter for Update Threat External Ticket ID |
filter.confidenceLevels | array | Optional | Unique identifier |
filter.cloudAccount__contains | array | Optional | Parameter for Update Threat External Ticket ID |
filter.classificationsNin | array | Optional | Parameter for Update Threat External Ticket ID |
filter.k8sControllerLabels__contains | array | Optional | Parameter for Update Threat External Ticket ID |
filter.osTypes | array | Optional | Type of the resource |
filter.osNamesNin | array | Optional | Name of the resource |
filter.realtimeAgentVersion__contains | array | Optional | Parameter for Update Threat External Ticket ID |
filter.awsSecurityGroups__contains | array | Optional | Parameter for Update Threat External Ticket ID |
Input Example
{"json_body":{"filter":{"accountIds":["225494730938493804","225494730938493915"],"osArchs":["32 bit"],"agentMachineTypes":["unknown"],"commandLineArguments__contains":["/usr/sbin/","wget"],"cloudImage__contains":["string"],"limit":0,"contentHashes":"ddd5030a3d029f3845fc1052419829f08f312240","tenant":true,"ids":["225494730938493804","225494730938493915"],"createdAt__lte":"2018-02-27T04:49:26.257525Z","noteExists":true,"k8sPodName__contains":["string"],"updatedAt__gte":"2018-02-27T04:49:26.257525Z","updatedAt__lt":"2018-02-27T04:49:26.257525Z","containerImageName__contains":["string"],"classificationSources":["Cloud"],"confidenceLevels":["malicious"],"cloudAccount__contains":["string"],"classificationsNin":["string"],"k8sControllerLabels__contains":["string"],"osTypes":["windows_legacy"],"osNamesNin":["Windows 10 Pro"],"realtimeAgentVersion__contains":["1.1.1.1","2.2."],"awsSecurityGroups__contains":["string"],"mitigatedPreemptively":true,"siteIds":["225494730938493804","225494730938493915"],"awsRole__contains":["string"],"detectionAgentDomain__contains":["sentinel","sentinelone.com"],"agentIds":["225494730938493804","225494730938493915"],"storylines":["string"],"createdAt__lt":"2018-02-27T04:49:26.257525Z","gcpServiceAccount__contains":["string"],"failedActions":true,"collectionIds":["225494730938493804","225494730938493915"],"pendingActions":true,"query":"string","externalTicketId__contains":["string"],"storyline__contains":["0000C2E97648","0006FC73-77B4-470F-AAC7-"],"initiatedByNin":["agent_policy","dv_command"],"cloudNetwork__contains":["string"],"externalTicketIds":["string"],"cloudProviderNin":["string"],"displayName":"string","countsFor":"osTypes,machineTypes","analystVerdicts":["true_positive","suspicious"],"detectionEnginesNin":["reputation"],"contentHash__contains":["5f09bcff3"],"confidenceLevelsNin":["malicious"],"computerName__contains":["john-office","WIN"],"threatDetails__contains":["malware.exe","virus.exe"],"initiatedBy":["agent_policy","dv_command"],"containerName__contains":["string"],"osTypesNin":["windows_legacy"],"azureResourceGroup__contains":["string"],"detectionAgentVersion__contains":["1.1.1.1","2.2."],"awsSubnetIds__contains":["string"],"cloudProvider":["string"],"agentIsActive":true,"groupIds":["225494730938493804","225494730938493915"],"cloudInstanceId__contains":["string"],"incidentStatuses":["unresolved","in_progress"],"updatedAt__gt":"2018-02-27T04:49:26.257525Z","containerLabels__contains":["string"],"agentVersionsNin":["2.5.1.1320"],"rebootRequired":true,"createdAt__gte":"2018-02-27T04:49:26.257525Z","detectionEngines":["reputation"],"classifications":["string"],"k8sNamespaceLabels__contains":["string"],"filePath__contains":["\\MyUser\\Downloads"],"agentVersions":["2.5.1.1320"],"agentMachineTypesNin":["unknown"],"analystVerdictsNin":["true_positive","suspicious"],"mitigationStatuses":["not_mitigated"],"k8sNodeName__contains":["string"],"k8sControllerName__contains":["string"],"initiatedByUsername__contains":["John","John Doe"],"originatedProcess__contains":["string"],"k8sClusterName__contains":["string"],"k8sPodLabels__contains":["string"],"classificationSourcesNin":["Cloud"],"mitigationStatusesNin":["not_mitigated"],"engines":["reputation"],"k8sNamespaceName__contains":["string"],"uuid__contains":["e92-01928","b055"],"cloudLocation__contains":["string"],"enginesNin":["reputation"],"incidentStatusesNin":["unresolved","in_progress"],"resolved":true,"externalTicketExists":true,"cloudInstanceSize__contains":["string"],"createdAt__gt":"2018-02-27T04:49:26.257525Z","publisherName__contains":["GOOGLE","Apple Inc."],"osNames":["Windows 10 Pro"],"updatedAt__lte":"2018-02-27T04:49:26.257525Z"},"data":{"externalTicketId":"string"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
Output Example
{"status_code":500,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 20:32:59 GMT","Content-Type":"application/json","Content-Length":"111","Connection":"keep-alive","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Security-Policy":"default-src 'self' ; connect-src 'self'...
Update Threat Incident
Update the details of a threat incident in SentinelOne by specifying data and filter criteria to modify relevant incident information.
Endpoint
- URL: /web/api/v2.1/threats/incident
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data | object | Optional | Response data |
data.incidentStatus | string | Required | Incident status to update for the threat. |
data.analystVerdict | string | Optional | The analyst verdict to set for the threat. |
filter | object | Optional | Parameter for Update Threat Incident |
filter.createdAt__lt | string | Optional | Created at lesser than. |
filter.createdAt__gt | string | Optional | Created at greater than. |
filter.updatedAt__gt | string | Optional | Updated at greater than. |
filter.updatedAt__lt | string | Optional | Updated at lesser than. |
filter.ids | array | Optional | List of threat IDs. |
filter.groupIds | array | Optional | List of Group IDs to filter by. |
filter.siteIds | array | Optional | List of Site IDs to filter by. |
filter.accountIds | array | Optional | List of Account IDs to filter by. |
filter.incidentStatuses | array | Optional | Filter threats by a specific incident status. |
filter.classificationSources | array | Optional | Classification sources list. |
filter.classifications | array | Optional | List of threat classifications to search. |
filter.agentIds | array | Optional | List of Agent IDs. |
filter.osTypes | array | Optional | Included OS types. |
filter.enginesNin | array | Optional | Excluded engines. |
filter.osTypesNin | array | Optional | Excluded OS types. |
filter.containerImageName__contains | array | Optional | Free-text filter by the endpoint container image name (supports multiple values). |
filter.k8sNodeName__contains | array | Optional | Free-text filter by the endpoint Kubernetes node name (supports multiple values). |
filter.k8sNamespaceName__contains | array | Optional | Free-text filter by the endpoint Kubernetes namespace name (supports multiple values). |
filter.analystVerdicts | array | Optional | Filter threats by a specific analyst verdict. |
filter.agentIsActive | boolean | Optional | Include Agents currently connected to the Management Console. |
filter.agentMachineTypes | array | Optional | Include Agent machine types. |
Input Example
{"data":{"incidentStatus":"active","analystVerdict":"string"},"filter":{"createdAt__lt":"string","createdAt__gt":"string","updatedAt__gt":"string","updatedAt__lt":"string","ids":["string"],"groupIds":["string"],"siteIds":["string"],"accountIds":["string"],"incidentStatuses":["string"],"classificationSources":["string"],"classifications":["string"],"agentIds":["string"],"osTypes":["string"],"enginesNin":["string"],"osTypesNin":["string"],"containerImageName__contains":["string"],"k8sNodeName__contains":["string"],"k8sNamespaceName__contains":["string"],"analystVerdicts":["string"],"agentIsActive":true,"agentMachineTypes":["string"],"agentMachineTypesNin":["string"],"agentTagsData":"string","agentVersions":["string"],"agentVersionsNin":["string"],"analystVerdictsNin":["string"],"awsRole__contains":["string"],"awsSecurityGroups__contains":["string"],"awsSubnetIds__contains":["string"],"azureResourceGroup__contains":["string"],"classificationsNin":["string"],"classificationSourcesNin":["string"],"cloudAccount__contains":["string"],"cloudImage__contains":["string"],"cloudInstanceId__contains":["string"],"cloudInstanceSize__contains":["string"],"cloudLocation__contains":["string"],"cloudNetwork__contains":["string"],"cloudProvider":["string"],"cloudProviderNin":["string"],"collectionIds":["string"],"commandLineArguments__contains":["string"],"computerName__contains":["string"],"confidenceLevels":["string"],"confidenceLevelsNin":["string"],"containerLabels__contains":["string"],"containerName__contains":["string"],"contentHash__contains":["string"],"contentHashes":["string"],"countsFor":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.affected | number | Response data |
data.details | array | Response data |
data.details.result | string | Response data |
data.details.analystVerdict | string | Response data |
data.details.threatId | string | Response data |
errors | object | Error message if any |
Output Example
{"data":{"affected":0,"details":[{}]},"errors":null}
Update Threat Note
Modify the content of a specific threat note in SentinelOne by specifying the threat ID, note ID, and new note data.
Endpoint
- URL: web/api/v2.1/threats/{{threat_id}}/notes/{{note_id}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.threat_id | string | Required | Parameters for the Update Threat Note action |
path_parameters.note_id | string | Required | Parameters for the Update Threat Note action |
data | object | Optional | Response data |
data.text | string | Required | Response data |
Input Example
{"json_body":{"data":{"text":"this is a text"}},"path_parameters":{"threat_id":"1311010475659095549","note_id":"1553834980127175650"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.createdAt | string | Response data |
data.edited | boolean | Response data |
data.id | string | Response data |
data.text | string | Response data |
data.updatedAt | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Wed, 16 Nov 2022 14:40:53 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","X-RQID":"83d1f963-2f8f-4f59-86dc-29b6bba6c497","Access-Control-Allow-Origin":"https://attivo-us.sentinelone.net","Access-Control-Allow-Credentials":"true","Vary":"Origin","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Se...
Upload Remote Script
Upload a plain-text script to the SentinelOne Script Library and receive a script ID for later execution. Requires script content and appropriate permissions.
Endpoint
- URL: /web/api/v2.1/remote-scripts
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
script_content | string | Required | Script source as plain text (.ps1, .sh, or .py). Required. |
data_body | object | Required | Multipart form fields for the Script Library entry. |
data_body.scriptName | string | Required | Display name in the Script Library. Example β swimlane-scan-credentials-20260907. |
data_body.scriptType | string | Required | RemoteOps script class. Allowed values β artifactCollection, dataCollection, action. Use dataCollection for a read-only hunt. |
data_body.osTypes | array | Required | Target operating systems. Allowed values β windows, linux, macos. |
data_body.scopeLevel | string | Required | Library visibility. Allowed values β site, account, global. |
data_body.scopeId | string | Optional | Site or account ID when scopeLevel is not global. Example β 225494730938493804. |
data_body.scriptDescription | string | Optional | Optional library description shown in the console. |
data_body.inputInstructions | string | Optional | Help text for script arguments when inputRequired is true. |
data_body.inputExample | string | Optional | Example argument string passed as inputParams on execute. |
data_body.inputRequired | boolean | Optional | Whether execute must send inputParams. Defaults to false. |
data_body.scriptRuntimeTimeoutSeconds | integer | Optional | Max runtime on the endpoint. Example β 3600. |
Input Example
{"data_body":{"scriptName":"swimlane-scan-credentials","scriptType":"dataCollection","osTypes":["windows"],"scopeLevel":"account","scopeId":"225494730938493804","scriptDescription":"Credential exposure data-collection script uploaded by Swimlane.","inputRequired":false,"scriptRuntimeTimeoutSeconds":3600}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.id | string | Response data |
data.scriptName | string | Response data |
errors | array | Error message if any |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":{"id":"225494730938493804","scriptName":"swimlane-scan-credentials"}}}
Response Headers
Header | Description | Example |
|---|---|---|
access-control-allow-credentials | HTTP response header: access-control-allow-credentials | true |
access-control-allow-headers | HTTP response header: access-control-allow-headers | X-CSRF, content-type |
access-control-allow-methods | HTTP response header: access-control-allow-methods | GET, HEAD, POST, OPTIONS, PUT, PATCH, DELETE |
Access-Control-Allow-Origin | HTTP response header: Access-Control-Allow-Origin | |
cache-control | Directives for caching mechanisms | no-cache, no-store, max-age=0, must-revalidate,no-store |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
Content-Length | The length of the response body in bytes | 111 |
Content-Security-Policy | HTTP response header: Content-Security-Policy | default-src 'self' ; connect-src 'self' *.pendo.io *.storage.googleapis.com cdn.auth0.com .sentinelone.net wss://.sentinelone.net https://cdnjs.cloudflare.com data: ; script-src 'self' 'unsafe-eval' *.sentinelone.net cdn.pendo.io app.pendo.io data.pendo.io pendo-io-static.storage.googleapis.com *.storage.googleapis.com https://cdnjs.cloudflare.com ; img-src 'self' data: *.pendo.io *.sentinelone.com *.sentinelone.net *.storage.googleapis.com; style-src 'self' 'unsafe-inline' .sentinelone.net app.pendo.io cdn.pendo.io .storage.googleapis.com https://cdnjs.cloudflare.com ; font-src 'self' data: .sentinelone.net; frame-src 'self' blob: https://.sentinelone.net https://.scalyr.com https://receptive.io https://.pendo.io https://pendo-io-extensions.storage.googleapis.com/ https://www.youtube.com/; object-src 'none'; frame-ancestors 'self' app.pendo.io *.sentinelone.net |
content-security-policy-report-only | HTTP response header: content-security-policy-report-only | default-src 'self' ; connect-src 'self' *.sentinelone.net *.pendo.io *.intercom.io *.intercomcdn.com *.scalyr.com *.storage.googleapis.com sentry.io *.sentry.io .google-analytics.com .gstatic.com unpkg.com cdn.auth0.com wss://.sentinelone.net wss://.intercom.io https://www.googletagmanager.com https://cdnjs.cloudflare.com https://dm64t97qsxvuz.cloudfront.net data: ; script-src 'self' blob: *.sentinelone.net *.pendo.io *.intercom.io *.intercomcdn.com *.storage.googleapis.com https://www.google-analytics.com https://www.googletagmanager.com https://unpkg.com https://cdnjs.cloudflare.com https://dm64t97qsxvuz.cloudfront.net ; img-src 'self' blob: *.sentinelone.net *.sentinelone.com dm64t97qsxvuz.cloudfront.net data: https://www.google-analytics.com *.pendo.io *.intercom.io *.intercomcdn.com *.intercomassets.com *.scalyr.com *.storage.googleapis.com ; style-src 'self' 'unsafe-inline' *.sentinelone.net *.pendo.io *.intercom.io *.intercomcdn.com .storage.googleapis.com https://cdnjs.cloudflare.com https://dm64t97qsxvuz.cloudfront.net ; font-src 'self' data: .sentinelone.net fonts.intercomcdn.com https://cdn.auth0.com https://dm64t97qsxvuz.cloudfront.net ; manifest-src 'self' https://dm64t97qsxvuz.cloudfront.net ; frame-src 'self' blob: https://receptive.io https://.pendo.io https://pendo-io-extensions.storage.googleapis.com/ https://.youtube.com *.sentinelone.net *.scalyr.com; frame-ancestors 'self' app.pendo.io *.sentinelone.net; object-src 'none' ; worker-src 'self' blob: ; report-to csp-violation-warning ; |
content-type | The media type of the resource | application/json |
cross-origin-opener-policy | HTTP response header: cross-origin-opener-policy | same-origin |
Date | The date and time at which the message was originated | Mon, 03 Jul 2023 03:42:11 GMT |
expires | The date/time after which the response is considered stale | 0,-1 |
Pragma | HTTP response header: Pragma | no-cache |
reporting-endpoints | HTTP response header: reporting-endpoints | csp-violation-warning="https://usea1-partners.sentinelone.net/web/api/v2.1/private/report-csp-violation/warning", csp-violation-blocked="https://usea1-partners.sentinelone.net/web/api/v2.1/private/report-csp-violation/blocked" |
Server | Information about the software used by the origin server | nginx |
Set-Cookie | HTTP response header: Set-Cookie | ο»Ώ |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000; includeSubDomains |
transfer-encoding | HTTP response header: transfer-encoding | chunked |
Vary | HTTP response header: Vary | Origin |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
x-envoy-upstream-service-time | HTTP response header: x-envoy-upstream-service-time | 54 |
x-frame-options | HTTP response header: x-frame-options | DENY, SAMEORIGIN, SAMEORIGIN |
X-RQID | HTTP response header: X-RQID | 19f65f98-24e9-42e2-b9bc-d1c075019219 |
x-xss-protection | HTTP response header: x-xss-protection | 0 |