Integrations
SentinelOne
Automatically respond to all S1 detections
To integrate SentinelOne you will need 2 pieces of information, the URL and the API Key of your SentinelOne account.
URL
SentinelOne uses different subdomains based on your region and who you purchased your licenses from. To get this value, log in to S1 and copy the URL from your address bar. It should look like https://usea1-011.sentinelone.net/
. Using console[.]sentinelone[.]net
is not a valid value.
API Key
To create an API Key you’ll need to create a service user.
- Settings > Users > Actions
- Service Users > Actions > Create New Service User
- You may name it anything you’d like, we suggest ‘Wirespeed’
- Select a role with the following permissions:
- Endpoints
- Reconnect to Network
- Disconnect from Network
- View
- Endpoint Threats
- View
- Update Incident Status
- Update Analyst Verdict
- Endpoints
- Set the expiration to a value you feel comfortable with, however we suggest 1 year. When the token expires you will receive an email notification from us saying the integration is experiencing errors. However, we suggest setting a calendar reminder to update the token before it expires. In an upcoming release we will automatically notify you ahead of time.