M ManySignal
MS
S1
Integration

Sentinelone Integration

SentinelOne verdicts and telemetry in your unified alert timeline.

What this integration does

SentinelOne meets agentic SOC

SentinelOne Singularity provides AI-powered endpoint detection and autonomous threat response. ManySignal ingests SentinelOne alerts, threats, and Deep Visibility telemetry, enriches events with entity graph context, and gives analysts a correlated view across endpoint, identity, and cloud — without switching consoles.

Alert and threat ingestion via SentinelOne REST API

Deep Visibility EDR telemetry for process, network, and file events

Storyline™ correlation ID mapping for attack chain reconstruction

Data collected

  • SentinelOne threats and alerts
  • Deep Visibility process, network, and file events
  • Agent heartbeat and version telemetry
  • Threat intelligence matches

Actions supported

  • Isolate endpoint from network
  • Kill malicious process
  • Quarantine and remove detected threat
  • Submit custom IOC to SentinelOne threat intelligence
  • Reconnect isolated endpoint after analyst approval

Getting started

Set up in minutes

  1. 1

    Generate a SentinelOne API token

  2. 2

    Connect in ManySignal

  3. 3

    Enable Deep Visibility (optional)

  4. 4

    Map sites to ManySignal environments

Sentinelone Integration: frequently asked questions

Is Deep Visibility required?

No. ManySignal works with SentinelOne alerts and threats without Deep Visibility. Deep Visibility adds process-level telemetry for richer attack chain reconstruction.

Can ManySignal auto-isolate endpoints?

Yes, with Analyst role permissions. Auto-isolation can be scoped to specific endpoint groups or severity thresholds in ManySignal response policies.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.