Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FR] Add SentinelOne XDR support #150

Open
2 of 10 tasks
xC0uNt3r7hr34t opened this issue Sep 8, 2023 · 0 comments
Open
2 of 10 tasks

[FR] Add SentinelOne XDR support #150

xC0uNt3r7hr34t opened this issue Sep 8, 2023 · 0 comments
Labels

Comments

@xC0uNt3r7hr34t
Copy link
Contributor

Which category is the feature part of?

  • Definition File
  • Code/Logic Feature
  • Other (please explain)

Which product is the feature part of?

  • All Products
  • Carbon Black Response
  • Carbon Black Threat Hunter
  • Defender for Endpoints
  • SentinelOne
  • Cortex
  • Other

Use Cases

  • Query and fetch results from SentinelOne XDR
  • Query and fetch results from SentinelOne Powerqueries

Proposal

Support to query SentinelOne's newest XDR platform is needed. This new platform uses a different URL and API tokens. It might make sense to integrate a new product for S1 XDR due to the major changes. However, much of the code and query language does overlap with the existing PQ code, but uses a completely different API. This new XDR platform supports both powerqueries and a similar XDR query language.

Additional Context

In depth documentation is available for anyone with access to a SentinelOne console or the SentinelOne support site.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant