Connect your own SentinelOne Singularity tenant to manage Agents (isolate/reconnect, scan), Threats (mitigate: kill/quarantine/remediate/rollback), Exclusions, Sites/Groups, and Deep Visibility thr...
What this app can do
16 tools registered
Connect SentineloneFree
Connect your own SentinelOne Singularity tenant (Management Console URL + API Token), verifying the credentials with a real call before saving.
List ConnectionsFree
List the connected SentinelOne tenants.
Disconnect SentineloneFree
Disconnect a SentinelOne tenant: deletes the saved console URL/API token. Nothing in SentinelOne itself is changed.
List Threats8 tok
List SentinelOne threats on the connected tenant, optionally filtered to resolved/unresolved only.
Get Threat8 tok
Read one SentinelOne threat in full by id.
Mitigate Threat16 tok
Apply a mitigation action to a SentinelOne threat: kill, quarantine, remediate, rollback-remediation, or un-quarantine. rollback-remediation is DESTRUCTIVE and irreversible -- it restores the affected filesystem to its state before infection.
List Agents8 tok
List agents (endpoints) enrolled in the connected SentinelOne tenant.
Isolate Agent16 tok
Isolate a SentinelOne agent from the network (network quarantine). The agent stays protected but loses almost all network access -- confirm the target host before running.
Reconnect Agent16 tok
Reconnect a previously isolated SentinelOne agent back to the network.
Initiate Scan20 tok
Trigger an on-demand full disk scan on a SentinelOne agent.
List Exclusions8 tok
List Exclusions (allowlisted hashes/paths/certificates) configured on the connected SentinelOne tenant.
Create Exclusion16 tok
Create a new Exclusion (allowlist entry) on the connected SentinelOne tenant -- e.g. a known-good file hash or path.
Delete Exclusion16 tok
Permanently delete an Exclusion from the connected SentinelOne tenant. Cannot be undone.
Run Deep Visibility Query20 tok
Start a Deep Visibility query (SentinelOne's fleet-wide threat hunting engine) against the connected tenant's telemetry. Returns a query_id -- fetch results with get_deep_visibility_results once it finishes running.
Get Deep Visibility Results20 tok
Read the results of a previously started Deep Visibility query by its query_id.
Audit Sentinelone Tenant40 tok
Build one aggregated health report across the connected SentinelOne tenant: active (unresolved) threats, infected agents, and inactive agents.