Endpoints derived from the SentinelOne API v2.1. Script-based (urllib, INTEGRATION_SECRETS/INPUTS contract) to express S1's nested filter bodies. Config: console url + api_token (ApiToken header). Commands: - enrich: get_threats, list_agents, get_agent, get_hash_verdict - respond: isolate_agent (disconnect), reconnect_agent (connect), mitigate_threat (kill/quarantine/remediate/rollback), initiate_scan, write_threat_note
- integrations/virustotal: VirusTotal v3 (request-based: IP & domain reports) - templates/: fully-commented manifest + script-command example - README: discovery rules, manifest schema, how to publish and wire into Riposte